| Control | Procedures | Type | Automation | Frequency | Owner | Frameworks | Latest test |
|---|---|---|---|---|---|---|---|
Quarterly privileged access reviewKey Privileged accounts are reviewed and recertified quarterly. | CDA 3 · COE 4 | detective | semi automated | quarterly | Identity Engineering | IAM-08IAM-10 | FAIL · 2026-03-31 |
MFA enforcement for remote accessKey All remote and privileged sessions require multi-factor authentication. | CDA 2 · COE 3 | preventive | automated | continuous | Information Security | IAM-14 | PASS · 2026-02-15 |
Joiner-mover-leaver deprovisioningKey Access is removed within 24 hours of termination or transfer. | CDA 3 · COE 3 | preventive | semi automated | continuous | Identity Engineering | IAM-06IAM-07 | PARTIAL · 2026-01-20 |
Payments above threshold require independent second approval. | CDA 2 · COE 3 | preventive | automated | continuous | Finance Operations | IAM-04IAM-16 | PASS · 2026-04-10 |
Daily payment reconciliationKey Payment runs are reconciled to settlement records daily. | CDA 2 · COE 3 | detective | semi automated | daily | Finance Operations | DSP-23LOG-11 | PARTIAL · 2026-05-05 |
Non-standard wire instructions are verified via independent callback. | CDA 2 · COE 3 | preventive | manual | continuous | Treasury Operations | Unmapped | PASS · 2026-03-18 |
All outbound payments are screened against current sanctions lists. | — | preventive | automated | continuous | Financial Crimes Compliance | A&A-04 | PASS · 2026-04-22 |
GenAI usage policy attestation Staff attest to acceptable-use policy before AI assistant access. | — | preventive | semi automated | annual | Digital Strategy | HRS-15GRC-09 | PARTIAL · 2026-02-28 |
AI output human review gateKey AI-generated content requires human review before customer or record use. | CDA 3 · COE 3 | preventive | manual | continuous | Digital Strategy | GRC-15LOG-15 | FAIL · 2026-04-30 |
Critical vendor SOC reports are reviewed annually with exception follow-up. | CDA 2 · COE 3 | detective | manual | annual | Procurement & TPRM | STA-06STA-12 | PARTIAL · 2025-12-15 |
Critical vendor SLAs are monitored via quarterly scorecards. | — | detective | semi automated | quarterly | Procurement & TPRM | STA-13STA-14 | PASS · 2026-04-05 |
Change advisory board approvalKey Production changes to critical systems require CAB approval. | CDA 2 · COE 3 | preventive | semi automated | continuous | Core Systems Engineering | CCC-01CCC-04 | PASS · 2026-03-25 |
Emergency changes receive retrospective approval within 5 days. | CDA 2 · COE 3 | detective | manual | weekly | Core Systems Engineering | CCC-08 | PARTIAL · 2026-03-25 |
Critical vulnerabilities are patched within 14 days of disclosure. | CDA 2 · COE 3 | corrective | semi automated | continuous | Information Security | TVM-03TVM-08 | FAIL · 2026-05-10 |
External attack surface scanning Internet-facing assets are scanned weekly for exposure. | — | detective | automated | weekly | Information Security | I&S-09TVM-08 | PASS · 2026-05-01 |
Cloud configuration guardrailsKey Policy-as-code blocks non-compliant cloud resource deployment. | CDA 2 · COE 3 | preventive | automated | continuous | Cloud Platform Team | CCC-06CCC-07 | PARTIAL · 2026-04-15 |
New cloud workloads pass architecture and security review before go-live. | CDA 2 · COE 3 | preventive | manual | continuous | Cloud Platform Team | I&S-07 | FAIL · 2026-02-20 |
Branch cash count and dual custodyKey Branch cash is dual-custodied and counted per schedule. | — | preventive | manual | daily | Retail Banking | Unmapped | PASS · 2026-04-08 |
Compensation and bank detail changes require independent approval. | — | preventive | semi automated | continuous | Human Resources | IAM-04 | PASS · 2026-01-30 |
Mobile app penetration testingKey Mobile channel undergoes annual independent penetration testing. | CDA 2 · COE 3 | detective | manual | annual | Digital Channels | TVM-06AIS-05 | PARTIAL · 2025-10-20 |
Device binding and session limitsKey Mobile sessions are bound to registered devices with timeout enforcement. | CDA 2 · COE 3 | preventive | automated | continuous | Digital Channels | IAM-14UEM-05 | PARTIAL · 2026-03-05 |
Fraud model performance monitoringKey Model capture rate and false positives are monitored monthly against thresholds. | — | detective | semi automated | monthly | Fraud Strategy | MDS-10 | PASS · 2026-05-31 |
Model changes are independently validated before production release. | — | preventive | manual | continuous | Model Risk Management | MDS-05CCC-02 | PASS · 2026-01-15 |
Access to customer data domains is certified semi-annually. | CDA 2 · COE 3 | detective | semi automated | quarterly | Chief Data Office | IAM-08IAM-17 | FAIL · 2026-02-28 |
Critical data elements are monitored against quality thresholds. | — | detective | automated | daily | Chief Data Office | DSP-23 | PASS · 2026-05-15 |
Marketing data use is validated against current consent records. | CDA 2 · COE 3 | preventive | semi automated | monthly | Chief Data Office | DSP-12DSP-08 | FAIL · 2026-04-30 |
Regulatory report certificationKey Reports are certified by preparers and reviewers before submission. | — | preventive | manual | quarterly | Finance Controllership | A&A-04 | PASS · 2026-04-12 |
Report data lineage documentation Regulatory report line items trace to authoritative sources. | CDA 2 · COE 3 | preventive | manual | annual | Finance Controllership | DSP-05DSP-20 | PARTIAL · 2025-12-01 |
HRIS role assignments are reviewed semi-annually. | CDA 2 · COE 3 | detective | semi automated | quarterly | HR Technology | IAM-08 | PASS · 2026-01-25 |
Liquidity forecasts are backtested against actuals monthly. | — | detective | semi automated | monthly | Corporate Treasury | Unmapped | PASS · 2026-05-31 |
Outbound sharing of classified data is blocked or quarantined. | CDA 2 · COE 3 | preventive | automated | continuous | Workplace Technology | UEM-11DSP-17 | PARTIAL · 2026-03-20 |
External sharing recertification External collaboration links are recertified quarterly. | — | detective | semi automated | quarterly | Workplace Technology | DSP-10 | PASS · 2026-04-18 |
Application data validation rules Loan applications enforce completeness and format validation at capture. | — | preventive | automated | continuous | Lending Technology | AIS-08 | PASS · 2026-02-10 |
AML scenario coverage reviewKey Monitoring scenarios are assessed annually against products and typologies. | CDA 2 · COE 3 | detective | manual | annual | Financial Crimes Compliance | A&A-04 | PARTIAL · 2025-11-30 |
Closed AML alerts are sampled monthly for disposition quality. | CDA 2 · COE 3 | detective | manual | monthly | Financial Crimes Compliance | SEF-06 | PASS · 2026-05-31 |
MSSP log source coverage reviewKey Critical log sources feeding the MSSP are verified quarterly. | CDA 2 · COE 3 | detective | semi automated | quarterly | Information Security | LOG-07LOG-03 | FAIL · 2026-03-31 |
Incident response tabletop exercises Cross-functional incident response is exercised twice yearly. | — | detective | manual | quarterly | Information Security | SEF-04 | PASS · 2026-04-25 |
Warehouse loads reconcile record counts and control totals to source. | — | detective | automated | daily | Data Platform Engineering | DSP-23 | PASS · 2026-05-20 |
Caller identity verification scriptKey Contact center verifies caller identity via layered challenge questions. | CDA 2 · COE 3 | preventive | manual | continuous | Customer Experience | IAM-14 | PARTIAL · 2026-02-14 |
Credit model fairness testingKey Underwriting model outcomes are tested for disparate impact before release. | CDA 2 · COE 3 | detective | semi automated | quarterly | Model Risk Management | GRC-11 | FAIL · 2026-03-15 |
Records disposal certification Expired records are disposed and certified per retention schedule. | CDA 2 · COE 3 | corrective | manual | quarterly | Legal & Compliance | DSP-02DSP-16 | FAIL · 2026-01-31 |
ATM cash positions are balanced and settled daily. | CDA 2 · COE 3 | detective | semi automated | daily | Channel Operations | Unmapped | PASS · 2026-05-28 |
Critical system backups are restore-tested quarterly. | CDA 2 · COE 3 | detective | semi automated | quarterly | Infrastructure Services | BCR-08 | PARTIAL · 2026-02-28 |
Data center environmental monitoring Facility power, cooling, and access are continuously monitored with alerts. | — | detective | automated | continuous | Infrastructure Services | DCS-13DCS-14 | PASS · 2026-05-15 |
Identity verification for onboardingKey Digital onboarding applies document and liveness verification to applicants. | CDA 2 · COE 3 | preventive | automated | continuous | Digital Channels | IAM-13IAM-14 | PARTIAL · 2026-04-20 |
Automated KYC decisions are sampled weekly for accuracy. | — | detective | manual | weekly | Financial Crimes Compliance | A&A-04 | PASS · 2026-05-22 |
External APIs enforce OAuth token validation and rate limiting. | — | preventive | automated | continuous | Digital Channels | AIS-10IAM-16 | PASS · 2026-03-10 |
Fee configuration change review Product fee changes are tested and approved before deployment. | CDA 2 · COE 3 | preventive | manual | continuous | Retail Banking | Unmapped | PARTIAL · 2026-04-02 |
Critical spreadsheets are inventoried with input and formula controls. | CDA 2 · COE 3 | detective | manual | annual | Finance Controllership | Unmapped | FAIL · 2025-10-31 |
Secure-area badge access is reviewed quarterly. | CDA 2 · COE 3 | detective | semi automated | quarterly | Corporate Services | DCS-07DCS-09 | PASS · 2026-04-15 |