ENTERPRISE register
3 scenario(s)
| Risk | Theme | Likelihood | Impact | Inherent | Residual | Remediation | Linked entities |
|---|---|---|---|---|---|---|---|
Customer data breach Unauthorized access to customer PII results in regulatory penalties and reputational damage. | Data Protection | 3/5 | 5/5 | 15/25 | 10/25 | In Remediation | 3 |
Change management failure Unauthorized or poorly tested changes cause production incidents on critical platforms. | Technology Lifecycle | 3/5 | 4/5 | 12/25 | 8/25 | In Remediation | 2 |
Facility physical security lapse Unauthorized physical access to secure areas compromises equipment or data. | Physical Operations | 2/5 | 3/5 | 6/25 | 4/25 | Risk Accepted | 2 |
IT register
16 scenario(s)
| Risk | Theme | Likelihood | Impact | Inherent | Residual | Remediation | Linked entities |
|---|---|---|---|---|---|---|---|
Privileged access misuse Excessive or orphaned privileged accounts enable unauthorized changes to critical systems. | Identity & Access | 4/5 | 5/5 | 20/25 | 12/25 | In Remediation | 1 |
Cloud misconfiguration exposure Misconfigured cloud storage or network rules expose internal data to the internet. | Cloud Security | 4/5 | 4/5 | 16/25 | 12/25 | In Remediation | 1 |
Mobile channel account takeover Weak device binding or session controls allow account takeover in the mobile channel. |
OPS register
13 scenario(s)
| Risk | Theme | Likelihood | Impact | Inherent | Residual | Remediation | Linked entities |
|---|---|---|---|---|---|---|---|
Payment processing error Manual intervention in payment runs introduces duplicate or misdirected settlements. | Transaction Integrity | 4/5 | 4/5 | 16/25 | 9/25 | In Remediation | 1 |
Wire fraud via social engineering Fraudulent wire instructions bypass callback verification through staff social engineering. | Fraud | 3/5 | 5/5 | 15/25 | 8/25 | Remediated | 1 |
AML monitoring coverage gap Monitoring scenarios fail to cover new products or channels, missing suspicious activity. |
INTEGRATED register
7 scenario(s)
| Risk | Theme | Likelihood | Impact | Inherent | Residual | Remediation | Linked entities |
|---|---|---|---|---|---|---|---|
Critical vendor failure A critical outsourced servicer fails operationally, interrupting customer-facing obligations. | Third Party | 3/5 | 4/5 | 12/25 | 8/25 | In Remediation | 3 |
End-user computing sprawl Critical calculations live in unmanaged spreadsheets outside system controls. | Data Governance | 4/5 | 3/5 | 12/25 | 9/25 | Open | 2 |
Vendor concentration risk Multiple critical services depend on a single vendor, amplifying failure impact. |
ADVISORY register
6 scenario(s)
| Risk | Theme | Likelihood | Impact | Inherent | Residual | Remediation | Linked entities |
|---|---|---|---|---|---|---|---|
Ungoverned generative AI output GenAI assistant produces inaccurate policy guidance that staff act upon without review. | AI Governance | 4/5 | 3/5 | 12/25 | 10/25 | Open | 1 |
Credit model fairness exposure Automated underwriting produces disparate outcomes without adequate fairness testing. | Model Risk | 3/5 | 4/5 | 12/25 | 10/25 | Open | 2 |
AI copilot data leakage Staff paste confidential data into AI tools that retain or expose the content. |