{
  "spec": "cabier.assurance-interchange/1",
  "generated_at": "2026-08-30T21:26:31.444Z",
  "licence": "Read-only reference. Attribution required. No warranty of regulatory sufficiency.",
  "scope": {
    "published": "Domain spine, tested control core, rail register.",
    "withheld": "Effectiveness grading, sample-size derivation, scoring weights, gated control set and client evidence."
  },
  "counts": {
    "domains": 40,
    "controls": 141,
    "rails": 14
  },
  "domains": [
    {
      "code": "C01",
      "name": "Governance and accountability",
      "intent": "A named executive owns each material obligation, and the board sees the position with evidence behind it.",
      "frameworks": [
        "SMCR",
        "DORA",
        "OSFI E-21",
        "SR 11-7",
        "ISO 42001"
      ],
      "strictest": "SMCR — individual accountability is personal and enforceable, not delegable to a committee.",
      "governs": "Legal entity",
      "layer": "Governance"
    },
    {
      "code": "C02",
      "name": "Regulatory obligation management",
      "intent": "Every applicable obligation is identified, versioned and mapped to the control that answers it.",
      "frameworks": [
        "DORA",
        "MiCA",
        "NIS2",
        "23 NYCRR 500",
        "OSFI B-10"
      ],
      "strictest": "DORA — obligations are examined against a register, not against a policy statement.",
      "governs": "Obligation",
      "layer": "Governance"
    },
    {
      "code": "C03",
      "name": "Policy lifecycle",
      "intent": "Policies are approved, versioned, attested and traceable to the obligations they discharge.",
      "frameworks": [
        "ISO 27001",
        "DORA",
        "NIST CSF"
      ],
      "strictest": "ISO 27001 — documented approval and review cadence are audited directly.",
      "governs": "Policy",
      "layer": "Governance"
    },
    {
      "code": "C04",
      "name": "Risk and control self-assessment",
      "intent": "Risks are assessed against operating controls, with challenge from the second line recorded.",
      "frameworks": [
        "Basel III",
        "OSFI E-21",
        "COSO"
      ],
      "strictest": "OSFI E-21 — assessment must connect to operational resilience outcomes, not risk registers alone.",
      "governs": "Risk",
      "layer": "Operational"
    },
    {
      "code": "C05",
      "name": "Reconciliation and financial integrity",
      "intent": "Ledgers, settlement records and reported figures reconcile, with breaks aged and escalated.",
      "frameworks": [
        "Basel III",
        "SOX",
        "BCBS 239"
      ],
      "strictest": "SOX — accuracy of the reported figure is personally certified.",
      "governs": "Data",
      "layer": "Financial"
    },
    {
      "code": "C06",
      "name": "IT general controls",
      "intent": "Access, change and operations controls over in-scope systems operate and are evidenced.",
      "frameworks": [
        "ISO 27001",
        "SOC 2",
        "NIST CSF",
        "SOX"
      ],
      "strictest": "SOC 2 — operating effectiveness is tested over a period, not at a point.",
      "governs": "Application",
      "layer": "Technology"
    },
    {
      "code": "C07",
      "name": "Cyber security",
      "intent": "Threats are identified, protected against, detected, responded to and recovered from on a stated cadence.",
      "frameworks": [
        "NIST CSF",
        "NIS2",
        "DORA",
        "23 NYCRR 500",
        "ISO 27001"
      ],
      "strictest": "23 NYCRR 500 — annual certification by a named officer with defined remediation windows.",
      "governs": "Application",
      "layer": "Technology"
    },
    {
      "code": "C08",
      "name": "Data privacy and protection",
      "intent": "Personal data is lawfully processed, minimised, and its cross-border movement is governed.",
      "frameworks": [
        "GDPR",
        "APPI",
        "PIPEDA",
        "CCPA"
      ],
      "strictest": "GDPR — lawful basis and transfer mechanism must both be demonstrable.",
      "governs": "Data",
      "layer": "Operational"
    },
    {
      "code": "C09",
      "name": "Financial crime and sanctions",
      "intent": "Screening, monitoring and investigation are effective, and effectiveness is tested rather than counted.",
      "frameworks": [
        "FATF",
        "6AMLD",
        "BSA",
        "MiCA"
      ],
      "strictest": "BSA — enforcement turns on programme effectiveness, not coverage statistics.",
      "governs": "Process",
      "layer": "Conduct"
    },
    {
      "code": "C10",
      "name": "Conduct and market integrity",
      "intent": "Conduct risk is surveilled, escalated and remediated with a defensible audit trail.",
      "frameworks": [
        "MAR",
        "FCA COCON",
        "MiFID II"
      ],
      "strictest": "MAR — surveillance gaps are treated as breaches in their own right.",
      "governs": "Process",
      "layer": "Conduct"
    },
    {
      "code": "C11",
      "name": "Third-party and outsourcing risk",
      "intent": "Providers are assessed, contracted, monitored and exitable, with concentration understood.",
      "frameworks": [
        "DORA",
        "OSFI B-10",
        "EBA Outsourcing",
        "NIS2"
      ],
      "strictest": "DORA — critical providers require a tested exit plan, not a documented intention.",
      "governs": "Third party",
      "layer": "Operational"
    },
    {
      "code": "C12",
      "name": "Operational resilience",
      "intent": "Important business services carry impact tolerances proven under severe but plausible stress.",
      "frameworks": [
        "DORA",
        "OSFI E-21",
        "FCA OpRes",
        "Basel III"
      ],
      "strictest": "FCA OpRes — tolerances must be evidenced as remaining within limits during testing.",
      "governs": "Business service",
      "layer": "Operational"
    },
    {
      "code": "C13",
      "name": "AI governance",
      "intent": "AI systems are classified, approved, bounded by human authority and logged for supervisory review.",
      "frameworks": [
        "EU AI Act",
        "ISO 42001",
        "NIST AI RMF",
        "Colorado SB 205"
      ],
      "strictest": "EU AI Act — high-risk classification triggers obligations that cannot be met retrospectively.",
      "governs": "AI model",
      "layer": "Technology"
    },
    {
      "code": "C14",
      "name": "Model risk management",
      "intent": "Models are inventoried, independently validated, monitored for drift and retired deliberately.",
      "frameworks": [
        "SR 11-7",
        "OSFI E-23",
        "EU AI Act",
        "PRA SS1/23"
      ],
      "strictest": "SR 11-7 — independent validation must be genuinely independent of the developer.",
      "governs": "AI model",
      "layer": "Technology"
    },
    {
      "code": "C15",
      "name": "Data lineage and reporting integrity",
      "intent": "Every reported figure traces to a golden source through recorded transformation.",
      "frameworks": [
        "BCBS 239",
        "FRB SR 15-18",
        "Solvency II"
      ],
      "strictest": "BCBS 239 — lineage must be demonstrable end to end, including manual adjustments.",
      "governs": "Data",
      "layer": "Financial"
    },
    {
      "code": "C16",
      "name": "Payments and transaction assurance",
      "intent": "Payment initiation, routing and settlement are controlled, monitored and recoverable.",
      "frameworks": [
        "PSD2",
        "CPMI-IOSCO",
        "Reg E"
      ],
      "strictest": "CPMI-IOSCO — recovery expectations are measured against market deadlines.",
      "governs": "Application",
      "layer": "Financial"
    },
    {
      "code": "C17",
      "name": "Settlement and market infrastructure",
      "intent": "Settlement obligations are met on time, and failure paths are governed rather than discovered.",
      "frameworks": [
        "CSDR",
        "CPMI-IOSCO",
        "T+1 rules"
      ],
      "strictest": "CSDR — settlement discipline penalties attach automatically to failure.",
      "governs": "Business service",
      "layer": "Financial"
    },
    {
      "code": "C18",
      "name": "Tokenisation and digital asset control",
      "intent": "Issuance, custody, reserve integrity and redemption under stress are all provable.",
      "frameworks": [
        "MiCA",
        "GENIUS Act",
        "MAS DTSP",
        "JFSA"
      ],
      "strictest": "MiCA — reserve composition and redemption rights are attested, not asserted.",
      "governs": "Business service",
      "layer": "Financial"
    },
    {
      "code": "C19",
      "name": "Capital and liquidity control",
      "intent": "Capital and liquidity positions are computed from controlled inputs and can be reproduced.",
      "frameworks": [
        "Basel III",
        "Basel 3.1",
        "LCR",
        "NSFR"
      ],
      "strictest": "Basel 3.1 — output floors constrain internal modelling discretion.",
      "governs": "Data",
      "layer": "Financial"
    },
    {
      "code": "C20",
      "name": "Concentration and dependency control",
      "intent": "Single points of failure across providers, models and infrastructure are identified and bounded.",
      "frameworks": [
        "DORA",
        "Basel III",
        "OSFI B-10"
      ],
      "strictest": "DORA — critical third-party concentration is supervised at sector level, not only at firm level.",
      "governs": "Third party",
      "layer": "Operational"
    },
    {
      "code": "C21",
      "name": "Change and release control",
      "intent": "Nothing reaches production without authorisation, segregation and a traceable record.",
      "frameworks": [
        "ISO 27001",
        "SOC 2",
        "SOX",
        "DORA"
      ],
      "strictest": "SOX — segregation failures are material weaknesses regardless of outcome.",
      "governs": "Application",
      "layer": "Technology"
    },
    {
      "code": "C22",
      "name": "Crisis management and continuity",
      "intent": "Playbooks exist, are rehearsed, and name the authority that invokes them.",
      "frameworks": [
        "DORA",
        "ISO 22301",
        "OSFI E-21"
      ],
      "strictest": "ISO 22301 — rehearsal evidence is required, not plan documentation alone.",
      "governs": "Business service",
      "layer": "Operational"
    },
    {
      "code": "C23",
      "name": "Incident and regulatory reporting",
      "intent": "Materiality is determined consistently and reporting clocks are met per jurisdiction and entity.",
      "frameworks": [
        "NIS2",
        "DORA",
        "CIRCIA",
        "SEC 8-K Item 1.05"
      ],
      "strictest": "NIS2 — 24-hour early warning leaves no room for a discretionary internal review period.",
      "governs": "Incident",
      "layer": "Operational"
    },
    {
      "code": "C24",
      "name": "Evidence, audit and attestation",
      "intent": "Evidence is complete, current, attributable and retained for the supervisory window.",
      "frameworks": [
        "ISO 27001",
        "SOC 2",
        "DORA",
        "SR 11-7"
      ],
      "strictest": "SOC 2 — evidence must support the assertion across the whole period under examination.",
      "governs": "Evidence",
      "layer": "Governance"
    },
    {
      "code": "C25",
      "name": "Legal risk and contractual enforceability",
      "intent": "Every material contract is enforceable in the governing forum, and the obligations it creates are held in the same register as regulatory obligations.",
      "frameworks": [
        "DORA",
        "OSFI B-10",
        "EBA outsourcing guidelines",
        "UCC Article 12"
      ],
      "strictest": "DORA — contractual clauses for critical ICT services are prescribed, and their absence is itself a finding.",
      "governs": "Contract",
      "layer": "Legal"
    },
    {
      "code": "C26",
      "name": "Regulatory engagement and examination response",
      "intent": "Supervisory requests, findings and commitments are tracked to closure by a named owner, with the evidence that closed them retained.",
      "frameworks": [
        "FRB SR 08-8",
        "OCC Handbook",
        "FCA SUP",
        "MAS Notices"
      ],
      "strictest": "SR 08-8 — the commitment, not the remediation activity, is what the supervisor tests.",
      "governs": "Obligation",
      "layer": "Legal"
    },
    {
      "code": "C27",
      "name": "Litigation, disputes and legal hold",
      "intent": "Preservation obligations attach on notice, hold scope is defensible, and deletion routines stop where the hold begins.",
      "frameworks": [
        "FRCP 37(e)",
        "EU eDiscovery practice",
        "SEC 17a-4",
        "GDPR Art. 17"
      ],
      "strictest": "FRCP 37(e) — spoliation sanctions attach to failure to preserve, irrespective of intent to lose the data.",
      "governs": "Evidence",
      "layer": "Legal"
    },
    {
      "code": "C28",
      "name": "Legal AI and privileged material handling",
      "intent": "AI used on legal work product cannot waive privilege, fabricate authority, or move privileged material outside the retained boundary.",
      "frameworks": [
        "ABA Formal Op. 512",
        "EU AI Act",
        "ISO 42001",
        "SRA guidance"
      ],
      "strictest": "ABA Formal Op. 512 — competence and confidentiality duties are personal to the lawyer and cannot be delegated to a tool.",
      "governs": "AI model",
      "layer": "Legal"
    },
    {
      "code": "C29",
      "name": "Market conduct and abuse surveillance",
      "intent": "Trading, communications and order-handling surveillance is calibrated, tested for false negatives, and escalates on a recorded path.",
      "frameworks": [
        "MAR",
        "MiFID II",
        "FINRA 3110",
        "SEC Rule 15c3-5"
      ],
      "strictest": "MAR — the obligation is to detect and report attempted abuse, not merely completed abuse.",
      "governs": "Process",
      "layer": "Conduct"
    },
    {
      "code": "C30",
      "name": "Payment and settlement finality",
      "intent": "Every rail the institution touches has a stated point of finality, a failure mode, and a control that proves settlement occurred.",
      "frameworks": [
        "PFMI",
        "CPMI-IOSCO",
        "Reg CC",
        "SEPA Rulebook",
        "T+1"
      ],
      "strictest": "PFMI Principle 8 — finality must be legally certain and operationally demonstrable, not assumed from a successful message.",
      "governs": "Business service",
      "layer": "Market infrastructure"
    },
    {
      "code": "C31",
      "name": "Custody, client assets and reconciliation",
      "intent": "Client property is segregated, reconciled to the external record daily, and shortfalls are funded on the same cycle they are found.",
      "frameworks": [
        "SEC Rule 15c3-3",
        "CASS 6/7",
        "MiCA Title III",
        "AIFMD"
      ],
      "strictest": "CASS — a reconciliation break is a breach on discovery, with same-day funding of the shortfall.",
      "governs": "Process",
      "layer": "Market infrastructure"
    },
    {
      "code": "C32",
      "name": "Correspondent and cross-border rails",
      "intent": "Nested relationships, respondent due diligence and message integrity across correspondent chains are known and monitored.",
      "frameworks": [
        "FATF R.13",
        "Wolfsberg CBDDQ",
        "SWIFT CSP",
        "OFAC"
      ],
      "strictest": "SWIFT CSP — mandatory controls are independently attested annually with no self-certification-only path.",
      "governs": "Third party",
      "layer": "Market infrastructure"
    },
    {
      "code": "C33",
      "name": "Legacy core and end-of-life technology",
      "intent": "Unsupported platforms carrying critical services are inventoried, compensating-controlled, and on a funded exit path with a date.",
      "frameworks": [
        "DORA",
        "FFIEC Architecture",
        "OSFI B-13",
        "NIST SP 800-53"
      ],
      "strictest": "DORA — the ICT risk of legacy estate must be assessed and reported, not deferred to a transformation programme.",
      "governs": "Application",
      "layer": "Technology"
    },
    {
      "code": "C34",
      "name": "Digital identity, authentication and fraud",
      "intent": "Identity proofing, authentication strength and fraud controls hold across channels, including at the human override point.",
      "frameworks": [
        "NIST 800-63",
        "PSD2 SCA",
        "eIDAS 2",
        "Reg E"
      ],
      "strictest": "NIST 800-63 — assurance levels are evidenced per channel; a strong front door does not cover a weak call centre.",
      "governs": "Process",
      "layer": "Technology"
    },
    {
      "code": "C35",
      "name": "Digital asset and reserve assurance",
      "intent": "Tokenised claims and stablecoin reserves are backed, attested and redeemable on the stated terms under stress.",
      "frameworks": [
        "MiCA Title III/IV",
        "GENIUS Act",
        "NYDFS Part 200",
        "MAS SCS"
      ],
      "strictest": "MiCA — reserve composition, custody and redemption at par are prescribed and independently attested.",
      "governs": "Business service",
      "layer": "Financial"
    },
    {
      "code": "C36",
      "name": "Treasury, collateral and intraday liquidity",
      "intent": "Intraday positions, collateral eligibility and margin calls are visible in time to act, not reconstructed the next morning.",
      "frameworks": [
        "BCBS 248",
        "Basel III LCR/NSFR",
        "UMR",
        "EMIR"
      ],
      "strictest": "BCBS 248 — intraday monitoring is a stated supervisory expectation, not an end-of-day metric.",
      "governs": "Process",
      "layer": "Financial"
    },
    {
      "code": "C37",
      "name": "Books, records and reporting integrity",
      "intent": "Regulatory and financial reporting reconciles to the source ledger, with lineage a reviewer can walk without assistance.",
      "frameworks": [
        "SOX 404",
        "SEC 17a-4",
        "BCBS 239",
        "IFRS 9"
      ],
      "strictest": "BCBS 239 — aggregation must be accurate and timely under stress, not only in the normal cycle.",
      "governs": "Dataset",
      "layer": "Financial"
    },
    {
      "code": "C38",
      "name": "Sanctions and export control screening",
      "intent": "Screening covers parties, payments, ownership and, where relevant, wallet addresses, with list-update latency measured.",
      "frameworks": [
        "OFAC",
        "EU sanctions regime",
        "UK OFSI",
        "BIS EAR"
      ],
      "strictest": "OFAC — strict liability applies; a screening gap is a violation whether or not intent existed.",
      "governs": "Process",
      "layer": "Conduct"
    },
    {
      "code": "C39",
      "name": "Payment tokenisation and credential integrity",
      "intent": "Network and vault tokens are inventoried, requestor identities are owned, provisioning verification is evidenced, lifecycle events propagate, and any compliance scope reduction is substantiated against live configuration.",
      "frameworks": [
        "PCI DSS v4.0.1",
        "EMVCo tokenisation specification",
        "Card scheme rules",
        "PSD2 SCA",
        "DORA"
      ],
      "strictest": "PCI DSS v4.0.1 — scope is determined by where account data can be retrieved or reconstructed, so a token programme reduces scope only where that is demonstrable.",
      "governs": "Process",
      "layer": "Market infrastructure"
    },
    {
      "code": "C40",
      "name": "Sustainability disclosure and claim integrity",
      "intent": "Every disclosed sustainability datapoint has an owner, a traceable source, a stated estimation basis and an individual sign-off; restatements are controlled; and every public claim resolves to a control that substantiates it.",
      "frameworks": [
        "Revised ESRS (2026) under CSRD",
        "IFRS S1 / S2",
        "California SB 253 / SB 261",
        "UK SRS",
        "SFDR",
        "Corporate sustainability due diligence"
      ],
      "strictest": "Revised ESRS under CSRD — the sustainability statement is subject to limited assurance, so a figure without traceable support is a finding rather than a presentational weakness.",
      "governs": "Data element",
      "layer": "Conduct"
    }
  ],
  "controls": [
    {
      "code": "C01.01",
      "domain": "C01",
      "name": "Named accountable executive per material obligation",
      "requirement": "Every obligation classified material has one named individual, not a committee or a function.",
      "test": "Reconcile the obligation register to the accountability map and confirm each material obligation resolves to a single named person in post at the test date.",
      "population": "All obligations flagged material; full population, no sampling.",
      "evidence": "Obligation register extract, accountability map, current organisation chart.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "Any material obligation with no owner, a vacant post, or a committee named in place of a person."
    },
    {
      "code": "C01.02",
      "domain": "C01",
      "name": "Board receives the position with evidence beneath it",
      "requirement": "Board risk reporting states each material position and can be traced to the underlying evidence without preparation.",
      "test": "Select the last two board packs, pick five assertions, and trace each to the evidence record that supported it on the pack date.",
      "population": "Board and board risk committee packs for the period.",
      "evidence": "Board pack, evidence vault references, minutes recording challenge.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "An assertion that cannot be traced, or whose supporting evidence post-dates the pack."
    },
    {
      "code": "C01.03",
      "domain": "C01",
      "name": "Delegation of authority is current and bounded",
      "requirement": "Delegated authorities state limits, expiry and escalation, and are re-approved on change of holder.",
      "test": "Inspect delegations against leaver and mover records for the period; confirm re-approval within the stated window.",
      "population": "All delegations touching material obligations plus all movers in period.",
      "evidence": "Delegation schedule, approval records, HR mover report.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "An authority exercised by a holder whose delegation had lapsed or was never re-approved."
    },
    {
      "code": "C01.04",
      "domain": "C01",
      "name": "Accountability survives outsourcing",
      "requirement": "Where an activity is outsourced, the accountable executive inside the institution remains named and is not the vendor relationship manager alone.",
      "test": "For each critical outsourced service, confirm an internal accountable owner distinct from the commercial owner.",
      "population": "All services classified critical or important.",
      "evidence": "Service register, accountability map, contract schedule.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "An outsourced critical service whose only named owner sits in procurement or at the vendor."
    },
    {
      "code": "C02.01",
      "domain": "C02",
      "name": "Obligation register completeness",
      "requirement": "Every regime applicable to the entity's licences and activities is represented in the register at clause level.",
      "test": "Reconcile licences held and activities conducted to regimes registered; confirm clause-level decomposition for each in-scope regime.",
      "population": "All legal entities and licences.",
      "evidence": "Licence schedule, obligation register, mapping worksheet.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "An activity conducted under a licence with no corresponding registered obligation set."
    },
    {
      "code": "C02.02",
      "domain": "C02",
      "name": "Obligation-to-control mapping with no orphans",
      "requirement": "Each registered obligation maps to at least one control, and each control maps to at least one obligation.",
      "test": "Run the mapping in both directions and list unmapped obligations and unmapped controls.",
      "population": "Full register and full control set.",
      "evidence": "Mapping export, exception list with owner and remediation date.",
      "method": "automated",
      "frequency": "continuous",
      "automation": "automated",
      "failure": "Any obligation with no control, or any control with no obligation it answers."
    },
    {
      "code": "C02.03",
      "domain": "C02",
      "name": "Horizon scanning to register latency",
      "requirement": "A published rule change enters the register, with impact assessed, inside the stated service level.",
      "test": "Select ten rule changes published in the period and measure publication date to register entry and to impact assessment sign-off.",
      "population": "All tracked publications from in-scope regulators in the period.",
      "evidence": "Horizon scanning log, register change history, impact assessment records.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A change registered after the service level, or registered without an impact assessment."
    },
    {
      "code": "C02.04",
      "domain": "C02",
      "name": "Versioning and point-in-time reconstruction",
      "requirement": "The register can be reproduced as it stood on any past date within the retention window.",
      "test": "Pick a date twelve months prior and reconstruct the register; compare against the pack issued at that date.",
      "population": "One reconstruction per annual cycle, plus one on supervisory request.",
      "evidence": "Version history, reconstruction output, contemporaneous report.",
      "method": "reperformance",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "Any material difference between the reconstruction and the contemporaneous record."
    },
    {
      "code": "C03.01",
      "domain": "C03",
      "name": "Policy in force and within review date",
      "requirement": "Every policy governing a material obligation is approved, in force, and inside its review period.",
      "test": "Inspect the policy inventory for approval date, review date and approving body; list all past review date.",
      "population": "Full policy inventory.",
      "evidence": "Policy inventory, approval minutes.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "automated",
      "failure": "A policy governing a material obligation past its review date."
    },
    {
      "code": "C03.02",
      "domain": "C03",
      "name": "Standards trace up to policy and down to control",
      "requirement": "Each standard or procedure cites the policy it implements and the controls that operate it.",
      "test": "Sample fifteen standards and trace both directions.",
      "population": "All standards attached to material policies.",
      "evidence": "Standard documents, mapping export.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "A standard with no parent policy or no operating control."
    },
    {
      "code": "C03.03",
      "domain": "C03",
      "name": "Attestation of read and understood",
      "requirement": "Staff in scope of a policy attest on issue and on material amendment.",
      "test": "Compare in-scope population to attestation records for the two most recent amendments.",
      "population": "All in-scope staff at amendment date.",
      "evidence": "Attestation register, HR population extract.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "automated",
      "failure": "Attestation coverage below the stated threshold, or measured against a stale population."
    },
    {
      "code": "C04.01",
      "domain": "C04",
      "name": "RCSA covers every material process",
      "requirement": "Each material process has a current assessment with inherent rating, controls and residual rating.",
      "test": "Reconcile the process inventory to completed assessments in the cycle.",
      "population": "All processes rated material.",
      "evidence": "Process inventory, RCSA records.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "A material process with no assessment in the current cycle."
    },
    {
      "code": "C04.02",
      "domain": "C04",
      "name": "Residual ratings are challenged independently",
      "requirement": "Second line reviews and can dissent from first-line residual ratings, with the dissent recorded.",
      "test": "Sample twenty assessments and confirm review evidence, including at least one recorded challenge.",
      "population": "All assessments completed in the cycle.",
      "evidence": "Review records, challenge log.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "manual",
      "failure": "Blanket second-line sign-off with no evidence of challenge across the cycle."
    },
    {
      "code": "C04.03",
      "domain": "C04",
      "name": "Loss and near-miss data feeds the next assessment",
      "requirement": "Operational loss and near-miss events update the inherent rating of the process that produced them.",
      "test": "Trace ten events to the assessment revision they triggered.",
      "population": "All events above the recording threshold.",
      "evidence": "Loss database, assessment version history.",
      "method": "reperformance",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "A material event with no corresponding assessment revision."
    },
    {
      "code": "C05.01",
      "domain": "C05",
      "name": "Reconciliation completeness by account",
      "requirement": "Every in-scope account is reconciled at the stated frequency with no silent omissions.",
      "test": "Reconcile the account inventory to completed reconciliations for three periods.",
      "population": "All in-scope accounts.",
      "evidence": "Account inventory, reconciliation log.",
      "method": "automated",
      "frequency": "monthly",
      "automation": "automated",
      "failure": "An in-scope account with a missed period or no owner."
    },
    {
      "code": "C05.02",
      "domain": "C05",
      "name": "Ageing and clearance of breaks",
      "requirement": "Breaks are cleared inside the stated window and ageing is reported at the level that can act on it.",
      "test": "Age the open break population and test clearance dates against the standard.",
      "population": "All open and cleared breaks in the period.",
      "evidence": "Break register, ageing report.",
      "method": "inspection",
      "frequency": "monthly",
      "automation": "automated",
      "failure": "Breaks aged beyond the window, or ageing measured from investigation rather than identification."
    },
    {
      "code": "C05.03",
      "domain": "C05",
      "name": "Manual journal review",
      "requirement": "Manual journals above threshold are independently reviewed before posting, with preparer and reviewer segregated.",
      "test": "Sample thirty journals and confirm segregation and pre-posting review.",
      "population": "All manual journals above threshold in the period.",
      "evidence": "Journal listing, approval records.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A journal posted by its own preparer or reviewed after posting."
    },
    {
      "code": "C06.01",
      "domain": "C06",
      "name": "Joiner, mover, leaver execution",
      "requirement": "Access is provisioned to role, amended on move, and removed on the leave date.",
      "test": "Sample HR events and test system access state against effective dates.",
      "population": "All joiners, movers and leavers in the period.",
      "evidence": "HR event report, access logs, revocation records.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "Any leaver with live access after the leave date."
    },
    {
      "code": "C06.02",
      "domain": "C06",
      "name": "Privileged access is brokered and recorded",
      "requirement": "Administrative access is time-bound, approved, and session-recorded on critical systems.",
      "test": "Inspect privileged sessions against approvals for the period.",
      "population": "All privileged sessions on critical systems.",
      "evidence": "Vault logs, approval tickets.",
      "method": "inspection",
      "frequency": "monthly",
      "automation": "automated",
      "failure": "Standing privileged access, or a session with no approval reference."
    },
    {
      "code": "C06.03",
      "domain": "C06",
      "name": "User access review with revocation follow-through",
      "requirement": "Periodic reviews complete on time and revocations identified are executed and verified.",
      "test": "Test review completion and re-test revocation execution thirty days later.",
      "population": "All critical applications.",
      "evidence": "Review records, revocation evidence.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "A review certified complete where identified revocations were never executed."
    },
    {
      "code": "C07.01",
      "domain": "C07",
      "name": "Known exploited vulnerability remediation",
      "requirement": "Vulnerabilities on the exploited-in-the-wild list are remediated inside the mandated window.",
      "test": "Measure detection-to-remediation for every catalogued vulnerability present in the estate.",
      "population": "Full population, no sampling.",
      "evidence": "Scanner output, KEV catalogue, change records.",
      "method": "automated",
      "frequency": "continuous",
      "automation": "automated",
      "failure": "Any catalogued vulnerability open past the window on an internet-facing asset."
    },
    {
      "code": "C07.02",
      "domain": "C07",
      "name": "Detection coverage against tested techniques",
      "requirement": "Monitoring detects the techniques the institution has assessed as relevant, proven by exercise not configuration.",
      "test": "Run purple-team cases and measure detection and alert-to-triage time.",
      "population": "Prioritised technique set for the period.",
      "evidence": "Exercise report, alert records, tuning changes.",
      "method": "observation",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A prioritised technique executed without detection, or detected without triage."
    },
    {
      "code": "C07.03",
      "domain": "C07",
      "name": "Backup restoration proven, not asserted",
      "requirement": "Critical service backups are restored on test to the stated recovery objective.",
      "test": "Restore a sample to an isolated environment and measure time and data integrity.",
      "population": "Critical services on a rotating cycle.",
      "evidence": "Restore logs, integrity checks, objective comparison.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "A restore that misses the objective, or a service never restored in the cycle."
    },
    {
      "code": "C08.01",
      "domain": "C08",
      "name": "Lawful basis recorded per processing activity",
      "requirement": "Every processing activity states its lawful basis and, where consent, the consent record.",
      "test": "Sample activities from the record of processing and trace basis and consent evidence.",
      "population": "All activities involving personal data.",
      "evidence": "Processing register, consent store extract.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "A processing activity with no recorded basis, or consent that cannot be evidenced."
    },
    {
      "code": "C08.02",
      "domain": "C08",
      "name": "Data subject request service level",
      "requirement": "Access, erasure and portability requests complete inside the statutory period across all systems holding the data.",
      "test": "Sample requests and confirm completeness against the data inventory and closure date.",
      "population": "All requests received in the period.",
      "evidence": "Request log, system search evidence.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A request closed after the statutory period, or closed without searching a system known to hold the data."
    },
    {
      "code": "C08.03",
      "domain": "C08",
      "name": "Cross-border transfer mechanism validity",
      "requirement": "Each transfer out of a restricted jurisdiction rests on a currently valid mechanism with a completed assessment.",
      "test": "Reconcile transfer inventory to mechanisms and assessment dates.",
      "population": "All transfers from restricted jurisdictions.",
      "evidence": "Transfer register, clauses, transfer impact assessments.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "A live transfer on a lapsed mechanism or with no assessment."
    },
    {
      "code": "C09.01",
      "domain": "C09",
      "name": "Customer due diligence at onboarding and refresh",
      "requirement": "Risk-rated due diligence is complete before the relationship transacts, and refreshed on the rated cycle.",
      "test": "Sample onboardings and refreshes; test completeness against the standard and first transaction date.",
      "population": "All onboardings in the period plus refreshes due.",
      "evidence": "Customer files, transaction timestamps, refresh log.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A relationship that transacted before diligence completed, or an overdue high-risk refresh."
    },
    {
      "code": "C09.02",
      "domain": "C09",
      "name": "Detection scenario tuning is evidenced",
      "requirement": "Monitoring scenarios have documented thresholds, above- and below-the-line testing, and dated approval.",
      "test": "Reperform below-the-line sampling on two scenarios and inspect approval of current thresholds.",
      "population": "All production scenarios.",
      "evidence": "Tuning documentation, sampling results, approvals.",
      "method": "reperformance",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "A production threshold with no approved rationale, or no below-the-line testing."
    },
    {
      "code": "C09.03",
      "domain": "C09",
      "name": "Suspicious activity escalation clock",
      "requirement": "From alert to decision to filing, each step meets the internal and statutory clock.",
      "test": "Measure elapsed time at each stage for a sample of filed and closed cases.",
      "population": "All cases escalated in the period.",
      "evidence": "Case records, filing receipts.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A filing outside the statutory window, or a closure with no recorded rationale."
    },
    {
      "code": "C10.01",
      "domain": "C10",
      "name": "Product governance through to distribution",
      "requirement": "Each product has an approved target market and distribution is tested against it.",
      "test": "Sample sales and compare customer characteristics to the approved target market.",
      "population": "All sales of products approved or amended in the period.",
      "evidence": "Product approval, sales data, exception reports.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "Sales outside the target market with no recorded exception."
    },
    {
      "code": "C10.02",
      "domain": "C10",
      "name": "Complaint root cause reaches the control",
      "requirement": "Complaint themes result in a control change, not only in individual redress.",
      "test": "Trace the top three themes to the control amendments they caused.",
      "population": "All complaints in the period.",
      "evidence": "Complaint data, root cause analysis, change records.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "A recurring theme with redress paid and no control change."
    },
    {
      "code": "C10.03",
      "domain": "C10",
      "name": "Outcome testing for vulnerable customers",
      "requirement": "Outcomes for identified vulnerable customers are tested against the outcomes for the wider book.",
      "test": "Compare outcome metrics across cohorts and inspect action taken on divergence.",
      "population": "All identified vulnerable customers.",
      "evidence": "Outcome analysis, remediation decisions.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "Unexplained divergence with no action recorded."
    },
    {
      "code": "C11.01",
      "domain": "C11",
      "name": "Criticality classification drives diligence depth",
      "requirement": "Each third party is classified, and diligence performed matches the depth required for that class.",
      "test": "Sample engagements across classes and test diligence artefacts against the required set.",
      "population": "All third parties onboarded or reclassified in the period.",
      "evidence": "Vendor register, diligence files.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A critical third party diligenced to a lower standard than its class requires."
    },
    {
      "code": "C11.02",
      "domain": "C11",
      "name": "Fourth-party dependency is known for critical services",
      "requirement": "Material subcontractors behind critical services are identified and monitored.",
      "test": "For each critical service, inspect the subcontractor disclosure and compare to contractual notification records.",
      "population": "All critical or important services.",
      "evidence": "Subcontractor schedules, notifications, register entries.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "A critical service with unknown or undisclosed material subcontractors."
    },
    {
      "code": "C11.03",
      "domain": "C11",
      "name": "Exit plan is tested, not drafted",
      "requirement": "Critical service exit plans state trigger, timeline, data return and an alternative that has been assessed.",
      "test": "Inspect plans and evidence of the most recent walkthrough or partial test.",
      "population": "All critical services.",
      "evidence": "Exit plans, test records.",
      "method": "observation",
      "frequency": "annual",
      "automation": "manual",
      "failure": "An exit plan with no named alternative or never walked through."
    },
    {
      "code": "C12.01",
      "domain": "C12",
      "name": "Impact tolerance set and breach-tested",
      "requirement": "Each important business service has a board-approved impact tolerance stated in time and volume.",
      "test": "Inspect approvals and test the most recent scenario against the tolerance.",
      "population": "All important business services.",
      "evidence": "Tolerance statements, scenario results.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "manual",
      "failure": "A service with no approved tolerance, or a tolerance never tested to breach."
    },
    {
      "code": "C12.02",
      "domain": "C12",
      "name": "Service mapping to the resource that fails",
      "requirement": "Mappings reach the specific people, premises, technology, data and third parties a service depends on.",
      "test": "Trace two services end to end and confirm each dependency resolves to a named asset.",
      "population": "All important business services on a rotating cycle.",
      "evidence": "Service maps, asset register references.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "A mapping that stops at a team or platform name rather than the dependency itself."
    },
    {
      "code": "C12.03",
      "domain": "C12",
      "name": "Severe but plausible scenario execution",
      "requirement": "Scenarios are severe enough to breach at least one tolerance and produce recorded lessons.",
      "test": "Inspect scenario design, execution evidence and the actions raised from it.",
      "population": "All scenarios run in the period.",
      "evidence": "Scenario pack, execution log, action tracker.",
      "method": "observation",
      "frequency": "annual",
      "automation": "manual",
      "failure": "A scenario designed so that no tolerance can breach, or lessons raised with no owner."
    },
    {
      "code": "C13.01",
      "domain": "C13",
      "name": "AI inventory completeness",
      "requirement": "Every AI or automated decision system in use is registered, including embedded vendor capability.",
      "test": "Reconcile the inventory to procurement records, model-serving logs and vendor release notes.",
      "population": "All systems in production plus vendor features enabled in the period.",
      "evidence": "AI inventory, procurement extract, serving logs.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "An AI capability in production and not registered, including one enabled by a vendor update."
    },
    {
      "code": "C13.02",
      "domain": "C13",
      "name": "Risk classification and gate before release",
      "requirement": "Each system carries a risk classification, and high-risk systems pass the stated gates before release.",
      "test": "Sample releases and test gate evidence against the classification held at release date.",
      "population": "All AI releases in the period.",
      "evidence": "Classification records, gate approvals, release records.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A high-risk system released with a gate unmet or a classification set after release."
    },
    {
      "code": "C13.03",
      "domain": "C13",
      "name": "Human authority is reachable and exercised",
      "requirement": "A named human can override an individual outcome, and overrides are recorded with reasons.",
      "test": "Test the override path on a live system and inspect the override log for the period.",
      "population": "All systems producing decisions affecting customers.",
      "evidence": "Override logs, walkthrough record.",
      "method": "observation",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "An override path that does not function, or a log with no reasons recorded."
    },
    {
      "code": "C13.04",
      "domain": "C13",
      "name": "Kill path tested end to end",
      "requirement": "Each high-risk system can be stopped and its effects reversed on a path that has been exercised.",
      "test": "Exercise the stop path in a controlled window and measure time to full stop and to reversal.",
      "population": "All high-risk and agentic systems.",
      "evidence": "Exercise record, timings, restoration evidence.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "A documented kill path that has never been exercised, or one that stops inference without reversing effects."
    },
    {
      "code": "C14.01",
      "domain": "C14",
      "name": "Independent validation before use",
      "requirement": "Models are validated by a party independent of development before production use, with findings tracked.",
      "test": "Sample production models and compare validation date and independence to first production use.",
      "population": "All models rated high materiality.",
      "evidence": "Validation reports, independence attestations, deployment records.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "manual",
      "failure": "Production use before validation, or validation performed by the development owner."
    },
    {
      "code": "C14.02",
      "domain": "C14",
      "name": "Ongoing monitoring inside threshold",
      "requirement": "Performance and drift metrics are monitored against approved thresholds, with breach escalation.",
      "test": "Reperform metric calculation for a sample period and compare to reported values and escalations.",
      "population": "All models in production.",
      "evidence": "Monitoring output, threshold approvals, escalation records.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "automated",
      "failure": "A breach not escalated, or a threshold changed without approval to avoid a breach."
    },
    {
      "code": "C14.03",
      "domain": "C14",
      "name": "Model inventory reconciles to what is serving",
      "requirement": "The inventory matches the model versions actually in production, including challenger and shadow deployments.",
      "test": "Compare inventory versions to serving infrastructure records.",
      "population": "All serving endpoints.",
      "evidence": "Inventory export, serving manifest.",
      "method": "automated",
      "frequency": "monthly",
      "automation": "automated",
      "failure": "A version serving traffic that the inventory does not hold."
    },
    {
      "code": "C15.01",
      "domain": "C15",
      "name": "Golden source designated per critical data element",
      "requirement": "Each critical data element has one designated authoritative source, with consumers recorded.",
      "test": "Sample elements and confirm single designation and consumer mapping.",
      "population": "All critical data elements.",
      "evidence": "Data dictionary, lineage export.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "An element with two competing sources or no designation."
    },
    {
      "code": "C15.02",
      "domain": "C15",
      "name": "Lineage is complete through transformation",
      "requirement": "Lineage traces from report line to source system through every transformation, including manual adjustment.",
      "test": "Trace three report lines to source and confirm every hop is documented.",
      "population": "All regulatory reports in scope.",
      "evidence": "Lineage records, transformation logic, adjustment log.",
      "method": "reperformance",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "A hop that cannot be evidenced, or a manual adjustment with no approval."
    },
    {
      "code": "C15.03",
      "domain": "C15",
      "name": "Aggregation under stress",
      "requirement": "Reporting can be produced at the required speed during a stress event, not only in the normal cycle.",
      "test": "Run an off-cycle production request against a compressed deadline and measure completeness.",
      "population": "Priority regulatory and board reports.",
      "evidence": "Off-cycle run output, timings, exception list.",
      "method": "reperformance",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "An off-cycle run that cannot complete, or completes only with unrecorded manual intervention."
    },
    {
      "code": "C16.01",
      "domain": "C16",
      "name": "Payment authorisation and limit enforcement",
      "requirement": "Payments above threshold require segregated authorisation and cannot bypass the limit path.",
      "test": "Attempt a limit breach in a controlled test and inspect the rejected population for the period.",
      "population": "All payments above threshold.",
      "evidence": "Payment logs, authorisation records, test evidence.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "automated",
      "failure": "Any payment released above limit without segregated authorisation."
    },
    {
      "code": "C16.02",
      "domain": "C16",
      "name": "End-to-end transaction reconciliation",
      "requirement": "Instructed, sent, settled and booked counts reconcile daily with breaks owned.",
      "test": "Reperform the four-way reconciliation for three days across a busy period.",
      "population": "All payment channels.",
      "evidence": "Channel reports, reconciliation output.",
      "method": "reperformance",
      "frequency": "monthly",
      "automation": "automated",
      "failure": "An unexplained count difference, or a reconciliation that compares only two of the four points."
    },
    {
      "code": "C16.03",
      "domain": "C16",
      "name": "Duplicate and mis-direction controls",
      "requirement": "Duplicate submissions and misdirected payments are detected before release, not after settlement.",
      "test": "Inject controlled duplicates in a test channel and inspect production detections.",
      "population": "All release channels.",
      "evidence": "Detection logs, test injections.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "automated",
      "failure": "A duplicate detected only after settlement, or a channel with detection disabled."
    },
    {
      "code": "C17.01",
      "domain": "C17",
      "name": "Settlement fail management",
      "requirement": "Fails are identified same-day, aged, and escalated against a stated tolerance with penalty exposure quantified.",
      "test": "Age the fail population and test escalation against tolerance for the period.",
      "population": "All trades failing to settle.",
      "evidence": "Fail reports, escalation records, penalty statements.",
      "method": "inspection",
      "frequency": "monthly",
      "automation": "automated",
      "failure": "Fails aged beyond tolerance with no escalation, or penalty exposure not quantified."
    },
    {
      "code": "C17.02",
      "domain": "C17",
      "name": "Membership and CSD obligation compliance",
      "requirement": "Obligations under each infrastructure membership are held in the register and tested.",
      "test": "Reconcile membership rulebooks to registered obligations and controls.",
      "population": "All infrastructure memberships.",
      "evidence": "Rulebooks, register extract, attestations.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "manual",
      "failure": "A membership obligation not represented in the register."
    },
    {
      "code": "C17.03",
      "domain": "C17",
      "name": "Cut-off and time-zone control",
      "requirement": "Cut-offs per market are enforced systemically, including on shortened settlement cycles.",
      "test": "Inspect late-instruction exceptions against configured cut-offs across markets.",
      "population": "All markets traded.",
      "evidence": "Cut-off configuration, exception reports.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "automated",
      "failure": "A market whose cut-off is enforced by convention rather than configuration."
    },
    {
      "code": "C18.01",
      "domain": "C18",
      "name": "On-chain to off-chain record parity",
      "requirement": "The token record and the books-and-records position reconcile at each cycle, with breaks investigated.",
      "test": "Reperform the parity reconciliation for three cycles.",
      "population": "All tokenised instruments issued or serviced.",
      "evidence": "Chain extracts, ledger balances, reconciliation output.",
      "method": "reperformance",
      "frequency": "monthly",
      "automation": "automated",
      "failure": "A parity break that survives a cycle, or a reconciliation performed on chain data alone."
    },
    {
      "code": "C18.02",
      "domain": "C18",
      "name": "Key management and quorum",
      "requirement": "Signing keys are held under quorum with no single-person spend path, and ceremonies are recorded.",
      "test": "Inspect ceremony records and attempt a single-signature spend in a controlled environment.",
      "population": "All production signing arrangements.",
      "evidence": "Ceremony records, policy configuration, test evidence.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "Any path by which one individual can move assets, or a ceremony with no record."
    },
    {
      "code": "C18.03",
      "domain": "C18",
      "name": "Smart contract change control",
      "requirement": "Contract deployments and upgrades pass independent review and match the audited bytecode.",
      "test": "Compare deployed bytecode to the audited artefact and inspect approval for each upgrade.",
      "population": "All production contracts and upgrades in the period.",
      "evidence": "Audit reports, deployment hashes, approvals.",
      "method": "reperformance",
      "frequency": "event-driven",
      "automation": "assisted",
      "failure": "Deployed bytecode that differs from the audited artefact, or an upgrade key held without quorum."
    },
    {
      "code": "C19.01",
      "domain": "C19",
      "name": "Ratio calculation reperformance",
      "requirement": "Reported capital and liquidity ratios can be reperformed independently from source positions.",
      "test": "Reperform one reported ratio end to end from source data.",
      "population": "Each reported ratio on a rotating cycle.",
      "evidence": "Source extracts, calculation workings, submitted return.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A reperformance that differs materially from the submitted figure."
    },
    {
      "code": "C19.02",
      "domain": "C19",
      "name": "Stress assumptions approved and challenged",
      "requirement": "Stress assumptions are approved, documented and challenged by a party independent of the modeller.",
      "test": "Inspect approval and challenge records for the current assumption set.",
      "population": "All stress scenarios used in planning.",
      "evidence": "Assumption documentation, challenge minutes.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "manual",
      "failure": "An assumption set in use without recorded independent challenge."
    },
    {
      "code": "C19.03",
      "domain": "C19",
      "name": "Early warning indicator escalation",
      "requirement": "Indicator breaches escalate to the named committee inside the stated window.",
      "test": "Test breaches in the period against escalation records and timing.",
      "population": "All indicator breaches.",
      "evidence": "Indicator reports, committee minutes.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "automated",
      "failure": "A breach escalated late or resolved by adjusting the indicator."
    },
    {
      "code": "C20.01",
      "domain": "C20",
      "name": "Single point of failure register",
      "requirement": "Concentrations in providers, regions, people and platforms behind critical services are recorded and rated.",
      "test": "Test the register against service mappings for undisclosed concentration.",
      "population": "All critical services.",
      "evidence": "Concentration register, service maps.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "A concentration visible in the mapping but absent from the register."
    },
    {
      "code": "C20.02",
      "domain": "C20",
      "name": "Substitutability assessed with a named alternative",
      "requirement": "Each concentrated dependency has an assessed alternative and an estimated switch time.",
      "test": "Inspect the assessment for the top ten concentrations.",
      "population": "Highest-rated concentrations.",
      "evidence": "Substitutability assessments, switch estimates.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "manual",
      "failure": "A concentration described as unavoidable with no assessment behind the conclusion."
    },
    {
      "code": "C20.03",
      "domain": "C20",
      "name": "Aggregate exposure across entities",
      "requirement": "Concentration is measured group-wide, not entity by entity.",
      "test": "Aggregate provider exposure across entities and compare to entity-level reporting.",
      "population": "All group entities.",
      "evidence": "Group aggregation, entity registers.",
      "method": "reperformance",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "A group-material concentration invisible at entity level."
    },
    {
      "code": "C21.01",
      "domain": "C21",
      "name": "Authorisation before production",
      "requirement": "No change reaches production without recorded authorisation from an approver other than the implementer.",
      "test": "Reconcile deployment records to approvals for the period.",
      "population": "All production changes.",
      "evidence": "Pipeline logs, approval records.",
      "method": "automated",
      "frequency": "continuous",
      "automation": "automated",
      "failure": "Any deployment with no approval, or approved by its implementer."
    },
    {
      "code": "C21.02",
      "domain": "C21",
      "name": "Emergency change retrospective approval",
      "requirement": "Emergency changes are approved retrospectively inside the stated window with justification.",
      "test": "Test all emergency changes for retrospective approval and timing.",
      "population": "All emergency changes, full population.",
      "evidence": "Emergency change log, approvals.",
      "method": "inspection",
      "frequency": "monthly",
      "automation": "assisted",
      "failure": "An emergency change never retrospectively approved, or emergency used to bypass routine control."
    },
    {
      "code": "C21.03",
      "domain": "C21",
      "name": "Rollback proven for critical releases",
      "requirement": "Critical releases carry a rollback that has been executed in a non-production environment.",
      "test": "Inspect rollback evidence for a sample of critical releases.",
      "population": "All releases affecting critical services.",
      "evidence": "Rollback test records, release notes.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A rollback plan asserted but never executed."
    },
    {
      "code": "C22.01",
      "domain": "C22",
      "name": "Invocation authority named and contactable",
      "requirement": "Each playbook names the authority who invokes it, with a tested contact path and a deputy.",
      "test": "Run an unannounced contact test outside business hours.",
      "population": "All crisis playbooks.",
      "evidence": "Contact test log, playbook records.",
      "method": "observation",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "An authority unreachable inside the stated window with no deputy responding."
    },
    {
      "code": "C22.02",
      "domain": "C22",
      "name": "Rehearsal against a live-like environment",
      "requirement": "Continuity arrangements are rehearsed with the systems and people who would actually operate them.",
      "test": "Observe the rehearsal and test that recovery objectives were met without unrecorded workaround.",
      "population": "All critical services on a rotating cycle.",
      "evidence": "Rehearsal report, objective comparison.",
      "method": "observation",
      "frequency": "annual",
      "automation": "manual",
      "failure": "A tabletop presented as a rehearsal, or objectives met only via undocumented workaround."
    },
    {
      "code": "C22.03",
      "domain": "C22",
      "name": "Communications hold under a real outage",
      "requirement": "Client, regulator and staff communications can be issued when primary channels are unavailable.",
      "test": "Exercise the out-of-band path and inspect approval of pre-cleared holding statements.",
      "population": "All critical services.",
      "evidence": "Exercise record, pre-approved statements.",
      "method": "observation",
      "frequency": "annual",
      "automation": "manual",
      "failure": "A communications plan dependent on the systems being recovered."
    },
    {
      "code": "C23.01",
      "domain": "C23",
      "name": "Materiality assessment is consistent",
      "requirement": "The same facts produce the same materiality determination irrespective of who assesses them.",
      "test": "Re-assess a sample of closed incidents blind and compare to the recorded determination.",
      "population": "All incidents assessed in the period.",
      "evidence": "Incident records, blind re-assessment worksheet.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "manual",
      "failure": "Divergent determinations on comparable facts, or a determination with no recorded rationale."
    },
    {
      "code": "C23.02",
      "domain": "C23",
      "name": "Reporting clocks per jurisdiction and entity",
      "requirement": "Each reportable incident meets the earliest applicable clock across every jurisdiction and entity affected.",
      "test": "Measure detection-to-notification against each applicable deadline for reported incidents.",
      "population": "All reportable incidents.",
      "evidence": "Incident timeline, submission receipts.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A notification measured against the most lenient deadline rather than the earliest."
    },
    {
      "code": "C23.03",
      "domain": "C23",
      "name": "Near-miss capture",
      "requirement": "Events that could have been reportable are captured and analysed even where no report was required.",
      "test": "Compare near-miss volumes to incident volumes and inspect analysis for the largest.",
      "population": "All near misses in the period.",
      "evidence": "Near-miss log, analysis records.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "A near-miss population implausibly small relative to incidents, indicating suppressed capture."
    },
    {
      "code": "C24.01",
      "domain": "C24",
      "name": "Evidence is attributable and time-stamped",
      "requirement": "Every evidence item records who produced it, from what source, and when.",
      "test": "Sample evidence items and test attribution and timestamp integrity.",
      "population": "All evidence supporting material assertions.",
      "evidence": "Vault metadata, source references.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "automated",
      "failure": "Evidence with no author, no source, or a timestamp that post-dates the assertion it supports."
    },
    {
      "code": "C24.02",
      "domain": "C24",
      "name": "Retention across the supervisory window",
      "requirement": "Evidence is retained for the longest applicable window and is retrievable within the stated period.",
      "test": "Request retrieval of items at the outer edge of the retention window and measure time to produce.",
      "population": "All retained evidence classes.",
      "evidence": "Retrieval log, retention schedule.",
      "method": "reperformance",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "An item deleted inside its window, or retrievable only outside the stated period."
    },
    {
      "code": "C24.03",
      "domain": "C24",
      "name": "Attestation is informed, not administrative",
      "requirement": "Attestors can identify the evidence they relied on and the exceptions they accepted.",
      "test": "Interview a sample of attestors against the evidence set as it stood at attestation.",
      "population": "All attestations in the period.",
      "evidence": "Attestation records, evidence versions, interview notes.",
      "method": "enquiry",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "An attestation the attestor cannot substantiate, or one made against evidence added afterwards."
    },
    {
      "code": "C25.01",
      "domain": "C25",
      "name": "Prescribed clauses present in critical contracts",
      "requirement": "Contracts for critical services contain every clause the applicable regime prescribes, including audit, subcontracting, exit and data location.",
      "test": "Test each critical contract against the prescribed clause checklist for its governing regime.",
      "population": "All critical and important service contracts, full population.",
      "evidence": "Executed contracts, clause checklist, legal sign-off.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "A critical contract missing a prescribed clause, or relying on a side letter that is not enforceable in the governing forum."
    },
    {
      "code": "C25.02",
      "domain": "C25",
      "name": "Contractual obligations enter the register",
      "requirement": "Obligations the institution accepts by contract are held in the same register as regulatory obligations, with owners.",
      "test": "Sample executed contracts and confirm the obligations they create appear in the register.",
      "population": "All contracts executed in the period above materiality.",
      "evidence": "Contract schedule, register extract.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A contractual commitment being performed with no registered obligation or owner."
    },
    {
      "code": "C25.03",
      "domain": "C25",
      "name": "Governing law and enforceability assessed",
      "requirement": "For each critical relationship, enforceability in the governing forum is assessed, including insolvency and title questions.",
      "test": "Inspect the legal assessment for the top ten critical relationships and any digital-asset title arrangements.",
      "population": "Critical relationships and all arrangements involving custody of client property.",
      "evidence": "Legal opinions, assessment memoranda.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "manual",
      "failure": "A critical arrangement whose enforceability rests on assumption rather than assessed opinion."
    },
    {
      "code": "C26.01",
      "domain": "C26",
      "name": "Every supervisory item tracked to closure",
      "requirement": "Findings, matters requiring attention and undertakings are tracked with owner, date and closure evidence.",
      "test": "Reconcile all supervisory correspondence in the period to tracked items and closure evidence.",
      "population": "Full population of supervisory items.",
      "evidence": "Correspondence log, remediation tracker, closure packs.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A supervisory item closed internally without evidence, or absent from the tracker entirely."
    },
    {
      "code": "C26.02",
      "domain": "C26",
      "name": "Commitment language is honoured as written",
      "requirement": "What was committed to the supervisor is what is delivered, including scope and date, with variations notified.",
      "test": "Compare the commitment text to delivered remediation for a sample of closed items.",
      "population": "All commitments closed in the period.",
      "evidence": "Commitment letters, delivery evidence, notification records.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "Delivery narrower than the commitment, or a date change never notified."
    },
    {
      "code": "C26.03",
      "domain": "C26",
      "name": "Information provided to supervisors is reconciled",
      "requirement": "Data submitted to supervisors reconciles to the internal record and to prior submissions.",
      "test": "Reperform reconciliation between a sample of submissions and the internal source.",
      "population": "All submissions in the period.",
      "evidence": "Submissions, source extracts, reconciliation workings.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A submission that cannot be reconciled, or that contradicts an earlier submission without explanation."
    },
    {
      "code": "C27.01",
      "domain": "C27",
      "name": "Hold attaches on notice and suspends deletion",
      "requirement": "On reasonable anticipation of dispute, preservation attaches and automated deletion routines are suspended for the scope.",
      "test": "Test hold notices against deletion job configuration for the affected repositories.",
      "population": "All holds active in the period.",
      "evidence": "Hold notices, retention job configuration, suspension records.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "Data inside hold scope deleted by routine, whatever the intent."
    },
    {
      "code": "C27.02",
      "domain": "C27",
      "name": "Hold scope is defensible and reviewed",
      "requirement": "Custodians, systems and date ranges within scope are documented and reviewed as the matter develops.",
      "test": "Inspect scope documentation and review history for open matters.",
      "population": "All open matters.",
      "evidence": "Scope memoranda, review records, custodian lists.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "manual",
      "failure": "A scope never revisited after issue, or one that omits a system known to hold relevant material."
    },
    {
      "code": "C27.03",
      "domain": "C27",
      "name": "Release of hold is authorised",
      "requirement": "Holds are released only on legal authorisation, with the release recorded.",
      "test": "Test released holds for authorisation and record.",
      "population": "All holds released in the period.",
      "evidence": "Release authorisations, hold register.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "A hold released by operational request rather than legal authorisation."
    },
    {
      "code": "C28.01",
      "domain": "C28",
      "name": "Privilege boundary is technically enforced",
      "requirement": "Privileged material cannot be sent to a model or retention path outside the agreed boundary.",
      "test": "Attempt controlled submission of marked privileged material and inspect egress logs for the period.",
      "population": "All AI tools available to legal and compliance staff.",
      "evidence": "Egress logs, boundary configuration, test evidence.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "automated",
      "failure": "Any privileged material reaching a model outside the boundary, whether or not it was retained."
    },
    {
      "code": "C28.02",
      "domain": "C28",
      "name": "Citation and authority verification",
      "requirement": "Any authority, citation or quotation produced with AI assistance is verified against the source before external use.",
      "test": "Sample outgoing work product and re-verify every cited authority.",
      "population": "All AI-assisted work product issued externally.",
      "evidence": "Work product, verification records, source copies.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A single unverifiable or non-existent citation in externally issued work product."
    },
    {
      "code": "C28.03",
      "domain": "C28",
      "name": "Lawyer of record accountability",
      "requirement": "AI-assisted output carries a named responsible lawyer who reviewed it, and the assistance is disclosed internally.",
      "test": "Inspect review records and internal disclosure for a sample of matters.",
      "population": "All matters using AI assistance.",
      "evidence": "Matter files, review sign-off, tool usage log.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "Output issued with no named reviewing lawyer, or assistance not disclosed on the matter file."
    },
    {
      "code": "C29.01",
      "domain": "C29",
      "name": "Surveillance coverage across venues and instruments",
      "requirement": "Every traded venue, instrument class and communication channel in use is within surveillance scope.",
      "test": "Reconcile trading and communication inventories to surveillance configuration.",
      "population": "All venues, instruments and channels.",
      "evidence": "Trading inventory, channel inventory, surveillance configuration.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "automated",
      "failure": "A traded instrument or live channel outside surveillance scope."
    },
    {
      "code": "C29.02",
      "domain": "C29",
      "name": "False negative testing on abuse scenarios",
      "requirement": "Scenarios are tested with seeded patterns to prove they detect attempted as well as completed abuse.",
      "test": "Seed known patterns, including cancelled and partial attempts, and measure detection.",
      "population": "All production abuse scenarios.",
      "evidence": "Seeding records, alert output, tuning changes.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "A seeded attempt not detected, or scenarios calibrated only to completed trades."
    },
    {
      "code": "C29.03",
      "domain": "C29",
      "name": "Alert-to-decision path is recorded",
      "requirement": "Every alert reaches a documented decision, and closures state the basis.",
      "test": "Test closed alerts for recorded rationale and reviewer independence.",
      "population": "All alerts closed in the period.",
      "evidence": "Alert records, closure rationales.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "Bulk closure with no rationale, or closure by the desk that generated the activity."
    },
    {
      "code": "C30.01",
      "domain": "C30",
      "name": "Finality point stated per rail",
      "requirement": "For every rail used, the legal and operational point of finality is documented and understood by operations.",
      "test": "Inspect the rail inventory for a stated finality point and test operations awareness by walkthrough.",
      "population": "All rails in use, full population.",
      "evidence": "Rail inventory, legal analysis, walkthrough notes.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "manual",
      "failure": "A rail whose finality is inferred from a successful message rather than legally stated."
    },
    {
      "code": "C30.02",
      "domain": "C30",
      "name": "Provisional credit and revocation exposure",
      "requirement": "Where credit is given before finality, the exposure is measured, limited and reported.",
      "test": "Quantify pre-finality exposure across rails and test against approved limits.",
      "population": "All rails where credit precedes finality.",
      "evidence": "Exposure reports, limit approvals.",
      "method": "reperformance",
      "frequency": "monthly",
      "automation": "assisted",
      "failure": "Pre-finality credit extended with no measured exposure or no limit."
    },
    {
      "code": "C30.03",
      "domain": "C30",
      "name": "Rail failure playbook per rail",
      "requirement": "Each rail has a documented failure mode, alternative route and customer-impact position.",
      "test": "Inspect playbooks and test one alternative route in a controlled exercise.",
      "population": "All critical rails.",
      "evidence": "Playbooks, exercise records.",
      "method": "observation",
      "frequency": "annual",
      "automation": "manual",
      "failure": "A critical rail with no alternative route, or an alternative never exercised."
    },
    {
      "code": "C31.01",
      "domain": "C31",
      "name": "Internal and external reconciliation daily",
      "requirement": "Client asset positions reconcile to both the internal record and the external custodian or chain record each business day.",
      "test": "Reperform both reconciliations for five business days including a month end.",
      "population": "All client asset accounts.",
      "evidence": "Custodian statements, internal ledgers, chain extracts, reconciliation output.",
      "method": "reperformance",
      "frequency": "monthly",
      "automation": "automated",
      "failure": "A missed day, or a reconciliation performed against only one of the two records."
    },
    {
      "code": "C31.02",
      "domain": "C31",
      "name": "Shortfall funded on discovery",
      "requirement": "Identified shortfalls are funded from own resources on the same cycle they are identified.",
      "test": "Test identified shortfalls in the period against funding date and amount.",
      "population": "All shortfalls identified, full population.",
      "evidence": "Shortfall register, funding evidence.",
      "method": "inspection",
      "frequency": "monthly",
      "automation": "assisted",
      "failure": "A shortfall carried past the cycle, or netted against another account."
    },
    {
      "code": "C31.03",
      "domain": "C31",
      "name": "Segregation holds legally and operationally",
      "requirement": "Client property is segregated in name and in fact, including at sub-custodians and on-chain addresses.",
      "test": "Trace a sample of holdings to the segregated account or address and to the legal arrangement behind it.",
      "population": "All custody arrangements including sub-custody.",
      "evidence": "Account documentation, address attestations, legal opinions.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "Client property in an account or address that is not demonstrably segregated."
    },
    {
      "code": "C32.01",
      "domain": "C32",
      "name": "Respondent due diligence and nesting",
      "requirement": "Respondent relationships are diligenced, and downstream nesting is identified and permitted or prohibited explicitly.",
      "test": "Sample respondent files for diligence currency and nesting disclosure.",
      "population": "All correspondent and respondent relationships.",
      "evidence": "Respondent files, questionnaires, nesting attestations.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "Undisclosed nesting, or diligence past its refresh date on an active relationship."
    },
    {
      "code": "C32.02",
      "domain": "C32",
      "name": "Message integrity and required field completeness",
      "requirement": "Payment messages carry complete originator and beneficiary information across borders.",
      "test": "Test outbound and inbound populations for missing required fields and for stripping.",
      "population": "All cross-border messages in the period.",
      "evidence": "Message samples, field completeness reports.",
      "method": "automated",
      "frequency": "monthly",
      "automation": "automated",
      "failure": "Any evidence of field stripping, or systematic omission of required information."
    },
    {
      "code": "C32.03",
      "domain": "C32",
      "name": "Infrastructure security attestation",
      "requirement": "Mandatory controls for financial messaging infrastructure are attested with independent assessment.",
      "test": "Inspect the current attestation and the independent assessor's findings.",
      "population": "All messaging infrastructure connections.",
      "evidence": "Attestation submission, assessor report, remediation plan.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "manual",
      "failure": "A self-attestation with no independent assessment, or open mandatory-control gaps."
    },
    {
      "code": "C33.01",
      "domain": "C33",
      "name": "End-of-life inventory against critical services",
      "requirement": "Every unsupported or end-of-life component carrying a critical service is identified and rated.",
      "test": "Reconcile the asset inventory to vendor support lifecycle data and to service mappings.",
      "population": "All components supporting critical services.",
      "evidence": "Asset inventory, vendor lifecycle data, service maps.",
      "method": "automated",
      "frequency": "quarterly",
      "automation": "automated",
      "failure": "An unsupported component behind a critical service and absent from the register."
    },
    {
      "code": "C33.02",
      "domain": "C33",
      "name": "Compensating controls stated and tested",
      "requirement": "Where exit is not yet possible, compensating controls are specific, tested and time-limited.",
      "test": "Test the compensating controls named in each risk acceptance.",
      "population": "All accepted end-of-life risks.",
      "evidence": "Risk acceptances, control test results, expiry dates.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "A risk acceptance citing controls that have never been tested, or with no expiry."
    },
    {
      "code": "C33.03",
      "domain": "C33",
      "name": "Exit path is funded with a date",
      "requirement": "Each end-of-life dependency has an approved remediation path with funding and a target date.",
      "test": "Inspect plans, funding approval and progress against the date.",
      "population": "All end-of-life dependencies rated high or critical.",
      "evidence": "Programme plans, funding approvals, status reports.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "A dependency rolled forward across cycles with no funded plan."
    },
    {
      "code": "C34.01",
      "domain": "C34",
      "name": "Assurance level evidenced per channel",
      "requirement": "Identity proofing and authentication strength meet the stated assurance level in every channel, including telephony and branch.",
      "test": "Test each channel against the assurance requirement, including the manual override path.",
      "population": "All customer-facing channels.",
      "evidence": "Channel configuration, proofing records, call-centre procedures.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "A channel meeting a lower assurance level than the account it can access."
    },
    {
      "code": "C34.02",
      "domain": "C34",
      "name": "Authorised push payment and social engineering controls",
      "requirement": "Controls address customer-authorised fraud, not only unauthorised access, with intervention evidence.",
      "test": "Test intervention rates and outcomes on high-risk payment patterns.",
      "population": "All payments flagged high-risk in the period.",
      "evidence": "Intervention logs, outcome data, reimbursement records.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "Fraud controls that detect only unauthorised access while authorised-payment losses go unaddressed."
    },
    {
      "code": "C34.03",
      "domain": "C34",
      "name": "Synthetic and deepfake resistance",
      "requirement": "Proofing and voice or video verification are tested against synthetic media, with a documented fallback.",
      "test": "Attempt controlled synthetic submissions and record detection and fallback behaviour.",
      "population": "All channels using biometric or voice verification.",
      "evidence": "Test records, detection logs, fallback procedure.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "A verification channel that accepts synthetic media, or has no non-biometric fallback."
    },
    {
      "code": "C35.01",
      "domain": "C35",
      "name": "Reserve composition within mandate",
      "requirement": "Reserve assets match the permitted composition, tenor and custody arrangements at all times, not only at reporting dates.",
      "test": "Test daily composition against mandate across the period, not month-end snapshots.",
      "population": "All reserve holdings, daily.",
      "evidence": "Custody statements, holdings data, mandate document.",
      "method": "reperformance",
      "frequency": "monthly",
      "automation": "automated",
      "failure": "Any day out of mandate, including intra-month breaches cured before reporting."
    },
    {
      "code": "C35.02",
      "domain": "C35",
      "name": "Redemption at par under stress",
      "requirement": "Redemption can be met at par within the stated period under a severe but plausible outflow.",
      "test": "Model the stated outflow against liquid reserve availability and test the operational redemption path.",
      "population": "All issued tokenised claims.",
      "evidence": "Liquidity analysis, redemption test records.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A stress in which redemption misses the stated period, or a path never operationally tested."
    },
    {
      "code": "C35.03",
      "domain": "C35",
      "name": "Independent attestation and publication",
      "requirement": "Reserve attestations are performed by an independent party on the stated cycle and published as required.",
      "test": "Inspect attestation scope, independence and publication timing.",
      "population": "All attestation cycles in the period.",
      "evidence": "Attestation reports, engagement letters, publication records.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "manual",
      "failure": "An attestation narrower in scope than the regime requires, or published late."
    },
    {
      "code": "C36.01",
      "domain": "C36",
      "name": "Intraday position visibility",
      "requirement": "Intraday liquidity positions and throughput are visible during the day, at the granularity needed to act.",
      "test": "Observe intraday monitoring in operation and reperform peak usage calculation for two dates.",
      "population": "All currencies and settlement accounts material to intraday flow.",
      "evidence": "Intraday reports, system screens, calculation workings.",
      "method": "observation",
      "frequency": "quarterly",
      "automation": "automated",
      "failure": "Intraday exposure known only from next-day reporting."
    },
    {
      "code": "C36.02",
      "domain": "C36",
      "name": "Collateral eligibility and valuation",
      "requirement": "Pledged collateral is eligible, correctly valued, and haircuts are applied as approved.",
      "test": "Reperform valuation and haircut application on a sample of pledged positions.",
      "population": "All pledged collateral.",
      "evidence": "Collateral records, valuation sources, haircut schedule.",
      "method": "reperformance",
      "frequency": "monthly",
      "automation": "assisted",
      "failure": "Ineligible collateral pledged, or a haircut applied below the approved level."
    },
    {
      "code": "C36.03",
      "domain": "C36",
      "name": "Margin call response within window",
      "requirement": "Margin calls are met inside the contractual window with disputes raised on a recorded path.",
      "test": "Test calls received in the period against response times and dispute records.",
      "population": "All margin calls, full population.",
      "evidence": "Call notices, settlement evidence, dispute log.",
      "method": "inspection",
      "frequency": "monthly",
      "automation": "automated",
      "failure": "A call met late, or a dispute raised without following the contractual path."
    },
    {
      "code": "C37.01",
      "domain": "C37",
      "name": "Report-to-ledger reconciliation",
      "requirement": "Regulatory and financial report lines reconcile to the general ledger with differences explained.",
      "test": "Reperform reconciliation for a sample of report lines across two periods.",
      "population": "All in-scope regulatory and financial reports.",
      "evidence": "Report submissions, ledger extracts, reconciliation workings.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "An unexplained difference, or a reconciliation performed only at aggregate level."
    },
    {
      "code": "C37.02",
      "domain": "C37",
      "name": "Record immutability and retrieval",
      "requirement": "Records required to be preserved in non-rewriteable form are stored accordingly and retrievable on request.",
      "test": "Attempt controlled amendment of a preserved record and test retrieval timing.",
      "population": "All record classes subject to preservation requirements.",
      "evidence": "Storage configuration, amendment test, retrieval log.",
      "method": "reperformance",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "A preserved record that can be altered, or retrieval outside the required period."
    },
    {
      "code": "C37.03",
      "domain": "C37",
      "name": "Manual adjustment transparency",
      "requirement": "Adjustments made outside the source system are approved, documented and visible in the lineage.",
      "test": "Test all adjustments above threshold for approval and lineage visibility.",
      "population": "All adjustments above threshold, full population.",
      "evidence": "Adjustment log, approvals, lineage records.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "An adjustment invisible in lineage, or approved after submission."
    },
    {
      "code": "C38.01",
      "domain": "C38",
      "name": "List update to screening latency",
      "requirement": "List changes are live in screening inside the stated window, and the window is measured, not assumed.",
      "test": "Measure publication-to-live time for every list update in the period, including intraday designations.",
      "population": "All list updates, full population.",
      "evidence": "List ingestion logs, screening configuration history.",
      "method": "automated",
      "frequency": "continuous",
      "automation": "automated",
      "failure": "Any designation live in screening later than the stated window."
    },
    {
      "code": "C38.02",
      "domain": "C38",
      "name": "Ownership, control and wallet screening",
      "requirement": "Screening reaches beneficial ownership and control, and, where relevant, digital asset addresses and counterparties.",
      "test": "Test the screening population against ownership data and, for digital assets, address screening coverage.",
      "population": "All customers, counterparties and, where applicable, addresses transacted.",
      "evidence": "Screening scope configuration, ownership data, address screening reports.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "automated",
      "failure": "Name-only screening where ownership thresholds apply, or unscreened addresses transacted."
    },
    {
      "code": "C38.03",
      "domain": "C38",
      "name": "Match handling and false-positive discipline",
      "requirement": "Potential matches are reviewed on a recorded path, and tuning to reduce false positives is approved and tested.",
      "test": "Sample discounted matches for rationale and reperform two tuning changes for suppressed true matches.",
      "population": "All potential matches in the period.",
      "evidence": "Match records, discount rationales, tuning approvals.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A discounted match with no rationale, or tuning that suppresses a true match."
    },
    {
      "code": "C39.01",
      "domain": "C39",
      "name": "Token estate register completeness",
      "requirement": "Every token type in production — network token, gateway or vault token, processor token — is registered with its owning legal entity, requestor identity and accountable owner.",
      "test": "Reconcile acceptance channels and stored-credential flows to the token register, and confirm each register entry resolves to a named owner in post at the test date.",
      "population": "All acceptance channels and all stored-credential flows; full population.",
      "evidence": "Token register extract, channel inventory, provider configuration exports, accountability map.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "Any production token type absent from the register, or registered against an entity or owner that no longer exists."
    },
    {
      "code": "C39.02",
      "domain": "C39",
      "name": "Token requestor identity governance",
      "requirement": "Each token requestor identity is registered to one legal entity, scoped to approved channels, and re-confirmed on change of relationship or ownership.",
      "test": "Inspect requestor registrations against the entity register and channel approvals; confirm no identity is shared across entities or used outside its approved scope.",
      "population": "All registered requestor identities.",
      "evidence": "Requestor registration records, entity register, channel approval records.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "manual",
      "failure": "A requestor identity shared across entities, used outside approved scope, or with no accountable owner."
    },
    {
      "code": "C39.03",
      "domain": "C39",
      "name": "Provisioning identification and verification evidenced",
      "requirement": "The identification-and-verification decision rule is versioned, and the rule in force on any past date can be reproduced with the outcomes recorded against it.",
      "test": "Select provisioning attempts across the period and reperform the decision against the versioned rule in force on each date; reconcile step-up channel to the contact record as it stood before the attempt.",
      "population": "All provisioning attempts in the period, sampled by outcome and by channel.",
      "evidence": "Decision rule version history, provisioning decision logs, step-up delivery records, contact change history.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "An approval that cannot be reproduced from the rule in force, or step-up delivered to a contact detail changed inside the exposure window."
    },
    {
      "code": "C39.04",
      "domain": "C39",
      "name": "Lifecycle event propagation",
      "requirement": "Reissue, block, close, suspend and portfolio-migration events propagate to every affected token inside the stated service level, with exceptions aged and owned.",
      "test": "Trace all lifecycle events in the period to token state changes and measure event-to-propagation time; age every unpropagated token.",
      "population": "All lifecycle events in the period; full population.",
      "evidence": "Lifecycle event log, token state history, exception ageing report.",
      "method": "automated",
      "frequency": "continuous",
      "automation": "automated",
      "failure": "Any token still transactable against a credential that was closed, blocked or reissued outside the stated window."
    },
    {
      "code": "C39.05",
      "domain": "C39",
      "name": "Token-to-credential reconciliation",
      "requirement": "The full active token population reconciles to the active credential population, with every mismatch investigated rather than netted off.",
      "test": "Run the reconciliation in both directions on the full population and confirm each break has an owner, a cause and a closure date.",
      "population": "All active tokens and all active credentials; no sampling.",
      "evidence": "Reconciliation output, break register, closure evidence.",
      "method": "automated",
      "frequency": "monthly",
      "automation": "automated",
      "failure": "A reconciliation performed on a sample, or a break carried forward without cause or owner."
    },
    {
      "code": "C39.06",
      "domain": "C39",
      "name": "Domain restriction and authentication data verified",
      "requirement": "Domain and transaction-type restrictions match the acceptance channels actually in use, and authentication data accompanying a token is verified rather than assumed.",
      "test": "Attempt controlled use outside the approved domain in a test environment, and sample production authorisations to confirm the expected indicator and cryptogram set was present and acted upon.",
      "population": "All acceptance channels; production sample per channel.",
      "evidence": "Restriction configuration, negative test results, authorisation message extracts, decline records.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A token accepted outside its approved domain, or accepted where the required authentication data was absent or invalid."
    },
    {
      "code": "C39.07",
      "domain": "C39",
      "name": "De-tokenisation enumerated and scope substantiated",
      "requirement": "Every system and identity able to retrieve or reconstruct an account number is enumerated, access is recertified, retrievals are logged to an accountable user, and the asserted compliance scope boundary contains that capability.",
      "test": "Walk the cardholder data flow against live configuration, enumerate de-tokenisation capability, and reconcile it to the asserted scope boundary and the current access recertification.",
      "population": "All systems inside and adjacent to the asserted scope boundary.",
      "evidence": "Current data-flow diagram, configuration export, de-tokenisation access list, retrieval logs, recertification records.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "De-tokenisation capability outside the asserted boundary, an unlogged retrieval, or a diagram that does not match live configuration."
    },
    {
      "code": "C39.08",
      "domain": "C39",
      "name": "Vault key custody and tested recovery",
      "requirement": "Token vault keys are held under split knowledge with evidenced rotation, and recovery has been exercised against the documented procedure within the last twelve months.",
      "test": "Inspect key ceremony and rotation records and custodian separation, then observe a recovery rehearsal end to end.",
      "population": "All vaults holding token-to-account mappings.",
      "evidence": "Key ceremony records, rotation logs, custodian register, rehearsal observation notes.",
      "method": "observation",
      "frequency": "annual",
      "automation": "manual",
      "failure": "Rotation not evidenced, custody held by a single individual, or a recovery that has never been exercised."
    },
    {
      "code": "C39.09",
      "domain": "C39",
      "name": "Dispute liability position evidenced from live messages",
      "requirement": "The liability position for each acceptance channel is documented against indicators actually observed in production authorisation messages, not inferred from a scheme summary.",
      "test": "Sample disputes lost in the period and trace the authorisation message field by field to establish which indicators were present at authorisation.",
      "population": "All disputes lost in the period, sampled by channel and reason code.",
      "evidence": "Dispute records, authorisation message extracts, channel liability documentation.",
      "method": "reperformance",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A liability assumption contradicted by the message data, or indicators dropped in transmission with no owner for the resulting exposure."
    },
    {
      "code": "C39.10",
      "domain": "C39",
      "name": "Token provider concentration and tested exit",
      "requirement": "Each vault or token service dependency has a criticality assessment, a substitutability position and a migration path that has been tested, not merely drafted.",
      "test": "Reconcile token dependencies to the third-party register and inspect the most recent exit or migration test for each critical provider.",
      "population": "All vault and token service providers.",
      "evidence": "Third-party register entries, criticality assessments, migration test results.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "manual",
      "failure": "A critical token dependency with no tested migration path, or credentials that cannot be moved without cardholder re-entry."
    },
    {
      "code": "C39.11",
      "domain": "C39",
      "name": "Fraud telemetry separated by token path",
      "requirement": "Fraud and dispute rates are reported separately for token-initiated, credential-on-file and agent-initiated flows.",
      "test": "Reperform the reporting split from source transaction data and confirm each path is separately visible in management reporting.",
      "population": "All transactions in the period.",
      "evidence": "Transaction extracts, fraud reporting pack, reporting logic.",
      "method": "reperformance",
      "frequency": "monthly",
      "automation": "automated",
      "failure": "A blended rate presented to management where a single path is deteriorating inside it."
    },
    {
      "code": "C39.12",
      "domain": "C39",
      "name": "Agent mandate retrievable with the transaction",
      "requirement": "Where software agents transact against a stored credential, the mandate — scope, limit, expiry and revocation path — is retrievable alongside the transaction record.",
      "test": "Sample agent-initiated transactions and retrieve the authorising mandate, confirming limit and expiry were satisfied and revocation was available.",
      "population": "All agent-initiated transactions in the period.",
      "evidence": "Mandate records, transaction records, revocation logs.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "An agent-initiated transaction with no retrievable mandate, or one executed outside a stated limit or after expiry."
    },
    {
      "code": "C40.01",
      "domain": "C40",
      "name": "Disclosure population is defined and owned",
      "requirement": "Every datapoint the entity intends to disclose is listed, mapped to its standard reference, and resolves to one named owner in post at the test date.",
      "test": "Reconcile the intended disclosure list to the standard's datapoint index and to the accountability map; confirm each entry has a single named owner.",
      "population": "All datapoints intended for disclosure; full population, no sampling.",
      "evidence": "Disclosure inventory, standard mapping worksheet, accountability map, organisation chart.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A datapoint disclosed that is absent from the inventory, or an inventory entry owned by a committee, a function or a vacant post."
    },
    {
      "code": "C40.02",
      "domain": "C40",
      "name": "Restatement control on changed definitions",
      "requirement": "Where a datapoint definition changed between standard versions, prior-period figures are recomputed on the new basis and the restatement is documented and approved before publication.",
      "test": "Select every datapoint flagged as reshaped and reperform the comparative on the current definition; confirm approval predates the statement date.",
      "population": "All datapoints whose definition, boundary or unit changed in the period.",
      "evidence": "Definition change log, restatement workpapers, approval record, prior statement extract.",
      "method": "reperformance",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "A comparative presented on the superseded basis, or a restatement approved after the statement was issued."
    },
    {
      "code": "C40.03",
      "domain": "C40",
      "name": "Source-to-disclosure lineage without reconstruction",
      "requirement": "Any disclosed figure can be traced to source system records through every transformation, on demand, without a manual reconstruction exercise.",
      "test": "Select ten disclosed figures at random and trace each to source within the stated service level; record elapsed time and any step that required reconstruction.",
      "population": "All disclosed quantitative datapoints.",
      "evidence": "Lineage records, source extracts with as-at dates, transformation logs.",
      "method": "reperformance",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "A figure whose trace requires rebuilding a workbook, or a step whose owner has left with no successor record."
    },
    {
      "code": "C40.04",
      "domain": "C40",
      "name": "Consolidation perimeter reconciles to the financial boundary",
      "requirement": "The sustainability reporting perimeter is stated, reconciled to the financial consolidation, and every difference is explained and approved.",
      "test": "Reconcile entity and site lists across both perimeters and inspect the approval for each difference.",
      "population": "All entities, sites and joint arrangements in either perimeter.",
      "evidence": "Perimeter schedule, consolidation list, difference log with approvals.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "manual",
      "failure": "An unexplained difference between the two perimeters, or a site included in one and silently omitted from the other."
    },
    {
      "code": "C40.05",
      "domain": "C40",
      "name": "Factor and method versioning is reproducible",
      "requirement": "Every conversion factor, emission factor and allocation method is versioned, and the version applied to any past period can be reproduced.",
      "test": "Recompute a prior-period figure using the factor version recorded as in force at that date and compare to the published value.",
      "population": "All factors and methods used in the current and comparative periods.",
      "evidence": "Factor register with version history, methodology notes, recomputation output.",
      "method": "reperformance",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "Factors updated in place with no history, or a recomputation that cannot reproduce the published figure."
    },
    {
      "code": "C40.06",
      "domain": "C40",
      "name": "Estimated values are marked and quantified",
      "requirement": "Each disclosed figure states the proportion that is estimated or modelled, with the method and the trigger that permits estimation.",
      "test": "For each quantitative datapoint, confirm the estimated proportion is recorded internally and disclosed where material.",
      "population": "All quantitative datapoints containing any estimated component.",
      "evidence": "Estimation policy, per-datapoint estimation record, disclosure text.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "Metered and estimated values combined into one figure presented with uniform confidence, or an estimate with no stated method."
    },
    {
      "code": "C40.07",
      "domain": "C40",
      "name": "Value-chain submissions carry provenance",
      "requirement": "Where a figure rests on a supplier submission, the submission, its date, the submitting entity and the basis on which it was accepted are held.",
      "test": "Sample value-chain figures and retrieve the underlying submission with its acceptance record; confirm response rates are reported on the population actually contacted.",
      "population": "All value-chain datapoints resting on third-party submissions.",
      "evidence": "Supplier submissions, acceptance records, request log, response-rate calculation.",
      "method": "inspection",
      "frequency": "semi-annual",
      "automation": "assisted",
      "failure": "A supplier figure with no retrievable submission, or a coverage percentage computed as though non-responses were responses."
    },
    {
      "code": "C40.08",
      "domain": "C40",
      "name": "Data requests respect the smaller-undertaking ceiling",
      "requirement": "Information requested from smaller suppliers stays within the applicable voluntary-standard ceiling, and requests exceeding it are approved and justified.",
      "test": "Inspect current questionnaire versions against the ceiling and review the approval for any request that exceeds it.",
      "population": "All standing data requests issued to suppliers below the reporting threshold.",
      "evidence": "Questionnaire versions, request log, approvals, supplier objections received.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "manual",
      "failure": "A standing request exceeding the ceiling with no approval, or supplier objections received and not escalated."
    },
    {
      "code": "C40.09",
      "domain": "C40",
      "name": "Transition plan milestones are funded and owned",
      "requirement": "Each quantified milestone in the published transition plan reconciles to an approved capital plan line and a named accountable executive, with variance recorded when it moves.",
      "test": "Trace every published milestone to the capital plan and the accountability map, and inspect the variance record for any milestone changed since last publication.",
      "population": "All quantified milestones in the published plan.",
      "evidence": "Published plan, approved capital plan, board minutes, variance log.",
      "method": "reperformance",
      "frequency": "annual",
      "automation": "manual",
      "failure": "A published milestone with no funded line, no named owner, or a movement that was never recorded as a variance."
    },
    {
      "code": "C40.10",
      "domain": "C40",
      "name": "Public claims resolve to a substantiating control",
      "requirement": "Every public sustainability claim, wherever it appears, is registered and traced to the disclosed figure and the control that substantiates it.",
      "test": "Sweep public surfaces — website, marketing, fund documentation, tender responses — and trace each claim found to the register and to its substantiating control.",
      "population": "All external surfaces carrying sustainability claims.",
      "evidence": "Claim register, surface sweep output, substantiation mapping, approval records.",
      "method": "inspection",
      "frequency": "quarterly",
      "automation": "assisted",
      "failure": "A live claim absent from the register, or a claim stronger than the disclosed figure it derives from."
    },
    {
      "code": "C40.11",
      "domain": "C40",
      "name": "Individual sign-off before statement approval",
      "requirement": "Each disclosed figure carries a recorded sign-off from the individual accountable, dated before the statement is approved.",
      "test": "Reconcile the sign-off register to the disclosure inventory and compare sign-off dates to the approval date.",
      "population": "All disclosed datapoints; full population.",
      "evidence": "Sign-off register, disclosure inventory, board or committee approval minutes.",
      "method": "inspection",
      "frequency": "annual",
      "automation": "automated",
      "failure": "A figure with no individual sign-off, a sign-off dated after approval, or collective approval standing in place of individual accountability."
    },
    {
      "code": "C40.12",
      "domain": "C40",
      "name": "Assurance pack assembles from held evidence",
      "requirement": "The limited-assurance pack is assembled from evidence already held, within the stated service level, rather than created during fieldwork.",
      "test": "Run an unannounced assembly for a selected topical standard and measure elapsed time and the proportion of items created rather than retrieved.",
      "population": "One topical standard per cycle, selected by the reviewer.",
      "evidence": "Assembly output, evidence vault references, creation-versus-retrieval log.",
      "method": "reperformance",
      "frequency": "annual",
      "automation": "assisted",
      "failure": "Any material proportion of the pack written for the first time during assembly, or assembly exceeding the stated service level."
    }
  ],
  "rails": [
    {
      "id": "correspondent",
      "name": "Correspondent banking",
      "era": "legacy",
      "railClass": "Correspondent banking",
      "role": "Cross-border value movement through nostro and vostro relationships, still the default path where no direct scheme access exists.",
      "obligation": "Respondent due diligence, nesting transparency, complete originator and beneficiary information, and sanctions screening on every leg.",
      "finality": "No single finality point — each leg settles on its own domestic rail, so exposure persists until the last leg completes.",
      "failure": "Nested relationships the institution never diligenced, and field stripping that removes the information screening depends on.",
      "domains": [
        "C32",
        "C38",
        "C20"
      ]
    },
    {
      "id": "ach-sepa",
      "name": "Retail clearing (ACH, SEPA, BACS)",
      "era": "legacy",
      "railClass": "Retail clearing",
      "role": "Batch retail credit and debit clearing, the volume backbone of domestic payments.",
      "obligation": "Authorisation controls, return and reversal handling inside scheme windows, and reconciliation of instructed to settled counts.",
      "finality": "Settlement at cycle net, with a return window in which a completed payment can still be reversed.",
      "failure": "Duplicate file submission and mandate failures found after settlement rather than before release.",
      "domains": [
        "C16",
        "C30",
        "C37"
      ]
    },
    {
      "id": "cards",
      "name": "Card networks",
      "era": "legacy",
      "railClass": "Card networks",
      "role": "Four-party authorisation, clearing and settlement for card-present and card-not-present acceptance, now largely token-mediated rather than account-number-mediated.",
      "obligation": "Scheme rule compliance, chargeback and dispute handling within stated windows, cardholder data protection, and evidence that the token estate maps to live credentials.",
      "finality": "Authorisation is not settlement — funds are provisional until clearing, and disputable long after.",
      "failure": "Dispute exposure that is not provisioned, authorisation controls that assume a successful auth means a good transaction, and tokens that outlive the credential they were minted against.",
      "domains": [
        "C16",
        "C34",
        "C30",
        "C39"
      ]
    },
    {
      "id": "network-tokenisation",
      "name": "Network tokenisation",
      "era": "hybrid",
      "railClass": "Card networks",
      "role": "Replacement of the account number with a domain-restricted network token, provisioned to a device, wallet, merchant or platform under a registered token requestor identity.",
      "obligation": "Token requestor governance, provisioning identification and verification, lifecycle propagation on reissue and closure, token-to-credential reconciliation, and substantiation of any compliance scope reduction claimed.",
      "finality": "None of its own — the token changes who can be proven to have authorised the transaction, not when value becomes final.",
      "failure": "Provisioning fraud where verification was relaxed for approval rates, orphaned tokens after reissue, and liability positions assumed from scheme summaries rather than from indicators actually present in the authorisation message.",
      "domains": [
        "C39",
        "C16",
        "C34",
        "C22"
      ]
    },
    {
      "id": "rtgs",
      "name": "High-value RTGS",
      "era": "legacy",
      "railClass": "High value / RTGS",
      "role": "Real-time gross settlement of large-value domestic payments across central bank accounts.",
      "obligation": "Intraday liquidity management, throughput monitoring, and cut-off discipline against the operator's timetable.",
      "finality": "Irrevocable on settlement in central bank money — there is no unwind path once posted.",
      "failure": "Intraday exposure known only from next-day reporting, and a missed cut-off that leaves an obligation unfunded overnight.",
      "domains": [
        "C36",
        "C30",
        "C22"
      ]
    },
    {
      "id": "messaging",
      "name": "Financial messaging infrastructure",
      "era": "legacy",
      "railClass": "Messaging",
      "role": "The instruction layer beneath most rails — the payment message is not the payment, but nothing moves without it.",
      "obligation": "Mandatory security controls attested with independent assessment, access segregation, and message integrity.",
      "finality": "None — a delivered message conveys instruction, not settlement.",
      "failure": "Treating message acknowledgement as finality, and self-attesting infrastructure controls with no independent assessment.",
      "domains": [
        "C32",
        "C21",
        "C23"
      ]
    },
    {
      "id": "cls",
      "name": "FX settlement (PvP)",
      "era": "legacy",
      "railClass": "FX settlement",
      "role": "Payment-versus-payment settlement that removes principal risk from FX trades in eligible currencies.",
      "obligation": "Settlement risk measurement on the ineligible-currency residue, and pay-in schedule discipline.",
      "finality": "Simultaneous final for eligible pairs; the residue settles gross and carries full principal risk.",
      "failure": "Reporting FX settlement risk as eliminated when a material share of volume settles outside the PvP mechanism.",
      "domains": [
        "C17",
        "C36",
        "C19"
      ]
    },
    {
      "id": "csd",
      "name": "Securities settlement and CSDs",
      "era": "hybrid",
      "railClass": "Securities settlement",
      "role": "Delivery-versus-payment settlement, custody chains and corporate action processing for securities positions.",
      "obligation": "Settlement discipline, fail penalty exposure, membership rulebook obligations, and client asset segregation.",
      "finality": "Book-entry transfer at the CSD, with the shortened cycle compressing the window for error correction to near zero.",
      "failure": "Fails aged past tolerance with no escalation, and a shortened cycle absorbed by manual effort rather than control.",
      "domains": [
        "C17",
        "C31",
        "C37"
      ]
    },
    {
      "id": "ccp",
      "name": "Derivatives clearing (CCPs)",
      "era": "hybrid",
      "railClass": "Derivatives clearing",
      "role": "Central counterparty novation, margining and default management for cleared derivatives.",
      "obligation": "Margin call response inside contractual windows, collateral eligibility, and default fund contribution management.",
      "finality": "Novation is final; the exposure that follows is a margin obligation, not a settled position.",
      "failure": "A margin call met late, or collateral pledged that is ineligible or valued without the approved haircut.",
      "domains": [
        "C36",
        "C19",
        "C20"
      ]
    },
    {
      "id": "instant",
      "name": "Instant payments",
      "era": "hybrid",
      "railClass": "Instant payments",
      "role": "Twenty-four hour irrevocable retail and business credit transfers with immediate availability.",
      "obligation": "Real-time screening and fraud intervention, and continuous availability against the scheme's uptime obligation.",
      "finality": "Immediate and irrevocable — recovery depends on the beneficiary bank's cooperation, not on a scheme unwind.",
      "failure": "Authorised push payment fraud, where the control set detects unauthorised access but not a deceived customer.",
      "domains": [
        "C34",
        "C16",
        "C22"
      ]
    },
    {
      "id": "stablecoin",
      "name": "Tokenised money and stablecoins",
      "era": "digital",
      "railClass": "Tokenised money",
      "role": "Bearer-style claims on reserve assets, used for settlement across venues and increasingly between institutions.",
      "obligation": "Reserve composition within mandate, redemption at par inside the stated period, and independent attestation.",
      "finality": "On-chain transfer is technically final; the legal claim on reserves is what actually determines value received.",
      "failure": "A reserve within mandate at month end and outside it during the month, and redemption tested on paper only.",
      "domains": [
        "C35",
        "C18",
        "C31"
      ]
    },
    {
      "id": "deposit-token",
      "name": "Tokenised deposits",
      "era": "digital",
      "railClass": "Tokenised money",
      "role": "Bank deposit liabilities represented on a programmable ledger for intraday and cross-entity settlement.",
      "obligation": "Books-and-records parity with the token record, capital and liquidity treatment, and programmability controls.",
      "finality": "Final in bank money on the issuing institution's ledger, subject to the parity between token and ledger holding.",
      "failure": "A parity break that survives a cycle, or programmatic transfer logic deployed without change control.",
      "domains": [
        "C18",
        "C37",
        "C19"
      ]
    },
    {
      "id": "tokenised-securities",
      "name": "Tokenised securities",
      "era": "digital",
      "railClass": "Tokenised securities",
      "role": "Securities issued or represented on distributed ledgers, with servicing and settlement executed in code.",
      "obligation": "Title and enforceability in the governing forum, custody segregation at address level, and smart contract change control.",
      "finality": "Depends entirely on the legal characterisation of the ledger entry, which is often assumed rather than assessed.",
      "failure": "Enforceability resting on assumption, and deployed bytecode that differs from the audited artefact.",
      "domains": [
        "C25",
        "C18",
        "C31"
      ]
    },
    {
      "id": "dlt-settlement",
      "name": "DLT settlement networks",
      "era": "digital",
      "railClass": "Digital settlement",
      "role": "Atomic delivery-versus-payment across tokenised cash and asset legs on a shared or permissioned ledger.",
      "obligation": "Operational resilience of the network operator, key quorum, and a stated finality position in the rulebook.",
      "finality": "Atomic where both legs are on-ledger; where one leg is off-ledger the atomicity claim does not hold.",
      "failure": "Marketing atomicity while one leg settles on a conventional rail, reintroducing the risk the design removed.",
      "domains": [
        "C18",
        "C30",
        "C20"
      ]
    }
  ]
}