Controls that cannot leave the platform are not infrastructure.
Assurance work is done by several parties at once — an institution, its auditors, its regulators and, increasingly, its counterparties. Each of them holds part of the record in a different system. The interchange publishes the reference spine in machine-readable form so mappings are built against a stable identifier rather than against a spreadsheet someone emailed in March.
Endpoint
GET https://cabierconsulting.com/api/public/assurance/controls GET https://cabierconsulting.com/api/public/assurance/controls?domain=C15 GET https://cabierconsulting.com/api/public/assurance/controls?layer=legal&include=domains,controls
Parameters
- domain
- Restrict to one domain code, C01 through C38. Example: ?domain=C15
- layer
- Restrict to a control layer: governance, operational, technology, financial, conduct, legal, market infrastructure.
- include
- Comma-separated sections to return: domains, controls, rails. Defaults to all three.
Each control carries its own test
The fields are the point, not the count
A control record returns the requirement, the test procedure, the population the test must run on, the evidence that satisfies it, the method, the frequency, the automation posture and the condition that constitutes failure. A mapping built on those fields survives a framework rename. A mapping built on titles does not.
Deliberately withheld
- Effectiveness grading and the rubric behind it
- Sample-size derivation
- Resilience scoring weights and dimension composition
- The gated portion of the control library
- Any client evidence, obligation register or attestation record
Authenticated interchange — obligation register, evidence pointers, attestation state and supervisory pack assembly — runs inside a client instance under contract, not on a public endpoint.
Discuss authenticated interchange