Module · Control Library

    One control library. Every framework it satisfies.

    Institutions do not have a DORA programme, a NIS2 programme and an SR 11-7 programme. They have one control estate that several supervisors read differently. The library is written once, mapped many times, and graded for effectiveness rather than presence.

    GOV-01

    Named executive accountability per material obligation

    Governance
    SMCR
    DORA
    OSFI E-23
    GOV-07

    Board reporting cadence with evidence-backed resilience position

    Governance
    DORA
    Basel III
    TPR-03

    Critical-provider register with substitutability assessment

    Third party
    DORA
    OSFI E-23
    NIS2
    TPR-11

    Concentration risk thresholds and exit-plan testing

    Third party
    DORA
    Basel III
    ITG-04

    Change authorisation with segregation of duties evidence

    IT general controls
    ISO 27001
    NIST CSF
    ITG-09

    Privileged access recertification on a defined cycle

    IT general controls
    ISO 27001
    NIS2
    CYB-06

    Known-exploited-vulnerability remediation within supervisory window

    Cyber
    NIST CSF
    NIS2
    DORA
    CYB-14

    Incident materiality determination with documented rationale

    Cyber
    NIS2
    DORA
    RES-02

    Impact tolerances set per important business service

    Resilience
    DORA
    Basel III
    RES-08

    Severe-but-plausible scenario testing with board sign-off

    Resilience
    DORA
    Basel III
    MDL-01

    Model inventory completeness attestation

    Model risk
    SR 11-7
    OSFI E-23
    MDL-05

    Independent validation before production deployment

    Model risk
    SR 11-7
    EU AI Act
    AIG-03

    Risk classification of each AI system by jurisdiction

    AI governance
    EU AI Act
    ISO 42001
    AIG-10

    Human oversight point recorded for every material AI decision

    AI governance
    EU AI Act
    SR 11-7
    ISO 42001
    TOK-02

    Issuance authorisation and supply-integrity reconciliation

    Tokenisation
    MiCA
    TOK-06

    Reserve composition attestation with independent confirmation

    Tokenisation
    MiCA
    Basel III
    TOK-12

    Wind-down and redemption-under-stress playbook testing

    Tokenisation
    MiCA
    DORA
    FIN-04

    Sanctions screening effectiveness testing, not coverage counting

    Financial crime
    MiCA

    This is a published sample. Test procedures, evidence specifications, effectiveness rubrics and the full 150+ control set are institutional IP, released under engagement.

    Request the full library