One control library. Every framework it satisfies.
Institutions do not have a DORA programme, a NIS2 programme and an SR 11-7 programme. They have one control estate that several supervisors read differently. The library is written once, mapped many times, and graded for effectiveness rather than presence.
Named executive accountability per material obligation
Board reporting cadence with evidence-backed resilience position
Critical-provider register with substitutability assessment
Concentration risk thresholds and exit-plan testing
Change authorisation with segregation of duties evidence
Privileged access recertification on a defined cycle
Known-exploited-vulnerability remediation within supervisory window
Incident materiality determination with documented rationale
Impact tolerances set per important business service
Severe-but-plausible scenario testing with board sign-off
Model inventory completeness attestation
Independent validation before production deployment
Risk classification of each AI system by jurisdiction
Human oversight point recorded for every material AI decision
Issuance authorisation and supply-integrity reconciliation
Reserve composition attestation with independent confirmation
Wind-down and redemption-under-stress playbook testing
Sanctions screening effectiveness testing, not coverage counting
This is a published sample. Test procedures, evidence specifications, effectiveness rubrics and the full 150+ control set are institutional IP, released under engagement.
Request the full library