One control library. Every framework it satisfies.
Institutions do not have a DORA programme, a NIS2 programme and an SR 11-7 programme. They have one control estate that several supervisors read differently. The library is written once, mapped many times, and graded for effectiveness rather than presence.
The control spine · C01 to C38
Thirty-eight domains, harmonised
Beneath the individual controls sits a spine of thirty-eight domains, spanning governance, technology, financial, conduct, legal and market infrastructure. Filter by regime to see how much of the estate a single supervisor actually reads. Open a domain to see which regime sets the binding bar, because a control tested to the weaker ask fails the stricter one.
Filter by regime
Filter by layer
Named executive accountability per material obligation
Board reporting cadence with evidence-backed resilience position
Critical-provider register with substitutability assessment
Concentration risk thresholds and exit-plan testing
Change authorisation with segregation of duties evidence
Privileged access recertification on a defined cycle
Known-exploited-vulnerability remediation within supervisory window
Incident materiality determination with documented rationale
Impact tolerances set per important business service
Severe-but-plausible scenario testing with board sign-off
Model inventory completeness attestation
Independent validation before production deployment
Risk classification of each AI system by jurisdiction
Human oversight point recorded for every material AI decision
Issuance authorisation and supply-integrity reconciliation
Reserve composition attestation with independent confirmation
Wind-down and redemption-under-stress playbook testing
Sanctions screening effectiveness testing, not coverage counting
This is a published sample. Test procedures, evidence specifications, effectiveness rubrics and the full 150+ control set are institutional IP, released under engagement.
Request the full library