CABIER Global Assurance · Regulatory packs

    Regulatory Packs: Canada, United States, EU, United Kingdom

    Each pack maps a regulator to its instrument, the obligation it creates, the control that answers it and the evidence that proves it. The same objects sit in TrustGraph and route through AssureCore's eight Trust Gates.

    Status is stated plainly. Pending or failed legislation is never presented as the operative control.

    Mapping only – not legal advice. Sources link to the primary publisher. Dates are as last verified.

    The chain

    RegulatorInstrumentObligationControlEvidence

    Starting object

    Custody key compromise at a crypto trading platform

    • OSFIIn forceKey date 2024-05-01

      Guideline B-10, Third-Party Risk Management

      Expectations for federally regulated financial institutions managing third-party arrangements across the lifecycle.

      Starting object: Where a custody or wallet provider is a third party, the arrangement and its exit plan are in scope.

      Obligation
      Identify, assess and monitor material third-party arrangements, including subcontractors.
      Control
      Third-party inventory with materiality rating and exit plan per arrangement.
      Evidence
      Inventory extract, due diligence file, exit plan test record.
      Primary sourceLast verified 2026-09-26Mapping only – not legal advice
    • OSFIIn forceKey date 2024-01-01

      Guideline B-13, Technology and Cyber Risk Management

      Technology and cyber risk governance, operations and resilience expectations.

      Starting object: Key compromise is a technology and cyber incident requiring response and recovery.

      Obligation
      Maintain cyber controls, incident response and recovery capability proportionate to risk.
      Control
      Key management and privileged access controls with tested incident playbooks.
      Evidence
      Access review, key ceremony record, incident exercise report.
      Primary sourceLast verified 2026-09-26Mapping only – not legal advice
    • Canadian Securities AdministratorsIn forceKey date 2023-02-22Pending primary-source verification

      CSA Staff Notice 21-332, Crypto Asset Trading Platforms: Pre-Registration Undertakings

      Enhanced expectations for crypto trading platforms, including custody of client assets.

      Starting object: Directly engaged: custody arrangements and client asset protection.

      Obligation
      Hold client crypto assets with an acceptable custodian and segregate them.
      Control
      Custodian qualification and segregation reconciliation.
      Evidence
      Custodian assessment, daily reconciliation, insurance evidence.
      Primary sourceLast verified 2026-09-26Mapping only – not legal advice
    • FINTRACIn forceKey date 2021-06-01

      PCMLTFA regulations, virtual currency obligations

      Anti-money laundering obligations for money services businesses dealing in virtual currency.

      Starting object: Outflows following a compromise may trigger reporting assessment.

      Obligation
      Report suspicious transactions and large virtual currency transactions.
      Control
      Transaction monitoring with reporting workflow.
      Evidence
      Alert log, report submissions, review sign-off.
      Primary sourceLast verified 2026-09-26Mapping only – not legal advice

    Last regulatory review: 26 September 2026

    Every row below is a traversable chain.

    See the relationship graph