CABIER Global Assurance · Regulatory packs
Regulatory Packs: Canada, United States, EU, United Kingdom
Each pack maps a regulator to its instrument, the obligation it creates, the control that answers it and the evidence that proves it. The same objects sit in TrustGraph and route through AssureCore's eight Trust Gates.
Status is stated plainly. Pending or failed legislation is never presented as the operative control.
Mapping only – not legal advice. Sources link to the primary publisher. Dates are as last verified.
The chain
Starting object
Custody key compromise at a crypto trading platform
- OSFIIn forceKey date 2024-05-01
Guideline B-10, Third-Party Risk Management
Expectations for federally regulated financial institutions managing third-party arrangements across the lifecycle.
Starting object: Where a custody or wallet provider is a third party, the arrangement and its exit plan are in scope.
- Obligation
- Identify, assess and monitor material third-party arrangements, including subcontractors.
- Control
- Third-party inventory with materiality rating and exit plan per arrangement.
- Evidence
- Inventory extract, due diligence file, exit plan test record.
- OSFIIn forceKey date 2024-01-01
Guideline B-13, Technology and Cyber Risk Management
Technology and cyber risk governance, operations and resilience expectations.
Starting object: Key compromise is a technology and cyber incident requiring response and recovery.
- Obligation
- Maintain cyber controls, incident response and recovery capability proportionate to risk.
- Control
- Key management and privileged access controls with tested incident playbooks.
- Evidence
- Access review, key ceremony record, incident exercise report.
- Canadian Securities AdministratorsIn forceKey date 2023-02-22Pending primary-source verification
CSA Staff Notice 21-332, Crypto Asset Trading Platforms: Pre-Registration Undertakings
Enhanced expectations for crypto trading platforms, including custody of client assets.
Starting object: Directly engaged: custody arrangements and client asset protection.
- Obligation
- Hold client crypto assets with an acceptable custodian and segregate them.
- Control
- Custodian qualification and segregation reconciliation.
- Evidence
- Custodian assessment, daily reconciliation, insurance evidence.
- FINTRACIn forceKey date 2021-06-01
PCMLTFA regulations, virtual currency obligations
Anti-money laundering obligations for money services businesses dealing in virtual currency.
Starting object: Outflows following a compromise may trigger reporting assessment.
- Obligation
- Report suspicious transactions and large virtual currency transactions.
- Control
- Transaction monitoring with reporting workflow.
- Evidence
- Alert log, report submissions, review sign-off.
Last regulatory review: 26 September 2026
Every row below is a traversable chain.
See the relationship graph