Resilience Spine
    Cross-cutting — IT General Controls

    ITGC as continuous attestation.

    ITGC carved-outs in SOC 2 / ISAE 3402 reports are the most common upstream cause of conduct, resilience and model-risk failures. The ITGC pack expresses every general-controls domain as a continuous attestation in the same evidence engine, with model-change ITGC bound through the AI Assurance OS registry.

    Domains

    Change management

    Segregated dev / test / prod, peer-review gates, change-advisory board evidence, emergency-change attestation.

    Logical access

    Joiner / mover / leaver, privileged-access reviews, MFA coverage, dormant-account discipline.

    Computer operations

    Job scheduling, batch monitoring, incident-to-problem linkage, backup success and restore tests.

    System development

    SDLC gating, secure-coding evidence, dependency / SBOM management, vulnerability remediation SLAs.

    Business continuity & DR

    RTO / RPO attestation, DR test cadence, dependency map, third-party continuity carve-out.

    Cloud configuration

    CIS / SCC baseline, drift detection, IaC review, secrets-management discipline.

    Model-change ITGC

    AI Assurance OS binding — model registry, change record, challenger evidence, monitoring re-baseline.

    Evidence chain

    Immutable evidence vault, hash-chain attestation, regulator-ready scoping (SR 15-18 / BCBS 239 aligned).

    Frameworks

    COBIT 2019
    Governance and management objectives — APO / BAI / DSS / MEA
    SOC 2 TSC
    Security, availability, processing integrity, confidentiality, privacy
    ISO 27001:2022
    A.5 / A.8 organisational, technical and ops controls (A.12, A.14 emphasised)
    FFIEC AIO
    Architecture, Infrastructure, Operations booklet
    NIST CSF 2.0
    Govern · Identify · Protect · Detect · Respond · Recover
    DORA RTS
    ICT risk-management framework — Articles 5–15 and RTS on sub-contracting