Evidence register
Every uploaded artefact, what it supports, and where it has been used. Click any row to open it.
12
Total artefacts
9
Valid
3
Stale — refresh due
8
Used in audits / exams
| Evidence | Type | Frameworks | Requirements | Used in audits / exams | Status | |
|---|---|---|---|---|---|---|
Q1 2026 Backup Restoration Test Full restore of the production payments database to an isolated environment; RTO/RPO, integrity, and end-to-end transaction validation. Sophie Lindqvist · updated 04 Apr 2026 Unconfirmed metadata | Test report | DORA | DORA Art. 5(1)DORA Art. 6(1) | FCA Op-Res Thematic · Q1.3 KPMG DORA Readiness | Valid | |
Risk Committee minutes — Q1 2026 Quarterly Risk Committee review of ICT risk posture, including approval of the ICT risk register and remediation tracking. Priya Shah · updated 18 Mar 2026 Unconfirmed metadata | Board minutes | — | — | Board Risk Committee — ICT Resilience | Valid | |
ICT risk register v12 Current ICT risk register with inherent/residual scoring, owners, and treatment plans across all in-scope systems. Marcus Allen · updated 02 Apr 2026 Unconfirmed metadata | Register export | — | — | — | Valid | |
Hardening baseline attestation 2025 CIS-aligned hardening baseline attestation for production servers. Superseded cadence — due for 2026 refresh. James Whitfield · updated 11 Jan 2025 Unconfirmed metadata | Attestation | — | — | ISO 27001 Surveillance 2025 | Stale | |
Critical third-party register — Apr 2026 Register of critical ICT third parties with criticality tiers, exit plans, and last assessment dates. Marcus Allen · updated 01 Apr 2026 Unconfirmed metadata | Register export | — | — | KPMG DORA Readiness KPMG concentration follow-up | Valid | |
Exit plan — Tier 1 cloud provider Documented exit and substitutability plan for the primary cloud provider, including data portability and run-book. Marcus Allen · updated 12 May 2024 Unconfirmed metadata | Policy excerpt | — | — | KPMG DORA Readiness | Stale | |
Encryption-at-rest attestation 2026 Attestation that all data stores holding personal data are encrypted at rest with managed keys. Inès Tremblay · updated 20 Jan 2026 Unconfirmed metadata | Attestation | — | — | — | Valid | |
IBS register 2026 (board-approved) Important Business Services register with impact tolerances, approved by the board. Priya Shah · updated 06 Feb 2026 Unconfirmed metadata | Register export | FCA | FCA SYSC 15A.2.5 | FCA Op-Res Thematic · Q1.1 PRA SS1/21 Self-Assessment | Valid | |
Scenario test — payments outage 2025 Severe-but-plausible scenario test of a payments outage against impact tolerances. Older than 12 months. Sophie Lindqvist · updated 14 Mar 2025 Unconfirmed metadata | Test report | — | — | FCA Op-Res Thematic · Q1.3 | Stale | |
DPIA register Q1 2026 Data Protection Impact Assessment register covering high-risk processing activities. Inès Tremblay · updated 31 Mar 2026 Unconfirmed metadata | Register export | — | — | — | Valid | |
Incident runbook v6 Incident handling runbook covering detection, triage, response, and post-incident review with notification routing. Inès Tremblay · updated 09 Feb 2026 Unconfirmed metadata | Policy excerpt | — | — | — | Valid | |
Annual review sign-off — Feb 2026 Formal annual review and sign-off of the ICT risk management framework. Marcus Allen · updated 08 Feb 2026 Unconfirmed metadata | Board minutes | — | — | Board Risk Committee — ICT Resilience | Valid |