Mapping
Review AI-suggested mappings, approve them, then see how each requirement is supported across processes, controls, policies, and evidence.
Requirement coverage19 of 19 shown2 compliant6 partial10 gap
| Ref | Regulatory requirement | Process | Controls | Policy / procedure | Evidence | Status | Scope | |
|---|---|---|---|---|---|---|---|---|
SYSC 15A.2.5 | A firm must identify its important business services by considering whether their disruption could cause intolerable harm to consumers or risk to market integrity. | — | — | Operational Resilience Framework | 1 valid | Partial | Country-specific UK | |
SYSC 15A.5.1 | A firm must carry out scenario testing to assess its ability to remain within its impact tolerances for each important business service in severe but plausible disruption. | — | — | Information Security Policy | None | Partial | Country-specific UK | |
PRIN 2A (Consumer Duty) | A firm must act to deliver good outcomes for retail customers. | — | — | — | None | Gap | Country-specific UK | |
SUP 15.3 | A firm must notify the FCA immediately of any matter that could have a significant adverse impact on the firm or its customers. | — | — | — | None | Gap | Country-specific UK | |
Art. 5(1) | Financial entities shall have an internal governance and control framework that ensures effective and prudent management of ICT risk. | — | C-031 | Operational Resilience Framework | 1 valid | Compliant | Regional FRIENLDE | |
Art. 6(1) | Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system. | — | C-031 | Information Security Policy | 1 valid | Compliant | Regional FRIENLDE | |
Art. 6(2) | The ICT risk management framework shall include at least strategies, policies, procedures, ICT protocols and tools necessary to duly and adequately protect all information assets and ICT assets. | — | — | — | None | Gap | Regional FRIENLDE | |
Art. 6(5) | The ICT risk management framework shall be documented and reviewed at least once a year, as well as upon the occurrence of major ICT-related incidents. | — | — | — | None | Gap | Regional FRIENLDE | |
Art. 28(1) | Financial entities shall manage ICT third-party risk as an integral component of ICT risk, including a documented strategy for ICT third-party risk. | — | — | — | None | Gap | Regional FRIENLDE | |
Art. 11(6) | Financial entities shall test ICT business continuity plans and ICT response and recovery plans in respect of ICT systems supporting all functions at least yearly. | — | — | — | None | Gap | Regional FRIENLDE | |
Recital 27 | In line with the principle of proportionality, the ICT risk management framework should reflect the size, business profile, and risk appetite of the financial entity. | — | — | — | None | N/A | Global | |
Art. 32(1) | The controller and processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. | — | — | Operational Resilience Framework | None | Partial | Global | |
Art. 33(1) | In the case of a personal data breach, the controller shall notify the supervisory authority not later than 72 hours after having become aware of it. | — | — | Information Security Policy | None | Partial | Regional FRIENLDE | |
Art. 30 | Each controller shall maintain a record of processing activities under its responsibility. | — | — | — | None | Gap | Global | |
Art. 21(2)(a) | Essential and important entities shall take measures including policies on risk analysis and information system security. | — | — | Operational Resilience Framework | None | Partial | Country-specific FRIENLDE | |
Art. 21(2)(b) | Measures shall include incident handling. | — | — | Information Security Policy | None | Partial | Country-specific FRIENLDE | |
Art. 23 | Entities shall notify, without undue delay, the CSIRT or competent authority of any incident having a significant impact (early warning within 24 hours). | — | — | — | None | Gap | Country-specific FRIENLDE | |
Art. 21(2)(d) | Measures shall include supply chain security, including security-related aspects of relationships with direct suppliers or service providers. | — | — | — | None | Gap | Country-specific FRIENLDE | |
Art. 20 | Management bodies of essential and important entities shall approve the cybersecurity risk-management measures and oversee their implementation. | — | — | — | None | Gap | Country-specific FRIENLDE |