Mappings

Mapping

Review AI-suggested mappings, approve them, then see how each requirement is supported across processes, controls, policies, and evidence.

Requirement coverage19 of 19 shown2 compliant6 partial10 gap
RefRegulatory requirementProcessControlsPolicy / procedureEvidenceStatusScope
SYSC 15A.2.5
A firm must identify its important business services by considering whether their disruption could cause intolerable harm to consumers or risk to market integrity.
Operational Resilience Framework
1 valid
Partial
Country-specific
UK
SYSC 15A.5.1
A firm must carry out scenario testing to assess its ability to remain within its impact tolerances for each important business service in severe but plausible disruption.
Information Security Policy
NonePartial
Country-specific
UK
PRIN 2A (Consumer Duty)
A firm must act to deliver good outcomes for retail customers.
NoneGap
Country-specific
UK
SUP 15.3
A firm must notify the FCA immediately of any matter that could have a significant adverse impact on the firm or its customers.
NoneGap
Country-specific
UK
Art. 5(1)
Financial entities shall have an internal governance and control framework that ensures effective and prudent management of ICT risk.
C-031
Operational Resilience Framework
1 valid
Compliant
Regional
FRIENLDE
Art. 6(1)
Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system.
C-031
Information Security Policy
1 valid
Compliant
Regional
FRIENLDE
Art. 6(2)
The ICT risk management framework shall include at least strategies, policies, procedures, ICT protocols and tools necessary to duly and adequately protect all information assets and ICT assets.
NoneGap
Regional
FRIENLDE
Art. 6(5)
The ICT risk management framework shall be documented and reviewed at least once a year, as well as upon the occurrence of major ICT-related incidents.
NoneGap
Regional
FRIENLDE
Art. 28(1)
Financial entities shall manage ICT third-party risk as an integral component of ICT risk, including a documented strategy for ICT third-party risk.
NoneGap
Regional
FRIENLDE
Art. 11(6)
Financial entities shall test ICT business continuity plans and ICT response and recovery plans in respect of ICT systems supporting all functions at least yearly.
NoneGap
Regional
FRIENLDE
Recital 27
In line with the principle of proportionality, the ICT risk management framework should reflect the size, business profile, and risk appetite of the financial entity.
NoneN/A Global
Art. 32(1)
The controller and processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
Operational Resilience Framework
NonePartial Global
Art. 33(1)
In the case of a personal data breach, the controller shall notify the supervisory authority not later than 72 hours after having become aware of it.
Information Security Policy
NonePartial
Regional
FRIENLDE
Art. 30
Each controller shall maintain a record of processing activities under its responsibility.
NoneGap Global
Art. 21(2)(a)
Essential and important entities shall take measures including policies on risk analysis and information system security.
Operational Resilience Framework
NonePartial
Country-specific
FRIENLDE
Art. 21(2)(b)
Measures shall include incident handling.
Information Security Policy
NonePartial
Country-specific
FRIENLDE
Art. 23
Entities shall notify, without undue delay, the CSIRT or competent authority of any incident having a significant impact (early warning within 24 hours).
NoneGap
Country-specific
FRIENLDE
Art. 21(2)(d)
Measures shall include supply chain security, including security-related aspects of relationships with direct suppliers or service providers.
NoneGap
Country-specific
FRIENLDE
Art. 20
Management bodies of essential and important entities shall approve the cybersecurity risk-management measures and oversee their implementation.
NoneGap
Country-specific
FRIENLDE