Loading officer dashboard…
Loading officer dashboard…
System health, incident posture, on-call cover, and world-class capability evidence for Kenya lending operations.
| Critical operation | Impact tolerance | RTO / last drill | RPO / data loss | Dependencies | Fallback mode | Status |
|---|---|---|---|---|---|---|
Loan servicing ledger posting loan servicing ops / last drill 2026-06-21 Repayments, balances, arrears, and GL journals continue to reconcile. | No customer balance older than 30 minutes without replay evidence. | 30m / 18m | 5m / 2m | GL engine, Payment rails, Read API, File storage | Offline payment queue with ledger replay and custody hash export. | within_tolerance |
Treasury disbursement release treasury operations / last drill 2026-06-18 Approved borrowers receive funds or a clear pending-state notice. | No approved disbursement remains ambiguous for more than 20 minutes. | 20m / 14m | 2m / 1m | M-Pesa Daraja, Bank EFT, Treasury float, Notification service | Bank EFT batch with cashier suspense account and borrower notification. | within_tolerance |
Credit decision and bureau checks credit risk / last drill 2026-06-24 New applications receive either a decision, manual review, or clear wait state. | No bureau-dependent application waits more than 60 minutes without manual-review routing. | 60m / 42m | 15m / 8m | Metropol CRB, Scorecard service, Origination STP, Officer queue | Manual affordability review with adverse-action reason custody if declined. | within_tolerance |
Collections promise and hold controls collections operations / last drill 2026-06-28 Promises-to-pay, repossession holds, and hardship commitments remain enforceable. | No customer-facing collection commitment is stale for more than 45 minutes. | 45m / 31m | 10m / 4m | Collections queue, Notification service, Repo readiness, Audit events | Branch hold register with event replay and supervisor reconciliation. | within_tolerance |
Officer queue triage platform operations / last drill 2026-07-02 Branch officers can continue prioritising urgent approvals and escalations. | Priority queue refresh must recover inside 20 minutes with branch fallback. | 20m / 14m | 5m / 3m | Websocket, Read API, Auth service, Officer inbox | Polling queue board with branch escalation channel. | within_tolerance |
| Scenario | Target / actual | Data loss | Result | Evidence |
|---|---|---|---|---|
Loan servicing ledger posting Primary GL posting worker halted during repayment ingest | 30m / 18m | 5m / 2m | pass | Replay manifest balanced repayment, ledger, and audit-event counts. Automate evidence attachment to the incident record. |
Treasury disbursement release Payment callback lag while borrower notification is pending | 20m / 14m | 2m / 1m | pass | Suspense account and borrower pending-state notices reconciled. Attach bank EFT evidence to the treasury runbook. |
Credit decision and bureau checks Bureau provider latency with active branch application queue | 60m / 42m | 15m / 8m | pass | Applications routed to manual affordability queue before tolerance breach. Keep bureau-failover drills on the monthly recovery calendar. |
Officer queue triage Websocket degradation during branch peak load | 20m / 14m | 5m / 3m | pass | Polling fallback preserved priority ordering and branch escalation status. Add automatic branch banner when websocket p99 exceeds 3 seconds. |
| Provider | Failure mode | Substitute path | Evidence | Status |
|---|---|---|---|---|
M-Pesa Daraja Mobile money disbursement and repayment confirmation | API outage or delayed callback acknowledgement | Bank EFT batch plus cashier suspense reconciliation | Batch settlement playbook tested against treasury float controls. Last tested 2026-06-18. | ready |
Metropol CRB Bureau score and credit-file pull | Score pull latency or provider outage | TransUnion bureau path plus manual affordability queue | Manual-review routing and adverse-action custody verified. Last tested 2026-06-24. | ready |
SMS aggregator Borrower and officer notifications | SMS delivery lag or vendor throttling | Push, email, and alternate SMS vendor failover | Borrower notification sequencing verified with delivery-cost variance signed off. Last tested 2026-06-27. | ready |
Object storage Document, evidence, and export custody | Regional object-store write degradation | Replica bucket with custody hash manifest replay | Export manifest replay tested with examiner evidence pack. Last tested 2026-06-21. | ready |
| Operation | Telemetry signal | Ticket route | Status | Evidence hash |
|---|---|---|---|---|
Loan servicing ledger posting GL engine / 30m RTO / 5m RPO | p99 96ms / queue 8m / burn 0.42x / ledger replay queue empty | not-required Continuous SLO guard confirms loan servicing ops remains inside impact tolerance. | ready Retain telemetry snapshot with the resilience automation pack. | 6f472c08930f...0ed144ef |
Treasury disbursement release M-Pesa Daraja / 20m RTO / 2m RPO | p99 410ms / queue 9m / burn 0.71x / pending-state notice under tolerance | not-required Continuous SLO guard confirms treasury operations remains inside impact tolerance. | ready Retain telemetry snapshot with the resilience automation pack. | e72c00926623...4a018640 |
Credit decision and bureau checks Metropol CRB / 60m RTO / 15m RPO | p99 690ms / queue 33m / burn 1.12x / manual affordability queue armed | not-required Continuous SLO guard confirms credit risk remains inside impact tolerance. | ready Retain telemetry snapshot with the resilience automation pack. | 66f774d3a743...124434f5 |
Collections promise and hold controls Notification service / 45m RTO / 10m RPO | p99 240ms / queue 16m / burn 0.83x / branch hold register reconciled | not-required Continuous SLO guard confirms collections operations remains inside impact tolerance. | ready Retain telemetry snapshot with the resilience automation pack. | f3367b4d4bca...96e903c6 |
Officer queue triage Websocket / 20m RTO / 5m RPO | p99 4800ms / queue 18m / burn 1.74x / polling fallback preserving priority order | AUTO-20260707-officer-queue-triage Incident automation routes AUTO-20260707-officer-queue-triage to platform operations before customer ambiguity breaches tolerance. | monitor Keep fallback mode armed and attach ticket evidence to recovery review. | ca5af9564157...af3a271f |
| Provider | Exit route | Contract clause | Regulator notice | Custody hash |
|---|---|---|---|---|
M-Pesa Daraja Mobile money disbursement and repayment confirmation | Bank EFT batch plus cashier suspense reconciliation KCB EFT host-to-host / RUNBOOK-RES-MPESA-EXIT-2026 | DAR-BCP-14.2 step-in and callback replay treasury vendor risk signed 2026-06-19 | signed CBK-NPS-DISRUPTION-72H | 590bab115321...58e1ecd4 |
Metropol CRB Bureau score and credit-file pull | TransUnion bureau path plus manual affordability queue TransUnion Kenya CRB / RUNBOOK-RES-CRB-EXIT-2026 | CRB-BCP-9.4 alternate bureau and data-return covenant credit vendor risk signed 2026-06-25 | signed CBK-CREDIT-REPORTING-OUTAGE | e2e97694d910...825ed464 |
SMS aggregator Borrower and officer notifications | Push, email, and alternate SMS vendor failover Safaricom bulk SMS failover / RUNBOOK-RES-NOTIFY-EXIT-2026 | SMS-BCP-7.1 burst failover and cost variance approval customer operations vendor risk signed 2026-06-28 | signed CUSTOMER-COMMS-DISRUPTION-NOTICE | 0c747d2a171a...9741e6e1 |
Object storage Document, evidence, and export custody | Replica bucket with custody hash manifest replay Secondary region custody bucket / RUNBOOK-RES-STORAGE-EXIT-2026 | STOR-BCP-11.6 object lock replica and evidence return examiner platform vendor risk signed 2026-06-22 | signed EXAMINER-EVIDENCE-CUSTODY-ATTEST | b09ba2e97c2c...a558e4fe |
| Incident | Postmortem | Recovery exercise | Customer harm review | Closure | Custody hash |
|---|---|---|---|---|---|
INC-2041 Websocket / Officer queue refresh delayed in Kisumu branch | PM-2041-DRAFT /officer/admin/op-readiness#incident-log | queue-websocket-degradation Websocket degradation during branch peak load | No lost approvals; fallback polling retained priority ordering. | active review site reliability | ecb733d44cd4...72939aa9 |
INC-2038 Report engine / CBK liquidity pack generated 18 minutes late | PM-2038-CLOSED /officer/regulatory#regulatory-obligation-radar | gl-worker-halt Primary GL posting worker halted during repayment ingest | No borrower-facing harm; regulator pack retained custody hash. | closure ready regulatory operations | 3dca50e10554...6cc69ba3 |
INC-2034 Metropol CRB / Bureau checks retried for 212 applications | PM-2034-CLOSED /officer/risk/models | bureau-provider-latency Bureau provider latency with active branch application queue | Manual review notices prevented ambiguous borrower decisions. | closure ready credit risk | b70ce998333f...71d70481 |
| Provider | Criticality | Lifecycle gates | Monitoring | Data / operations | Status | Hash |
|---|---|---|---|---|---|---|
Safaricom M-Pesa Daraja Payment initiation, collections, reversals, and webhook settlement payments operations and vendor risk / Kenya | critical active | Due diligence: ready Contract: ready Subcontractors: current | SLA 99.94% / 99.50% 0 incidents / cyber 30d / finance 68d daily settlement, webhook, incident, and concentration monitoring | loan-disbursement, payment-collections payment instruction, borrower mobile number, transaction reference concentration 29.00% / exit tested | within | ab490524c45e...24161f1b |
Metropol CRB Credit bureau score pull and report enrichment credit operations and vendor risk / Kenya | critical active | Due diligence: ready Contract: ready Subcontractors: current | SLA 99.42% / 99.00% 1 incidents / cyber 45d / finance 91d daily bureau latency, retry, consent, and score-completeness monitoring | credit-decisioning national ID hash, bureau score, credit report concentration 24.00% / exit tested | within | eda1ef2e14dc...372047e7 |
AWS Africa infrastructure Primary cloud compute, storage, network edge, and backup vault platform reliability and infrastructure security / South Africa / global | critical active | Due diligence: ready Contract: ready Subcontractors: current | SLA 99.99% / 99.90% 0 incidents / cyber 22d / finance 75d continuous cloud posture, backup, resilience, and service health monitoring | loan-disbursement, credit-decisioning, payment-collections, regulatory-reporting encrypted borrower data, application logs, backup snapshots concentration 34.00% / exit tested | within | 992e6c67e46a...5c543282 |
Twilio Africa SMS aggregator SMS OTP, collections reminders, and borrower notifications customer communications and vendor risk / Kenya / EU | high active | Due diligence: ready Contract: ready Subcontractors: current | SLA 99.81% / 99.50% 0 incidents / cyber 51d / finance 100d daily OTP delivery, fraud abuse, template, and fallback route monitoring | customer-notifications phone number, notification content, delivery metadata concentration 18.00% / exit tested | within | f9a6911a3d9f...2d26ce2d |
Onfido identity verification KYC document, selfie, and fraud signal verification fraud operations and compliance / UK / EU | high active | Due diligence: ready Contract: ready Subcontractors: current | SLA 99.70% / 99.50% 0 incidents / cyber 36d / finance 120d daily KYC throughput, false-positive, SLA, and privacy-control monitoring | identity-verification, fraud-triage identity document, biometric selfie, fraud signal concentration 16.00% / exit tested | within | 98c4d6666868...3db01c02 |
SendGrid email delivery Statement, regulatory notice, and board pack notification delivery customer communications / US / EU | moderate active | Due diligence: ready Contract: ready Subcontractors: current | SLA 99.87% / 99.50% 0 incidents / cyber 60d / finance 110d weekly delivery, bounce, spoofing, and fallback template monitoring | customer-notifications email address, notification metadata concentration 11.00% / exit tested | within | b7e4b5799b8e...fb4e2f4f |
| Monitoring signal | Provider scope | Current / limit | Playbook | Status | Hash |
|---|---|---|---|---|---|
Critical provider due diligence coverage vendor risk Critical/high relationships with current due diligence | all-critical | 100.00% / 100.00% minimum limit | block onboarding or renewal until due diligence, risk acceptance, and control evidence are complete | within | 71bb0cc36ef4...d60823fb |
Critical provider contract audit and exit rights legal control and vendor risk Critical/high relationships with audit, data, subcontractor, resilience, and exit rights | all-critical | 100.00% / 100.00% minimum limit | renegotiate contract, add side letter, or exit provider before expanding critical processing | within | 6fc5b4d2fe7d...0f8c3f2d |
Highest third-party concentration exposure enterprise risk and vendor risk Largest single-provider exposure share across critical operations | AWS Africa infrastructure | 34.00% / 35.00% maximum limit | activate multi-provider strategy, reduce dependency, or document board-approved concentration exception | within | e100799b9b29...169f6763 |
Critical provider incident count vendor risk and operational risk Critical provider incidents in the prior 90 days | all-critical | 1 / 2 maximum limit | open provider remediation, customer-harm review, and operational-risk event linkage | within | d43be991c01e...70ea189c |
Oldest critical-provider cyber review application security and vendor risk Oldest cyber assurance review age for critical/high providers | all-critical | 51d / 90d maximum limit | refresh SOC report, pen test, vulnerability, access, and incident-response evidence | within | f18313182d9c...d1212021 |
Oldest provider resilience test operational resilience and vendor risk Oldest exit, fallback, or resilience test age for critical/high providers | all-critical | 70d / 180d maximum limit | run exit, fallback, substitute-route, and customer-impact exercises before board attestation | within | 6606bd2830e1...99ed6d8a |
| Lifecycle control | Stage | Mapped evidence | Status | Hash |
|---|---|---|---|---|
Third-party lifecycle governance, risk appetite, and inventory Planning, due diligence, contracting, active monitoring, termination, ownership, criticality, and board route evidence is captured for material relationships. | strategy | 3/3 3 hashes | within | 047336528c9e...7b8a7361 |
Critical service due diligence and contract rights Critical provider due diligence covers financial condition, cyber posture, operational resilience, subcontractors, audit rights, exit rights, and data obligations. | due_diligence | 2/2 2 hashes | within | f408b73f5aa3...013ade57 |
ICT third-party cyber, DORA, and operational resilience monitoring ICT providers map to cyber review recency, incident telemetry, resilience tests, API posture, and operational resilience evidence. | monitor | 3/3 3 hashes | within | 3b83ab0d0e00...c40cc43f |
Outsourced data protection, privacy, and data residency governance Providers with borrower, bureau, payment, biometric, notification, or backup data preserve lawful basis, data residency, minimisation, audit, and custody evidence. | contract | 3/3 3 hashes | within | e1a4fecb87c3...c70f1679 |
Provider concentration, substitutability, and exit readiness Critical provider concentration, substitute routes, fallback modes, tested exits, and critical operation coverage are linked to resilience packs. | resilience | 3/3 3 hashes | within | 811cda26a698...3cc7845a |
Ongoing provider SLA, incident, financial, and control monitoring Provider SLA, incident count, cyber review age, financial review age, resilience test age, customer harm, and operational-risk links are monitored. | monitor | 3/3 3 hashes | within | e37d8c303ed2...66500e91 |
Termination, exit, data return, and evidence custody Termination packs retain exit runbooks, provider notices, data return or deletion evidence, customer-impact controls, custody hashes, and board evidence. | termination | 3/3 3 hashes | within | c5c3ce62cfd8...68077449 |
| Governance gate | Metric | Current | Limit | Status | Hash |
|---|---|---|---|---|---|
Critical and high third-party relationship readiness Critical third-party relationships should be governed across the full lifecycle before they support material operations. | Critical/high providers inside due diligence, contract, monitoring, resilience, and data protection gates | 100.00% | 100.00% | within | 10e294474360...adb46744 |
Third-party planning and due diligence coverage Risk-based due diligence should assess provider capability, financial condition, cyber posture, compliance, resilience, and subcontracting. | Critical/high providers with completed risk-based due diligence | 100.00% | 100.00% | within | 9f52b532af3b...ef301a9d |
Contract rights and subcontractor inventory Contracts should preserve audit, access, data, cyber, subcontractor, resilience, termination, and exit rights. | Critical/high providers with audit rights, exit rights, and current subcontractor inventory | 100.00% | 100.00% | within | 193fd2a5f9c9...25a1f92d |
Ongoing monitoring, SLA, incident, and assurance recency Ongoing monitoring should identify provider performance, incidents, financial stress, control drift, and customer harm quickly enough for action. | Critical/high providers inside SLA, incident, cyber review, and financial review limits | 100.00% | 100.00% | within | a41c9c9238d6...b9351da7 |
Provider concentration and substitutability Provider concentration should remain inside appetite or have board-approved compensating resilience and exit controls. | Largest single-provider concentration exposure | 34.00% | 35.00% | within | 32e43f48fb6a...b47172c6 |
Resilience, exit, and termination readiness Critical providers should have tested contingency, exit, substitute-route, data-return, and customer-impact controls. | Critical/high providers with tested resilience, exit, and substitute-route evidence | 100.00% | 100.00% | within | 1dd577cceebe...0efa947e |
Third-party data protection and residency control Third-party data processing should preserve lawful basis, minimisation, residency, retention, audit, and deletion or return evidence. | Critical/high data processors with approved data residency and protection evidence | 100.00% | 100.00% | within | 20d817a97b42...585f5ddb |
Third-party controls mapped to enterprise evidence manifest Third-party risk controls should trace to resilience, cyber, operational risk, privacy, risk data, board, and assurance evidence. | Lifecycle, due diligence, ICT, privacy, concentration, monitoring, and termination controls with mapped evidence | 100.00% | 100.00% | within | 6d669e4cdfe2...dc877f46 |
Third-party evidence custody and supervisory reproducibility Third-party risk evidence should be reproducible for audit, board oversight, supervisory discussion, and provider exit. | Relationship, signal, risk-control, action, and manifest evidence with custody hashes | 100.00% | 100.00% | within | 699be74aa883...d58cfdc1 |
| Trigger | Status | Evidence | Owner | Deadline |
|---|---|---|---|---|
| No third-party risk action packs are required for the current evidence set. | ||||
| Principal | Authentication | Authorization | Review / JML | Operational control | Status | Hash |
|---|---|---|---|---|---|---|
platform.security.admin privileged / IdP and admin console identity platform | MFA yes / phishing-resistant yes | 2/2 roles SoD clear | current / 12d / JML automated | privileged / stale no / session enforced | within | 1e8696f691e9...c4e6b7ca |
credit.operations.lead workforce / LMS officer workspace credit operations | MFA yes / phishing-resistant yes | 3/3 roles SoD clear | current / 41d / JML automated | standard / stale no / session enforced | within | 954a92088533...a5ce48a8 |
customer.support.supervisor customer_support / Customer support console customer dignity operations | MFA yes / phishing-resistant yes | 2/2 roles SoD clear | current / 39d / JML automated | standard / stale no / session enforced | within | 38e1228e0229...b0d6108c |
svc.api-read-proxy service_account / Read API proxy platform reliability | MFA yes / phishing-resistant yes | 1/1 roles SoD clear | current / 18d / JML automated | privileged / stale no / session enforced | within | 3eba535f7aad...55ee25bf |
breakglass.incident.commander break_glass / Emergency admin lane security operations | MFA yes / phishing-resistant yes | 1/1 roles SoD clear | current / 7d / JML automated | privileged / stale no / session enforced | within | 017944e971e0...b8f232ca |
model.risk.validator workforce / Model governance workbench model risk | MFA yes / phishing-resistant yes | 2/2 roles SoD clear | current / 45d / JML automated | standard / stale no / session enforced | within | 80863695b753...fc0fdc72 |
| Access event | Approval | Expiry / review | Status | Hash |
|---|---|---|---|---|
privilege_grant idp-admin-1 high / 3h / approved | approved / ticket linked / evidence linked | 21h / reviewer assigned / revoke ready | within | 4e4a68da6d7e...1d776bf2 |
break_glass break-glass-1 critical / 2h / closed | approved / ticket linked / evidence linked | 0h / reviewer assigned / revoke ready | within | c6ea24bdb419...0ace50ff |
key_rotation service-api-1 medium / 6h / closed | approved / ticket linked / evidence linked | 0h / reviewer assigned / revoke ready | within | d6f051ef843a...c08c0f8d |
access_review credit-ops-1 medium / 8h / closed | approved / ticket linked / evidence linked | 0h / reviewer assigned / revoke ready | within | a59f3252b69d...ed164b2f |
session_exception customer-support-1 low / 1h / closed | approved / ticket linked / evidence linked | 0h / reviewer assigned / revoke ready | within | 8946e6454e5f...55a608c2 |
| Risk control | Stage | Mapped evidence | Status | Hash |
|---|---|---|---|---|
Identity and account inventory governance identity platform and security governance | inventory | 3/3 Workforce, privileged, service, customer-support, and break-glass principals are inventoried with owner, system, review, and custody evidence. | within | 968da36e3afa...7cef9e89 |
MFA, phishing-resistant authentication, and session policy identity platform and application security | authenticate | 3/3 MFA, phishing-resistant controls, session policy, API access, and cyber resilience evidence are joined for privileged and sensitive access. | within | c5dd0e5afed0...8ac26d99 |
Least privilege RBAC and segregation-of-duties governance security governance and business system owners | authorize | 2/2 Actual roles, least-privilege targets, SoD conflicts, customer-harm guardrails, and assurance evidence are reconciled. | within | c93442cb80dd...240e27d2 |
Privileged access review, expiry, and revocation security operations and internal control | review | 2/2 Privileged access grants, break-glass activations, access reviews, expiry, revocation, and board evidence routes are linked. | within | 5b39489ed46a...7f938969 |
Service account, API credential, and secret rotation governance platform reliability and application security | operate | 3/3 Service accounts, API credentials, partner access, secret rotation, third-party dependency, and cyber controls are joined. | within | fd046fa373ce...b14039e3 |
Break-glass session recording and evidence custody security operations and platform reliability | operate | 3/3 Emergency sessions, incident tickets, session recordings, revocation, and custody hashes are tied to incident response evidence. | within | 9a19fc41f4ab...6891a205 |
Identity governance assurance and board reporting security governance, control assurance, and board secretariat | assure | 3/3 Identity inventory, access reviews, SoD, service accounts, break-glass, assurance, board route, and risk-data evidence feed board packs. | within | 9256c4aa0a37...9e69b9ed |
| Control | Metric | Current / limit | Status | Hash |
|---|---|---|---|---|
MFA and phishing-resistant authentication coverage Identity access should enforce strong authentication, especially for privileged and sensitive access. | Principals with MFA enforced and privileged principals using phishing-resistant MFA | 100.00% / 100.00% | within | ea4a2c7b47a4...3ebf8915 |
Phishing-resistant MFA for sensitive lanes Sensitive access lanes should resist credential phishing and session theft. | Principals with phishing-resistant MFA evidence | 100.00% / 100.00% | within | 0db4b8b5514a...c96d74a3 |
Least privilege role governance Access should be limited to roles needed for approved duties. | Principals at or below least-privilege role target | 100.00% / 100.00% | within | 366c83f2d720...569b6115 |
Access review and recertification SLA Access should be reviewed on schedule, with privileged access reviewed more frequently. | Principals inside review SLA by privilege tier | 100.00% / 100.00% | within | 6cffc48e6cec...77c90673 |
Segregation-of-duties conflict control Identity governance should prevent toxic duty combinations and customer-harm paths. | Principals without conflicting approval, disbursement, support, or model duties | 100.00% / 100.00% | within | 0a966ccdef03...8a133dae |
Privileged access event approval and expiry High-risk access changes should be approved, time-bound, reviewed, and auditable. | High-risk grants and break-glass events with approval, reviewer, expiry, and evidence | 100.00% / 100.00% | within | fb0c32e62eea...2996491a |
Service account and break-glass operational control Service and emergency access should be actively controlled, tested, rotated, and evidence-backed. | Privileged principals with session policy, JML automation, break-glass test, and no stale access | 100.00% / 100.00% | within | 86c68b360cc1...5cee2c28 |
Identity controls mapped to enterprise evidence manifest Identity controls should trace to cyber, API, third-party, risk data, assurance, and board evidence. | Identity risk controls with source routes, artifacts, export packs, and custody hashes | 100.00% / 100.00% | within | 4f5966347cd4...c15a37d6 |
Identity access evidence custody Identity and access evidence should be reproducible for audit, incident review, and board oversight. | Principal, event, risk-control, manifest, and action evidence with SHA-256 custody hashes | 100.00% / 100.00% | within | 145f3fa64a92...a0a20671 |
| Trigger | Owner | Action | Deadline | Status |
|---|---|---|---|---|
| No identity access governance action packs are required for the current evidence set. | ||||
| Cyber domain | Function | Mapped evidence | Coverage | Test recency | Board route | Status | Hash |
|---|---|---|---|---|---|---|---|
Cyber risk governance, appetite, and board oversight security governance, risk, and compliance | govern | 3/3 3 sources / 3 hashes | Control 100.00% Automation 100.00% 0 open findings | 24d | Board Risk Committee cyber risk appetite, exception, and assurance pack | within | 321151218ed0...c368012d |
Asset inventory, attack surface, and data-flow exposure management security engineering and data governance | identify | 2/2 2 sources / 2 hashes | Control 100.00% Automation 100.00% 0 open findings | 18d | Technology Committee asset exposure and API attack-surface pack | within | 2967303de317...ad41dbd3 |
Privileged access, strong authentication, secrets, and data protection identity platform and application security | protect | 3/3 3 sources / 3 hashes | Control 100.00% Automation 100.00% 0 open findings | 14d | Risk and Technology Committee identity and data protection pack | within | 734462af5546...64986785 |
Threat detection, alert triage, incident response, and evidence custody security operations center | detect | 3/3 3 sources / 3 hashes | Control 100.00% Automation 100.00% 0 open findings | 12d | SOC detection, incident, and evidence-custody pack | within | d7406478fdea...94b86535 |
Ransomware recovery, immutable backup, and critical operation restore platform reliability and infrastructure security | recover | 3/3 3 sources / 3 hashes | Control 100.00% Automation 100.00% 0 open findings | 31d | Operational Resilience Committee ransomware and restore-readiness pack | within | 24c7b48564ad...9c62e1b5 |
Third-party, API, software supply-chain, and AI operator cyber risk vendor risk, application security, and AI governance | identify | 3/3 3 sources / 3 hashes | Control 100.00% Automation 100.00% 0 open findings | 27d | Technology Committee third-party, software, and AI cyber-risk pack | within | e351f2e9e2dd...4d062eb8 |
| Telemetry signal | Category | Current / limit | Playbook | Status | Hash |
|---|---|---|---|---|---|
External attack surface inventory coverage security engineering Internet-facing applications, APIs, DNS, storage, and edge routes inventoried | asset_exposure | 100.00% / 100.00% minimum limit / 2/2 controls | block production releases missing inventory, owner, data classification, and attack-surface evidence | within | cf5248fc197b...dec9f072 |
Privileged access MFA and break-glass coverage identity platform Privileged users, service accounts, and break-glass paths with phishing-resistant MFA or compensating control | identity_access | 100.00% / 100.00% minimum limit / 2/2 controls | disable unmanaged privileged sessions and rotate break-glass credentials with incident evidence | within | f588fa1af552...a74ab793 |
Overdue production secret rotation application security Production secrets overdue against rotation policy | identity_access | 0 / 0 maximum limit / 2/2 controls | rotate exposed or overdue credentials, revoke stale tokens, and attach release evidence | within | b80316020212...2e32b6c2 |
Critical vulnerability remediation SLA breaches security engineering and platform owners Critical vulnerabilities older than approved SLA | vulnerability | 0 / 0 maximum limit / 2/2 controls | open security exception, patch, isolate, or remove exposed service before next release window | within | da4f926d4f51...f2bc69b4 |
Endpoint and workload telemetry coverage security operations center Critical workloads shipping endpoint, cloud, API, and identity telemetry | detection | 100.00% / 100.00% minimum limit / 2/2 controls | quarantine workloads without telemetry and restore alert coverage before release | within | 154a403c75fa...5a1d765c |
Priority threat detection coverage security operations center Mapped priority threats with active detection, triage, and response playbooks | detection | 100.00% / 100.00% minimum limit / 2/2 controls | write or tune detections for identity abuse, API abuse, data exfiltration, fraud, and ransomware scenarios | within | 4344d053b832...ad577856 |
Immutable backup and restore evidence coverage platform reliability Critical systems with immutable backup, restore test, and custody hash | resilience | 100.00% / 100.00% minimum limit / 2/2 controls | block critical operation attestation until immutable backup and restore evidence is current | within | df57dc5041d0...616f532c |
High-risk role phishing simulation failure rate security awareness and conduct risk High-risk operators failing current phishing simulation | human_risk | 3.00% / 5.00% maximum limit / 2/2 controls | refresh targeted training, remove high-risk permissions, and retest before privileged task assignment | within | 35315e416528...352ce96a |
| Scenario | Contain / recover | Response evidence | Status | Hash |
|---|---|---|---|---|
Ransomware on lending and payment critical operations recover / platform reliability and security operations | 22m / 30m 2.7h / 4h | Immutable backup restore, containment timeline, customer-harm review, regulator-notice draft, and lesson closure pack harm ready / notice ready / lessons closed | within | d30e13d7379c...b7f08b4b |
Privileged account compromise and break-glass rotation respond / identity platform and SOC | 15m / 20m 0.7h / 1h | Session revocation, break-glass rotation, privileged access review, and incident evidence hash harm ready / notice ready / lessons closed | within | 708802c4828f...6084af1c |
Partner API abuse and borrower data exfiltration attempt respond / API platform and privacy office | 18m / 25m 1.2h / 2h | API key revocation, tenant object-boundary proof, privacy impact review, and customer-harm disposition harm ready / notice ready / lessons closed | within | e17c8d542f46...0979733b |
Critical third-party service provider compromise recover / vendor risk and operational resilience | 34m / 45m 4.5h / 6h | Provider isolation, substitute route activation, customer-impact review, and vendor assurance evidence harm ready / notice ready / lessons closed | within | 9e8026ec8235...01faea10 |
| Cyber control | Metric | Current | Limit | Status | Hash |
|---|---|---|---|---|---|
Cyber risk governance and accountability coverage Cybersecurity risk should be governed across Govern, Identify, Protect, Detect, Respond, and Recover with named owners and board oversight. | NIST CSF functions with mapped owners, board route, test recency, and assurance evidence | 6 | 6 | within | 20155d6559b9...47327912 |
Asset inventory and attack-surface exposure management Critical assets, APIs, data flows, cloud services, and third parties should be continuously inventoried and tied to controls. | Cyber domains inside coverage and automation thresholds | 100.00% | 100.00% | within | 6a8cf5139737...41d55db4 |
Privileged identity, MFA, and secrets resilience Privileged access and secrets should be strongly authenticated, monitored, rotated, and evidence-backed. | Privileged access and secrets controls inside policy limits | 100.00% | 100.00% | within | b9c7bf48e36d...f68cd395 |
Critical vulnerability remediation SLA Critical vulnerabilities should be remediated, isolated, or formally excepted inside appetite. | Critical vulnerabilities breaching approved remediation SLA | 0 | 0 | within | 5b44e9b630ae...6799f8bd |
Threat detection, telemetry, and response playbook coverage Priority threats should be observable, triaged, and response-ready across endpoint, cloud, API, identity, and data layers. | Detection signals and response playbooks operating inside target | 100.00% | 100.00% | within | d3d00cd0b366...3b56c37e |
Ransomware recovery and immutable backup readiness Ransomware and destructive-event recovery should prove containment, immutable restore, customer-harm review, and critical-operation recovery. | Backup, restore, and recovery exercises inside target | 100.00% | 100.00% | within | 494cf00357a2...198b25d6 |
Incident response, regulator notice, and customer-harm readiness Cyber incidents should preserve evidence, assess customer harm, prepare regulator notification, and close lessons learned. | Cyber incident exercises with containment, recovery, customer-harm, regulator notice, and lessons closure | 100.00% | 100.00% | within | 0c345b39b6fe...35ef7693 |
Cyber evidence custody and supervisory reproducibility Cyber resilience evidence should be reproducible for audit, board oversight, incident review, and supervisory discussion. | Domains, telemetry, exercises, manifest rows, and action packs with custody hashes | 100.00% | 100.00% | within | 6e2e126e416f...79b5c621 |
| Trigger | Status | Evidence | Owner | Deadline |
|---|---|---|---|---|
| No cyber resilience action packs are required for the current evidence set. | ||||
| Control | Owner | Source | Artifact | Export package | Retention | Custody hash |
|---|---|---|---|---|---|---|
Critical operation and dependency map BCBS operational resilience / exceeds | platform ops | /officer/admin/op-readiness#operational-resilience | operational-resilience-impact-table operator_matrix | operational-resilience-pack | 7 years | 9a2890f34de2...40b228f0 |
Impact tolerance and recovery drill coverage BCBS operational resilience / exceeds | site reliability | /officer/admin/op-readiness#operational-resilience-automation | impact-tolerance-automation-table operator_matrix | operational-resilience-automation-pack | 7 years | c6b8b26247c3...f24010f0 |
Third-party service substitutability BCBS third-party dependency management / exceeds | vendor risk | /officer/admin/op-readiness#operational-resilience-automation | third-party-exit-evidence-pack-table operator_matrix | third-party-exit-evidence-pack | 7 years | 0c2febd37c6f...90245402 |
Operational risk RCSA, loss-event, KRI, scenario, remediation, and board reporting evidence packs BCBS Principles for the Sound Management of Operational Risk / BCBS operational resilience / CBK Risk Management Guidelines / exceeds | operational risk management, control assurance, and first-line process owners | /officer/admin/op-readiness#operational-risk-governance | operational-risk-control-table governance_calendar | operational-risk-governance-pack | 7 years | 4f7c31cce46d...d79bb160 |
Third-party lifecycle, due diligence, contract rights, subcontractor, concentration, SLA, incident, cyber, data protection, exit, and evidence-custody packs Interagency Guidance on Third-Party Relationships: Risk Management / EBA outsourcing arrangements / EU DORA ICT third-party risk / FFIEC cyber and outsourcing risk governance / BCBS operational resilience third-party dependency management / exceeds | vendor risk, procurement, legal control, operational resilience, security governance, privacy, payments operations, credit operations, and enterprise risk | /officer/admin/op-readiness#third-party-risk-governance | third-party-risk-gate-table governance_calendar | third-party-risk-governance-pack | 7 years | a70bf47270a0...56345045 |
Model inventory, validation, and governance controls SR 11-7 model risk management / exceeds | model risk | /officer/risk/models#model-validation-attestation-pack | model-validation-attestation-table read_model | model-validation-attestation-pack | 7 years | 9850224317f2...350fd64c |
Ongoing monitoring and back-testing SR 11-7 model risk management / exceeds | credit risk | /officer/risk/models | model-risk-breach-ticket-table read_model | model-risk-pack | 7 years | bb69e934e216...e9687e9e |
Specific adverse-action reason generation CFPB complex-algorithm adverse action / exceeds | fair lending | /officer/risk/models | adverse-action-specific-reasons server_component | fair-lending-pack | 7 years | aa4216b0f7ac...99afc398 |
Model lifecycle, development data, independent validation, challenger, fair-lending, drift, override, retirement, and evidence-custody packs Revised Interagency Guidance on Model Risk Management (2026) / NIST AI RMF / CFPB complex-algorithm adverse action / ECOA fair-lending lifecycle governance / exceeds | model risk, fair lending, credit risk, data governance, conduct risk, change management, and board secretariat | /officer/risk/models#model-lifecycle-fair-lending-governance | model-lifecycle-control-table read_model | model-lifecycle-fair-lending-governance-pack | 7 years | 0c3ecc813cdc...ad713b71 |
Credit bureau consent, data furnishing, negative-listing notice, dispute investigation, correction, cure reporting, privacy, retention, synthetic-action, and evidence-custody packs Kenya Banking Credit Reference Bureau Regulations 2020 / CFPB Regulation V FCRA furnisher accuracy and direct dispute duties / World Bank General Principles for Credit Reporting / credit-information consent, data furnishing, negative-listing notice, dispute investigation, correction, privacy, retention, and evidence-custody governance / exceeds | underwriting operations, credit operations, credit risk, data governance, privacy office, collections conduct, customer dignity operations, regulatory operations, control assurance, and board secretariat | /officer/applications/[id]/uw/bureau#credit-bureau-furnishing-governance | credit-bureau-furnishing-control-table governance_calendar | credit-bureau-furnishing-governance-pack | 7 years | ebb9f59d2598...d79f04e5 |
Income verification, expense reasonableness, obligation completeness, DSR/PTI/residual-income, stress affordability, vulnerable-customer, manual-exception, decline, synthetic-action, and evidence-custody packs EBA Guidelines on loan origination and monitoring creditworthiness assessment / World Bank responsible lending and over-indebtedness consumer protection / FCA Consumer Duty and borrower financial-difficulty outcomes / Kenya Financial Consumer Protection Framework affordability and fair-treatment expectations / income verification, expense reasonableness, obligation completeness, debt-service capacity, stress affordability, vulnerable-customer safeguards, exception, decline, and evidence-custody governance / exceeds | underwriting operations, credit policy, credit risk, conduct risk, model risk, privacy office, data governance, control assurance, and board secretariat | /officer/applications/[id]/uw/dsr#responsible-lending-affordability-governance | responsible-lending-affordability-control-table governance_calendar | responsible-lending-affordability-governance-pack | 7 years | 152024d504ad...e584ff22 |
AI operator tool-agency, approval, confidence, provenance, prompt-injection, privacy, incident, and evidence-custody packs NIST AI RMF / NIST AI 600-1 Generative AI Profile / OWASP LLM Top 10 2025 / ISO/IEC 42001 AI management system / exceeds | AI governance council, model risk, AI security, privacy, and operations risk | /officer/ai-operator#ai-operator-governance-pack | ai-operator-governance-control-table read_model | ai-operator-governance-pack | 7 years | 140ba2ab9352...1a796641 |
Financial-grade API authentication, consent scope, sandbox, partner, quota, webhook, release-assurance, and evidence-custody packs OpenID FAPI 2.0 Security Profile / OWASP API Security Top 10 2023 / NIST SP 800-204A microservices security / NIST SP 800-218 SSDF / consumer-permissioned financial data rights / exceeds | API platform, identity platform, application security, privacy, partner operations, and operational risk | /officer/admin/api-platform#api-platform-governance-pack | api-platform-governance-control-table read_model | api-platform-governance-pack | 7 years | a292a31bd0f9...8aef35b0 |
Open-finance consent journey, data-access grant, revocation, portability, restriction, deletion, data-recipient, reconciliation, live-read, synthetic-action, and evidence-custody packs CFPB Personal Financial Data Rights Rule 12 CFR Part 1033 / eCFR Regulation 1033 / Open Banking Standard consent and data management good practice / EBA PSD2 strong customer authentication and common secure communication / FCA open banking and open finance consumer protection / Kenya Financial Consumer Protection Framework consent, privacy, digital finance, complaint, and redress expectations / consumer-permissioned data sharing, scope minimization, revocation, portability, recipient oversight, reconciliation, and evidence-custody governance / exceeds | API platform, privacy office, data governance, identity platform, security governance, partner operations, vendor risk, legal control, conduct risk, records manager, customer outcomes operations, control assurance, and board secretariat | /officer/admin/api-platform#open-finance-consent-governance | open-finance-consent-control-table governance_calendar | open-finance-consent-governance-pack | 7 years | 5bfa6c3b3caa...7b4f2367 |
Fraud typology, alert, case, disbursement hold, vulnerable-customer, loss recovery, signal validation, and evidence-custody packs FFIEC authentication and access risk management / FATF risk-based financial-crime controls / CFPB elder financial exploitation response / NIST CSF 2.0 Detect-Respond-Recover / operational risk fraud loss governance / exceeds | fraud operations, financial crime compliance, application security, credit operations, conduct risk, model risk, and operational risk | /officer/fraud#fraud-risk-governance-pack | fraud-risk-governance-control-table read_model | fraud-risk-governance-pack | 7 years | 2ab129d8e0f9...21679a9e |
Authorized payment scam and unauthorized-transfer intake, liability, reimbursement, victim-care, receiving-party recovery, fraud reporting, live-read, synthetic-action, and evidence-custody packs PSR APP scam reimbursement protections and compliance monitoring / EBA PSD2 fraud reporting / CFPB Regulation E unauthorized transfer and error-resolution controls / Kenya Financial Consumer Protection Framework and CBK fraud safety / World Bank financial consumer protection complaints and redress good practices / exceeds | fraud operations, payment error resolution, payments operations, MLRO, customer outcomes, conduct risk, finance control, regulatory operations, privacy office, and board secretariat | /officer/admin/aml#scam-reimbursement-governance | scam-control-table governance_calendar | scam-reimbursement-governance-pack | 7 years | f30e2e2f684b...26a0f600 |
Portfolio risk appetite, concentration, and stress evidence packs BCBS 239 risk data aggregation / Basel credit risk principles / CBK risk management guidelines / exceeds | enterprise risk management | /officer/risk/stress#portfolio-risk-appetite-evidence | portfolio-risk-appetite-table read_model | portfolio-risk-appetite-pack | 7 years | c92b6dc5263e...9a42d0c2 |
Credit policy, granting, collateral, monitoring, early-warning, workout, write-off, and recovery evidence packs BCBS Principles for the Management of Credit Risk / CBK Risk Management Guidelines / CBK PG/04 Risk Classification and Provisioning / exceeds | enterprise credit risk, credit operations, special assets, and finance control | /officer/risk/stress#credit-lifecycle-governance-pack | credit-lifecycle-control-table read_model | credit-lifecycle-governance-pack | 7 years | b1ee77f73026...52cd1641 |
Co-lending partner eligibility, loan participation, allocation fairness, risk retention, settlement waterfall, servicing disclosure, concentration, live-read, synthetic-action, and evidence-custody packs Basel Committee Principles for the Management of Credit Risk / Basel large exposures and securitisation risk-transfer framework / EBA loan origination and monitoring / IFRS 9 financial asset transfer and derecognition controls / CBK Risk Management Guidelines / Kenya Financial Consumer Protection Framework / World Bank financial consumer protection good practices / co-lending, loan participation, allocation fairness, risk retention, partner due diligence, settlement, servicing, concentration, live-read, and evidence-custody governance / exceeds | co-lending operations, partner operations, enterprise credit risk, credit policy, structured credit, syndication desk, treasury reconciliation, finance control, loan servicing operations, conduct risk, vendor risk, legal control, data governance, privacy office, control assurance, and board secretariat | /officer/co-lending#co-lending-participation-governance | co-lending-participation-control-table governance_calendar | co-lending-participation-governance-pack | 7 years | d184f6629432...fea7b643 |
Capital markets issuance approval, investor suitability, bookbuilding allocation fairness, subscription settlement, secondary trading surveillance, ongoing disclosure, funding concentration, live-read, synthetic-action, and evidence-custody packs IOSCO Objectives and Principles of Securities Regulation / IOSCO Principles for Ongoing Disclosure and Material Development Reporting / IOSCO suitability requirements for complex financial products / IOSCO international debt disclosure principles / Kenya Capital Markets Authority issuer, corporate bond, collective investment, custody, and market-conduct expectations / Basel large exposures and securitisation framework / CPMI-IOSCO PFMI settlement finality / IFRS 7 and IFRS 9 disclosure and financial instrument controls / exceeds | capital markets desk, investor relations, treasury risk, settlement operations, market surveillance, finance control, legal control, conduct risk, financial crime compliance, custodian oversight, regulatory operations, data governance, control assurance, and board secretariat | /officer/capital-markets#capital-markets-issuance-governance | capital-markets-issuance-control-table governance_calendar | capital-markets-issuance-governance-pack | 7 years | 0fcd48e83a3a...506e2374 |
Structured credit loan-pool eligibility, true-sale, derecognition, SPV tranche, cashflow waterfall, servicer continuity, investor reporting, capital relief, risk retention, live-read, synthetic-action, and evidence-custody packs Basel securitisation framework / IOSCO disclosure principles for public offerings and listings of asset-backed securities / IFRS 9 financial asset transfer and derecognition / IFRS 7 transferred financial asset disclosures / EBA simple, transparent and standardised securitisation and risk-retention expectations / Kenya Capital Markets Authority asset-backed securities expectations / exceeds | structured credit, capital markets desk, treasury risk, capital planning, finance control, legal control, investor relations, loan servicing operations, conduct risk, data governance, privacy office, control assurance, ALCO, capital committee, audit committee, and board secretariat | /officer/capital-markets#structured-credit-securitisation-governance | structured-credit-control-table governance_calendar | structured-credit-securitisation-governance-pack | 7 years | e65bfff3e67b...3330ddb6 |
External data-room room approval, recipient access, legal basis, redaction, privilege review, package integrity, watermark, activity audit, revocation, live-read, synthetic-export blocking, and evidence-custody packs NIST CSF 2.0 Govern-Protect-Detect-Respond / NIST SP 800-53 Rev. 5 access, audit, media protection, and privacy controls / ISO/IEC 27001 information security management / EU GDPR data minimisation and security of processing / Kenya Data Protection Act and ODPC data sharing safeguards / IOSCO disclosure and investor-protection principles / exceeds | data room operations, investor relations, regulatory operations, legal control, privacy office, security governance, data governance, records manager, finance control, board secretariat, control assurance, and board risk | /officer/capital-markets#external-data-room-governance | external-data-room-control-table governance_calendar | external-data-room-governance-pack | 7 years | 5c9abcf8056a...fe21256f |
Market abuse surveillance, insider and restricted list governance, market sounding control, best execution evidence, communications surveillance, regulatory reporting decisioning, live-read, synthetic-action blocking, and custody packs IOSCO Objectives and Principles of Securities Regulation / EU Market Abuse Regulation insider dealing, unlawful disclosure, and market manipulation controls / ESMA suspicious transaction and order reporting expectations / Kenya Capital Markets Act and CMA conduct-of-business expectations / best execution, insider list, market sounding, communications surveillance, STOR, live-read, synthetic-action blocking, and evidence-custody governance / exceeds | market surveillance, trading oversight, compliance surveillance, conduct risk, legal control, investor relations, regulatory operations, records manager, data governance, control assurance, and board secretariat | /officer/capital-markets#market-conduct-surveillance-governance | market-conduct-control-table governance_calendar | market-conduct-surveillance-governance-pack | 7 years | 6e25c9e5f841...da37e30a |
Sustainable finance taxonomy eligibility, use-of-proceeds allocation, impact-claim measurement, target calibration, verification assurance, social safeguard, greenwashing, live-read, synthetic-action, and evidence-custody packs ICMA Green Bond Principles / ICMA Social Bond Principles / ICMA Sustainability-Linked Bond Principles / ICMA Sustainability Bond Guidelines / Kenya Green Finance Taxonomy / IFRS S1 and IFRS S2 sustainability and climate disclosures / UNDP SDG Impact Standards / UNEP FI climate target-setting for banks / sustainable-finance taxonomy eligibility, use-of-proceeds, impact-claim, greenwashing, social-safeguard, assurance, target-setting, live-read, and evidence-custody governance / exceeds | sustainable finance, climate risk, impact measurement, treasury reconciliation, finance control, conduct risk, privacy office, data governance, control assurance, legal control, and board secretariat | /officer/risk/stress#sustainable-finance-impact-governance | sustainable-finance-control-table governance_calendar | sustainable-finance-impact-governance-pack | 7 years | e320c1951e88...c74ba94b |
Collateral valuation, LTV, lien perfection, registry search, custody, insurance, repossession, dispute, synthetic-action, and evidence-custody packs Basel Principles for the Management of Credit Risk / CBK Risk Management Guidelines / EBA loan origination and monitoring collateral valuation expectations / IFRS 13 fair value measurement / legal enforceability, custody, insurance, repossession, dispute, and evidence-custody governance / exceeds | collateral operations, credit risk, legal control, recoveries, insurance operations, records manager, fraud operations, conduct risk, and board secretariat | /officer/collateral#collateral-valuation-custody-governance | collateral-governance-control-table governance_calendar | collateral-valuation-custody-governance-pack | 7 years | c7711e4e2bdb...5cff2b38 |
Collections conduct, hardship forbearance, promise-to-pay, repossession, write-off, recovery, and borrower-outcome evidence packs CBK Risk Management Guidelines / Kenya Financial Consumer Protection Framework / World Bank Good Practices for Financial Consumer Protection / FCA Consumer Duty borrower difficulty protections / exceeds | collections operations, conduct risk, special assets, legal control, and credit risk finance control | /officer/collections#collections-forbearance-governance-pack | collections-forbearance-control-table read_model | collections-forbearance-governance-pack | 7 years | 0a154acf0d0f...46936db9 |
Loan statement accuracy, repayment waterfall allocation, payoff and settlement quote, waiver, reversal, refund, notice, dispute, reconciliation, live-read, synthetic-action, and evidence-custody packs CFPB Regulation Z periodic statement, payoff statement, and payment allocation expectations / World Bank financial consumer protection servicing and disclosure good practices / FCA Consumer Duty borrower support and fair treatment / Kenya Financial Consumer Protection Framework servicing, disclosure, complaint, redress, and fair-treatment expectations / loan statement accuracy, repayment waterfall, payoff quote, waiver, reversal, refund, notice, dispute, reconciliation, and evidence-custody governance / exceeds | loan servicing operations, payments operations, finance control, treasury reconciliation, customer outcomes operations, conduct risk, special assets, collateral operations, data governance, records manager, control assurance, and board secretariat | /officer/loans/[id]/waterfall#loan-servicing-repayment-governance | loan-servicing-repayment-control-table governance_calendar | loan-servicing-repayment-governance-pack | 7 years | d8f2b474cda6...ca06fd6b |
IFRS 9 staging, allowance adequacy, loan-level evidence, and impairment action packs IFRS 9 expected credit loss impairment / Basel credit risk and ECL guidance / CBK provisioning comparison / exceeds | CFO, credit risk, and impairment committee | /officer/risk/ecl#ifrs9-ecl-governance-pack | ifrs9-ecl-control-table read_model | ifrs9-ecl-governance-pack | 7 years | a741c4fb98af...7651cc3f |
Capital adequacy, ICAAP, stress capital, and leverage evidence packs Basel III capital framework / Basel leverage ratio / CBK PG/04 capital adequacy / exceeds | CFO and enterprise risk | /financials/capital-adequacy#capital-icaap-evidence-pack | capital-icaap-control-table read_model | capital-icaap-evidence-pack | 7 years | b855cc64dc39...9033310c |
Climate financial risk, scenario, financed-emissions, and disclosure evidence packs BCBS climate-related financial risk principles / CBK Climate-Related Risk Management / IFRS S2 / TCFD / exceeds | enterprise risk, CFO, and sustainability | /officer/risk/stress#climate-risk-disclosure-pack | climate-risk-control-table read_model | climate-risk-disclosure-pack | 7 years | c1b4287c907d...990037a3 |
Liquidity risk appetite and contingency funding evidence packs BCBS sound liquidity risk management / Basel III LCR / CBK Basel III liquidity standards / exceeds | treasury risk and ALCO | /officer/treasury/alm#treasury-liquidity-risk-evidence | treasury-liquidity-appetite-table read_model | treasury-liquidity-risk-pack | 7 years | 34b55ca25081...9c9d245a |
FX open-position, hedge, revaluation, stress, KRI, and market-risk evidence packs Basel market risk framework / BCBS Minimum capital requirements for market risk / CBK Foreign Exchange Exposure Limits / CBK Risk Management Guidelines / exceeds | treasury risk, ALCO, payments risk, and finance control | /officer/treasury/fx#market-risk-governance-pack | market-risk-control-table read_model | market-fx-risk-governance-pack | 7 years | 5b6075288f0b...55e45d13 |
IRRBB earnings, EVE, repricing, basis-risk, optionality, and ALM governance evidence packs Basel IRRBB standards / Basel Framework SRP31-SRP98 / CBK Risk Management Guidelines / exceeds | treasury risk, ALCO, and finance control | /officer/treasury/alm#irrbb-governance-pack | irrbb-control-table read_model | irrbb-governance-pack | 7 years | 03260f224ca9...251f0ec9 |
Payment settlement finality, rail resilience, and exception evidence packs CPMI-IOSCO PFMI / CPMI ISO 20022 harmonisation / Kenya National Payment System risk controls / exceeds | payments operations and treasury control | /officer/treasury/disbursement#payment-settlement-assurance | payment-settlement-control-table read_model | payment-settlement-assurance-pack | 7 years | 1c6143926a38...af87bf26 |
Payment error intake, unauthorized-transfer, investigation, provisional-credit, reversal, refund, provider-dispute, reconciliation, notice, redress, live-read, synthetic-action, and evidence-custody packs CFPB Regulation E Electronic Fund Transfer Act error-resolution and unauthorized-transfer expectations / World Bank financial consumer protection complaints, disclosure, and redress good practices / CPMI-IOSCO PFMI payment finality and operational-risk expectations / Kenya Financial Consumer Protection Framework fair-treatment, complaint, redress, and digital-finance expectations / payment error intake, unauthorized transfer, investigation, provisional credit, reversal, refund, provider dispute, reconciliation, notice, redress, and evidence-custody governance / exceeds | payment error resolution, payments operations, treasury reconciliation, finance control, customer outcomes operations, conduct risk, privacy office, data governance, vendor risk, operational risk, control assurance, and board secretariat | /officer/treasury/recon#payment-error-resolution-governance | payment-error-control-table governance_calendar | payment-error-resolution-governance-pack | 7 years | cd0bf436dc06...0ccac581 |
Deposit product, wallet float, customer-fund safeguarding, liquidity run, dormant balance, synthetic-action, and evidence-custody packs Basel Core Principles for effective banking supervision / CBK prudential and deposit-taking microfinance guidance / EBA payment services and e-money safeguarding / FCA payment and e-money safeguarding requirements / customer-fund segregation, liquidity, dormant balance, and run-protection governance / exceeds | deposit operations, treasury risk, payments finance control, records manager, conduct risk, ALCO, and board secretariat | /officer/deposits#deposits-wallet-safeguarding-governance | deposits-wallet-control-table governance_calendar | deposits-wallet-safeguarding-governance-pack | 7 years | 91d9211a853c...48bc0517 |
Insurance product, Cap17 gate, premium trust-fund, claims fairness, reinsurance, synthetic-action, and evidence-custody packs IAIS Insurance Core Principles / Kenya insurance conduct and licensing controls / Cap17 trust-pool segregation / IFRS 17 insurance contract evidence / customer outcome, claims fairness, and reinsurance governance / exceeds | insurance operations, Cap17 control, conduct risk, finance control, claims operations, reinsurance risk, and board secretariat | /officer/insurance#insurance-protection-governance | insurance-protection-control-table governance_calendar | insurance-protection-governance-pack | 7 years | 1108d02a4d11...02269a69 |
Agent onboarding, fit-and-proper, training, liquidity, teller cash reconciliation, commission payout, fraud/AML, conduct, synthetic-action, and evidence-custody packs CBK prudential and agency banking guidance / Basel operational risk and resilience principles / FATF risk-based AML/CFT financial inclusion guidance / GSMA mobile money agent network and safeguarding practices / agent liquidity, cash reconciliation, commission, conduct, and evidence-custody governance / exceeds | agent network operations, cash operations, treasury risk, payments finance control, fraud operations, MLRO, conduct risk, operational risk, agent finance control, and board secretariat | /officer/agents#agent-network-cash-governance | agent-network-cash-control-table governance_calendar | agent-network-cash-governance-pack | 7 years | bb5b5cfef85b...8ccbdca5 |
Proactive regulatory obligation radar CBK/ODPC/FRC regulatory horizon management / exceeds | regulatory operations | /officer/regulatory#regulatory-obligation-radar | regulatory-obligation-table governance_calendar | regulatory-horizon-pack | 7 years | 2a6668e55d9b...c0f96b96 |
Regulatory return inventory, source reconciliation, validation-rule, maker-checker, CFO, compliance, API-submission, acknowledgement, amendment, prudential-capital, board-route, live-read, and evidence-custody packs CBK Digital Credit Provider data submission testing / CBK Risk Management Guidelines reliable regulatory reporting / BCBS 239 risk data aggregation and risk reporting / Basel Core Principles supervisory reporting / exceeds | regulatory reporting, finance control, compliance assurance, data governance, API platform, board secretariat, and control assurance | /officer/regulatory/cbk#regulatory-return-production-governance | regulatory-return-control-table governance_calendar | regulatory-return-production-governance-pack | 7 years | 8709adcfda25...c54196b9 |
Regulatory perimeter, licence, registration, authorization, key-person, fit-and-proper, ownership, third-party notice, change-control, product launch, country expansion, synthetic-action, and evidence-custody packs CBK Digital Credit Providers Regulations 2022 / CBK Digital Credit Provider licensing procedures / National Payment System Regulations 2014 and PSP authorisation procedures / ODPC Data Controller and Processor registration guidance / Capital Markets licensing requirements / POCAMLA AML-CFT-CPF reporting institution obligations / exceeds | legal control, regulatory operations, company secretary, privacy office, financial crime compliance, payments operations, capital markets desk, insurance governance, product governance, platform expansion, and board secretariat | /officer/regulatory#regulatory-perimeter-licensing-governance | regulatory-perimeter-control-table governance_calendar | regulatory-perimeter-licensing-governance-pack | 7 years | 7e06d4c85f55...40906846 |
Supervisory exam request, regulator response, finding remediation, commitment tracking, board escalation, and legal evidence-custody packs Basel Core Principles for Effective Banking Supervision / BCBS Compliance and the compliance function in banks / BCBS corporate governance principles for banks / CBK Risk Management Guidelines / exceeds | regulatory operations, compliance assurance, legal control, enterprise risk, privacy office, financial crime compliance, payments risk, records manager, and board secretariat | /officer/regulatory#regulatory-supervisory-response-governance | supervisory-control-table governance_calendar | regulatory-supervisory-response-governance-pack | 7 years | 8d47bf1da9ee...adbb173a |
Tax obligation registration, iTax filing calendar, KRA VAT/PAYE/WHT/corporate tax remittance, SHA/SHIF, NSSF, housing levy, NITA, eTIMS, ledger reconciliation, transfer-pricing, stamp-duty, audit-query, live-read, synthetic-action, and evidence-custody packs OECD Tax Control Framework and co-operative compliance / COSO Internal Control Integrated Framework / Kenya Revenue Authority iTax, eTIMS, VAT, PAYE, withholding tax, corporate income tax, transfer-pricing, affordable housing levy, and statutory payment expectations / Social Health Authority employer contribution expectations / NSSF employer contribution expectations / tax obligation registration, return preparation, payment, filing calendar, payroll statutory contribution, ledger reconciliation, tax-position, live-read, synthetic-action, and evidence-custody governance / exceeds | tax operations, CFO tax control, payroll tax, people operations, finance control, treasury reconciliation, legal control, compliance assurance, privacy office, records manager, control assurance, and board secretariat | /officer/admin/op-readiness#tax-statutory-obligation-governance | tax-statutory-control-table governance_calendar | tax-statutory-obligation-governance-pack | 7 years | 78031b65a996...95074bb4 |
Privacy impact and high-risk processing launch gates ODPC Data Protection Act / NIST Privacy Framework / NIST AI RMF / exceeds | privacy engineering | /officer/regulatory/consent#privacy-impact-launch-gates | privacy-impact-activity-table governance_calendar | privacy-impact-pack | 7 years | 159ded020d42...20ede0c1 |
Records inventory, retention schedule, legal hold, DSAR disposition, immutable archive, backup propagation, and evidence-custody packs NIST Privacy Framework data processing lifecycle / ISO 15489 records management / Kenya Data Protection Act storage limitation and data-subject rights / regulator, AML, dispute, tax, and audit evidence retention / exceeds | records manager, privacy office, legal control, MLRO, platform reliability, and data governance | /officer/operations/readiness#records-data-lifecycle-governance | records-data-lifecycle-control-table governance_calendar | records-data-lifecycle-governance-pack | 7 years | edecc15cc411...5ccf34f6 |
AML typology surveillance and STR evidence packs FATF risk-based AML/CFT/CPF / Kenya FRC suspicious transaction reporting / CBK AML supervision / exceeds | MLRO and financial crime compliance | /officer/admin/aml#aml-typology-surveillance | aml-typology-table governance_calendar | aml-str-evidence-pack | 7 years | b8abdf04dda5...082c0465 |
Financial-crime KYC, CDD, beneficial ownership, EDD, screening, monitoring, STR/SAR, no-tipping-off, goAML, risk-control, and evidence-custody packs FATF Recommendations risk-based AML/CFT/CPF / FinCEN customer due diligence and beneficial ownership / Kenya FRC suspicious and unusual transaction reporting / sanctions, PEP, adverse media, and STR governance / exceeds | MLRO, KYC operations, financial crime compliance, screening operations, model risk, data governance, and board secretariat | /officer/admin/aml#financial-crime-governance-pack | financial-crime-control-table read_model | financial-crime-governance-pack | 7 years | 51dc69226553...94b6f187 |
Business-network KYB, merchant, supplier, anchor-buyer, dealer-importer, relationship exposure, marketplace abuse, renewal, action, and evidence-custody packs FATF Recommendations risk-based CDD and ongoing monitoring / FATF Recommendation 24 beneficial ownership of legal persons / Kenya beneficial ownership and digital credit provider controls / OECD responsible business conduct due diligence / World Bank integrity compliance and IFC due diligence / exceeds | marketplace operations, MLRO, financial crime compliance, fraud operations, credit risk, payments operations, vendor risk, data governance, and board secretariat | /officer/soko#business-network-kyb-governance | business-network-control-table governance_calendar | business-network-kyb-governance-pack | 7 years | 00af638c52ae...3742c906 |
Cross-domain risk data lineage, quality, timeliness, adaptability, reconciliation, and board reporting evidence packs BCBS 239 risk data aggregation and risk reporting / CBK Risk Management Guidelines / exceeds | data governance, enterprise risk, and control assurance | /officer/admin/op-readiness#risk-data-aggregation-governance | risk-data-quality-control-table governance_calendar | risk-data-aggregation-governance-pack | 7 years | cd8cd7204760...916d4c11 |
Finance ledger, posting-rule, reconciliation, suspense, period-close, financial-reporting, audit, synthetic-action, and evidence-custody packs IFRS Conceptual Framework and IFRS financial reporting discipline / COSO Internal Control Integrated Framework / Basel corporate governance principles for banks / CBK Risk Management Guidelines / ledger integrity, period-close, reconciliation, suspense, adjustment, and audit-evidence custody governance / exceeds | CFO, finance control, risk finance, treasury finance control, reconciliation operations, tax, regulatory reporting, audit liaison, control assurance, and board secretariat | /officer/gl#finance-ledger-close-governance | finance-ledger-control-table governance_calendar | finance-ledger-close-governance-pack | 7 years | 5f59bc1e436f...f5abcbc3 |
Product fair-value, pricing, total-cost-of-credit, fee transparency, target-market, disclosure, lifecycle, complaints, redress, synthetic-action, and evidence-custody packs FCA Consumer Duty price and value outcome / EBA product oversight and governance for retail banking products / Kenya Financial Consumer Protection Framework / World Bank Good Practices for Financial Consumer Protection / fair-value, fee-transparency, suitability, disclosure, product lifecycle, and evidence-custody governance / exceeds | product governance, pricing committee, conduct risk, credit policy, product finance control, digital product, agent conduct control, regulatory operations, control assurance, and board secretariat | /officer/admin/pricing#product-pricing-fair-value-governance | product-pricing-control-table governance_calendar | product-pricing-fair-value-governance-pack | 7 years | 6e43efb00066...c23158de |
Product launch queue, regulatory perimeter linkage, product-pricing linkage, manifest coverage, approval-route, live-read, upstream-action, post-launch review, synthetic-action, and evidence-custody packs Product launch regulatory readiness / regulatory perimeter licensing governance / product pricing fair-value governance / privacy, AML, responsible-lending, live-read, board approval, and evidence-custody launch controls / exceeds | product governance, regulatory operations, legal control, conduct risk, pricing committee, credit policy, privacy office, financial crime compliance, payments operations, and board secretariat | /officer/admin/product-launch#product-launch-regulatory-readiness | product-launch-control-table governance_calendar | product-launch-regulatory-readiness-pack | 7 years | 39181e86ef9a...19528c2f |
Risk-adjusted profitability, funds-transfer-pricing, RAROC hurdle, cost-stack, stressed return, attribution, customer-outcome, and evidence-custody packs Interagency FTP guidance for funding and contingent liquidity risk / BCBS sound liquidity risk management / OCC lending and loan portfolio risk management / OCC earnings quality / EBA loan origination and monitoring loan pricing / Basel Core Principles risk governance / World Bank financial consumer protection / exceeds | pricing committee, treasury risk, ALCO, risk finance, product finance control, conduct risk, enterprise risk, and board secretariat | /officer/admin/pricing#risk-adjusted-profitability-ftp-governance | profitability-control-table governance_calendar | risk-adjusted-profitability-ftp-governance-pack | 7 years | 073ed713d691...153a857f |
Production-change, release-gate, configuration-baseline, software-supply-chain, deployment-health, emergency-change, rollback, synthetic-action, and evidence-custody packs FFIEC Development, Acquisition, and Maintenance change management / FFIEC Architecture, Infrastructure, and Operations configuration management / NIST SP 800-128 security-focused configuration management / NIST SP 800-218 Secure Software Development Framework / NIST CSF 2.0 Govern and Protect / CBK Risk Management and Business Continuity guidance / exceeds | release management, platform engineering, security operations, service owners, enterprise risk, vendor risk, data governance, customer operations, control assurance, internal audit liaison, and board secretariat | /officer/admin/op-readiness#change-release-configuration-governance | change-release-control-table governance_calendar | change-release-configuration-governance-pack | 7 years | b6137626a882...9a8c2b89 |
Recovery trigger, recovery option, solvent wind-down, communication, and board escalation evidence packs FSB Key Attributes recovery and resolution planning / BCBS operational resilience / CBK Risk Management Guidelines / exceeds | enterprise risk, treasury risk, CFO, operational resilience, and board secretariat | /officer/admin/op-readiness#recovery-resolution-governance | recovery-control-table governance_calendar | recovery-resolution-governance-pack | 7 years | 7a6a093ee86c...cbc59f2c |
Critical-function exit, provider substitutability, data-portability, transition-runbook, solvent wind-down, communication, and evidence-custody packs BCBS operational resilience critical operation mapping and testing / EBA outsourcing exit strategies / EU DORA ICT third-party risk / PRA SS2/21 outsourcing and third-party risk / CBK Risk Management and Business Continuity guidance / exceeds | operational resilience, vendor risk, legal control, data governance, privacy, platform engineering, treasury operations, customer operations, enterprise risk, control assurance, and board secretariat | /officer/admin/op-readiness#operational-continuity-exit-governance | exit-control-table governance_calendar | operational-continuity-exit-governance-pack | 7 years | 4fbeceed1299...9f1a09cb |
Crisis command, war-room, regulator/customer communications, recovery bridge, after-action, recurrence-monitoring, and evidence-custody packs BCBS operational resilience incident management and business continuity testing / BCBS corporate governance board oversight / FSB Key Attributes crisis management and resolution planning / FFIEC business continuity crisis management communications / regulator, customer, staff, provider, board, recovery, after-action, and evidence-custody governance / exceeds | enterprise crisis management team, operational resilience, legal control, regulatory operations, customer operations, vendor risk, security operations, control assurance, internal audit liaison, and board secretariat | /officer/admin/op-readiness#crisis-command-governance | crisis-command-control-table governance_calendar | crisis-command-governance-pack | 7 years | 91558653ccc0...0abb9f69 |
Enterprise risk appetite statement, risk-limit, KRI, breach, exception, committee-challenge, tolerance-use, and evidence-custody packs FSB Principles for an Effective Risk Appetite Framework / BCBS corporate governance principles for banks / Basel Core Principles for effective banking supervision / OCC Corporate and Risk Governance / COSO ERM Integrating with Strategy and Performance / ISO 31000 risk management guidelines / exceeds | board risk committee, enterprise risk, CRO, ALCO, conduct risk, technology risk, operational risk, risk data governance, and board secretariat | /officer/admin/op-readiness#enterprise-risk-appetite-limit-governance | risk-appetite-control-table governance_calendar | enterprise-risk-appetite-limit-governance-pack | 7 years | 4da21427bbd9...6eaa502d |
Enterprise-wide scenario inventory, severe-but-plausible design, reverse stress, model and data lineage, capital-liquidity-profit-customer impact, management action, board challenge, and evidence-custody packs BCBS Stress testing principles / EBA Guidelines on institutions' stress testing / Federal Reserve SR 12-7 stress testing guidance / PRA SS31/15 ICAAP and SREP / ISO 31000 risk management guidelines / exceeds | enterprise risk, CRO, capital planning, treasury risk, ALCO, risk analytics, model risk, operational resilience, conduct risk, climate risk, risk data governance, and board secretariat | /officer/risk/stress#enterprise-stress-testing-governance | enterprise-stress-control-table governance_calendar | enterprise-stress-testing-governance-pack | 7 years | 0001de18f269...05ad2c60 |
Three-lines control assurance and board escalation NIST CSF 2.0 Govern / IIA Three Lines Model / Basel corporate governance principles / exceeds | risk and compliance assurance | /officer/admin/op-readiness#control-assurance-reviews | control-assurance-table governance_calendar | control-assurance-pack | 7 years | 2156fef73cca...14bf45a9 |
Internal audit charter, independence, risk-based audit universe, annual plan, engagement, issue-validation, QAIP, external-assessment, audit committee, synthetic-action, and evidence-custody packs IIA 2024 Global Internal Audit Standards / Basel Committee internal audit function in banks / OCC internal and external audit handbook / CBK Risk Management Guidelines and Risk Based Supervisory Framework / exceeds | chief audit executive, board audit committee, internal audit operations, control assurance, enterprise risk, data governance, records manager, and board secretariat | /officer/admin/op-readiness#internal-audit-governance | internal-audit-control-table governance_calendar | internal-audit-governance-pack | 7 years | 770479b6a11a...b7de513f |
Board charter, reserved matters, fit-and-proper directors, composition, independence, committee, meeting, conflict, related-party, policy, evaluation, succession, disclosure, stakeholder, synthetic-action, and evidence-custody packs Basel Committee Corporate governance principles for banks / OCC Corporate and Risk Governance / CBK Prudential Guideline on Corporate Governance / G20-OECD Principles of Corporate Governance / exceeds | board chair, company secretary, board secretariat, nominations and governance committee, legal control, enterprise risk, compliance assurance, internal audit, records manager, and board committee chairs | /officer/admin/op-readiness#corporate-board-governance | corporate-board-control-table governance_calendar | corporate-board-governance-pack | board lifetime | b32e0277ab8c...242c4a07 |
Board risk committee evidence pack and decision trail NIST CSF 2.0 Govern / BCBS corporate governance principles / IIA Three Lines Model / exceeds | board secretariat and enterprise risk | /officer/board-pack#board-risk-committee-pack | board-risk-committee-pack-table governance_calendar | board-risk-committee-pack | board lifetime | 8862a4353246...6deb4b8d |
Enterprise remediation source-action, owner-queue, board-decision, independent-validation, recurrence-monitoring, and signed-minute evidence packs BCBS corporate governance principles for banks / BCBS Principles for the Sound Management of Operational Risk / COSO Internal Control monitoring and deficiency remediation / IIA Three Lines Model / board decision execution, owner accountability, independent validation, issue closure, signed minutes, and evidence-custody governance / exceeds | enterprise risk, control assurance, board secretariat, records manager, data governance, first-line owners, and internal audit liaison | /officer/admin/op-readiness#enterprise-remediation-governance | enterprise-remediation-control-table governance_calendar | enterprise-remediation-governance-pack | 7 years | 5d8a3ae164ab...38e96fa3 |
Cyber resilience governance, asset exposure, privileged access, vulnerability, detection, incident, ransomware recovery, and evidence-custody packs NIST CSF 2.0 Govern-Identify-Protect-Detect-Respond-Recover / CIS Critical Security Controls v8.1 / ISO/IEC 27001:2022 ISMS / FFIEC cyber risk management and self-assessment guidance / exceeds | security governance, security operations, identity platform, application security, platform reliability, vendor risk, privacy, and operational risk | /officer/admin/op-readiness#cyber-resilience-governance | cyber-resilience-control-table governance_calendar | cyber-resilience-governance-pack | 7 years | c7e2a6a69e1e...96732d66 |
Identity inventory, MFA, phishing-resistant authentication, least privilege, segregation-of-duties, access review, privileged event, service account, break-glass, and evidence-custody packs NIST CSF 2.0 PR.AA identity management, authentication, and access control / CIS Controls v8.1 account and access control management / FFIEC Architecture, Infrastructure, and Operations identity and privileged access governance / exceeds | identity platform, security governance, security operations, application security, platform reliability, control assurance, and board secretariat | /officer/admin/op-readiness#identity-access-governance | identity-access-control-table governance_calendar | identity-access-governance-pack | 7 years | 4d171c384c96...921af4a9 |
Cryptographic key and secrets custody governance NIST SP 800-57 key management / NIST SP 800-130 CKMS design / NIST SP 800-152 CKMS profile / FIPS 140-3 validated cryptographic modules / NIST CSF 2.0 data security / FFIEC AIO cryptographic operations / PCI DSS 4.0.1 key management / exceeds | security governance, application security, platform reliability, payments security, identity platform, data governance, privacy office, control assurance, and board secretariat | /officer/admin/op-readiness#cryptographic-key-custody-governance | crypto-key-control-table governance_calendar | cryptographic-key-custody-governance-pack | 7 years | 1fe8bd02a62b...c5c6b430 |
Governance, risk ownership, and policy evidence NIST CSF 2.0 Govern / exceeds | security governance | /officer/admin/op-readiness#control-evidence-manifest | control-evidence-manifest-table server_component | governance-evidence-pack | 7 years | 32d1764a69a2...aaae8e81 |
Incident detection, response, and recovery visibility NIST CSF 2.0 Detect/Respond/Recover / exceeds | security operations | /officer/admin/op-readiness#operational-resilience-automation | incident-recovery-link-table governance_calendar | incident-recovery-pack | 7 years | eb66e1a9835f...aaa695b9 |
Session-bound access and secret isolation NIST CSF 2.0 Protect / exceeds | identity platform | /officer/admin/op-readiness#world-class-benchmark | frontend-auth-hardening-ci ci_verification | security-control-pack | release lifetime | 890e0dff8bf2...851f37a0 |
Customer outcome, vulnerable-customer, and fair-value monitoring CBK consumer protection / FCA Consumer Duty / World Bank financial consumer protection / exceeds | customer dignity operations | /officer/dignity#conduct-outcomes-monitor | conduct-outcomes-control-table governance_calendar | conduct-outcomes-pack | 7 years | 9794621ea8cf...6f3d0c89 |
Complaint intake, fair handling, vulnerable-customer support, redress calculation, dispute escalation, root-cause remediation, recurrence monitoring, third-party accountability, synthetic-action, and evidence-custody packs World Bank financial consumer protection complaints handling and dispute resolution / FCA Consumer Duty consumer support and vulnerable-customer outcomes / CBK Prudential Guideline on Consumer Protection complaint procedures / G20-OECD financial consumer protection complaints handling and redress / complaint intake, fair handling, vulnerable-customer support, redress, dispute escalation, root-cause remediation, third-party accountability, and evidence-custody governance / exceeds | customer dignity operations, conduct risk, customer remediation finance control, regulatory operations, legal control, control assurance, data governance, records manager, and board secretariat | /officer/dignity#customer-outcomes-redress-governance | customer-redress-control-table governance_calendar | customer-outcomes-redress-governance-pack | 7 years | 84f98f346b62...d559067e |
Accessible, plain-language, translated, assisted-channel, USSD, low-bandwidth, financial education, comprehension, defect remediation, and evidence-custody packs WCAG 2.2 accessibility / W3C cognitive accessibility / UN CRPD accessible information and communications / G20-OECD financial consumer protection / World Bank financial consumer protection / CGAP responsible digital credit / GSMA mobile money customer treatment / Kenya consumer protection and financial consumer protection / exceeds | accessibility lead, product engineering, conduct risk, customer dignity operations, customer education, mobile channel operations, data governance, control assurance, and board secretariat | /officer/dignity#inclusive-customer-access-governance | inclusive-access-control-table governance_calendar | inclusive-customer-access-governance-pack | 7 years | 366a1e48a990...54130487 |
No representative rows on read outage Situ fail-closed operating standard / exceeds | product engineering | /officer/admin/op-readiness#world-class-benchmark | test_frontend_auth_hardening.py ci_verification | live-data-trust-pack | release lifetime | aab17e90518e...67609973 |
Tamper-evident examiner and operator evidence Examiner-grade auditability / exceeds | examiner platform | /officer/admin/op-readiness#control-evidence-manifest | control-evidence-package-hash server_component | examiner-custody-pack | 7 years | 107d025d42a6...d60ccb09 |
Blocked action states for synthetic or unavailable data Customer harm prevention / exceeds | customer operations | /officer/admin/op-readiness#world-class-benchmark | blocked-action-state-ci ci_verification | customer-harm-pack | release lifetime | ed0ab7b91b73...f090fc5f |
| Domain | Required controls | Evidence routes | Timeliness | Reconciliation | Board report | Custody hash |
|---|---|---|---|---|---|---|
Credit lifecycle, AI operator, portfolio, and model risk enterprise risk management | 9/9 complete lineage | 8 sources / 9 artifacts 9 export packages / 9 hashes | within 12m / 30m SLA | daily credit lifecycle, AI operator, portfolio, collateral, and model-risk evidence reconciliation; daily credit lifecycle, responsible lending affordability, AI operator, portfolio, collateral, model lifecycle, fair-lending, validation, challenger, PSI, override, and model-risk evidence reconciliation | Credit Risk Committee, AI Governance Council, and Board Risk Committee credit lifecycle, AI operator, model, and risk appetite pack | 5cdd6c901042...2a9e35e4 |
Enterprise risk appetite, limit, KRI, breach, exception, and committee decision evidence enterprise risk, CRO office, risk data governance, ALCO, conduct risk, technology risk, operational risk, and board secretariat | 12/12 complete lineage | 12 sources / 12 artifacts 12 export packages / 12 hashes | within 12m / 30m SLA | daily appetite statement, risk capacity, tolerance, limit, KRI, utilization, breach, exception, compensating control, second-line challenge, committee decision, signed minute, owner action, and custody evidence reconciliation | Board Risk Committee, ALCO, Conduct Committee, Technology Risk Committee, and Audit Committee enterprise risk appetite, limit breach, exception, and challenge pack | 1c870539585e...a8fe2b68 |
Enterprise stress scenario, reverse-stress, model, data, management-action, and board challenge evidence enterprise risk, risk analytics, model risk, capital planning, treasury risk, operational resilience, conduct risk, climate risk, and board secretariat | 13/13 complete lineage | 13 sources / 13 artifacts 13 export packages / 13 hashes | within 12m / 30m SLA | daily scenario inventory, severe-but-plausible variable, sensitivity, reverse-stress, model validation, challenger, data lineage, capital headroom, liquidity survival, stressed loss, customer harm, management action, committee decision, signed minute, and custody evidence reconciliation | Board Risk Committee, ALCO, Capital Committee, Operational Risk Committee, Conduct Committee, and Audit Committee enterprise stress testing pack | 99a036789b6b...85956854 |
Impairment, capital, and finance CFO and finance control | 2/2 complete lineage | 2 sources / 2 artifacts 2 export packages / 2 hashes | within 18m / 45m SLA | daily ECL recomputation evidence and monthly finance close reconciliation | Impairment Committee, Capital Committee, and Audit and Risk Committee pack | 63897837b789...5a9099fd |
Collateral valuation, lien custody, insurance, recovery, and asset disposition collateral operations, credit risk, legal control, recoveries, insurance operations, records manager, and conduct risk | 8/8 complete lineage | 8 sources / 8 artifacts 8 export packages / 8 hashes | within 18m / 45m SLA | daily collateral valuation, LTV, forced-sale value, registry search, lien perfection, custody, insurance, recovery, dispute hold, repossession, sale valuation, shortfall, impairment, and conduct evidence reconciliation | Credit Risk Committee, Impairment Committee, Conduct Risk Committee, and Board Risk Committee collateral valuation, lien custody, insurance, recovery, dispute, and asset disposition pack | 9dd9d67d0b80...76c5dcbc |
Treasury, deposits, wallet safeguarding, ALM, market risk, payments, and settlement treasury risk and payments operations | 5/5 complete lineage | 5 sources / 5 artifacts 5 export packages / 5 hashes | within 15m / 30m SLA | intraday liquidity ladder, deposit ledger, wallet float, safeguarding account, dormant balance, FX exposure, payment settlement, and ALM source reconciliation | ALCO and Board Risk Committee liquidity, deposits, wallet safeguarding, market risk, IRRBB, and settlement pack | c77d84fd418b...b4eaa704 |
Regulatory returns, regulatory horizon, and regulatory, fraud, collections conduct, insurance protection, financial crime KYC/CDD, records lifecycle, and privacy compliance, regulatory reporting, finance control, fraud risk, MLRO, conduct risk, insurance risk, data governance, and privacy office | 11/11 complete lineage | 11 sources / 11 artifacts 11 export packages / 11 hashes | within 22m / 60m SLA | daily fraud case and alert, collections conduct, insurance product, claim, trust-fund, reinsurance, regulatory obligation, AML case, KYC/CDD/beneficial ownership, STR/SAR, consent, DSAR, retention hold, archive, and complaint evidence reconciliation; daily regulatory return inventory, source-to-return tie-out, validation-rule, acknowledgement, amendment, fraud case and alert, collections conduct, insurance product, claim, trust-fund, reinsurance, regulatory obligation, AML case, KYC/CDD/beneficial ownership, STR/SAR, consent, DSAR, retention hold, archive, and complaint evidence reconciliation. Regulatory, fraud, collections conduct, insurance protection, financial crime KYC/CDD, records lifecycle, and privacy evidence remains grouped for board reporting continuity. | Risk and Compliance Committee fraud risk, collections conduct, insurance protection, regulatory, AML/KYC/CDD, records lifecycle, and privacy pack; regulatory returns and regulatory horizon evidence pack | c3344ebc22ff...a4ec5f1f |
Business network KYB, merchant, supplier, anchor buyer, RFQ, SCF invoice, RBF, vehicle import, procurement, exposure, and marketplace abuse evidence marketplace operations, MLRO, financial crime compliance, fraud risk, credit risk, payments operations, vendor risk, data governance, and board secretariat | 14/14 complete lineage | 14 sources / 14 artifacts 14 export packages / 14 hashes | within 10m / 30m SLA | daily legal entity, registration, tax PIN, beneficial ownership, ownership-register recency, sanctions, PEP, adverse media, bank account, permit, privacy notice, expected activity, RFQ, bid, award, SCF invoice, RBF drawdown, vehicle import, group procurement, duplicate invoice, settlement-account match, concentration, velocity, fraud signal, relationship review, manifest, action pack, and custody evidence reconciliation | Risk and Compliance Committee, Credit Risk Committee, Fraud Risk Committee, and Board Risk Committee business-network KYB, merchant, supplier, anchor-buyer, RFQ, SCF, RBF, import, procurement, exposure, and marketplace abuse pack | c82466316460...9fc7a9ae |
Agent network, teller cash, commission payouts, field liquidity, fraud, AML, and conduct operations agent network operations, cash operations, finance control, fraud operations, MLRO, and conduct risk | 8/8 complete lineage | 8 sources / 8 artifacts 8 export packages / 8 hashes | within 14m / 30m SLA | daily agent cluster, fit-and-proper, training, field liquidity, cash-out SLA, teller till, cash variance, commission payout, tax withholding, clawback, complaint, fraud, AML, and redress evidence reconciliation | Operational Risk Committee, Financial Crime Committee, ALCO, and Board Risk Committee agent network, teller cash, liquidity, commission, fraud, AML, and conduct pack | ac4fbddcee39...e5f501e0 |
Finance ledger, reconciliation, period close, financial reporting, audit, and regulatory returns finance control, CFO, reconciliation operations, tax, regulatory reporting, audit liaison, and data governance | 10/10 complete lineage | 10 sources / 10 artifacts 10 export packages / 10 hashes | within 9m / 30m SLA | daily ledger domain, chart-of-accounts, posting-rule, journal, subledger tie-out, reconciliation break, suspense balance, close milestone, report variance, audit PBC, regulatory return source reconciliation, validation exception, acknowledgement, CFO sign-off, and board finance evidence reconciliation. daily ledger domain, chart-of-accounts, posting-rule, journal, subledger tie-out, reconciliation break, suspense balance, close milestone, report variance, audit PBC, regulatory return, CFO sign-off, and board finance evidence reconciliation remains the baseline close-control cadence. | Audit Committee, ALCO, Impairment Committee, and Board Risk Committee finance ledger, reconciliation, suspense, close, reporting, audit, and regulatory return pack | 206565639c30...d583c1c8 |
Product pricing, fair value, RAROC, FTP, fee transparency, disclosure, lifecycle, complaints, and redress product governance, conduct risk, pricing committee, treasury risk, ALCO, risk finance, product finance control, credit policy, regulatory operations, and data governance | 19/19 complete lineage | 19 sources / 19 artifacts 19 export packages / 19 hashes | within 16m / 45m SLA | daily product APR, cost-stack, FTP curve, liquidity-cost allocation, contingent-liquidity premium, expected loss, capital charge, RAROC hurdle, stressed return, profitability attribution; daily product launch queue, regulatory perimeter, product APR, cost-stack, FTP curve, liquidity-cost allocation, contingent-liquidity premium, expected loss, capital charge, RAROC hurdle, stressed return, profitability attribution, fee cap, fair-value, total-cost-of-credit, key facts, affordability, vulnerable-customer, target-market, disclosure, distributor training, lifecycle gate, regulator notice, board approval, live-read, post-launch review, complaint, redress, pricing action, and product evidence reconciliation | Product Governance Committee, ALCO, Conduct Committee, Credit Risk Committee, Capital Committee, Audit Committee, and Board Risk Committee product pricing, fair value, RAROC, FTP, fee transparency, disclosure, lifecycle, complaints, and redress pack | ebf5f07f04da...13737d8a |
Loan servicing statements, repayment allocation, payoff quotes, waivers, reversals, refunds, disputes, and reconciliation evidence loan servicing operations, payments operations, finance control, treasury reconciliation, customer outcomes operations, conduct risk, special assets, data governance, and control assurance | 14/14 complete lineage | 13 sources / 14 artifacts 14 export packages / 14 hashes | within 11m / 30m SLA | daily statement amount, principal, interest, fee, due-date, delivery, dispute route, accessibility, payment rail, paid amount, allocation amount, suspense, waterfall order, fee cap, borrower instruction, overpayment, GL posting, schedule update, payoff quote, good-through date, per-diem, waiver credit, collateral release, exception, notice, redress, root cause, payment rail-to-ledger, allocation-to-schedule, statement-to-ledger, payoff-to-ledger, manifest, and custody evidence reconciliation | Conduct Committee, Credit Risk Committee, Audit Committee, and Board Risk Committee loan servicing statement, repayment waterfall, payoff quote, waiver, reversal, refund, dispute, redress, reconciliation, and evidence custody pack | e82817990cfc...c7686252 |
Payment error intake, unauthorized transfer, investigation, provisional credit, refund, provider dispute, redress, and reconciliation evidence payment error resolution, payments operations, treasury reconciliation, finance control, customer outcomes operations, conduct risk, privacy office, data governance, vendor risk, operational risk, and control assurance | 16/16 complete lineage | 15 sources / 16 artifacts 16 export packages / 16 hashes | within 9m / 30m SLA | daily payment error notice, unauthorized transfer, account, transaction, amount, acknowledgement, liability, investigation, transaction trace, ledger trace, provider trace, customer interview, written explanation, provisional credit, reversal, refund, provider dispute, callback, settlement file, customer impact, GL correction, redress, reconciliation, manifest, and custody evidence reconciliation | Payments Risk Committee, Conduct Committee, Audit Committee, and Board Risk Committee payment error, unauthorized transfer, provisional credit, refund, provider dispute, redress, reconciliation, and custody pack | 780ebe3a5cd1...58fcbc32 |
Scam reimbursement, unauthorized transfer, fraud victim care, receiving-party recovery, mule tracing, and fraud reporting evidence fraud operations, payment error resolution, payments operations, MLRO, conduct risk, customer outcomes, finance control, regulatory operations, privacy office, data governance, and control assurance | 21/21 complete lineage | 20 sources / 21 artifacts 21 export packages / 21 hashes | within 8m / 30m SLA | daily scam case, unauthorized transfer, claim amount, acknowledgement, payment trace, customer interview, liability assessment, exception review, vulnerable-customer override, reimbursement decision, reimbursement clock, GL posting, redress link, freeze request, recall, provider dispute, mule escalation, financial-crime case, settlement recovery, victim-care support, safe contact, language, hardship, fraud statistics, CBK pack, regulator route, board pack, root cause, manifest, action, and custody evidence reconciliation | Fraud Risk Committee, Financial Crime Committee, Payments Risk Committee, Conduct Committee, Audit Committee, and Board Risk Committee scam reimbursement, victim recovery, provider recovery, mule tracing, and fraud reporting pack | a59cff4b6d26...54a07c1d |
Customer outcomes, complaint handling, vulnerable support, redress, dispute escalation, and root-cause remediation customer dignity operations, conduct risk, customer remediation finance control, regulatory operations, legal control, control assurance, data governance, and records manager | 18/18 complete lineage | 17 sources / 18 artifacts 18 export packages / 18 hashes | within 10m / 30m SLA | daily complaint source, channel, acknowledgement, SLA, owner, impartial review, vulnerable-customer support, adjusted communication, hardship review, redress eligibility, calculation, approval, payout, ledger correction, tax treatment, dispute escalation, ombudsman/CBK route, legal review, third-party accountability, root cause, recurrence, validation, board minute, manifest, and custody evidence reconciliation | Conduct Committee, Risk and Compliance Committee, Audit Committee, and Board Risk Committee customer outcomes, complaint handling, vulnerable support, redress, dispute escalation, recurrence, and evidence custody pack | 398a1b96bf55...1d38405c |
Inclusive customer access, WCAG journey, language, comprehension, assisted channel, USSD fallback, financial education, and accessibility defect evidence accessibility lead, customer dignity operations, conduct risk, product governance, customer education, mobile channel operations, technology risk, data governance, and control assurance | 19/19 complete lineage | 18 sources / 19 artifacts 19 export packages / 19 hashes | within 12m / 30m SLA | daily WCAG critical check, keyboard, screen reader, focus, error prevention, timeout, contrast, low-bandwidth, language, translation, plain-language score, comprehension test, assisted support, USSD fallback, call center, agent, field officer, consent, transcript, privacy script, vulnerable-customer handoff, complaint route, education module, numeracy example, cost-of-credit, data-use, redress education, knowledge check, completion, defect, synthetic-action blocker, manifest, action, and custody evidence reconciliation | Customer and Conduct Committee, Technology Committee, Product Governance Committee, and Board Risk Committee inclusive access, language, assisted-channel, USSD fallback, financial education, defect remediation, and customer capability pack | 0bc3dcdc6881...1b66540a |
Credit bureau consent, data furnishing, negative-listing notice, dispute correction, and CRB update evidence credit operations, underwriting operations, data governance, privacy office, collections conduct, customer dignity operations, regulatory operations, and control assurance | 15/15 complete lineage | 14 sources / 15 artifacts 15 export packages / 15 hashes | within 11m / 30m SLA | daily bureau consent, named bureau, purpose, withdrawal, privacy notice, retention, portfolio furnishing, source ledger, exposure, identity match, account status, arrears balance, negative-listing notice, dispute right, cure route, vulnerable-customer review, adverse reason trace, notice of dispute, investigation, source-record trace, correction, deletion, bureau update, customer response, regulator escalation, manifest, and custody evidence reconciliation | Credit Risk Committee, Conduct Committee, Risk and Compliance Committee, and Board Risk Committee credit bureau furnishing, CRB dispute, correction, and evidence custody pack | a65b639f62e9...9f2db03c |
Responsible lending, income verification, expense reasonableness, obligations, DSR/PTI, stress affordability, exceptions, and decline evidence underwriting operations, credit policy, credit risk, conduct risk, model risk, privacy office, data governance, and control assurance | 16/16 complete lineage | 14 sources / 16 artifacts 16 export packages / 16 hashes | within 10m / 30m SLA | daily verified income, source recency, confidence, documentary evidence, bank statement, tax/payroll, M-Pesa cashflow, volatility, consent, privacy, retention, expense benchmark, household need, essential expense, obligation, bureau link, internal ledger link, off-balance commitment, priority debt, duplicate suppression, hardship check, DSR, PTI, residual income, stress installment, vulnerable-customer review, hardship history, manual override, second-line approval, adverse-action notice, explainability, customer choice, exception expiry, manifest, and custody evidence reconciliation | Credit Risk Committee, Conduct Committee, Model Risk Committee, Risk and Compliance Committee, and Board Risk Committee responsible lending, affordability, creditworthiness, vulnerable-customer, exception, decline, and evidence custody pack | 70f9c44e8e96...2bb05bcd |
Co-lending partner eligibility, allocation fairness, risk retention, settlement, servicing, concentration, and evidence custody co-lending operations, partner operations, enterprise credit risk, structured credit, treasury reconciliation, finance control, loan servicing operations, conduct risk, vendor risk, data governance, and control assurance | 18/18 complete lineage | 17 sources / 18 artifacts 18 export packages / 18 hashes | within 10m / 30m SLA | daily co-lending partner eligibility, due diligence, contract, audit rights, credit approval, risk share, allocation eligibility, borrower disclosure, risk retention, adverse-selection guard, waterfall match, partner share, borrower posting, GL posting, suspense, participant statement, servicing report, borrower notice, hardship protocol, complaint handoff, concentration limit, stressed exposure, early warning, capital impact, manifest, and custody evidence reconciliation | Credit Risk Committee, Vendor Risk Committee, Audit Committee, Conduct Committee, and Board Risk Committee co-lending partner, allocation, risk-retention, settlement, servicing, concentration, and custody pack | 1d8befeb91da...b07f8f85 |
Capital markets issuance, investor suitability, bookbuilding, settlement, trading, disclosure, funding concentration, and evidence custody capital markets desk, investor relations, treasury risk, settlement operations, market surveillance, finance control, legal control, conduct risk, financial crime compliance, regulatory operations, data governance, and control assurance | 16/16 complete lineage | 15 sources / 16 artifacts 16 export packages / 16 hashes | within 9m / 30m SLA | daily capital markets issuer approval, prospectus, legal review, regulator filing, credit rating, trustee, custodian, use-of-proceeds, listing, investor eligibility, KYC, AML, suitability, risk disclosure, appropriateness, concentration, cooling-off, complaint route, order compliance, allocation fairness, price discovery, conflict check, insider restriction, audit trail, settlement match, segregated funds, CSD instruction, refund route, GL posting, investor statement, trade verification, price exception, late report, best execution, market abuse, settlement finality, investor report, covenant status, material development, performance, ECL, lineage, redaction, board signoff, funding concentration, liquidity impact, refinancing plan, investor call, contingency funding, manifest, and custody evidence reconciliation | ALCO, Conduct Committee, Audit Committee, Capital Markets Committee, and Board Risk Committee issuance, investor suitability, bookbuilding, settlement, trading, disclosure, funding concentration, and custody pack | 38fef31186aa...506b7275 |
Structured credit loan-pool, true-sale, SPV, waterfall, servicer, investor-reporting, capital-relief, and risk-retention evidence structured credit, capital markets desk, treasury risk, capital planning, finance control, legal control, investor relations, loan servicing operations, conduct risk, data governance, privacy office, and control assurance | 23/23 complete lineage | 22 sources / 23 artifacts 23 export packages / 23 hashes | within 8m / 30m SLA | daily loan pool eligibility, data tape, concentration, delinquency, customer notice, consent, adverse-selection, true sale, derecognition, originator isolation, SPV document, tranche enhancement, reserve fund, liquidity facility, trustee, custodian, waterfall, collection reconciliation, trigger, segregated account, investor distribution, GL posting, servicer continuity, backup servicer, data escrow, investor report, material development, RWA, capital relief, significant risk transfer, risk retention, cleanup call, implicit support, stress impact, board minute, manifest, and custody evidence reconciliation | ALCO, Capital Committee, Audit Committee, Conduct Committee, and Board Risk Committee structured-credit loan-pool, true-sale, SPV, waterfall, servicer, investor-reporting, capital-relief, risk-retention, and custody pack | 582a98b5a3be...f8b83bef |
External data-room, due-diligence, disclosure, redaction, recipient access, activity audit, revocation, and evidence custody data room operations, investor relations, regulatory operations, legal control, privacy office, security governance, data governance, records manager, finance control, board secretariat, and control assurance | 15/15 complete lineage | 14 sources / 15 artifacts 15 export packages / 15 hashes | within 7m / 30m SLA | daily room purpose, legal basis, NDA, recipient approval, MFA, expiry, export scope, redaction, classification, privilege, PII scan, disclosure index, hash manifest, watermark, download control, materiality review, Q&A, activity log, anomaly, revocation, legal hold, regulator route, manifest, and custody evidence reconciliation | Board Risk Committee, Audit Committee, Technology Committee, Conduct Committee, and Capital Markets Committee external data-room room approval, recipient access, redaction, disclosure, activity audit, revocation, regulator route, and custody pack | 7ce4dc46897f...a3949acd |
Market abuse, insider list, market sounding, best execution, communications surveillance, STOR reporting, and evidence custody market surveillance, trading oversight, compliance surveillance, conduct risk, legal control, investor relations, regulatory operations, records manager, data governance, control assurance, and board secretariat | 20/20 complete lineage | 19 sources / 20 artifacts 20 export packages / 20 hashes | within 6m / 30m SLA | daily alerts, trades, orders, price-volume benchmarks, insider lists, restricted lists, watch lists, wall crossings, personal-account dealing, market soundings, consent, disclosure packs, recordings, cleanse notices, best-execution benchmarks, venue policies, cost disclosure, communications capture, lexicon hits, escalation closure, retention, STOR decisions, regulator route, filing SLA, manifest, live-read, synthetic-action, and custody evidence reconciliation | Conduct Committee, Capital Markets Committee, Audit Committee, Technology Committee, and Board Risk Committee market-abuse surveillance, insider-list, market-sounding, best-execution, communications, STOR, regulator-route, and custody pack | 1d086203385f...42f7a209 |
Sustainable finance taxonomy, proceeds, impact claims, targets, verification, social safeguards, greenwashing, and evidence custody sustainable finance, climate risk, impact measurement, treasury reconciliation, finance control, conduct risk, privacy office, legal control, data governance, and control assurance | 17/17 complete lineage | 16 sources / 17 artifacts 17 export packages / 17 hashes | within 8m / 30m SLA | daily taxonomy criteria, climate objective, DNSH, minimum safeguard, exclusion screen, eligible allocation, unallocated proceeds, allocation age, escrow, invoice, borrower consent, refinancing lookback, impact target, measured value, verified value, method, lineage, beneficiary, double-counting, negative-impact review, disclosure approval, sustainability target, KPI calibration, penalty, external benchmark, board approval, verification age, independence, scope, sample coverage, opinion, remediation, public report, population screening, grievance, vulnerable-customer, community consent, privacy, no-harm, redress, manifest, and custody evidence reconciliation | Sustainable Finance Committee, Conduct Committee, Audit Committee, ALCO, and Board Risk Committee taxonomy, proceeds, impact-claim, target, assurance, safeguard, greenwashing, and custody pack | e95a4076c3e0...6c3810a2 |
Supervisory exam requests, regulator responses, findings, regulatory commitments, and board escalation regulatory operations, compliance assurance, legal control, enterprise risk, records manager, and data governance | 10/10 complete lineage | 10 sources / 10 artifacts 10 export packages / 10 hashes | within 11m / 30m SLA | daily supervisory request intake, scope, due-date, owner, legal privilege, confidentiality, response artifact, QA, redaction, approval, submission, acknowledgement, finding root-cause, customer-harm, validation, commitment milestone, regulator update, board route, action, and custody evidence reconciliation | Risk and Compliance Committee and Board Risk Committee supervisory request, response, finding remediation, commitment delivery, legal review, and regulator communication pack | ee94bac817e1...e83a250f |
Regulatory perimeter, licensing, key-person, change-control, product approval, country expansion, and no-objection evidence legal control, regulatory operations, company secretary, privacy office, financial crime compliance, payments operations, product governance, platform expansion, and risk data governance | 20/20 complete lineage | 20 sources / 20 artifacts 20 export packages / 20 hashes | within 9m / 30m SLA | daily regulated activity, authority, jurisdiction, licence, registration, authorization, key person, fit-and-proper, shareholder, source of funds, ownership change, third-party notice, payment change, data-processing registration, AML reporting-institution, CMA approval, insurance gate, product launch, country expansion, no-objection, board minute, regulator acknowledgement, action pack, and custody evidence reconciliation | Risk and Compliance Committee and Board Risk Committee regulatory perimeter, licence, authorization, fit-and-proper, change-control, product approval, country expansion, and custody pack | 7b23d7afe833...bf2c2f71 |
Tax statutory obligations, payroll contributions, iTax/eTIMS filings, ledger reconciliations, tax positions, audit queries, and evidence custody tax operations, CFO tax control, payroll tax, people operations, finance control, treasury reconciliation, legal control, compliance assurance, records manager, privacy office, and data governance | 13/13 complete lineage | 12 sources / 13 artifacts 13 export packages / 13 hashes | within 8m / 30m SLA | daily KRA obligation, iTax registration, return draft, payment slip, portal acknowledgement, bank proof, certificate, VAT, PAYE, withholding tax, corporate tax, affordable housing levy, SHA/SHIF, NSSF, NITA, payroll population, employee deduction, employer contribution, remittance file, payslip disclosure, eTIMS source invoice, source ledger, return amount, payment amount, variance, suspense, technical memo, legal basis, external advisor review, provision approval, disclosure assessment, board visibility, tax audit query, manifest, and custody evidence reconciliation | Audit Committee, Risk and Compliance Committee, ALCO, and Board Risk Committee tax obligation, statutory payroll, iTax, eTIMS, reconciliation, tax-position, audit-query, and custody pack | 7e45413cbebf...744061a4 |
Resilience, cybersecurity, identity access, third-party, cyber resilience, API platform, and live data trust platform ops, security governance, security operations, identity platform, vendor risk, API platform, and data governance | 15/15 complete lineage | 10 sources / 15 artifacts 15 export packages / 15 hashes | within 10m / 30m SLA | release-lifetime CI, third-party provider monitoring, identity access review, privileged event, service-account, cyber resilience telemetry, API platform governance, and monthly evidence-manifest reconciliation; release-lifetime CI, third-party provider monitoring, identity access review, privileged event, service-account, cryptographic key custody, FIPS module boundary, rotation, escrow, destruction, cyber resilience telemetry, API platform governance, and monthly evidence-manifest reconciliation; daily open-finance consent, scope, token, recipient, revocation, portability, DSAR, and custody evidence reconciliation | Technology Committee and Audit and Risk Committee resilience, third-party, identity access, cyber resilience, API platform, and data-trust pack | 94965956624b...50e00014 |
Board, assurance, and supervisory reporting risk and compliance assurance and board secretariat | 2/2 complete lineage | 2 sources / 2 artifacts 2 export packages / 2 hashes | within 20m / 45m SLA | monthly three-lines assurance review and board minutes custody reconciliation | Board Risk Committee control assurance and decision trail pack | 52a8e3996ce3...530a78c4 |
Internal audit universe, annual plan, engagement workpapers, issue validation, QAIP, audit committee, and examiner evidence chief audit executive, audit data analytics, control assurance, enterprise risk, records manager, and board secretariat | 13/13 complete lineage | 13 sources / 13 artifacts 13 export packages / 13 hashes | within 10m / 30m SLA | daily audit universe, annual plan, audit committee approval, independence attestation, data access, engagement scope, RCM, sample coverage, workpaper review, report, management response, issue validation, recurrence monitoring, QAIP, external assessment, manifest mapping, board minute, examiner request, action pack, and custody evidence reconciliation | Audit Committee and Board Risk Committee internal audit governance, issue validation, QAIP, and examiner evidence pack | 62da3fb1c7cc...ee0b6fed |
Corporate board governance, director fit-and-proper, committee, conflict, related-party, policy, disclosure, and board evidence board secretariat, company secretary, enterprise risk, legal control, compliance assurance, records manager, and risk data governance | 14/14 complete lineage | 14 sources / 14 artifacts 14 export packages / 14 hashes | within 9m / 30m SLA | daily board charter, reserved matter, delegated authority, director fit-and-proper, CBK filing, independence, attendance, CPD, conflict, directorship, tenure, committee mandate, quorum, minutes, related-party exposure, recusal, independent review, policy approval, risk appetite, evaluation, succession, disclosure, stakeholder channel, board minute, action pack, and custody evidence reconciliation | Audit Committee and Board Risk Committee corporate board governance, director suitability, conflict, related-party, policy, disclosure, and evidence custody pack | 752477fe9bcb...037a32e2 |
Crisis command, war-room operations, regulator/customer communications, recovery activation, after-action lessons, and custody enterprise crisis management team, operational resilience, legal control, regulatory operations, customer operations, vendor risk, security operations, control assurance, and board secretariat | 15/15 complete lineage | 15 sources / 15 artifacts 15 export packages / 15 hashes | within 6m / 15m SLA | near-real-time crisis event, severity, incident ID, critical operation, war-room, command cell, contact tree, approved script, regulator notice, customer notice, provider escalation, recovery option, impact tolerance, remediation action, postmortem, recurrence monitoring, board minute, manifest, and custody evidence reconciliation | Board Risk Committee and Audit Committee crisis command, communications, recovery activation, after-action, recurrence, and custody pack | 01de295cffc1...f1bd150d |
Operational continuity, critical-function exit tests, provider substitutability, data portability, transition rehearsal, solvent wind-down, communications, and custody operational resilience, vendor risk, legal control, data governance, privacy, platform engineering, treasury operations, customer operations, enterprise risk, control assurance, and board secretariat | 15/15 complete lineage | 15 sources / 15 artifacts 15 export packages / 15 hashes | within 12m / 30m SLA | daily critical-function, provider-exit, data-export, checksum, lineage, transition-runbook, wind-down, communication, board-minute, manifest, action, and custody evidence reconciliation | Board Risk Committee operational continuity, exit portability, provider substitution, transition rehearsal, wind-down, communication, and custody pack | 070c6bffc1d5...fb1657a5 |
Production change, release gates, configuration baselines, software supply-chain artifacts, deployment health, rollback, customer harm, and evidence custody release management, platform engineering, security operations, service owners, enterprise risk, vendor risk, customer operations, control assurance, and board secretariat | 15/15 complete lineage | 14 sources / 15 artifacts 15 export packages / 15 hashes | within 11m / 30m SLA | daily production-change, approval, SoD, release-gate, test, security, performance, canary, feature-flag, rollback, configuration-drift, SBOM, provenance, vulnerability, deployment-health, customer-harm, remediation, manifest, and custody evidence reconciliation | Technology Committee and Board Risk Committee change, release, configuration, software supply-chain, deployment health, rollback, customer harm, and custody pack | a83223d79d0f...95b8b760 |
Enterprise remediation, owner queues, board decisions, signed minutes, validation, and recurrence monitoring enterprise risk, control assurance, board secretariat, records manager, data governance, and internal audit liaison | 10/10 complete lineage | 10 sources / 10 artifacts 10 export packages / 10 hashes | within 10m / 30m SLA | daily source action, source control, owner queue, SLA, overdue, blocked, board decision, signed minute, owner notification, due-date acceptance, validation, customer impact, recurrence monitoring, manifest, action, and custody evidence reconciliation | Audit Committee and Board Risk Committee enterprise remediation, owner queue, signed-minute, validation, recurrence, and custody pack | 44f7f27cd80b...ad4e3039 |
| BCBS 239 control | Metric | Current | Limit | Status | Custody hash |
|---|---|---|---|---|---|
Risk data ownership and governance Risk data aggregation must be governed with clear accountability, ownership, and oversight. | Risk data domains with accountable owners and board report routes | 35 | 35 | within | c67f6779b568...9098ab09 |
Risk data lineage completeness Risk reports must trace material risk measures back to source systems and control evidence. | Required cross-domain controls mapped to source routes, artifacts, and export packages | 100.00% | 100.00% | within | bbea1e624a92...74087730 |
Risk domain completeness Risk aggregation must cover all material risk types and concentrations across the group. | Domains with every required control represented in the manifest | 35 | 35 | within | c254798eb399...e04ef8e9 |
Risk data accuracy and integrity custody Risk reports must be accurate, reconciled, and tamper-evident. | Required manifest rows with SHA-256 custody hashes | 100.00% | 100.00% | within | b482f7ac566f...7aca9576 |
Risk reporting timeliness Aggregated risk data must be available quickly enough for normal and stress decision-making. | Risk data domains delivered inside reporting SLA | 100.00% | 100.00% | within | 7f3d519f08d2...924c6aff |
Adaptability and stress reporting Risk data architecture must adapt to stress, crisis, and supervisory reporting requests. | Domains ready for ad hoc stress, scenario, and supervisory information requests | 100.00% | 100.00% | within | 36b224aa3f39...31fdf433 |
Risk data reconciliation cadence Risk data must be reconciled across source systems, control evidence, and reports. | Distinct export packages supporting recurring reconciliation evidence | 76 | 35 | within | 1a806a53f302...04036cef |
Board risk reporting coverage Senior management and boards must receive complete, useful, and decision-ready risk reports. | Risk domains with board report route and evidence package | 100.00% | 100.00% | within | 4ac20b90a9c6...032c1139 |
| Trigger | Status | Evidence | Action | Deadline |
|---|---|---|---|---|
| No BCBS 239 risk data action packs are required for the current manifest. | ||||
| Recovery trigger | Metric | Current / watch / breach | Evidence | Linked options | Status | Custody hash |
|---|---|---|---|---|---|---|
Capital buffer deterioration CFO and enterprise risk / daily during stress and monthly in BAU | Capital buffer headroom against approved ICAAP floor | 134.00% / 112.00% / 100.00% | 1/1 1 source routes / 1 hashes | capital-conservation-actions, equity-injection-plan, solvent-origination-wind-down | within | 02e6bced601b...2be48332 |
Liquidity survival horizon deterioration treasury risk and ALCO / intraday during stress and weekly in BAU | Days of liquidity survival under stressed outflow | 47d / 35d / 30d | 1/1 1 source routes / 1 hashes | contingency-funding-drawdown, portfolio-sale-liquidity-release, provider-failover-liquidity-protection | within | f5ed1d47afcb...9018600c |
Funding concentration escalation treasury risk / daily concentration ladder | Largest stressed funding source concentration | 22.00% / 35.00% / 40.00% | 2/2 2 source routes / 2 hashes | contingency-funding-drawdown, portfolio-sale-liquidity-release | within | c5f988555ba0...263a162b |
IRRBB earnings and economic value stress treasury risk and finance control / monthly ALCO and ad hoc stress | Interest-rate shock exposure against board appetite | 9.00% / 15.00% / 20.00% | 1/1 1 source routes / 1 hashes | pricing-and-duration-reset, portfolio-sale-liquidity-release | within | da8da52574a5...11a3c8f8 |
Payment settlement disruption payments operations and treasury control / near real-time payment rail monitoring | Pending settlement exposure against daily disbursement capacity | 4.00% / 8.00% / 12.00% | 2/2 2 source routes / 2 hashes | provider-failover-liquidity-protection, customer-communication-and-hardship-controls | within | b37a4f4202b8...3be27672 |
Critical operation outside tolerance platform operations and operational risk / continuous operational telemetry | Critical operations inside approved impact tolerance | 100.00% / 95.00% / 90.00% | 3/3 2 source routes / 3 hashes | provider-failover-liquidity-protection, customer-communication-and-hardship-controls, solvent-origination-wind-down | within | 3a6fc7042210...bc5ab016 |
Risk data aggregation and reporting degradation data governance and enterprise risk / daily evidence manifest reconciliation | Risk data domains delivered inside reporting SLA | 100.00% / 95.00% / 90.00% | 2/2 2 source routes / 2 hashes | board-and-regulator-communications | within | 177a7fcb1f35...64fd209d |
Customer harm, conduct, or financial-crime stress conduct risk, MLRO, and privacy office / daily severe customer-harm and financial-crime review | Open severe conduct, AML, or privacy control exceptions | 0 / 1 / 2 | 3/3 3 source routes / 3 hashes | customer-communication-and-hardship-controls, board-and-regulator-communications | within | 5384ec391110...80454e67 |
| Recovery option | Capacity | Activation | Critical ops | Communications | Status | Hash |
|---|---|---|---|---|---|---|
Contingency funding drawdown Restore stressed liquidity survival horizon with approved committed lines and treasury float actions. treasury risk and ALCO | Liq KES 175m Cap KES 0m | treasurer 6h / tested 2026-06-18 Reversibility high | 2 treasury-disbursement, loan-servicing-ledger | CBK liquidity stress notice route approved borrower pending-state and payment-status communications | within | e1f85fa1aaa8...9d1101e1 |
Seasoned loan portfolio sale or participation Release liquidity and lower RWA density through pre-approved separable loan pools. CFO and enterprise risk | Liq KES 210m Cap KES 42m | capital committee chair 48h / tested 2026-06-27 Reversibility medium | 2 loan-servicing-ledger, collections-promises | CBK portfolio transfer and material change notice route servicing continuity and customer notice review | within | 99078cce366b...b2a8395a |
Capital conservation and expense controls Slow capital consumption through distribution lock, expense controls, and appetite tightening. CFO and enterprise risk | Liq KES 55m Cap KES 68m | CFO 24h / tested 2026-06-30 Reversibility high | 2 credit-decisioning, officer-queue-triage | CBK capital conservation supervisory update route fair-value and adverse-action reason review for tightened underwriting | within | acf6c5db6ee2...d86e697d |
Shareholder capital injection package Restore capital buffers through pre-cleared investor evidence and board subscription authorities. CFO and board secretariat | Liq KES 0m Cap KES 190m | board chair 72h / tested 2026-06-26 Reversibility low | 2 credit-decisioning, loan-servicing-ledger | CBK capital plan and shareholder approval route no customer-facing service degradation | within | 0c15acd1c633...1541e120 |
Pricing, duration, and origination appetite reset Reduce IRRBB and credit losses by repricing new production, reducing tenor, and pausing weak segments. ALCO and credit risk | Liq KES 35m Cap KES 28m | ALCO chair 12h / tested 2026-07-01 Reversibility high | 2 credit-decisioning, officer-queue-triage | board-approved pricing and product governance minutes route fair-value monitoring and vulnerable-customer review | within | 6e54db979e75...2110d9cd |
Critical provider failover and payment rail substitution Keep critical operations inside tolerance while payment, bureau, notification, or storage providers degrade. platform operations, vendor risk, and treasury operations | Liq KES 40m Cap KES 0m | incident commander 4h / tested 2026-06-28 Reversibility high | 5 treasury-disbursement, credit-decisioning, collections-promises, loan-servicing-ledger, officer-queue-triage | material service disruption notice route clear wait-state, reversal, and hardship communications | within | 810db5c78be1...db3365a6 |
Solvent origination wind-down and servicing continuity Stop new risk intake while preserving servicing, collections promises, disbursement finality, and evidence exports. CEO, CFO, enterprise risk, and board secretariat | Liq KES 90m Cap KES 75m | CEO 24h / tested 2026-07-02 Reversibility medium | 4 credit-decisioning, loan-servicing-ledger, collections-promises, officer-queue-triage | CBK solvent wind-down and material business change notice route borrower communication, complaint triage, and hardship protection plan | within | 40e1bedfcf74...8c5b59e9 |
Customer communication and hardship control package Protect borrowers during recovery actions with clear notices, complaint triage, hardship routing, and conduct evidence. customer dignity operations and conduct risk | Liq KES 10m Cap KES 8m | chief customer officer 8h / tested 2026-07-03 Reversibility high | 2 collections-promises, officer-queue-triage | customer harm and conduct risk committee notice route vulnerable-customer and complaint SLA oversight | within | 6b136714b8cf...58e57fc3 |
Board, regulator, and market communication package Maintain decision trail, supervisory transparency, and consistent stakeholder communications during recovery. board secretariat, compliance, and CEO office | Liq KES 0m Cap KES 0m | board secretary 6h / tested 2026-07-04 Reversibility high | 2 officer-queue-triage, loan-servicing-ledger | CBK and relevant regulator crisis communication route consistent customer notice and complaint escalation script | within | 334c6a2f77dc...b846330f |
| FSB recovery control | Current | Limit | Status | Action |
|---|---|---|---|---|
Recovery trigger framework completeness Recovery planning must define quantitative and qualitative triggers that escalate before non-viability. | 8 | 8 | within | Map every recovery trigger to evidence controls, owners, cadence, and board escalation before relying on the recovery plan. 71b21a8b5227...ca060659 |
Recovery option depth and feasibility Recovery plans must include credible, actionable options across capital, liquidity, operations, and communications. | 100.00% | 100.00% | within | Refresh feasibility testing, preconditions, and execution authorities for any option that is untested or too slow. 8fc618a586ec...9a2e9cc0 |
Capital and liquidity restoration capacity Recovery options must be capable of restoring capital and liquidity buffers under severe but plausible stress. | KES 1026m | KES 300m | within | Increase committed funding, portfolio-sale capacity, capital plan depth, or capital conservation authority. 1b26d4d32aa4...7439d0ca |
Critical operation continuity through recovery Recovery and resolution planning must preserve critical functions and critical shared services. | 100.00% | 100.00% | within | Attach recovery options to any critical operation without fallback, servicing, or evidence export coverage. 4166a2b53e8b...fda06b28 |
Provider substitutability and shared-service resilience Recovery planning must address outsourced critical services and operational dependencies. | 100.00% | 100.00% | within | Close provider exit, data-return, step-in, and fallback test evidence before crisis activation. ec8a16e0cded...0e18029c |
Separability and solvent wind-down readiness Recovery and resolution plans should support separability, continuity, and orderly wind-down where needed. | 1 | 1 | within | Maintain a tested solvent wind-down option with customer communications, board authorities, and regulator notice routes. a127279d4ced...152090e6 |
Board, regulator, and customer communication readiness Recovery planning must include communication procedures for authorities, governance bodies, markets, and affected customers. | 100.00% | 100.00% | within | Complete regulator-notice, customer-protection, and single-message scripts for every recovery option. 2647cb7a0d72...d427dc80 |
Board governance and crisis decision trail The board and senior management must approve, challenge, and maintain recovery planning and crisis escalation. | 100.00% | 100.00% | within | Attach crisis governance authorities, decision logs, and committee routes to all triggers. a58778d60a43...28bd368d |
Testing, evidence custody, and resolvability pack integrity Recovery and resolution planning should be regularly tested, maintained, and supported by reliable information. | 100.00% | 100.00% | within | Regenerate missing custody hashes and retest stale recovery options before board or supervisory submission. 50ceb42e1c3d...7d3ba78c |
| Trigger | Status | Evidence | Owner | Action | Deadline |
|---|---|---|---|---|---|
| No recovery and resolution action packs are required for the current evidence set. | |||||
| RCSA process | Category | Owners | Risk score | Controls | Scenario / board route | Status | Hash |
|---|---|---|---|---|---|---|---|
Digital origination, scorecard, and product change management model-release approval gate, adverse-action notice QA, privacy launch gate, customer outcome review | clients_products_business_practices | product and credit operations 2L: operational risk and compliance | Inherent 4.4 Residual 1.8 / appetite 2.5 Test 100% | 4/4 3 sources / 4 hashes | scenario tested credit and conduct committee operational risk pack 2026-06-24 to 2026-09-24 | within | e213ac782b80...5b6e06eb |
Payment initiation, settlement finality, and exception repair rail health monitor, settlement reconciliation, exception repair queue, cash suspense review | execution_delivery_process_management | treasury payments operations 2L: payments risk and treasury control | Inherent 4.2 Residual 1.7 / appetite 2.4 Test 100% | 3/3 3 sources / 3 hashes | scenario tested payments risk committee and board risk committee pack 2026-06-18 to 2026-09-18 | within | 8e621cd7e3b3...fd7505b7 |
Loan servicing, repayment allocation, and ledger posting ledger replay custody, critical operation tolerance, audit event reconciliation | business_disruption_system_failures | servicing operations 2L: operational risk and finance control | Inherent 4.1 Residual 1.6 / appetite 2.3 Test 100% | 3/3 3 sources / 3 hashes | scenario tested operational resilience and finance control pack 2026-06-21 to 2026-09-21 | within | 87e7ef02364e...7a572f1e |
Fraud detection, AML case handling, and sanctions escalation typology surveillance, sanctions escalation, case disposition QA, fail-closed read access | external_fraud | fraud operations 2L: MLRO and financial crime compliance | Inherent 4.5 Residual 1.9 / appetite 2.2 Test 100% | 3/3 3 sources / 3 hashes | scenario tested financial crime and risk committee pack 2026-06-26 to 2026-09-26 | within | d10d454601e8...d9ab742e |
Privileged access, segregation of duties, and internal abuse prevention server session token isolation, privileged access review, segregation of duties, assurance review | internal_fraud | security engineering 2L: security governance risk and compliance | Inherent 4.0 Residual 1.5 / appetite 2.0 Test 100% | 3/3 3 sources / 3 hashes | scenario tested technology and audit committee access governance pack 2026-06-29 to 2026-09-29 | within | 0058cc2837c8...a6285511 |
Staff conduct, branch handling, and customer vulnerability controls vulnerable-customer review, complaint SLA oversight, branch conduct sampling, board conduct reporting | employment_practices | branch operations 2L: conduct risk and compliance | Inherent 3.5 Residual 1.4 / appetite 2.0 Test 100% | 3/3 3 sources / 3 hashes | scenario tested customer and conduct committee pack 2026-07-01 to 2026-10-01 | within | e0bfe8f3f447...3b3c67c0 |
Evidence custody, document handling, and physical continuity object-lock custody, provider exit pack, evidence replay test, recovery pack archive | damage_to_physical_assets | examiner evidence operations 2L: operational risk and internal audit | Inherent 3.7 Residual 1.5 / appetite 2.1 Test 100% | 3/3 3 sources / 3 hashes | scenario tested audit and risk committee custody continuity pack 2026-07-02 to 2026-10-02 | within | 2e03448ad321...24fb6e62 |
| Loss event / near miss | Loss | Root cause | Remediation | Evidence | Status | Hash |
|---|---|---|---|---|---|---|
Mobile-money callback lag created temporary settlement suspense execution_delivery_process_management / payments operations 2026-06-27 detected 2026-06-27 (0d) | Gross KES 1.2m Net KES 0.0m 42 customers | provider callback queue degradation | closed / complete due 2026-06-28 payments risk committee closure note | 2/2 2 linked hashes | within | 4d5745c6fc76...645e8c81 |
Bureau retry spike increased manual review workload external_fraud / credit risk and fraud operations 2026-06-24 detected 2026-06-24 (0d) | Gross KES 0.7m Net KES 0.0m 0 customers | bureau provider latency and retry backoff tuning | closed / complete due 2026-06-25 credit risk committee operational event closure | 3/3 3 linked hashes | within | 222150b93701...8de0e696 |
Complaint SLA exception cluster after repayment notice delay clients_products_business_practices / customer dignity operations 2026-06-30 detected 2026-07-01 (1d) | Gross KES 0.3m Net KES 0.0m 18 customers | notification sequencing and branch follow-up gap | closed / complete due 2026-07-02 customer and conduct committee closure note | 2/2 2 linked hashes | within | 4a6cd9fc488d...d1010b14 |
Privileged access near-miss blocked by server session isolation internal_fraud / identity platform 2026-07-02 detected 2026-07-02 (0d) | Gross KES 0.0m Net KES 0.0m 0 customers | stale temporary access role removed during review | closed / complete due 2026-07-02 technology committee access governance note | 2/2 2 linked hashes | within | c22201c9f646...8507b59c |
| KRI | Current / watch / breach | Playbook | Status | Hash |
|---|---|---|---|---|
Manual payment repair rate payments operations / daily Share of payment items requiring manual repair | 1.20% / 2.50% / 4.00% | activate settlement exception tiger team and provider callback review 1/1 controls / 1 hashes | within | d8222ae9a36a...8d85d58d |
Critical operation exception rate platform operations / continuous Critical operation checks outside tolerance | 0 / 1 / 2 | open impact tolerance incident and recovery action pack 2/2 controls / 2 hashes | within | 7004fbf3eac7...b18985ce |
Conduct and complaint SLA breach rate customer dignity operations / daily Severe complaint SLA breach share | 0.40% / 2.00% / 5.00% | activate complaint triage capacity and product root-cause review 2/2 controls / 2 hashes | within | 38ba98fa053c...7c2c7243 |
Privileged access review exceptions identity platform / weekly Open privileged access exceptions | 0 / 1 / 2 | remove stale grants and require security governance sign-off 2/2 controls / 2 hashes | within | 8faceed97c23...8b2157c7 |
Financial crime case aging financial crime compliance / daily High-risk AML cases past internal SLA | 0 / 1 / 3 | escalate to MLRO and case quality review 1/1 controls / 1 hashes | within | f8c72755ff0a...d2877e8c |
Evidence custody replay gaps examiner platform / weekly Custody artifacts missing replay hash | 0 / 1 / 2 | replay custody manifest and provider exit evidence pack 2/2 controls / 2 hashes | within | f740c8d6b173...4d37525d |
Staff conduct control training gaps people operations and conduct risk / monthly Staff in critical roles with overdue conduct refresher | 0 / 3 / 10 | block high-risk assignments and refresh branch conduct controls 2/2 controls / 2 hashes | within | 46ad00369e72...660ff89b |
| Operational risk control | Current | Limit | Status | Action |
|---|---|---|---|---|
Operational risk governance and ownership The board and senior management should establish strong operational risk culture, governance, and accountability. | 7 | 7 | within | Assign first-line owners, second-line reviewers, and board reporting routes before accepting operational risk exposure. ba38b5f6ae46...62ac3e3a |
Operational risk taxonomy coverage Operational risk identification should cover products, activities, processes, systems, people, external events, and material categories. | 7 | 7 | within | Extend the RCSA taxonomy to every Basel operational risk event category before board reporting. 2b80474e9dfe...ba12d712 |
RCSA and control testing coverage Operational risk management should use risk and control self-assessments, control testing, and action-plan monitoring. | 100.00% | 100.00% | within | Refresh stale RCSAs, missing evidence links, and failed control tests before relying on operational risk reports. b6cdb4dd4f2f...5440e030 |
Residual operational risk appetite Operational risk appetite and tolerance should be articulated, monitored, and escalated. | 100.00% | 100.00% | within | Lower residual risk through controls, staffing, automation, or acceptance authority for any process over appetite. 5686c123e45a...b44db3f8 |
Loss-event, near-miss, and root-cause capture Operational risk frameworks should capture loss events, near misses, root causes, and lessons learned. | 4 | 4 | within | Record complete gross loss, recovery, root-cause, and remediation evidence for every operational event. 99b8cc4a4d5f...aed217e7 |
Operational loss remediation closure Operational risk action plans should be monitored through closure with accountable ownership. | 0 | 0 | within | Close remediation, customer restitution, and root-cause actions before committee sign-off. 3a32cc170be4...0185935c |
Key risk indicator monitoring and escalation Operational risk should be monitored through timely indicators, reporting, and escalation. | 100.00% | 100.00% | within | Activate owner playbooks for KRIs outside threshold and update operational risk reports. fa7f9ceebe48...cb4cf349 |
Operational risk scenario analysis Operational risk identification and assessment should include scenario analysis and forward-looking tools. | 100.00% | 100.00% | within | Run scenario analysis for untested processes and attach loss, customer harm, continuity, and capital implications. bdda6533a328...a70b4ba2 |
Board operational risk reporting and disclosure readiness Senior management and the board should receive useful operational risk reports and support appropriate disclosure. | 100.00% | 100.00% | within | Route RCSA, loss-event, KRI, scenario, and remediation evidence into board and disclosure packs. 3acfd62aed91...b5eca526 |
Operational risk evidence custody Operational risk reporting should be reliable, complete, and traceable to underlying evidence. | 100.00% | 100.00% | within | Regenerate custody hashes and evidence routes before board, audit, or supervisory submission. 3bf481f3f7eb...bef6e144 |
| Trigger | Status | Evidence | Owner | Deadline |
|---|---|---|---|---|
| No operational risk action packs are required for the current evidence set. | ||||
KRA, SHA/SHIF, NSSF, payroll statutory deductions, iTax filing calendar, eTIMS and ledger reconciliation, transfer-pricing, audit-query, live-read, synthetic-action, and evidence-custody controls.
| Obligation | Liability / remittance | Filing and portal controls | Status | Hash |
|---|---|---|---|---|
VAT monthly return and payment Kenya Revenue Authority / tax operations | KES 12.8M / KES 12.8M / outstanding KES 0 of KES 50K | due 12/5d / return ready / slip ready / ack ready / cert ready / live ready | within | 9774afdc5b41...f2f769dc |
PAYE monthly deduction and remittance Kenya Revenue Authority / payroll tax | KES 18.4M / KES 18.4M / outstanding KES 0 of KES 50K | due 9/5d / return ready / slip ready / ack ready / cert ready / live ready | within | e3938da3c7a1...d20c3835 |
Withholding tax remittance and certificates Kenya Revenue Authority / accounts payable tax | KES 4.2M / KES 4.2M / outstanding KES 0 of KES 25K | due 4/2d / return ready / slip ready / ack ready / cert ready / live ready | within | 87e059e69210...4e814076 |
Corporate income tax instalment Kenya Revenue Authority / tax operations | KES 33.0M / KES 33.0M / outstanding KES 0 of KES 100K | due 20/10d / return ready / slip ready / ack ready / cert ready / live ready | within | 4cf04b0ac8b1...eebe3de6 |
Affordable Housing Levy payroll remittance Kenya Revenue Authority / payroll tax | KES 3.1M / KES 3.1M / outstanding KES 0 of KES 25K | due 8/5d / return ready / slip ready / ack ready / cert ready / live ready | within | 5123f23a3629...6754f8f1 |
Annual income tax return and self-assessment Kenya Revenue Authority / CFO tax control | KES 68.0M / KES 68.0M / outstanding KES 0 of KES 100K | due 45/20d / return ready / slip ready / ack ready / cert ready / live ready | within | 4fe74261bc9b...aa32a180 |
| Payroll statutory row | Population / remittance | Control evidence | Status | Hash |
|---|---|---|---|---|
PAYE payroll deduction Kenya Revenue Authority / payroll tax | 1840/1840 / 100.0% / remittance 100.0% | deduction ready / employer ready / file ready / portal ready / payslip ready / bank ready | within | 4c0184861406...d654c093 |
SHA/SHIF health contribution Social Health Authority / people operations and payroll | 1840/1840 / 100.0% / remittance 100.0% | deduction ready / employer ready / file ready / portal ready / payslip ready / bank ready | within | af6f4f6d46d0...675a3969 |
NSSF pension contribution National Social Security Fund / people operations and payroll | 1840/1840 / 100.0% / remittance 100.0% | deduction ready / employer ready / file ready / portal ready / payslip ready / bank ready | within | eacfd04621ec...50c20c6d |
Affordable Housing Levy Kenya Revenue Authority / people operations and payroll | 1840/1840 / 100.0% / remittance 100.0% | deduction ready / employer ready / file ready / portal ready / payslip ready / bank ready | within | efc39889693b...25ca640c |
NITA training levy National Industrial Training Authority / people operations and payroll | 1840/1840 / 100.0% / remittance 100.0% | deduction ready / employer ready / file ready / portal ready / payslip ready / bank ready | within | 07673057b38e...eee649c3 |
| Filing | Due control | Maker-checker evidence | Status | Hash |
|---|---|---|---|---|
VAT iTax return Kenya Revenue Authority / tax operations | 12d to due / lead 5d / ready | draft ready / payment ready / reviewer ready / approver ready / portal ready | within | 9644b3fd57aa...723ae511 |
PAYE iTax return Kenya Revenue Authority / payroll tax | 9d to due / lead 5d / ready | draft ready / payment ready / reviewer ready / approver ready / portal ready | within | a691eab43227...7fdf0aa6 |
Withholding tax remittance Kenya Revenue Authority / accounts payable tax | 4d to due / lead 2d / ready | draft ready / payment ready / reviewer ready / approver ready / portal ready | within | c25cd3e9915a...658bd624 |
SHA/SHIF employer contribution filing Social Health Authority / people operations and payroll | 8d to due / lead 5d / ready | draft ready / payment ready / reviewer ready / approver ready / portal ready | within | 7ce308c5d781...8f22a28f |
Annual corporate income tax return Kenya Revenue Authority / CFO tax control | 45d to due / lead 20d / ready | draft ready / payment ready / reviewer ready / approver ready / portal ready | within | be0385a97456...0fd302de |
| Reconciliation | Amounts | Break controls | Status | Hash |
|---|---|---|---|---|
VAT output/input/eTIMS to iTax reconciliation sales, purchasing, eTIMS, and tax payable ledgers / tax operations | source KES 12.8M / return KES 12.8M / paid KES 12.8M | variance KES 0 of KES 20K / open 0/0 / age 0/5d / bank ready / ERP ready | within | f0040914e087...e8dce90d |
PAYE payroll to iTax reconciliation payroll, employee, and tax payable ledgers / payroll tax | source KES 18.4M / return KES 18.4M / paid KES 18.4M | variance KES 0 of KES 20K / open 0/0 / age 0/5d / bank ready / ERP ready | within | 3c778700e2af...c4f7204c |
Withholding tax AP to certificate reconciliation accounts payable and withholding certificates / accounts payable tax | source KES 4.2M / return KES 4.2M / paid KES 4.2M | variance KES 0 of KES 10K / open 0/0 / age 0/5d / bank ready / ERP ready | within | 37642b7d9518...438aed9d |
Payroll statutory suspense reconciliation payroll, bank, and statutory deduction suspense ledgers / finance control | source KES 18.7M / return KES 18.7M / paid KES 18.7M | variance KES 0 of KES 20K / open 0/0 / age 0/5d / bank ready / ERP ready | within | 2c3df7da396e...71f05c08 |
Tax payable GL to bank proof reconciliation tax payable, bank, M-Pesa, and payment settlement ledgers / finance control | source KES 68.0M / return KES 68.0M / paid KES 68.0M | variance KES 0 of KES 50K / open 0/0 / age 0/5d / bank ready / ERP ready | within | 0acf75b86176...faa5e81e |
| Tax position | Exposure | Support controls | Status | Hash |
|---|---|---|---|---|
Corporate income tax provision and deferred tax support income tax / CFO tax control | KES 68.0M / material KES 10.0M / findings 0/0 | memo ready / legal ready / advisor ready / provision ready / disclosure ready / board ready | within | 830a12b7c41c...4b5e7410 |
Transfer-pricing and related-party support transfer pricing / tax operations and legal control | KES 18.0M / material KES 10.0M / findings 0/0 | memo ready / legal ready / advisor ready / provision ready / disclosure ready / board ready | within | b40a54cbc26c...f9d9cd5b |
VAT exemption and input apportionment support VAT / tax operations | KES 12.8M / material KES 5.0M / findings 0/0 | memo ready / legal ready / advisor ready / provision ready / disclosure ready / board ready | within | e8c4e1fa802a...a82e3806 |
Stamp duty security-document register support stamp duty / legal control and collateral operations | KES 7.5M / material KES 5.0M / findings 0/0 | memo ready / legal ready / advisor ready / provision ready / disclosure ready / board ready | within | 581ba82519d7...f5a59764 |
KRA audit query and uncertain tax position support tax controversy / tax operations and legal control | KES 6.0M / material KES 5.0M / findings 0/0 | memo ready / legal ready / advisor ready / provision ready / disclosure ready / board ready | within | b6a9cdf73f4e...45a09ddd |
| Domain control | Coverage | Missing controls | Status | Hash |
|---|---|---|---|---|
Tax registration, return preparation, filing calendar, iTax acknowledgement, and statutory obligation domain filing / tax operations, compliance assurance, records manager, and regulatory operations | 5/5 / 100.0% / findings 0 | none | within | 318281c9eef9...30f4ec3b |
Payroll statutory deduction, employer contribution, remittance file, payslip disclosure, and bank-payment domain payroll / people operations, payroll tax, finance control, and conduct risk | 5/5 / 100.0% / findings 0 | none | within | b67ff09600ce...aa42dfae |
Tax payable, eTIMS, iTax, bank, GL, suspense, and payment reconciliation domain reconciliation / finance control, tax operations, treasury reconciliation, and data governance | 5/5 / 100.0% / findings 0 | none | within | 1910702d1ddd...bc6046e4 |
Tax position, transfer-pricing, deferred tax, stamp duty, audit query, and controversy domain position / CFO tax control, legal control, audit liaison, and control assurance | 5/5 / 100.0% / findings 0 | none | within | 0dbf89255e38...0f0bb8db |
Tax evidence privacy, retention, employee data, certificate, regulator response, and custody domain custody / privacy office, records manager, tax operations, people operations, and legal control | 5/5 / 100.0% / findings 0 | none | within | 2f21a237030f...5a0329b6 |
| Control | Metric | Current / limit | Status | Hash |
|---|---|---|---|---|
Tax and statutory obligation registration and filing governance Material tax and statutory obligations are registered, prepared, acknowledged, paid, certified, evidenced, and custody-backed. | obligations with current registration, prepared return, payment slip, portal acknowledgement, payment match, certificate evidence, live-read, synthetic-action, and custody controls | 100.00% / 100.00% | within | 8d1ba0b1e30d...6ba0f001 |
Tax and statutory payment remittance governance Tax liabilities are remitted on time, matched to bank proof, and free of unexplained unpaid balances. | tax obligations with remitted amounts equal to liabilities and outstanding balances inside tolerance | 100.00% / 100.00% | within | c07b7ced3a87...b3141714 |
Payroll statutory contribution integrity Payroll statutory deductions and employer contributions reconcile across employee population, payroll files, portal submissions, payslips, and bank proof. | PAYE, SHA/SHIF, NSSF, housing levy, NITA, and payroll statutory rows with population match, deduction, employer contribution, remittance file, portal submission, payslip disclosure, bank proof, and custody controls | 100.00% / 100.00% | within | 68ceb659d57b...8fc0776d |
Tax statutory filing calendar readiness Filing calendars provide accountable lead time and maker-checker evidence before due dates. | filings with enough lead time, return draft, payment instruction, reviewer, approver, portal route, and evidence controls | 100.00% / 100.00% | within | 11decf82aac7...b9a88748 |
Tax ledger reconciliation and bank proof governance Tax returns and payments reconcile to source ledgers, bank proof, suspense accounts, and ERP traces. | reconciliations with source ledger, return, payment, variance, open item, item age, maker-checker, bank proof, ERP trace, and custody controls | 100.00% / 100.00% | within | 4f154dbf868e...7010f961 |
Tax position, transfer-pricing, deferred tax, stamp duty, and audit query governance Material tax positions are technically supported, legally grounded, externally reviewed when needed, provisioned, disclosed, board-visible, and custody-backed. | tax positions with technical memo, legal basis, external review, provision approval, disclosure assessment, board visibility for material exposures, finding control, and custody evidence | 100.00% / 100.00% | within | 8d86ca9dda57...5bb45a0c |
Tax control framework and co-operative compliance governance Tax control framework evidence covers ownership, risk assessment, controls, monitoring, testing, correction, and disclosure discipline. | obligation, payroll, filing, reconciliation, position, and domain evidence rows ready across tax control framework components | 100.00% / 100.00% | within | 8d721cd66e3f...403b3404 |
Tax statutory live-read and synthetic-action blocking Tax filings, payments, certificates, and board attestations fail closed when source reads are unavailable or synthetic rows would drive action. | tax obligation rows sourced from live read paths with synthetic action blocked | 100.00% / 100.00% | within | 6a7b275257c1...1d53faa9 |
Tax statutory enterprise manifest coverage Tax governance maps to regulatory horizon, supervisory response, finance ledger, payments, risk data, privacy, records, assurance, board, live-read, customer harm, and auditability controls. | domain controls mapped to required enterprise controls without open findings | 100.00% / 100.00% | within | 64f6f79ccdd5...89567ce6 |
Tax statutory evidence custody Every tax and statutory row carries reproducible custody for management, auditors, board, and regulators. | tax obligation, payroll, filing, reconciliation, position, domain, and control rows with custody-ready hashes and ready statuses | 100.00% / 100.00% | within | b2a79fef1ae2...0ec8ce1b |
Zero overdue statutory filing posture Statutory returns do not pass due dates without filed, acknowledged, paid, and evidenced status. | tax and statutory filings past due date | 0 / 0 | within | bf476df90572...501e5784 |
Zero unpaid statutory balance breach posture Unpaid statutory balances remain inside approved tolerance and have same-cycle remediation evidence. | tax obligations with outstanding balances above approved tolerance | 0 / 0 | within | a52285b83aa8...c4dba1bc |
Zero payroll statutory population gap posture Every employee in payroll is mapped to required statutory contribution treatment before payroll close. | employee statutory records missing from payroll contribution remittance population | 0 / 0 | within | 36c3e7c8c216...1bf3a838 |
Zero statutory reconciliation breach posture Tax ledgers, returns, payments, and bank proofs reconcile without stale open items before close. | tax ledger reconciliations with variance, open item, age, maker-checker, bank proof, ERP trace, or custody gaps | 0 / 0 | within | 0e12da5691e2...2106e94f |
Zero unsupported material tax position posture Material tax positions and audit matters are supported, reviewed, provisioned, disclosed, and board-visible. | material tax positions missing technical support, legal basis, review, provision, disclosure, board visibility, or custody evidence | 0 / 0 | within | 9469247fea93...9183441d |
| Trigger | Owner | Action | Deadline | Status |
|---|---|---|---|---|
| No tax or statutory obligation action packs are required for the current evidence set. | ||||
Charter independence, risk-based audit universe, annual plan, engagement workpapers, issue validation, QAIP, external assessment, audit committee, enterprise manifest, action-pack, and evidence-custody controls.
| Auditable entity | Risk tier | Coverage gates | Manifest | Status | Hash |
|---|---|---|---|---|---|
Credit lifecycle, affordability, bureau, and model risk chief audit executive / last audit 5/12 months | critical | planned ready / committee ready / data ready / tech ready / conduct ready / financial ready | 4/4 / missing none | within | 70ad3850e676...4b604be1 |
Payments, scam reimbursement, fraud, and financial crime chief audit executive / last audit 4/12 months | critical | planned ready / committee ready / data ready / tech ready / conduct ready / financial ready | 5/5 / missing none | within | 5f323ed88458...1b3a5594 |
Cyber resilience, identity, cryptographic custody, third-party, and API platform chief audit executive / last audit 6/12 months | critical | planned ready / committee ready / data ready / tech ready / conduct ready / financial gap | 5/5 / missing none | within | c34af93a653b...02ff4c80 |
Finance close, regulatory returns, tax statutory, risk data, and capital evidence chief audit executive / last audit 8/18 months | high | planned ready / committee ready / data ready / tech ready / conduct gap / financial ready | 5/5 / missing none | within | 58d05ade48b3...b72607d1 |
Customer outcomes, inclusion, conduct, records, and privacy chief audit executive / last audit 7/18 months | high | planned ready / committee ready / data ready / tech ready / conduct ready / financial gap | 5/5 / missing none | within | 40f20fe3b249...bcae9b34 |
| Plan area | Resources | Governance | Status | Hash |
|---|---|---|---|---|
Credit lifecycle, affordability, bureau, and model risk 2026 / Q1 / critical | 58/55 days / resource 105.5% / skill 96.0% / gaps 0 | committee ready / independence ready / analytics ready / QAIP ready | within | 3f3bcf18b896...928acc50 |
Payments, scam reimbursement, fraud, and financial crime 2026 / Q2 / critical | 63/60 days / resource 105.0% / skill 96.0% / gaps 0 | committee ready / independence ready / analytics ready / QAIP ready | within | ecd684b5d615...32cc90e1 |
Cyber resilience, identity, cryptographic custody, third-party, and API platform 2026 / Q2 / critical | 67/65 days / resource 103.1% / skill 96.0% / gaps 0 | committee ready / independence ready / analytics ready / QAIP ready | within | e03598c6603b...e688b058 |
Finance close, regulatory returns, tax statutory, risk data, and capital evidence 2026 / Q3 / high | 48/45 days / resource 106.7% / skill 96.0% / gaps 0 | committee ready / independence ready / analytics ready / QAIP ready | within | 2f9853c743c8...758e3c12 |
Customer outcomes, inclusion, conduct, records, and privacy 2026 / Q4 / high | 42/40 days / resource 105.0% / skill 96.0% / gaps 0 | committee ready / independence ready / analytics ready / QAIP ready | within | c01d68dbf578...28faa672 |
| Engagement | Stage | Workpaper controls | Status | Hash |
|---|---|---|---|---|
Credit lifecycle, affordability, bureau, and model risk eng-credit-models | closed | planning ready / scope ready / RCM ready / sample 96.0% of 90.0% / review ready / report ready / response ready / handoff ready | within | 62eb55715104...5141b019 |
Payments, scam reimbursement, fraud, and financial crime eng-payments-scam | reporting | planning ready / scope ready / RCM ready / sample 94.0% of 90.0% / review ready / report ready / response ready / handoff ready | within | 6fbf7404ec6f...da2b9ca4 |
Cyber resilience, identity, cryptographic custody, third-party, and API platform eng-cyber-identity | fieldwork | planning ready / scope ready / RCM ready / sample 93.0% of 90.0% / review ready / report ready / response ready / handoff ready | within | c1b6e2693c7e...18be9197 |
Finance close, regulatory returns, tax statutory, risk data, and capital evidence eng-finance-regulatory | reporting | planning ready / scope ready / RCM ready / sample 92.0% of 90.0% / review ready / report ready / response ready / handoff ready | within | 40a852a2cfd4...db33a644 |
Customer outcomes, inclusion, conduct, records, and privacy eng-conduct-records | planning | planning ready / scope ready / RCM ready / sample 91.0% of 90.0% / review ready / report ready / response ready / handoff ready | within | 3a0b5638da8e...f121212c |
| Issue | Due posture | Validation evidence | Status | Hash |
|---|---|---|---|---|
issue-credit-evidence-lineage eng-credit-models / credit risk owner / high | 18/45d / due ready | action ready / validation ready / recurrence ready / impact ready / evidence ready / board ready | within | 1cc8155b5462...907f24c6 |
issue-payment-provider-recall eng-payments-scam / payments operations / high | 12/45d / due ready | action ready / validation ready / recurrence ready / impact ready / evidence ready / board ready | within | 22c28d5d9e18...738491ca |
issue-identity-recertification eng-cyber-identity / identity platform / medium | 20/60d / due ready | action ready / validation ready / recurrence ready / impact ready / evidence ready / board ready | within | 50189aaa5b78...10e5c596 |
issue-regulatory-return-tieout eng-finance-regulatory / finance control / medium | 15/60d / due ready | action ready / validation ready / recurrence ready / impact ready / evidence ready / board ready | within | ba5ac54ca49e...c8eb2b5e |
| Quality activity | Cadence | Evidence | Status | Hash |
|---|---|---|---|---|
QAIP internal assessment chief audit executive | 3/12 months | QAIP ready / external ready / skills ready / independence ready / committee ready / improvements ready | within | aecb9c34a3f3...cd493975 |
External quality assessment readiness audit committee chair | 24/60 months | QAIP ready / external ready / skills ready / independence ready / committee ready / improvements ready | within | 8633dc4c1751...ea90ee58 |
Audit skills and certification matrix audit operations | 2/12 months | QAIP ready / external ready / skills ready / independence ready / committee ready / improvements ready | within | 1f8ea6f5e140...76782a08 |
Annual independence and conflict attestation chief audit executive | 1/12 months | QAIP ready / external ready / skills ready / independence ready / committee ready / improvements ready | within | 0bbc440f4d02...854af3af |
| Domain control | Coverage | Missing controls | Status | Hash |
|---|---|---|---|---|
Internal audit charter, audit committee, assurance, and board route charter / chief audit executive and board audit committee | 3/3 / 100.0% / findings 0 | none | within | 26d1701418d8...56682253 |
Internal audit issue validation and enterprise remediation linkage issue / internal audit issue validation lead | 3/3 / 100.0% / findings 0 | none | within | 0cc87718b607...cc7c2023 |
Internal audit risk-data, regulatory, and supervisor evidence route oversight / audit data analytics and regulatory liaison | 3/3 / 100.0% / findings 0 | none | within | 3821a298048c...43524a8b |
Internal audit coverage of finance, cyber, identity, and third-party critical controls engagement / audit engagement managers | 4/4 / 100.0% / findings 0 | none | within | 98ec99293096...a496b413 |
Internal audit coverage of model, AI, conduct, privacy, and records controls universe / audit methodology and data governance liaison | 5/5 / 100.0% / findings 0 | none | within | f814eabdba6d...2fdab31b |
| Control | Metric | Current / limit | Status | Hash |
|---|---|---|---|---|
Internal audit charter and independence Internal audit should be independently positioned, board accountable, and conflict-free. | independence conflicts or missing attestations | 0 / 0 | within | de917f0a1362...671a2fe7 |
Risk-based internal audit universe coverage The audit universe should cover material activities, risk domains, technology, conduct, and financial reporting controls. | auditable entities current, approved, scoped, data-ready, and mapped to control evidence | 100.00% / 100.00% | within | f5c53b659b78...f6d0a81c |
Critical-risk audit coverage Critical-risk areas should be current-year planned and audit-committee approved. | critical auditable entities inside audit age and current-year plan | 100.00% / 100.00% | within | 648bdebce82d...8c062100 |
Audit plan approval, skills, and resources The audit plan should be risk-based, board approved, adequately resourced, and competency aligned. | plans approved, independent, resourced, analytics-enabled, and QAIP-linked | 100.00% / 100.00% | within | cc77a42d4233...c6e46664 |
Internal audit engagement quality Engagements should follow a documented methodology with reviewed evidence and clear reporting. | engagements with scope, RCM, samples, reviewed workpapers, report, response, issue handoff, and data lineage | 100.00% / 100.00% | within | 1537de8c18f8...17d7b407 |
Internal audit finding validation and recurrence monitoring Audit issues should close only after independent validation, impact review, and recurrence monitoring. | issues within due date with accepted actions, validation, recurrence monitoring, impact assessment, and evidence | 100.00% / 100.00% | within | 1db1a5cc8849...d1cde157 |
Overdue audit issue zero tolerance Overdue audit issues should be zero or board-escalated with accepted remediation actions. | audit issues beyond due date | 0 / 0 | within | 2a37519c5ede...e48dc9d1 |
QAIP, external assessment, skills, and improvement action readiness Internal audit should maintain a quality assurance and improvement program with external assessment readiness. | QAIP activities current, external-assessment ready, skills mapped, independence attested, committee reported, and actions closed | 100.00% / 100.00% | within | fda90ca6be80...94e81595 |
Internal audit enterprise manifest coverage Internal audit evidence should reconcile to board, remediation, risk-data, supervisory, finance, cyber, third-party, model, AI, conduct, privacy, and records controls. | domain controls mapped to enterprise control evidence with no open findings | 100.00% / 100.00% | within | 67366577c29b...5528dd0c |
Internal audit evidence custody and package integrity Audit evidence should be tamper-evident, retained, reproducible, and exportable for examiner reliance. | evidence rows with custody hashes and within status | 100.00% / 100.00% | within | 7afc26614cc6...1bd29620 |
| Trigger | Owner | Action | Deadline | Status | Hash |
|---|---|---|---|---|---|
| No internal audit action packs are required for the current evidence set. | |||||
114 custody hashes reconcile universe, plan, engagement, issue, quality, domain, control, action, and manifest evidence into the package hash.
Charter, composition, committees, meetings, related-party exposure, policy oversight, evaluation, disclosure, stakeholder, enterprise-mapping, action-pack, and custody controls.
| Director | Role | Fit, attendance, CPD | Independence and skills | Status | Hash |
|---|---|---|---|---|---|
Amina Oketch Board, Nominations | chair | fit ready / CBK ready / attendance 95.0% of 75.0% / CPD 18/12h | independent ready / NED ready / conflicts 0 / other boards 0/2 / skills 4/5 | within | 7181c1b7574e...f24f5261 |
Daniel Mwangi Board | ceo | fit ready / CBK ready / attendance 95.0% of 75.0% / CPD 16/12h | independent gap / NED gap / conflicts 0 / other boards 0/2 / skills 4/5 | within | 2e93858fbe50...4b42b916 |
Grace Wanjiru Audit, Remuneration | independent_non_executive | fit ready / CBK ready / attendance 95.0% of 75.0% / CPD 20/12h | independent ready / NED ready / conflicts 0 / other boards 1/2 / skills 3/5 | within | 053922ad95e9...330aab4a |
Hassan Ali Risk, Credit | independent_non_executive | fit ready / CBK ready / attendance 95.0% of 75.0% / CPD 22/12h | independent ready / NED ready / conflicts 0 / other boards 1/2 / skills 4/5 | within | 9333d383c57b...45b5b111 |
Mercy Cherono Technology, Risk | independent_non_executive | fit ready / CBK ready / attendance 95.0% of 75.0% / CPD 19/12h | independent ready / NED ready / conflicts 0 / other boards 1/2 / skills 3/5 | within | 2f0ed48be552...691d5942 |
Peter Njoroge Credit, Audit | non_executive | fit ready / CBK ready / attendance 95.0% of 75.0% / CPD 17/12h | independent gap / NED ready / conflicts 0 / other boards 1/2 / skills 4/5 | within | 8a45b4085dce...e3a8c11c |
| Committee | Mandate | Evidence | Status | Hash |
|---|---|---|---|---|
Board Audit Committee Grace Wanjiru / required ready | mandate ready / chair independent ready / independent majority ready / NED-only ready | meetings 6/4 / quorum ready / minutes ready / board reports ready / advice ready | within | a348ae5ab144...9b92f3a3 |
Board Risk Management Committee Hassan Ali / required ready | mandate ready / chair independent ready / independent majority ready / NED-only ready | meetings 6/4 / quorum ready / minutes ready / board reports ready / advice ready | within | 95470ca5b6ba...3566fa80 |
Board Credit Committee Peter Njoroge / required ready | mandate ready / chair independent ready / independent majority ready / NED-only ready | meetings 8/4 / quorum ready / minutes ready / board reports ready / advice ready | within | c389917bb486...d7096dff |
Nominations and Governance Committee Amina Oketch / required gap | mandate ready / chair independent ready / independent majority ready / NED-only ready | meetings 4/2 / quorum ready / minutes ready / board reports ready / advice ready | within | 1725e96887ad...782a5a80 |
Remuneration Committee Grace Wanjiru / required gap | mandate ready / chair independent ready / independent majority ready / NED-only ready | meetings 4/2 / quorum ready / minutes ready / board reports ready / advice ready | within | 2d47d2ad5e3f...e3d00f77 |
| Meeting | Quorum and packs | Decision evidence | Status | Hash |
|---|---|---|---|---|
| Q1 full board and strategy review | attendance 96.0% / quorum ready / pack 7/5d / minutes 5/10d | decisions ready / recusals ready / appetite ready / policies ready / actions ready | within | c65ae2416c06...51466661 |
| Q2 risk appetite and financial performance review | attendance 94.0% / quorum ready / pack 7/5d / minutes 5/10d | decisions ready / recusals ready / appetite ready / policies ready / actions ready | within | 725bafe55533...5aeec056 |
| Q3 supervisory commitments and policy approvals | attendance 95.0% / quorum ready / pack 7/5d / minutes 5/10d | decisions ready / recusals ready / appetite ready / policies ready / actions ready | within | c37a7891629a...f7f7ec00 |
| Q4 annual plan, budget, succession, and governance evaluation | attendance 97.0% / quorum ready / pack 7/5d / minutes 5/10d | decisions ready / recusals ready / appetite ready / policies ready / actions ready | within | ffd231d73a27...6567dd65 |
| Related party | Exposure | Approval controls | Status | Hash |
|---|---|---|---|---|
Director-associated vehicle finance dealer director associate / arms-length credit facility | KES 18.0M / limit KES 42.0M / within ready / review 20/90d | board ready / independent review ready / recusal ready / arms-length ready / disclosure ready / CBK ready | within | df5a3249ef9a...297f5a87 |
Significant shareholder technology supplier significant shareholder associate / technology services contract | KES 9.0M / limit KES 30.0M / within ready / review 20/90d | board ready / independent review ready / recusal ready / arms-length ready / disclosure ready / CBK ready | within | c567f21bbd4d...e6a4ec8c |
Executive-connected borrower exposure executive associate / secured term loan | KES 6.0M / limit KES 20.0M / within ready / review 20/90d | board ready / independent review ready / recusal ready / arms-length ready / disclosure ready / CBK ready | within | 5364c30e1dff...2dbbe94d |
Group service arrangement group affiliate / shared service recharge | KES 4.0M / limit KES 15.0M / within ready / review 20/90d | board ready / independent review ready / recusal ready / arms-length ready / disclosure ready / CBK ready | within | 7088f71240fe...cad8af2b |
| Policy | Review | Oversight evidence | Status | Hash |
|---|---|---|---|---|
Board charter, reserved matters, and delegated authority board secretariat | 90/365d | board ready / appetite ready / management ready / implementation ready / exception ready / challenge ready | within | 243d51e19253...6e024154 |
Risk appetite statement and limit governance CRO office | 45/180d | board ready / appetite ready / management ready / implementation ready / exception ready / challenge ready | within | 37b877011f8d...5481be4f |
Conflict of interest and related-party transaction policy legal control | 60/365d | board ready / appetite ready / management ready / implementation ready / exception ready / challenge ready | within | a416cb5e256b...124ebd13 |
Code of ethics, conduct, and whistleblowing compliance assurance | 90/365d | board ready / appetite ready / management ready / implementation ready / exception ready / challenge ready | within | 758929a2d03e...5b109a2a |
Board information, minutes, and records retention policy board secretariat | 60/365d | board ready / appetite ready / management ready / implementation ready / exception ready / challenge ready | within | 493a4657ffe2...11a2b136 |
| Evaluation | Cadence | Evidence | Status | Hash |
|---|---|---|---|---|
Annual board effectiveness evaluation nominations and governance committee | 6/12 months | external ready / actions ready / succession ready / training ready / diversity ready / report ready | within | c48858c73d57...ca5173af |
Board committee self-assessments board secretariat | 5/12 months | external ready / actions ready / succession ready / training ready / diversity ready / report ready | within | f7e9b75251fa...1c41b19f |
Director succession and skills matrix refresh nominations and governance committee | 4/12 months | external ready / actions ready / succession ready / training ready / diversity ready / report ready | within | 1c6a09197af2...abcb54d7 |
Director induction and continuing professional development company secretary | 3/12 months | external ready / actions ready / succession ready / training ready / diversity ready / report ready | within | 89269c69524e...79315011 |
| Disclosure | Cadence | Transparency controls | Status | Hash |
|---|---|---|---|---|
Board composition, independence, attendance, and committee disclosure board secretariat | 5/12 months | composition ready / remuneration ready / committees ready / related parties ready / stakeholder ready / sustainability ready | within | e017744171a8...d9241985 |
Director remuneration and compensation governance disclosure remuneration committee | 6/12 months | composition ready / remuneration ready / committees ready / related parties ready / stakeholder ready / sustainability ready | within | 75211d7673cc...97aee305 |
Related-party and insider-exposure disclosure legal control | 3/6 months | composition ready / remuneration ready / committees ready / related parties ready / stakeholder ready / sustainability ready | within | 4b2d78205092...b62f462e |
Stakeholder, ethics, whistleblowing, and sustainability governance disclosure compliance assurance | 4/12 months | composition ready / remuneration ready / committees ready / related parties ready / stakeholder ready / sustainability ready | within | f78c2b09d47b...70853a29 |
| Domain control | Coverage | Missing controls | Status | Hash |
|---|---|---|---|---|
Board charter, assurance, audit committee, and custody route charter / board secretariat and chief audit executive | 5/5 / 100.0% / findings 0 | none | within | 7a57f0997b04...14ac4bd8 |
Board decision execution and enterprise remediation linkage oversight / board secretariat and enterprise risk | 4/4 / 100.0% / findings 0 | none | within | 9769442adb7f...39f1539e |
Board risk-data, supervisory response, and regulator evidence route oversight / risk data governance and regulatory liaison | 4/4 / 100.0% / findings 0 | none | within | c02663a76ef0...f8040d7c |
Board finance, tax, pricing, and profitability policy oversight oversight / CFO, legal control, and board secretariat | 5/5 / 100.0% / findings 0 | none | within | 8d5a0876ede4...15812906 |
Board privacy, third-party, conduct, and stakeholder governance route disclosure / privacy office, vendor risk, conduct risk, and board secretariat | 5/5 / 100.0% / findings 0 | none | within | 87a0cbdda37c...5bbc020f |
| Control | Metric | Current / limit | Status | Hash |
|---|---|---|---|---|
Board charter, reserved matters, and delegated authority The board should have clear authority, reserved matters, delegated powers, and directors capable of fulfilling oversight duties. | directors fit-and-proper, CPD, attendance, conflicts, tenure, succession, and expertise ready | 100.00% / 100.00% | within | 14a5fd874b81...3f0906e2 |
Board composition, fit-and-proper, and skills coverage Board composition should be fit-and-proper, skilled, diverse, and independently able to challenge management. | independent directors as share of full board | 66.67% / 33.33% | within | 3565682c0571...71c6124a |
Non-executive and independent challenge capacity The board should retain non-executive challenge capacity and avoid management domination. | non-executive directors as share of full board | 83.33% / 60.00% | within | e15af6befa97...ce24a4cd |
Board meeting cadence, quorum, minutes, and decision records Board and committee meetings should evidence informed deliberation, votes, recusals, approved minutes, and follow-up actions. | meetings with quorum, timely packs, minutes, recusals, risk appetite, policy approvals, and owner actions | 100.00% / 100.00% | within | 1ad18baf9b21...f7386726 |
Board committee mandate, independence, quorum, and reporting Audit, risk, credit, nomination, and remuneration committees should have mandates, independent challenge, records, and full-board reporting. | committees with approved mandate, independent chair/majority, quorum, minutes, and board reporting | 100.00% / 100.00% | within | 5ef864e78008...2652c6b4 |
Conflicts, related-party transactions, and insider exposure control Conflicts and related-party transactions should be disclosed, independently reviewed, recused, arms-length, board-approved, reported, and inside exposure limits. | unresolved director conflicts plus related-party rows not ready | 0 / 0 | within | f02354f1cdd4...770f2286 |
Policy approval, risk appetite, and management accountability The board should approve key policies, risk appetite, exceptions, and hold management accountable for implementation. | board-approved policies current, appetite-aligned, challenged, and implemented | 100.00% / 100.00% | within | 50fd059243f3...4006c19f |
Board information quality and escalation Board packs should provide timely, accurate, complete, contextual risk, finance, policy, and supervisory information. | meetings and policies with timely information, risk appetite review, policy approvals, and owner actions | 100.00% / 100.00% | within | bfd677d563fd...3fce2806 |
Board evaluation, succession, diversity, and director development Boards should regularly evaluate effectiveness, refresh skills, plan succession, and maintain director development. | evaluations current, action plans closed, succession ready, CPD ready, diversity reviewed, and board reported | 100.00% / 100.00% | within | 654e0aaf6f11...82f6ef4c |
Disclosure, transparency, and stakeholder governance Corporate governance disclosures should be timely, transparent, and cover board composition, remuneration, committees, conflicts, stakeholders, and sustainability governance. | disclosures current for board composition, remuneration, committees, related parties, stakeholder channels, and sustainability governance | 100.00% / 100.00% | within | eb8e7560ec89...2ae6464e |
Corporate board enterprise manifest coverage Board governance should reconcile to assurance, internal audit, risk appetite, remediation, risk data, supervisory, finance, tax, third-party, privacy, records, and auditability controls. | domain controls mapped to enterprise evidence with no open findings | 100.00% / 100.00% | within | 90f4876bf99b...514eb12e |
Corporate board evidence custody and package integrity Board governance evidence should be tamper-evident, retained, reproducible, and exportable for supervisors and auditors. | evidence rows with custody hashes and within status | 100.00% / 100.00% | within | f114f272c309...b0b15236 |
| Trigger | Owner | Action | Deadline | Status | Hash |
|---|---|---|---|---|---|
| No corporate board governance action packs are required for the current evidence set. | |||||
125 custody hashes reconcile director, committee, meeting, related-party, policy, evaluation, disclosure, domain, control, action, and manifest evidence into the package hash.
Board-approved appetite statements, risk capacity, limit utilization, limits, KRIs, breach cases, exceptions, second-line challenge, committee decisions, signed minutes, customer-impact assessment, manifest mapping, and SHA-256 evidence custody.
| Appetite statement | Capacity / appetite / tolerance | Current profile | Governance | Status | Hash |
|---|---|---|---|---|---|
Credit risk Maintain portfolio credit losses, delinquency migration, and concentration within board-approved capacity while preserving responsible access to credit. | portfolio NPL ratio: capacity 8.0% / appetite 5.0% / tolerance 6.5% | 3.8% / utilization 76.0% | BRC-2026-APP-CREDIT review 36/365d / 2L ready / board ready | within | b431691d0be0...37fb9d98 |
Liquidity and funding risk Maintain sufficient survival horizon, funding diversification, and contingency actions for stressed deposit and wholesale funding outflows. | liquidity survival horizon: capacity 45d / appetite 35d / tolerance 30d | 42d / utilization 83.3% | BRC-2026-APP-LIQ review 30/365d / 2L ready / board ready | within | c33d5a7f0592...973fb9e8 |
Capital and solvency risk Maintain capital headroom above internal capital adequacy needs and regulatory minimums through stress cycles and product growth. | capital buffer headroom: capacity 10.0% / appetite 7.0% / tolerance 5.0% | 8.4% / utilization 83.3% | BRC-2026-APP-CAP review 42/365d / 2L ready / board ready | within | cd1dbcc8a245...8e3e4596 |
Operational resilience Keep critical lending, payment, servicing, and reporting operations inside impact tolerances with tested recovery and provider exit routes. | severe incident count: capacity 3 / appetite 1 / tolerance 2 | 0 / utilization 0.0% | BRC-2026-APP-OPS review 28/365d / 2L ready / board ready | within | 10010d0789a9...cb46e4a8 |
Conduct and customer outcomes Avoid material customer harm by keeping upheld complaints, redress delays, product exceptions, and affordability overrides inside board tolerance. | upheld complaint rate: capacity 3.0% / appetite 1.5% / tolerance 2.2% | 1.1% / utilization 73.3% | BRC-2026-APP-CONDUCT review 25/365d / 2L ready / board ready | within | 405e1aca3042...01a85c79 |
Cyber and technology risk Maintain critical vulnerability, privileged access, ransomware recovery, and change failure exposures inside risk appetite before digital growth. | critical vulnerability SLA breaches: capacity 4 / appetite 1 / tolerance 2 | 0 / utilization 0.0% | BRC-2026-APP-CYBER review 21/365d / 2L ready / board ready | within | 75d4d0f02b4e...f5bff24e |
| Limit | Threshold | Governance | Status | Hash |
|---|---|---|---|---|
NPL ratio board limit Credit risk / chief credit officer | portfolio NPL ratio: 3.8% / warn 5.0% / breach 6.5% | approved yes / daily ready / workflow ready | within | a4a05451cb90...05ab1ea0 |
Stage 2 migration watch limit Credit risk / portfolio risk | 30-day Stage 2 migration: 4.2% / warn 6.0% / breach 8.0% | approved yes / daily ready / workflow ready | within | 51053169370e...e8886416 |
Liquidity survival horizon floor Liquidity and funding risk / treasury risk | days survival under stress: 42d / warn 35d / breach 30d | approved yes / daily ready / workflow ready | within | 2453d2ebd6c6...9d64913d |
Capital buffer headroom floor Capital and solvency risk / capital planning | capital headroom above internal minimum: 8.4% / warn 7.0% / breach 5.0% | approved yes / daily ready / workflow ready | within | 10687136e3b8...ae74283e |
Severe operational incident tolerance Operational resilience / operational risk | severe incidents in quarter: 0 / warn 1 / breach 2 | approved yes / daily ready / workflow ready | within | 4c4733934b8c...2ed0ab63 |
Customer harm redress SLA tolerance Conduct and customer outcomes / customer outcomes operations | overdue redress cases: 0 / warn 2 / breach 5 | approved yes / daily ready / workflow ready | within | 8dcbb2787cea...a08d303a |
Critical vulnerability SLA tolerance Cyber and technology risk / security operations | critical vulnerabilities outside SLA: 0 / warn 1 / breach 2 | approved yes / daily ready / workflow ready | within | 392b61e4ad6c...3ab94993 |
Model drift PSI tolerance Model risk / model risk | largest population stability index: 8.0% / warn 15.0% / breach 25.0% | approved yes / daily ready / workflow ready | within | c358d8c2aaea...4c329565 |
| KRI | Threshold | Feed | Status | Hash |
|---|---|---|---|---|
Credit loss early-warning KRI Credit risk / portfolio risk | 2.1% / warn 4.0% / breach 6.0% | risk-data-mart / 12/60m / trend explained | within | 3b5c4798ef12...5c88c2e5 |
Funding concentration KRI Liquidity and funding risk / treasury risk | 16.0% / warn 22.0% / breach 30.0% | treasury-ledger / 18/60m / trend explained | within | ae24c815fdad...66d4654a |
Operational loss KRI Operational resilience / operational risk | 0.4% / warn 1.0% / breach 2.0% | loss-event-register / 20/120m / trend explained | within | 44eefdc864a5...fbf3ccd4 |
Upheld complaint rate KRI Conduct and customer outcomes / conduct risk | 1.1% / warn 1.5% / breach 2.2% | complaints-platform / 15/60m / trend explained | within | 8d1054aa2371...cebd4134 |
Cyber critical vulnerability KRI Cyber and technology risk / security operations | 0 / warn 1 / breach 2 | vulnerability-platform / 10/60m / trend explained | within | c86bc74a2eb8...da318618 |
Model override rate KRI Model risk / model risk | 3.0% / warn 6.0% / breach 10.0% | decision-engine / 25/60m / trend explained | within | 7a5484694314...d19f2bcf |
| Breach case | SLA | Closure evidence | Status | Hash |
|---|---|---|---|---|
NPL limit watch remediation Credit risk / portfolio risk / npl-ratio-board-limit | medium / age 4/10d / open no | root ready / customer ready / 2L ready / board yes | within | 7c67faeaf24f...086fd121 |
Liquidity concentration watch Liquidity and funding risk / treasury risk / liquidity-survival-horizon-limit | medium / age 2/5d / open no | root ready / customer ready / 2L ready / board yes | within | e7f145d96f52...19b0c13d |
Customer redress SLA watch Conduct and customer outcomes / customer outcomes operations / customer-harm-redress-sla-limit | low / age 1/7d / open no | root ready / customer ready / 2L ready / board yes | within | b6c61f406302...55dae7a4 |
Critical vulnerability watch Cyber and technology risk / security operations / critical-vulnerability-sla-limit | medium / age 1/3d / open no | root ready / customer ready / 2L ready / board yes | within | e1d5e91400ca...0fd4dbaf |
| Exception | Approval | Controls | Status | Hash |
|---|---|---|---|---|
Temporary MSME growth frontier exception Credit risk / chief credit officer / stage2-migration-watch-limit | Board Risk Committee / expiry 42/90d | compensating ready / 2L ready / customer ready | within | 57f44b17b71c...a014aeab |
Seasonal agri-liquidity tolerance exception Liquidity and funding risk / treasury risk / liquidity-survival-horizon-limit | ALCO / expiry 28/60d | compensating ready / 2L ready / customer ready | within | 330146c489d7...df5fa908 |
Model override monitoring exception Model risk / model risk / model-drift-psi-limit | Model Risk Committee / expiry 21/45d | compensating ready / 2L ready / customer ready | within | c84e779371a8...4e35c625 |
Third-party exit window exception Operational resilience / vendor risk / severe-incident-tolerance-limit | Technology Risk Committee / expiry 30/60d | compensating ready / 2L ready / customer ready | within | 21e819b7cbe2...cec02107 |
| Decision | Mappings | Execution evidence | Status | Hash |
|---|---|---|---|---|
Annual board risk appetite approval Board Risk Committee / BRC-2026-07-APPETITE / board secretariat and CRO office | 6/6 statements / 3/3 limits / 0/0 exceptions | signed yes / challenge yes / notified yes / custody ready | within | 5df31c3af0d5...50acb827 |
ALCO liquidity limit recalibration ALCO / ALCO-2026-07-LIQ / treasury risk | 1/1 statements / 1/1 limits / 1/1 exceptions | signed yes / challenge yes / notified yes / custody ready | within | a5006e39192e...6426ad41 |
Conduct risk customer harm tolerance Conduct Committee / CONDUCT-2026-07-HARM / conduct risk | 1/1 statements / 1/1 limits / 0/0 exceptions | signed yes / challenge yes / notified yes / custody ready | within | 82024bdaf5bc...a3a3bf94 |
Technology risk cyber limit challenge Technology Risk Committee / TRC-2026-07-CYBER / CISO | 1/1 statements / 1/1 limits / 0/0 exceptions | signed yes / challenge yes / notified yes / custody ready | within | 1f08540c5225...d08a2c56 |
| Domain control | Manifest links | Coverage | Status | Hash |
|---|---|---|---|---|
Board-owned risk appetite statement, risk capacity, tolerance, and strategy linkage appetite_statement / board risk committee, CRO office, and board secretariat | 3/3 mapped manifest complete | 100.0% / findings 0 | within | d7ab48a02bff...5fc26dde |
Risk limit, threshold, KRI, data lineage, and daily monitoring control limit / enterprise risk and risk data governance | 3/3 mapped manifest complete | 100.0% / findings 0 | within | 09b99d4859d4...d55c9cbc |
Limit breach escalation, root-cause, remediation, and closure control breach / enterprise risk and control assurance | 3/3 mapped manifest complete | 100.0% / findings 0 | within | 986dc57fa31a...70b178f7 |
Risk exception approval, expiry, compensating control, and tolerance-use governance exception / enterprise risk, legal control, and committee secretariat | 3/3 mapped manifest complete | 100.0% / findings 0 | within | ad074919a574...402e7a98 |
Committee challenge, decision, signed-minute, owner notification, and due-date acceptance control committee_decision / board secretariat and committee secretariats | 3/3 mapped manifest complete | 100.0% / findings 0 | within | 3aca9fddca04...0a509101 |
Risk appetite evidence custody, enterprise manifest mapping, and reproducible export evidence_custody / risk data governance, control assurance, and records manager | 3/3 mapped manifest complete | 100.0% / findings 0 | within | 60e52389ea4a...399fd9b9 |
| Control | Metric | Current / limit | Status | Hash |
|---|---|---|---|---|
Risk appetite statement coverage and cascade The board should approve and oversee risk appetite across material risk types, with clear risk capacity, appetite, tolerance, strategy linkage, and accountable owners. | Board appetite statements with capacity, appetite, tolerance, strategy linkage, limit cascade, metrics, challenge, and evidence | 100.0% / 100.0% | within | b8a8e2ea854d...70e9183b |
Board risk appetite review cadence and challenge evidence Risk appetite should be refreshed at least annually and when risk profile, strategy, or operating conditions change materially. | Statements reviewed within cadence with board challenge recorded | 100.0% / 100.0% | within | 813e15865ccf...db5a829f |
Risk limit and KRI monitoring coverage Risk appetite should be translated into measurable limits, KRIs, escalation triggers, and routine reporting. | Limits and KRIs inside threshold with approved data lineage, monitoring, breach workflows, and owner action | 100.0% / 100.0% | within | 022db8572df1...045db783 |
Active breach escalation and remediation readiness Risk limit breaches should have defined escalation, remediation, root-cause analysis, customer-impact assessment, and board reporting. | Breach cases closed or inside SLA with root cause, customer impact, remediation, second-line challenge, board notice, and closure evidence | 100.0% / 100.0% | within | 7bbcc4a908c0...d11deda2 |
Second-line challenge coverage Risk appetite governance should include independent challenge from enterprise risk, compliance, treasury risk, conduct risk, technology risk, or model risk. | Statements, breaches, exceptions, and committee decisions with second-line challenge recorded | 100.0% / 100.0% | within | 9d3defdcd68e...3c567674 |
Risk exception expiry and compensating-control governance Tolerance use and exceptions should be formally approved, time bounded, independently challenged, and backed by compensating controls. | Exceptions approved, inside expiry, supported by compensating controls, challenged by second line, customer assessed, and board approved | 100.0% / 100.0% | within | 04148c81e6e8...ed334252 |
Customer impact appetite assessment Risk appetite and tolerance decisions should assess customer harm, fair outcomes, redress, access to credit, and service continuity. | Statements, limits, breach cases, and exceptions with customer-impact evidence | 100.0% / 100.0% | within | bbc17c3f74d1...7387a2fb |
Committee decision and signed-minute execution readiness Risk appetite governance should evidence how committee challenge and decisions are executed, minuted, owned, and retained. | Committee decisions mapped to statements, limits, exceptions, challenge, signed minutes, owner notices, due date acceptance, and custody evidence | 100.0% / 100.0% | within | 8b538f608135...fd77c626 |
Risk appetite manifest coverage Risk appetite evidence should be traceable to source systems, control owners, board reports, retention rules, and reproducible export packages. | Domain controls mapped to enterprise evidence manifest and retained export packages | 100.0% / 100.0% | within | f6c068fe50d4...d825014d |
Risk appetite evidence custody Risk appetite and limit evidence should be reproducible, tamper-evident, and ready for board, audit, and supervisory challenge. | Evidence rows, controls, actions, and manifest entries with SHA-256 custody hashes | 100.0% / 100.0% | within | 551235a052d4...e5339138 |
| Trigger | Owner | Action | Deadline | Status |
|---|---|---|---|---|
| No enterprise risk appetite or limit action packs are required for the current evidence set. | ||||
| Control | Three-lines route | Review cadence | Assurance state | Evidence custody | Finding / action | Assurance hash |
|---|---|---|---|---|---|---|
Critical operation and dependency map Operational resilience / BCBS operational resilience | 1L: platform ops 2L: operational risk 3L: internal audit risk and technology committee | quarterly 2026-07-07 to 2026-08-21 | effective Residual risk: low Line: second_line | operational-resilience-impact-table /officer/admin/op-readiness#operational-resilience 9a2890f34de2...40b228f0 | Evidence supports effective design and operating posture. Owner: operational risk / due none | fac5be496226...8c111c80 |
Impact tolerance and recovery drill coverage Operational resilience / BCBS operational resilience | 1L: site reliability 2L: operational risk 3L: internal audit risk and technology committee | quarterly 2026-07-10 to 2026-08-24 | effective Residual risk: low Line: second_line | impact-tolerance-automation-table /officer/admin/op-readiness#operational-resilience-automation c6b8b26247c3...f24010f0 | Evidence supports effective design and operating posture. Owner: operational risk / due none | a795b9bc5438...9f79c47c |
Third-party service substitutability Operational resilience / BCBS third-party dependency management | 1L: vendor risk 2L: operational risk 3L: internal audit risk and technology committee | quarterly 2026-07-13 to 2026-08-27 | effective Residual risk: low Line: second_line | third-party-exit-evidence-pack-table /officer/admin/op-readiness#operational-resilience-automation 0c2febd37c6f...90245402 | Evidence supports effective design and operating posture. Owner: operational risk / due none | 8f300708aa7e...813a483a |
Operational risk RCSA, loss-event, KRI, scenario, remediation, and board reporting evidence packs Operational risk management / BCBS Principles for the Sound Management of Operational Risk / BCBS operational resilience / CBK Risk Management Guidelines | 1L: operational risk management, control assurance, and first-line process owners 2L: operational risk management 3L: internal audit board risk committee | quarterly 2026-07-16 to 2026-08-30 | effective Residual risk: low Line: second_line | operational-risk-control-table /officer/admin/op-readiness#operational-risk-governance 4f7c31cce46d...d79bb160 | Evidence supports effective design and operating posture. Owner: operational risk management / due none | a1f0d9beb693...ddeb986d |
Third-party lifecycle, due diligence, contract rights, subcontractor, concentration, SLA, incident, cyber, data protection, exit, and evidence-custody packs Third-party and outsourcing risk governance / Interagency Guidance on Third-Party Relationships: Risk Management / EBA outsourcing arrangements / EU DORA ICT third-party risk / FFIEC cyber and outsourcing risk governance / BCBS operational resilience third-party dependency management | 1L: vendor risk, procurement, legal control, operational resilience, security governance, privacy, payments operations, credit operations, and enterprise risk 2L: vendor risk, operational resilience, and compliance 3L: internal audit risk and technology committee | monthly 2026-07-19 to 2026-09-02 | effective Residual risk: low Line: second_line | third-party-risk-gate-table /officer/admin/op-readiness#third-party-risk-governance a70bf47270a0...56345045 | Evidence supports effective design and operating posture. Owner: vendor risk, operational resilience, and compliance / due none | b149461c6f28...28c21f1e |
Model inventory, validation, and governance controls Model risk and fair lending / SR 11-7 model risk management | 1L: model risk 2L: model risk and compliance 3L: internal audit credit and conduct committee | quarterly 2026-07-22 to 2026-09-05 | effective Residual risk: low Line: second_line | model-validation-attestation-table /officer/risk/models#model-validation-attestation-pack 9850224317f2...350fd64c | Evidence supports effective design and operating posture. Owner: model risk and compliance / due none | 81dbb09dc9e0...5e081f4b |
Ongoing monitoring and back-testing Model risk and fair lending / SR 11-7 model risk management | 1L: credit risk 2L: model risk and compliance 3L: internal audit credit and conduct committee | quarterly 2026-07-25 to 2026-09-08 | effective Residual risk: low Line: second_line | model-risk-breach-ticket-table /officer/risk/models bb69e934e216...e9687e9e | Evidence supports effective design and operating posture. Owner: model risk and compliance / due none | f5dbb39a00ff...10ae8914 |
Specific adverse-action reason generation Model risk and fair lending / CFPB complex-algorithm adverse action | 1L: fair lending 2L: model risk and compliance 3L: internal audit credit and conduct committee | quarterly 2026-07-28 to 2026-09-11 | effective Residual risk: low Line: second_line | adverse-action-specific-reasons /officer/risk/models aa4216b0f7ac...99afc398 | Evidence supports effective design and operating posture. Owner: model risk and compliance / due none | 494b03645789...f6710e38 |
Model lifecycle, development data, independent validation, challenger, fair-lending, drift, override, retirement, and evidence-custody packs Model risk and fair lending / Revised Interagency Guidance on Model Risk Management (2026) / NIST AI RMF / CFPB complex-algorithm adverse action / ECOA fair-lending lifecycle governance | 1L: model risk, fair lending, credit risk, data governance, conduct risk, change management, and board secretariat 2L: model risk and compliance 3L: internal audit credit and conduct committee | quarterly 2026-07-31 to 2026-09-14 | effective Residual risk: low Line: second_line | model-lifecycle-control-table /officer/risk/models#model-lifecycle-fair-lending-governance 0c3ecc813cdc...ad713b71 | Evidence supports effective design and operating posture. Owner: model risk and compliance / due none | 5e5a5e43d002...c6003006 |
Credit bureau consent, data furnishing, negative-listing notice, dispute investigation, correction, cure reporting, privacy, retention, synthetic-action, and evidence-custody packs Model risk and fair lending / Kenya Banking Credit Reference Bureau Regulations 2020 / CFPB Regulation V FCRA furnisher accuracy and direct dispute duties / World Bank General Principles for Credit Reporting / credit-information consent, data furnishing, negative-listing notice, dispute investigation, correction, privacy, retention, and evidence-custody governance | 1L: underwriting operations, credit operations, credit risk, data governance, privacy office, collections conduct, customer dignity operations, regulatory operations, control assurance, and board secretariat 2L: model risk and compliance 3L: internal audit credit and conduct committee | quarterly 2026-08-03 to 2026-09-17 | effective Residual risk: low Line: second_line | credit-bureau-furnishing-control-table /officer/applications/[id]/uw/bureau#credit-bureau-furnishing-governance ebb9f59d2598...d79f04e5 | Evidence supports effective design and operating posture. Owner: model risk and compliance / due none | e0e1ac661c5b...b7c15971 |
Income verification, expense reasonableness, obligation completeness, DSR/PTI/residual-income, stress affordability, vulnerable-customer, manual-exception, decline, synthetic-action, and evidence-custody packs Responsible lending and affordability governance / EBA Guidelines on loan origination and monitoring creditworthiness assessment / World Bank responsible lending and over-indebtedness consumer protection / FCA Consumer Duty and borrower financial-difficulty outcomes / Kenya Financial Consumer Protection Framework affordability and fair-treatment expectations / income verification, expense reasonableness, obligation completeness, debt-service capacity, stress affordability, vulnerable-customer safeguards, exception, decline, and evidence-custody governance | 1L: underwriting operations, credit policy, credit risk, conduct risk, model risk, privacy office, data governance, control assurance, and board secretariat 2L: credit risk, conduct risk, model risk, and compliance 3L: internal audit credit risk committee and board risk committee | monthly 2026-08-06 to 2026-09-20 | effective Residual risk: low Line: second_line | responsible-lending-affordability-control-table /officer/applications/[id]/uw/dsr#responsible-lending-affordability-governance 152024d504ad...e584ff22 | Evidence supports effective design and operating posture. Owner: credit risk, conduct risk, model risk, and compliance / due none | e9f859bb5595...d8c0b7d7 |
AI operator tool-agency, approval, confidence, provenance, prompt-injection, privacy, incident, and evidence-custody packs AI operator governance / NIST AI RMF / NIST AI 600-1 Generative AI Profile / OWASP LLM Top 10 2025 / ISO/IEC 42001 AI management system | 1L: AI governance council, model risk, AI security, privacy, and operations risk 2L: model risk and AI governance 3L: internal audit board risk committee | monthly 2026-08-09 to 2026-09-23 | effective Residual risk: low Line: second_line | ai-operator-governance-control-table /officer/ai-operator#ai-operator-governance-pack 140ba2ab9352...1a796641 | Evidence supports effective design and operating posture. Owner: model risk and AI governance / due none | 7468d2d4de84...174b5530 |
Financial-grade API authentication, consent scope, sandbox, partner, quota, webhook, release-assurance, and evidence-custody packs API platform governance / OpenID FAPI 2.0 Security Profile / OWASP API Security Top 10 2023 / NIST SP 800-204A microservices security / NIST SP 800-218 SSDF / consumer-permissioned financial data rights | 1L: API platform, identity platform, application security, privacy, partner operations, and operational risk 2L: API security, privacy, and operational risk 3L: internal audit risk and technology committee | monthly 2026-08-12 to 2026-09-26 | effective Residual risk: low Line: second_line | api-platform-governance-control-table /officer/admin/api-platform#api-platform-governance-pack a292a31bd0f9...8aef35b0 | Evidence supports effective design and operating posture. Owner: API security, privacy, and operational risk / due none | 9090dd0dd394...f5348588 |
Open-finance consent journey, data-access grant, revocation, portability, restriction, deletion, data-recipient, reconciliation, live-read, synthetic-action, and evidence-custody packs API platform governance / CFPB Personal Financial Data Rights Rule 12 CFR Part 1033 / eCFR Regulation 1033 / Open Banking Standard consent and data management good practice / EBA PSD2 strong customer authentication and common secure communication / FCA open banking and open finance consumer protection / Kenya Financial Consumer Protection Framework consent, privacy, digital finance, complaint, and redress expectations / consumer-permissioned data sharing, scope minimization, revocation, portability, recipient oversight, reconciliation, and evidence-custody governance | 1L: API platform, privacy office, data governance, identity platform, security governance, partner operations, vendor risk, legal control, conduct risk, records manager, customer outcomes operations, control assurance, and board secretariat 2L: API security, privacy, and operational risk 3L: internal audit risk and technology committee | monthly 2026-08-15 to 2026-09-29 | effective Residual risk: low Line: second_line | open-finance-consent-control-table /officer/admin/api-platform#open-finance-consent-governance 5bfa6c3b3caa...7b4f2367 | Evidence supports effective design and operating posture. Owner: API security, privacy, and operational risk / due none | bfb36ff44d6f...72f99f06 |
Fraud typology, alert, case, disbursement hold, vulnerable-customer, loss recovery, signal validation, and evidence-custody packs Fraud and scam risk governance / FFIEC authentication and access risk management / FATF risk-based financial-crime controls / CFPB elder financial exploitation response / NIST CSF 2.0 Detect-Respond-Recover / operational risk fraud loss governance | 1L: fraud operations, financial crime compliance, application security, credit operations, conduct risk, model risk, and operational risk 2L: fraud risk, financial crime compliance, payments risk, conduct risk, customer outcomes, and operational risk 3L: internal audit fraud risk, conduct, and board risk committee | monthly 2026-08-18 to 2026-10-02 | effective Residual risk: low Line: second_line | fraud-risk-governance-control-table /officer/fraud#fraud-risk-governance-pack 2ab129d8e0f9...21679a9e | Evidence supports effective design and operating posture. Owner: fraud risk, financial crime compliance, payments risk, conduct risk, customer outcomes, and operational risk / due none | e4c8dc242064...38fab8ed |
Authorized payment scam and unauthorized-transfer intake, liability, reimbursement, victim-care, receiving-party recovery, fraud reporting, live-read, synthetic-action, and evidence-custody packs Fraud and scam risk governance / PSR APP scam reimbursement protections and compliance monitoring / EBA PSD2 fraud reporting / CFPB Regulation E unauthorized transfer and error-resolution controls / Kenya Financial Consumer Protection Framework and CBK fraud safety / World Bank financial consumer protection complaints and redress good practices | 1L: fraud operations, payment error resolution, payments operations, MLRO, customer outcomes, conduct risk, finance control, regulatory operations, privacy office, and board secretariat 2L: fraud risk, financial crime compliance, payments risk, conduct risk, customer outcomes, and operational risk 3L: internal audit fraud risk, conduct, and board risk committee | monthly 2026-08-21 to 2026-10-05 | effective Residual risk: low Line: second_line | scam-control-table /officer/admin/aml#scam-reimbursement-governance f30e2e2f684b...26a0f600 | Evidence supports effective design and operating posture. Owner: fraud risk, financial crime compliance, payments risk, conduct risk, customer outcomes, and operational risk / due none | 5bd14d9734ff...3b659607 |
Portfolio risk appetite, concentration, and stress evidence packs Portfolio risk governance / BCBS 239 risk data aggregation / Basel credit risk principles / CBK risk management guidelines | 1L: enterprise risk management 2L: enterprise risk management 3L: internal audit board risk committee | monthly 2026-08-24 to 2026-10-08 | effective Residual risk: low Line: second_line | portfolio-risk-appetite-table /officer/risk/stress#portfolio-risk-appetite-evidence c92b6dc5263e...9a42d0c2 | Evidence supports effective design and operating posture. Owner: enterprise risk management / due none | 8b899bed7d34...0cc2314a |
Credit policy, granting, collateral, monitoring, early-warning, workout, write-off, and recovery evidence packs Credit risk lifecycle governance / BCBS Principles for the Management of Credit Risk / CBK Risk Management Guidelines / CBK PG/04 Risk Classification and Provisioning | 1L: enterprise credit risk, credit operations, special assets, and finance control 2L: credit risk and credit review 3L: internal audit board risk committee | monthly 2026-08-27 to 2026-10-11 | effective Residual risk: low Line: second_line | credit-lifecycle-control-table /officer/risk/stress#credit-lifecycle-governance-pack b1ee77f73026...52cd1641 | Evidence supports effective design and operating posture. Owner: credit risk and credit review / due none | 54b95c2e221a...1cc03251 |
Co-lending partner eligibility, loan participation, allocation fairness, risk retention, settlement waterfall, servicing disclosure, concentration, live-read, synthetic-action, and evidence-custody packs Credit risk lifecycle governance / Basel Committee Principles for the Management of Credit Risk / Basel large exposures and securitisation risk-transfer framework / EBA loan origination and monitoring / IFRS 9 financial asset transfer and derecognition controls / CBK Risk Management Guidelines / Kenya Financial Consumer Protection Framework / World Bank financial consumer protection good practices / co-lending, loan participation, allocation fairness, risk retention, partner due diligence, settlement, servicing, concentration, live-read, and evidence-custody governance | 1L: co-lending operations, partner operations, enterprise credit risk, credit policy, structured credit, syndication desk, treasury reconciliation, finance control, loan servicing operations, conduct risk, vendor risk, legal control, data governance, privacy office, control assurance, and board secretariat 2L: credit risk and credit review 3L: internal audit board risk committee | monthly 2026-08-30 to 2026-10-14 | effective Residual risk: low Line: second_line | co-lending-participation-control-table /officer/co-lending#co-lending-participation-governance d184f6629432...fea7b643 | Evidence supports effective design and operating posture. Owner: credit risk and credit review / due none | 7989ed467c9d...0189bb9a |
Capital markets issuance approval, investor suitability, bookbuilding allocation fairness, subscription settlement, secondary trading surveillance, ongoing disclosure, funding concentration, live-read, synthetic-action, and evidence-custody packs Liquidity and funding risk / IOSCO Objectives and Principles of Securities Regulation / IOSCO Principles for Ongoing Disclosure and Material Development Reporting / IOSCO suitability requirements for complex financial products / IOSCO international debt disclosure principles / Kenya Capital Markets Authority issuer, corporate bond, collective investment, custody, and market-conduct expectations / Basel large exposures and securitisation framework / CPMI-IOSCO PFMI settlement finality / IFRS 7 and IFRS 9 disclosure and financial instrument controls | 1L: capital markets desk, investor relations, treasury risk, settlement operations, market surveillance, finance control, legal control, conduct risk, financial crime compliance, custodian oversight, regulatory operations, data governance, control assurance, and board secretariat 2L: treasury risk 3L: internal audit board risk committee | monthly 2026-09-02 to 2026-10-17 | effective Residual risk: low Line: second_line | capital-markets-issuance-control-table /officer/capital-markets#capital-markets-issuance-governance 0fcd48e83a3a...506e2374 | Evidence supports effective design and operating posture. Owner: treasury risk / due none | 5fd1f9d37a8c...7968fc31 |
Structured credit loan-pool eligibility, true-sale, derecognition, SPV tranche, cashflow waterfall, servicer continuity, investor reporting, capital relief, risk retention, live-read, synthetic-action, and evidence-custody packs Structured credit and securitisation governance / Basel securitisation framework / IOSCO disclosure principles for public offerings and listings of asset-backed securities / IFRS 9 financial asset transfer and derecognition / IFRS 7 transferred financial asset disclosures / EBA simple, transparent and standardised securitisation and risk-retention expectations / Kenya Capital Markets Authority asset-backed securities expectations | 1L: structured credit, capital markets desk, treasury risk, capital planning, finance control, legal control, investor relations, loan servicing operations, conduct risk, data governance, privacy office, control assurance, ALCO, capital committee, audit committee, and board secretariat 2L: structured credit risk, capital planning, treasury risk, finance control, legal control, conduct risk, and risk data governance 3L: internal audit board risk committee, ALCO, capital committee, audit committee, and conduct committee | monthly transaction surveillance, quarterly securitisation board review, and pre-issuance or sale approval 2026-09-05 to 2026-10-20 | effective Residual risk: low Line: second_line | structured-credit-control-table /officer/capital-markets#structured-credit-securitisation-governance e65bfff3e67b...3330ddb6 | Evidence supports effective design and operating posture. Owner: structured credit risk, capital planning, treasury risk, finance control, legal control, conduct risk, and risk data governance / due none | 67f868d54b99...13107d69 |
External data-room room approval, recipient access, legal basis, redaction, privilege review, package integrity, watermark, activity audit, revocation, live-read, synthetic-export blocking, and evidence-custody packs External disclosure and data-room governance / NIST CSF 2.0 Govern-Protect-Detect-Respond / NIST SP 800-53 Rev. 5 access, audit, media protection, and privacy controls / ISO/IEC 27001 information security management / EU GDPR data minimisation and security of processing / Kenya Data Protection Act and ODPC data sharing safeguards / IOSCO disclosure and investor-protection principles | 1L: data room operations, investor relations, regulatory operations, legal control, privacy office, security governance, data governance, records manager, finance control, board secretariat, control assurance, and board risk 2L: privacy office, security governance, legal control, data governance, investor relations, regulatory operations, and control assurance 3L: internal audit board risk committee, audit committee, technology committee, conduct committee, and capital markets committee | monthly external data-room review, per-room activation approval, and same-business-day leakage or revocation review 2026-09-08 to 2026-10-23 | effective Residual risk: low Line: second_line | external-data-room-control-table /officer/capital-markets#external-data-room-governance 5c9abcf8056a...fe21256f | Evidence supports effective design and operating posture. Owner: privacy office, security governance, legal control, data governance, investor relations, regulatory operations, and control assurance / due none | 2911df73eced...765bc784 |
Market abuse surveillance, insider and restricted list governance, market sounding control, best execution evidence, communications surveillance, regulatory reporting decisioning, live-read, synthetic-action blocking, and custody packs Market conduct surveillance governance / IOSCO Objectives and Principles of Securities Regulation / EU Market Abuse Regulation insider dealing, unlawful disclosure, and market manipulation controls / ESMA suspicious transaction and order reporting expectations / Kenya Capital Markets Act and CMA conduct-of-business expectations / best execution, insider list, market sounding, communications surveillance, STOR, live-read, synthetic-action blocking, and evidence-custody governance | 1L: market surveillance, trading oversight, compliance surveillance, conduct risk, legal control, investor relations, regulatory operations, records manager, data governance, control assurance, and board secretariat 2L: market conduct compliance, surveillance operations, legal control, investor relations, trading oversight, regulatory operations, records manager, data governance, and control assurance 3L: internal audit board risk committee, conduct committee, audit committee, technology committee, and capital markets committee | daily surveillance disposition, monthly market conduct forum, same-business-day market abuse escalation, and per-sounding approval 2026-09-11 to 2026-10-26 | effective Residual risk: low Line: second_line | market-conduct-control-table /officer/capital-markets#market-conduct-surveillance-governance 6e25c9e5f841...da37e30a | Evidence supports effective design and operating posture. Owner: market conduct compliance, surveillance operations, legal control, investor relations, trading oversight, regulatory operations, records manager, data governance, and control assurance / due none | e93a3f1d5d9a...e6be3e23 |
Sustainable finance taxonomy eligibility, use-of-proceeds allocation, impact-claim measurement, target calibration, verification assurance, social safeguard, greenwashing, live-read, synthetic-action, and evidence-custody packs Climate financial risk and disclosure / ICMA Green Bond Principles / ICMA Social Bond Principles / ICMA Sustainability-Linked Bond Principles / ICMA Sustainability Bond Guidelines / Kenya Green Finance Taxonomy / IFRS S1 and IFRS S2 sustainability and climate disclosures / UNDP SDG Impact Standards / UNEP FI climate target-setting for banks / sustainable-finance taxonomy eligibility, use-of-proceeds, impact-claim, greenwashing, social-safeguard, assurance, target-setting, live-read, and evidence-custody governance | 1L: sustainable finance, climate risk, impact measurement, treasury reconciliation, finance control, conduct risk, privacy office, data governance, control assurance, legal control, and board secretariat 2L: climate risk and sustainability control 3L: internal audit board risk committee | quarterly 2026-09-14 to 2026-10-29 | effective Residual risk: low Line: second_line | sustainable-finance-control-table /officer/risk/stress#sustainable-finance-impact-governance e320c1951e88...c74ba94b | Evidence supports effective design and operating posture. Owner: climate risk and sustainability control / due none | 00f08e583095...4e98e847 |
Collateral valuation, LTV, lien perfection, registry search, custody, insurance, repossession, dispute, synthetic-action, and evidence-custody packs Collateral valuation and custody governance / Basel Principles for the Management of Credit Risk / CBK Risk Management Guidelines / EBA loan origination and monitoring collateral valuation expectations / IFRS 13 fair value measurement / legal enforceability, custody, insurance, repossession, dispute, and evidence-custody governance | 1L: collateral operations, credit risk, legal control, recoveries, insurance operations, records manager, fraud operations, conduct risk, and board secretariat 2L: credit risk, collateral risk, legal control, and conduct risk 3L: internal audit credit risk committee and board risk committee | monthly 2026-09-17 to 2026-11-01 | effective Residual risk: low Line: second_line | collateral-governance-control-table /officer/collateral#collateral-valuation-custody-governance c7711e4e2bdb...5cff2b38 | Evidence supports effective design and operating posture. Owner: credit risk, collateral risk, legal control, and conduct risk / due none | 522af9a73c50...1dbebcab |
Collections conduct, hardship forbearance, promise-to-pay, repossession, write-off, recovery, and borrower-outcome evidence packs Collections and forbearance governance / CBK Risk Management Guidelines / Kenya Financial Consumer Protection Framework / World Bank Good Practices for Financial Consumer Protection / FCA Consumer Duty borrower difficulty protections | 1L: collections operations, conduct risk, special assets, legal control, and credit risk finance control 2L: conduct risk and credit review 3L: internal audit board risk committee | monthly 2026-09-20 to 2026-11-04 | effective Residual risk: low Line: second_line | collections-forbearance-control-table /officer/collections#collections-forbearance-governance-pack 0a154acf0d0f...46936db9 | Evidence supports effective design and operating posture. Owner: conduct risk and credit review / due none | cc92dfd66e51...a9e192db |
Loan statement accuracy, repayment waterfall allocation, payoff and settlement quote, waiver, reversal, refund, notice, dispute, reconciliation, live-read, synthetic-action, and evidence-custody packs Loan servicing and repayment governance / CFPB Regulation Z periodic statement, payoff statement, and payment allocation expectations / World Bank financial consumer protection servicing and disclosure good practices / FCA Consumer Duty borrower support and fair treatment / Kenya Financial Consumer Protection Framework servicing, disclosure, complaint, redress, and fair-treatment expectations / loan statement accuracy, repayment waterfall, payoff quote, waiver, reversal, refund, notice, dispute, reconciliation, and evidence-custody governance | 1L: loan servicing operations, payments operations, finance control, treasury reconciliation, customer outcomes operations, conduct risk, special assets, collateral operations, data governance, records manager, control assurance, and board secretariat 2L: conduct risk, finance control, credit risk, and operational risk 3L: internal audit conduct committee and board risk committee | monthly 2026-09-23 to 2026-11-07 | effective Residual risk: low Line: second_line | loan-servicing-repayment-control-table /officer/loans/[id]/waterfall#loan-servicing-repayment-governance d8f2b474cda6...ca06fd6b | Evidence supports effective design and operating posture. Owner: conduct risk, finance control, credit risk, and operational risk / due none | c1a736f61196...394bfc75 |
IFRS 9 staging, allowance adequacy, loan-level evidence, and impairment action packs Allowance and impairment governance / IFRS 9 expected credit loss impairment / Basel credit risk and ECL guidance / CBK provisioning comparison | 1L: CFO, credit risk, and impairment committee 2L: credit risk finance control 3L: internal audit audit and risk committee | monthly 2026-09-26 to 2026-11-10 | effective Residual risk: low Line: second_line | ifrs9-ecl-control-table /officer/risk/ecl#ifrs9-ecl-governance-pack a741c4fb98af...7651cc3f | Evidence supports effective design and operating posture. Owner: credit risk finance control / due none | 6e99a9c5ca09...416e41cb |
Capital adequacy, ICAAP, stress capital, and leverage evidence packs Capital adequacy and ICAAP / Basel III capital framework / Basel leverage ratio / CBK PG/04 capital adequacy | 1L: CFO and enterprise risk 2L: enterprise risk and finance control 3L: internal audit board risk committee | quarterly 2026-09-29 to 2026-11-13 | effective Residual risk: low Line: second_line | capital-icaap-control-table /financials/capital-adequacy#capital-icaap-evidence-pack b855cc64dc39...9033310c | Evidence supports effective design and operating posture. Owner: enterprise risk and finance control / due none | 14b86b7e67a0...f50c0492 |
Climate financial risk, scenario, financed-emissions, and disclosure evidence packs Climate financial risk and disclosure / BCBS climate-related financial risk principles / CBK Climate-Related Risk Management / IFRS S2 / TCFD | 1L: enterprise risk, CFO, and sustainability 2L: climate risk and sustainability control 3L: internal audit board risk committee | quarterly 2026-10-02 to 2026-11-16 | effective Residual risk: low Line: second_line | climate-risk-control-table /officer/risk/stress#climate-risk-disclosure-pack c1b4287c907d...990037a3 | Evidence supports effective design and operating posture. Owner: climate risk and sustainability control / due none | 177f716d557a...21261838 |
Liquidity risk appetite and contingency funding evidence packs Liquidity and funding risk / BCBS sound liquidity risk management / Basel III LCR / CBK Basel III liquidity standards | 1L: treasury risk and ALCO 2L: treasury risk 3L: internal audit board risk committee | monthly 2026-10-05 to 2026-11-19 | effective Residual risk: low Line: second_line | treasury-liquidity-appetite-table /officer/treasury/alm#treasury-liquidity-risk-evidence 34b55ca25081...9c9d245a | Evidence supports effective design and operating posture. Owner: treasury risk / due none | 7f4dc1e0567d...2246902f |
FX open-position, hedge, revaluation, stress, KRI, and market-risk evidence packs Market and foreign exchange risk / Basel market risk framework / BCBS Minimum capital requirements for market risk / CBK Foreign Exchange Exposure Limits / CBK Risk Management Guidelines | 1L: treasury risk, ALCO, payments risk, and finance control 2L: treasury risk and market risk control 3L: internal audit board risk committee | monthly 2026-10-08 to 2026-11-22 | effective Residual risk: low Line: second_line | market-risk-control-table /officer/treasury/fx#market-risk-governance-pack 5b6075288f0b...55e45d13 | Evidence supports effective design and operating posture. Owner: treasury risk and market risk control / due none | 65ddf3fc135c...67399f9c |
IRRBB earnings, EVE, repricing, basis-risk, optionality, and ALM governance evidence packs Interest rate risk and ALM governance / Basel IRRBB standards / Basel Framework SRP31-SRP98 / CBK Risk Management Guidelines | 1L: treasury risk, ALCO, and finance control 2L: treasury risk and finance control 3L: internal audit board risk committee | monthly 2026-10-11 to 2026-11-25 | effective Residual risk: low Line: second_line | irrbb-control-table /officer/treasury/alm#irrbb-governance-pack 03260f224ca9...251f0ec9 | Evidence supports effective design and operating posture. Owner: treasury risk and finance control / due none | 8579aa939ecd...2fc7876c |
Payment settlement finality, rail resilience, and exception evidence packs Payments and settlement risk / CPMI-IOSCO PFMI / CPMI ISO 20022 harmonisation / Kenya National Payment System risk controls | 1L: payments operations and treasury control 2L: payments risk and treasury control 3L: internal audit board risk committee | monthly 2026-10-14 to 2026-11-28 | effective Residual risk: low Line: second_line | payment-settlement-control-table /officer/treasury/disbursement#payment-settlement-assurance 1c6143926a38...af87bf26 | Evidence supports effective design and operating posture. Owner: payments risk and treasury control / due none | 816e63aa9e1b...f4b24873 |
Payment error intake, unauthorized-transfer, investigation, provisional-credit, reversal, refund, provider-dispute, reconciliation, notice, redress, live-read, synthetic-action, and evidence-custody packs Payments and settlement risk / CFPB Regulation E Electronic Fund Transfer Act error-resolution and unauthorized-transfer expectations / World Bank financial consumer protection complaints, disclosure, and redress good practices / CPMI-IOSCO PFMI payment finality and operational-risk expectations / Kenya Financial Consumer Protection Framework fair-treatment, complaint, redress, and digital-finance expectations / payment error intake, unauthorized transfer, investigation, provisional credit, reversal, refund, provider dispute, reconciliation, notice, redress, and evidence-custody governance | 1L: payment error resolution, payments operations, treasury reconciliation, finance control, customer outcomes operations, conduct risk, privacy office, data governance, vendor risk, operational risk, control assurance, and board secretariat 2L: payments risk and treasury control 3L: internal audit board risk committee | monthly 2026-10-17 to 2026-12-01 | effective Residual risk: low Line: second_line | payment-error-control-table /officer/treasury/recon#payment-error-resolution-governance cd0bf436dc06...0ccac581 | Evidence supports effective design and operating posture. Owner: payments risk and treasury control / due none | ec8da1005016...dec8f7a3 |
Deposit product, wallet float, customer-fund safeguarding, liquidity run, dormant balance, synthetic-action, and evidence-custody packs Deposits and wallet safeguarding / Basel Core Principles for effective banking supervision / CBK prudential and deposit-taking microfinance guidance / EBA payment services and e-money safeguarding / FCA payment and e-money safeguarding requirements / customer-fund segregation, liquidity, dormant balance, and run-protection governance | 1L: deposit operations, treasury risk, payments finance control, records manager, conduct risk, ALCO, and board secretariat 2L: treasury risk, deposits compliance, and finance control 3L: internal audit ALCO and board risk committee | monthly 2026-10-20 to 2026-12-04 | effective Residual risk: low Line: second_line | deposits-wallet-control-table /officer/deposits#deposits-wallet-safeguarding-governance 91d9211a853c...48bc0517 | Evidence supports effective design and operating posture. Owner: treasury risk, deposits compliance, and finance control / due none | c72f05826977...e8276001 |
Insurance product, Cap17 gate, premium trust-fund, claims fairness, reinsurance, synthetic-action, and evidence-custody packs Insurance and protection governance / IAIS Insurance Core Principles / Kenya insurance conduct and licensing controls / Cap17 trust-pool segregation / IFRS 17 insurance contract evidence / customer outcome, claims fairness, and reinsurance governance | 1L: insurance operations, Cap17 control, conduct risk, finance control, claims operations, reinsurance risk, and board secretariat 2L: insurance risk, conduct risk, and finance control 3L: internal audit risk and conduct committee | monthly 2026-10-23 to 2026-12-07 | effective Residual risk: low Line: second_line | insurance-protection-control-table /officer/insurance#insurance-protection-governance 1108d02a4d11...02269a69 | Evidence supports effective design and operating posture. Owner: insurance risk, conduct risk, and finance control / due none | d31abc344239...7c43c57f |
Agent onboarding, fit-and-proper, training, liquidity, teller cash reconciliation, commission payout, fraud/AML, conduct, synthetic-action, and evidence-custody packs Agent network and cash operations governance / CBK prudential and agency banking guidance / Basel operational risk and resilience principles / FATF risk-based AML/CFT financial inclusion guidance / GSMA mobile money agent network and safeguarding practices / agent liquidity, cash reconciliation, commission, conduct, and evidence-custody governance | 1L: agent network operations, cash operations, treasury risk, payments finance control, fraud operations, MLRO, conduct risk, operational risk, agent finance control, and board secretariat 2L: operational risk, financial crime compliance, and conduct risk 3L: internal audit operational risk committee and board risk committee | monthly 2026-10-26 to 2026-12-10 | effective Residual risk: low Line: second_line | agent-network-cash-control-table /officer/agents#agent-network-cash-governance bb5b5cfef85b...8ccbdca5 | Evidence supports effective design and operating posture. Owner: operational risk, financial crime compliance, and conduct risk / due none | 4e68c1d1c6aa...eb69ac4f |
Proactive regulatory obligation radar Regulatory operations / CBK/ODPC/FRC regulatory horizon management | 1L: regulatory operations 2L: compliance assurance 3L: internal audit risk and compliance committee | monthly 2026-10-29 to 2026-12-13 | effective Residual risk: low Line: second_line | regulatory-obligation-table /officer/regulatory#regulatory-obligation-radar 2a6668e55d9b...c0f96b96 | Evidence supports effective design and operating posture. Owner: compliance assurance / due none | 007bc83c4b8c...715cc291 |
Regulatory return inventory, source reconciliation, validation-rule, maker-checker, CFO, compliance, API-submission, acknowledgement, amendment, prudential-capital, board-route, live-read, and evidence-custody packs Regulatory operations / CBK Digital Credit Provider data submission testing / CBK Risk Management Guidelines reliable regulatory reporting / BCBS 239 risk data aggregation and risk reporting / Basel Core Principles supervisory reporting | 1L: regulatory reporting, finance control, compliance assurance, data governance, API platform, board secretariat, and control assurance 2L: compliance assurance 3L: internal audit risk and compliance committee | monthly 2026-11-01 to 2026-12-16 | effective Residual risk: low Line: second_line | regulatory-return-control-table /officer/regulatory/cbk#regulatory-return-production-governance 8709adcfda25...c54196b9 | Evidence supports effective design and operating posture. Owner: compliance assurance / due none | f75198799bc0...bf4148a6 |
Regulatory perimeter, licence, registration, authorization, key-person, fit-and-proper, ownership, third-party notice, change-control, product launch, country expansion, synthetic-action, and evidence-custody packs Regulatory operations / CBK Digital Credit Providers Regulations 2022 / CBK Digital Credit Provider licensing procedures / National Payment System Regulations 2014 and PSP authorisation procedures / ODPC Data Controller and Processor registration guidance / Capital Markets licensing requirements / POCAMLA AML-CFT-CPF reporting institution obligations | 1L: legal control, regulatory operations, company secretary, privacy office, financial crime compliance, payments operations, capital markets desk, insurance governance, product governance, platform expansion, and board secretariat 2L: compliance assurance 3L: internal audit risk and compliance committee | monthly 2026-11-04 to 2026-12-19 | effective Residual risk: low Line: second_line | regulatory-perimeter-control-table /officer/regulatory#regulatory-perimeter-licensing-governance 7e06d4c85f55...40906846 | Evidence supports effective design and operating posture. Owner: compliance assurance / due none | bf20f4a197bd...c59b31e2 |
Supervisory exam request, regulator response, finding remediation, commitment tracking, board escalation, and legal evidence-custody packs Supervisory response and regulatory commitments / Basel Core Principles for Effective Banking Supervision / BCBS Compliance and the compliance function in banks / BCBS corporate governance principles for banks / CBK Risk Management Guidelines | 1L: regulatory operations, compliance assurance, legal control, enterprise risk, privacy office, financial crime compliance, payments risk, records manager, and board secretariat 2L: compliance assurance, legal control, enterprise risk, and regulatory operations 3L: internal audit risk and compliance committee and board risk committee | monthly and for every material supervisory request 2026-11-07 to 2026-12-22 | effective Residual risk: low Line: second_line | supervisory-control-table /officer/regulatory#regulatory-supervisory-response-governance 8d47bf1da9ee...adbb173a | Evidence supports effective design and operating posture. Owner: compliance assurance, legal control, enterprise risk, and regulatory operations / due none | 551f65bbc6cc...d7b6cd2a |
Tax obligation registration, iTax filing calendar, KRA VAT/PAYE/WHT/corporate tax remittance, SHA/SHIF, NSSF, housing levy, NITA, eTIMS, ledger reconciliation, transfer-pricing, stamp-duty, audit-query, live-read, synthetic-action, and evidence-custody packs Tax and statutory compliance governance / OECD Tax Control Framework and co-operative compliance / COSO Internal Control Integrated Framework / Kenya Revenue Authority iTax, eTIMS, VAT, PAYE, withholding tax, corporate income tax, transfer-pricing, affordable housing levy, and statutory payment expectations / Social Health Authority employer contribution expectations / NSSF employer contribution expectations / tax obligation registration, return preparation, payment, filing calendar, payroll statutory contribution, ledger reconciliation, tax-position, live-read, synthetic-action, and evidence-custody governance | 1L: tax operations, CFO tax control, payroll tax, people operations, finance control, treasury reconciliation, legal control, compliance assurance, privacy office, records manager, control assurance, and board secretariat 2L: tax control, finance control, compliance assurance, and legal control 3L: internal audit and external audit liaison audit committee and board risk committee | monthly close, statutory filing cycle, and quarterly board audit review 2026-11-10 to 2026-12-25 | effective Residual risk: low Line: second_line | tax-statutory-control-table /officer/admin/op-readiness#tax-statutory-obligation-governance 78031b65a996...95074bb4 | Evidence supports effective design and operating posture. Owner: tax control, finance control, compliance assurance, and legal control / due none | 48efaeb480ae...392f0346 |
Privacy impact and high-risk processing launch gates Data protection and privacy / ODPC Data Protection Act / NIST Privacy Framework / NIST AI RMF | 1L: privacy engineering 2L: privacy office 3L: internal audit risk and compliance committee | quarterly 2026-11-13 to 2026-12-28 | effective Residual risk: low Line: second_line | privacy-impact-activity-table /officer/regulatory/consent#privacy-impact-launch-gates 159ded020d42...20ede0c1 | Evidence supports effective design and operating posture. Owner: privacy office / due none | 0c49daba5161...32e95b9e |
Records inventory, retention schedule, legal hold, DSAR disposition, immutable archive, backup propagation, and evidence-custody packs Data protection and privacy / NIST Privacy Framework data processing lifecycle / ISO 15489 records management / Kenya Data Protection Act storage limitation and data-subject rights / regulator, AML, dispute, tax, and audit evidence retention | 1L: records manager, privacy office, legal control, MLRO, platform reliability, and data governance 2L: privacy office 3L: internal audit risk and compliance committee | quarterly 2026-11-16 to 2026-12-31 | effective Residual risk: low Line: second_line | records-data-lifecycle-control-table /officer/operations/readiness#records-data-lifecycle-governance edecc15cc411...5ccf34f6 | Evidence supports effective design and operating posture. Owner: privacy office / due none | 2e2f56a91d8f...e8598017 |
AML typology surveillance and STR evidence packs Financial crime compliance / FATF risk-based AML/CFT/CPF / Kenya FRC suspicious transaction reporting / CBK AML supervision | 1L: MLRO and financial crime compliance 2L: financial crime compliance 3L: internal audit risk and compliance committee | monthly 2026-11-19 to 2027-01-03 | effective Residual risk: low Line: second_line | aml-typology-table /officer/admin/aml#aml-typology-surveillance b8abdf04dda5...082c0465 | Evidence supports effective design and operating posture. Owner: financial crime compliance / due none | 57ceb2aa96e8...c238bb1c |
Financial-crime KYC, CDD, beneficial ownership, EDD, screening, monitoring, STR/SAR, no-tipping-off, goAML, risk-control, and evidence-custody packs Financial crime compliance / FATF Recommendations risk-based AML/CFT/CPF / FinCEN customer due diligence and beneficial ownership / Kenya FRC suspicious and unusual transaction reporting / sanctions, PEP, adverse media, and STR governance | 1L: MLRO, KYC operations, financial crime compliance, screening operations, model risk, data governance, and board secretariat 2L: financial crime compliance 3L: internal audit risk and compliance committee | monthly 2026-11-22 to 2027-01-06 | effective Residual risk: low Line: second_line | financial-crime-control-table /officer/admin/aml#financial-crime-governance-pack 51dc69226553...94b6f187 | Evidence supports effective design and operating posture. Owner: financial crime compliance / due none | 385bad007056...4df3275e |
Business-network KYB, merchant, supplier, anchor-buyer, dealer-importer, relationship exposure, marketplace abuse, renewal, action, and evidence-custody packs Business network and KYB governance / FATF Recommendations risk-based CDD and ongoing monitoring / FATF Recommendation 24 beneficial ownership of legal persons / Kenya beneficial ownership and digital credit provider controls / OECD responsible business conduct due diligence / World Bank integrity compliance and IFC due diligence | 1L: marketplace operations, MLRO, financial crime compliance, fraud operations, credit risk, payments operations, vendor risk, data governance, and board secretariat 2L: marketplace risk, financial crime compliance, fraud risk, credit risk, payments risk, and data governance 3L: internal audit risk and compliance committee, credit risk committee, and board risk committee | monthly KYB review, same-business-day prohibited-party escalation, and pre-award or pre-financing gate review 2026-11-25 to 2027-01-09 | effective Residual risk: low Line: second_line | business-network-control-table /officer/soko#business-network-kyb-governance 00af638c52ae...3742c906 | Evidence supports effective design and operating posture. Owner: marketplace risk, financial crime compliance, fraud risk, credit risk, payments risk, and data governance / due none | 045c139ae235...068e2149 |
Cross-domain risk data lineage, quality, timeliness, adaptability, reconciliation, and board reporting evidence packs Risk data aggregation and reporting / BCBS 239 risk data aggregation and risk reporting / CBK Risk Management Guidelines | 1L: data governance, enterprise risk, and control assurance 2L: data governance and enterprise risk 3L: internal audit board risk committee | monthly 2026-11-28 to 2027-01-12 | effective Residual risk: low Line: second_line | risk-data-quality-control-table /officer/admin/op-readiness#risk-data-aggregation-governance cd8cd7204760...916d4c11 | Evidence supports effective design and operating posture. Owner: data governance and enterprise risk / due none | c012235005b1...d0161652 |
Finance ledger, posting-rule, reconciliation, suspense, period-close, financial-reporting, audit, synthetic-action, and evidence-custody packs Finance ledger and close governance / IFRS Conceptual Framework and IFRS financial reporting discipline / COSO Internal Control Integrated Framework / Basel corporate governance principles for banks / CBK Risk Management Guidelines / ledger integrity, period-close, reconciliation, suspense, adjustment, and audit-evidence custody governance | 1L: CFO, finance control, risk finance, treasury finance control, reconciliation operations, tax, regulatory reporting, audit liaison, control assurance, and board secretariat 2L: finance control, regulatory reporting, operational risk, and data governance 3L: internal audit and external audit liaison audit committee and board risk committee | monthly close and quarterly reporting 2026-12-01 to 2027-01-15 | effective Residual risk: low Line: second_line | finance-ledger-control-table /officer/gl#finance-ledger-close-governance 5f59bc1e436f...f5abcbc3 | Evidence supports effective design and operating posture. Owner: finance control, regulatory reporting, operational risk, and data governance / due none | 1cde749dd801...e775cf48 |
Product fair-value, pricing, total-cost-of-credit, fee transparency, target-market, disclosure, lifecycle, complaints, redress, synthetic-action, and evidence-custody packs Product pricing and fair-value governance / FCA Consumer Duty price and value outcome / EBA product oversight and governance for retail banking products / Kenya Financial Consumer Protection Framework / World Bank Good Practices for Financial Consumer Protection / fair-value, fee-transparency, suitability, disclosure, product lifecycle, and evidence-custody governance | 1L: product governance, pricing committee, conduct risk, credit policy, product finance control, digital product, agent conduct control, regulatory operations, control assurance, and board secretariat 2L: conduct risk, product control, credit risk, and compliance assurance 3L: internal audit product governance committee and board conduct committee | monthly and before launch or repricing 2026-12-04 to 2027-01-18 | effective Residual risk: low Line: second_line | product-pricing-control-table /officer/admin/pricing#product-pricing-fair-value-governance 6e43efb00066...c23158de | Evidence supports effective design and operating posture. Owner: conduct risk, product control, credit risk, and compliance assurance / due none | d78803c70add...aa1dec7e |
Product launch queue, regulatory perimeter linkage, product-pricing linkage, manifest coverage, approval-route, live-read, upstream-action, post-launch review, synthetic-action, and evidence-custody packs Product pricing and fair-value governance / Product launch regulatory readiness / regulatory perimeter licensing governance / product pricing fair-value governance / privacy, AML, responsible-lending, live-read, board approval, and evidence-custody launch controls | 1L: product governance, regulatory operations, legal control, conduct risk, pricing committee, credit policy, privacy office, financial crime compliance, payments operations, and board secretariat 2L: conduct risk, product control, credit risk, and compliance assurance 3L: internal audit product governance committee and board conduct committee | monthly and before launch or repricing 2026-12-07 to 2027-01-21 | effective Residual risk: low Line: second_line | product-launch-control-table /officer/admin/product-launch#product-launch-regulatory-readiness 39181e86ef9a...19528c2f | Evidence supports effective design and operating posture. Owner: conduct risk, product control, credit risk, and compliance assurance / due none | 833254982a5e...62fff297 |
Risk-adjusted profitability, funds-transfer-pricing, RAROC hurdle, cost-stack, stressed return, attribution, customer-outcome, and evidence-custody packs Risk-adjusted profitability and FTP governance / Interagency FTP guidance for funding and contingent liquidity risk / BCBS sound liquidity risk management / OCC lending and loan portfolio risk management / OCC earnings quality / EBA loan origination and monitoring loan pricing / Basel Core Principles risk governance / World Bank financial consumer protection | 1L: pricing committee, treasury risk, ALCO, risk finance, product finance control, conduct risk, enterprise risk, and board secretariat 2L: risk finance, treasury risk, product control, and enterprise risk 3L: internal audit ALCO, product governance committee, capital committee, and board risk committee | monthly and before material pricing, FTP curve, product launch, or repricing decisions 2026-12-10 to 2027-01-24 | effective Residual risk: low Line: second_line | profitability-control-table /officer/admin/pricing#risk-adjusted-profitability-ftp-governance 073ed713d691...153a857f | Evidence supports effective design and operating posture. Owner: risk finance, treasury risk, product control, and enterprise risk / due none | 99df03a55b10...ec659172 |
Production-change, release-gate, configuration-baseline, software-supply-chain, deployment-health, emergency-change, rollback, synthetic-action, and evidence-custody packs Change, release, and configuration governance / FFIEC Development, Acquisition, and Maintenance change management / FFIEC Architecture, Infrastructure, and Operations configuration management / NIST SP 800-128 security-focused configuration management / NIST SP 800-218 Secure Software Development Framework / NIST CSF 2.0 Govern and Protect / CBK Risk Management and Business Continuity guidance | 1L: release management, platform engineering, security operations, service owners, enterprise risk, vendor risk, data governance, customer operations, control assurance, internal audit liaison, and board secretariat 2L: technology risk, operational risk, security assurance, and control assurance 3L: internal audit technology committee, audit committee, and board risk committee | weekly release review, monthly configuration review, and quarterly board technology-risk review 2026-12-13 to 2027-01-27 | effective Residual risk: low Line: second_line | change-release-control-table /officer/admin/op-readiness#change-release-configuration-governance b6137626a882...9a8c2b89 | Evidence supports effective design and operating posture. Owner: technology risk, operational risk, security assurance, and control assurance / due none | aacf99ba7422...62840569 |
Recovery trigger, recovery option, solvent wind-down, communication, and board escalation evidence packs Recovery and resolution planning / FSB Key Attributes recovery and resolution planning / BCBS operational resilience / CBK Risk Management Guidelines | 1L: enterprise risk, treasury risk, CFO, operational resilience, and board secretariat 2L: enterprise risk and recovery planning 3L: internal audit board risk committee | quarterly 2026-12-16 to 2027-01-30 | effective Residual risk: low Line: second_line | recovery-control-table /officer/admin/op-readiness#recovery-resolution-governance 7a6a093ee86c...cbc59f2c | Evidence supports effective design and operating posture. Owner: enterprise risk and recovery planning / due none | 2696fcfbfcc4...8f307525 |
Critical-function exit, provider substitutability, data-portability, transition-runbook, solvent wind-down, communication, and evidence-custody packs Recovery and resolution planning / BCBS operational resilience critical operation mapping and testing / EBA outsourcing exit strategies / EU DORA ICT third-party risk / PRA SS2/21 outsourcing and third-party risk / CBK Risk Management and Business Continuity guidance | 1L: operational resilience, vendor risk, legal control, data governance, privacy, platform engineering, treasury operations, customer operations, enterprise risk, control assurance, and board secretariat 2L: enterprise risk and recovery planning 3L: internal audit board risk committee | quarterly 2026-12-19 to 2027-02-02 | effective Residual risk: low Line: second_line | exit-control-table /officer/admin/op-readiness#operational-continuity-exit-governance 4fbeceed1299...9f1a09cb | Evidence supports effective design and operating posture. Owner: enterprise risk and recovery planning / due none | 2f2f6befd595...a3a4630a |
Crisis command, war-room, regulator/customer communications, recovery bridge, after-action, recurrence-monitoring, and evidence-custody packs Crisis command and communications governance / BCBS operational resilience incident management and business continuity testing / BCBS corporate governance board oversight / FSB Key Attributes crisis management and resolution planning / FFIEC business continuity crisis management communications / regulator, customer, staff, provider, board, recovery, after-action, and evidence-custody governance | 1L: enterprise crisis management team, operational resilience, legal control, regulatory operations, customer operations, vendor risk, security operations, control assurance, internal audit liaison, and board secretariat 2L: operational risk, legal control, regulatory operations, customer operations, and operational resilience 3L: internal audit board risk committee and audit committee | quarterly, after every material crisis event, and after every crisis simulation 2026-12-22 to 2027-02-05 | effective Residual risk: low Line: second_line | crisis-command-control-table /officer/admin/op-readiness#crisis-command-governance 91558653ccc0...0abb9f69 | Evidence supports effective design and operating posture. Owner: operational risk, legal control, regulatory operations, customer operations, and operational resilience / due none | b2b3a05625f5...95abc3ee |
Enterprise risk appetite statement, risk-limit, KRI, breach, exception, committee-challenge, tolerance-use, and evidence-custody packs Enterprise risk appetite and limit governance / FSB Principles for an Effective Risk Appetite Framework / BCBS corporate governance principles for banks / Basel Core Principles for effective banking supervision / OCC Corporate and Risk Governance / COSO ERM Integrating with Strategy and Performance / ISO 31000 risk management guidelines | 1L: board risk committee, enterprise risk, CRO, ALCO, conduct risk, technology risk, operational risk, risk data governance, and board secretariat 2L: enterprise risk, CRO office, risk data governance, and compliance assurance 3L: internal audit board risk committee and audit committee | monthly limit review, quarterly appetite dashboard, and annual board appetite approval 2026-12-25 to 2027-02-08 | effective Residual risk: low Line: second_line | risk-appetite-control-table /officer/admin/op-readiness#enterprise-risk-appetite-limit-governance 4da21427bbd9...6eaa502d | Evidence supports effective design and operating posture. Owner: enterprise risk, CRO office, risk data governance, and compliance assurance / due none | 8e36ec758b3d...3cd550bb |
Enterprise-wide scenario inventory, severe-but-plausible design, reverse stress, model and data lineage, capital-liquidity-profit-customer impact, management action, board challenge, and evidence-custody packs Enterprise stress testing governance / BCBS Stress testing principles / EBA Guidelines on institutions' stress testing / Federal Reserve SR 12-7 stress testing guidance / PRA SS31/15 ICAAP and SREP / ISO 31000 risk management guidelines | 1L: enterprise risk, CRO, capital planning, treasury risk, ALCO, risk analytics, model risk, operational resilience, conduct risk, climate risk, risk data governance, and board secretariat 2L: enterprise risk, model risk, capital planning, treasury risk, operational risk, conduct risk, climate risk, and risk data governance 3L: internal audit board risk committee, ALCO, capital committee, operational risk committee, and audit committee | quarterly enterprise stress test, monthly sensitivity monitoring, and annual reverse-stress board challenge 2026-12-28 to 2027-02-11 | effective Residual risk: low Line: second_line | enterprise-stress-control-table /officer/risk/stress#enterprise-stress-testing-governance 0001de18f269...05ad2c60 | Evidence supports effective design and operating posture. Owner: enterprise risk, model risk, capital planning, treasury risk, operational risk, conduct risk, climate risk, and risk data governance / due none | 152747c5b6c2...c64d011a |
Three-lines control assurance and board escalation Governance assurance / NIST CSF 2.0 Govern / IIA Three Lines Model / Basel corporate governance principles | 1L: risk and compliance assurance 2L: risk and compliance assurance 3L: internal audit audit and risk committee | quarterly 2026-12-31 to 2027-02-14 | effective Residual risk: low Line: second_line | control-assurance-table /officer/admin/op-readiness#control-assurance-reviews 2156fef73cca...14bf45a9 | Evidence supports effective design and operating posture. Owner: risk and compliance assurance / due none | 5466f1945510...31a869a2 |
Internal audit charter, independence, risk-based audit universe, annual plan, engagement, issue-validation, QAIP, external-assessment, audit committee, synthetic-action, and evidence-custody packs Governance assurance / IIA 2024 Global Internal Audit Standards / Basel Committee internal audit function in banks / OCC internal and external audit handbook / CBK Risk Management Guidelines and Risk Based Supervisory Framework | 1L: chief audit executive, board audit committee, internal audit operations, control assurance, enterprise risk, data governance, records manager, and board secretariat 2L: risk and compliance assurance 3L: internal audit audit and risk committee | quarterly 2027-01-03 to 2027-02-17 | effective Residual risk: low Line: second_line | internal-audit-control-table /officer/admin/op-readiness#internal-audit-governance 770479b6a11a...b7de513f | Evidence supports effective design and operating posture. Owner: risk and compliance assurance / due none | 613c12148870...0a6aaaa0 |
Board charter, reserved matters, fit-and-proper directors, composition, independence, committee, meeting, conflict, related-party, policy, evaluation, succession, disclosure, stakeholder, synthetic-action, and evidence-custody packs Governance assurance / Basel Committee Corporate governance principles for banks / OCC Corporate and Risk Governance / CBK Prudential Guideline on Corporate Governance / G20-OECD Principles of Corporate Governance | 1L: board chair, company secretary, board secretariat, nominations and governance committee, legal control, enterprise risk, compliance assurance, internal audit, records manager, and board committee chairs 2L: risk and compliance assurance 3L: internal audit audit and risk committee | quarterly 2027-01-06 to 2027-02-20 | effective Residual risk: low Line: second_line | corporate-board-control-table /officer/admin/op-readiness#corporate-board-governance b32e0277ab8c...242c4a07 | Evidence supports effective design and operating posture. Owner: risk and compliance assurance / due none | e4762307a003...804bc409 |
Board risk committee evidence pack and decision trail Governance assurance / NIST CSF 2.0 Govern / BCBS corporate governance principles / IIA Three Lines Model | 1L: board secretariat and enterprise risk 2L: risk and compliance assurance 3L: internal audit audit and risk committee | quarterly 2027-01-09 to 2027-02-23 | effective Residual risk: low Line: second_line | board-risk-committee-pack-table /officer/board-pack#board-risk-committee-pack 8862a4353246...6deb4b8d | Evidence supports effective design and operating posture. Owner: risk and compliance assurance / due none | 48c237f7b6d5...e2eb645a |
Enterprise remediation source-action, owner-queue, board-decision, independent-validation, recurrence-monitoring, and signed-minute evidence packs Enterprise remediation and board decision execution / BCBS corporate governance principles for banks / BCBS Principles for the Sound Management of Operational Risk / COSO Internal Control monitoring and deficiency remediation / IIA Three Lines Model / board decision execution, owner accountability, independent validation, issue closure, signed minutes, and evidence-custody governance | 1L: enterprise risk, control assurance, board secretariat, records manager, data governance, first-line owners, and internal audit liaison 2L: control assurance, enterprise risk, legal control, and board secretariat 3L: internal audit audit committee and board risk committee | monthly and after every material board decision 2027-01-12 to 2027-02-26 | effective Residual risk: low Line: second_line | enterprise-remediation-control-table /officer/admin/op-readiness#enterprise-remediation-governance 5d8a3ae164ab...38e96fa3 | Evidence supports effective design and operating posture. Owner: control assurance, enterprise risk, legal control, and board secretariat / due none | eff9ec46daf4...014cf774 |
Cyber resilience governance, asset exposure, privileged access, vulnerability, detection, incident, ransomware recovery, and evidence-custody packs Cybersecurity governance / NIST CSF 2.0 Govern-Identify-Protect-Detect-Respond-Recover / CIS Critical Security Controls v8.1 / ISO/IEC 27001:2022 ISMS / FFIEC cyber risk management and self-assessment guidance | 1L: security governance, security operations, identity platform, application security, platform reliability, vendor risk, privacy, and operational risk 2L: security governance risk and compliance 3L: internal audit risk and technology committee | monthly 2027-01-15 to 2027-03-01 | effective Residual risk: low Line: second_line | cyber-resilience-control-table /officer/admin/op-readiness#cyber-resilience-governance c7e2a6a69e1e...96732d66 | Evidence supports effective design and operating posture. Owner: security governance risk and compliance / due none | 07dd51dcf494...503fe2c3 |
Identity inventory, MFA, phishing-resistant authentication, least privilege, segregation-of-duties, access review, privileged event, service account, break-glass, and evidence-custody packs Cybersecurity governance / NIST CSF 2.0 PR.AA identity management, authentication, and access control / CIS Controls v8.1 account and access control management / FFIEC Architecture, Infrastructure, and Operations identity and privileged access governance | 1L: identity platform, security governance, security operations, application security, platform reliability, control assurance, and board secretariat 2L: security governance risk and compliance 3L: internal audit risk and technology committee | monthly 2027-01-18 to 2027-03-04 | effective Residual risk: low Line: second_line | identity-access-control-table /officer/admin/op-readiness#identity-access-governance 4d171c384c96...921af4a9 | Evidence supports effective design and operating posture. Owner: security governance risk and compliance / due none | fd7162d5f944...9abaeaf6 |
Cryptographic key and secrets custody governance Cybersecurity governance / NIST SP 800-57 key management / NIST SP 800-130 CKMS design / NIST SP 800-152 CKMS profile / FIPS 140-3 validated cryptographic modules / NIST CSF 2.0 data security / FFIEC AIO cryptographic operations / PCI DSS 4.0.1 key management | 1L: security governance, application security, platform reliability, payments security, identity platform, data governance, privacy office, control assurance, and board secretariat 2L: security governance risk and compliance 3L: internal audit risk and technology committee | monthly 2027-01-21 to 2027-03-07 | effective Residual risk: low Line: second_line | crypto-key-control-table /officer/admin/op-readiness#cryptographic-key-custody-governance 1fe8bd02a62b...c5c6b430 | Evidence supports effective design and operating posture. Owner: security governance risk and compliance / due none | e50e2e8b2847...555291c3 |
Governance, risk ownership, and policy evidence Cybersecurity governance / NIST CSF 2.0 Govern | 1L: security governance 2L: security governance risk and compliance 3L: internal audit risk and technology committee | monthly 2027-01-24 to 2027-03-10 | effective Residual risk: low Line: second_line | control-evidence-manifest-table /officer/admin/op-readiness#control-evidence-manifest 32d1764a69a2...aaae8e81 | Evidence supports effective design and operating posture. Owner: security governance risk and compliance / due none | 95d4cff55478...8c905038 |
Incident detection, response, and recovery visibility Cybersecurity governance / NIST CSF 2.0 Detect/Respond/Recover | 1L: security operations 2L: security governance risk and compliance 3L: internal audit risk and technology committee | monthly 2027-01-27 to 2027-03-13 | effective Residual risk: low Line: second_line | incident-recovery-link-table /officer/admin/op-readiness#operational-resilience-automation eb66e1a9835f...aaa695b9 | Evidence supports effective design and operating posture. Owner: security governance risk and compliance / due none | 5540bffe2f95...11a88efb |
Session-bound access and secret isolation Cybersecurity governance / NIST CSF 2.0 Protect | 1L: identity platform 2L: security governance risk and compliance 3L: internal audit risk and technology committee | monthly 2027-01-30 to 2027-03-16 | effective Residual risk: low Line: second_line | frontend-auth-hardening-ci /officer/admin/op-readiness#world-class-benchmark 890e0dff8bf2...851f37a0 | Evidence supports effective design and operating posture. Owner: security governance risk and compliance / due none | bf3132178b99...3e214f9e |
Customer outcome, vulnerable-customer, and fair-value monitoring Customer outcomes and conduct / CBK consumer protection / FCA Consumer Duty / World Bank financial consumer protection | 1L: customer dignity operations 2L: conduct risk and compliance 3L: internal audit customer and conduct committee | monthly 2027-02-02 to 2027-03-19 | effective Residual risk: low Line: second_line | conduct-outcomes-control-table /officer/dignity#conduct-outcomes-monitor 9794621ea8cf...6f3d0c89 | Evidence supports effective design and operating posture. Owner: conduct risk and compliance / due none | ca2be0405a3d...0e42a2c4 |
Complaint intake, fair handling, vulnerable-customer support, redress calculation, dispute escalation, root-cause remediation, recurrence monitoring, third-party accountability, synthetic-action, and evidence-custody packs Customer outcomes and conduct / World Bank financial consumer protection complaints handling and dispute resolution / FCA Consumer Duty consumer support and vulnerable-customer outcomes / CBK Prudential Guideline on Consumer Protection complaint procedures / G20-OECD financial consumer protection complaints handling and redress / complaint intake, fair handling, vulnerable-customer support, redress, dispute escalation, root-cause remediation, third-party accountability, and evidence-custody governance | 1L: customer dignity operations, conduct risk, customer remediation finance control, regulatory operations, legal control, control assurance, data governance, records manager, and board secretariat 2L: conduct risk and compliance 3L: internal audit customer and conduct committee | monthly 2027-02-05 to 2027-03-22 | effective Residual risk: low Line: second_line | customer-redress-control-table /officer/dignity#customer-outcomes-redress-governance 84f98f346b62...d559067e | Evidence supports effective design and operating posture. Owner: conduct risk and compliance / due none | 89751cfbe6bc...e42449e7 |
Accessible, plain-language, translated, assisted-channel, USSD, low-bandwidth, financial education, comprehension, defect remediation, and evidence-custody packs Inclusive customer access and capability governance / WCAG 2.2 accessibility / W3C cognitive accessibility / UN CRPD accessible information and communications / G20-OECD financial consumer protection / World Bank financial consumer protection / CGAP responsible digital credit / GSMA mobile money customer treatment / Kenya consumer protection and financial consumer protection | 1L: accessibility lead, product engineering, conduct risk, customer dignity operations, customer education, mobile channel operations, data governance, control assurance, and board secretariat 2L: conduct risk, accessibility lead, customer operations, privacy office, product governance, and technology risk 3L: internal audit customer and conduct committee, technology committee, and board risk committee | monthly, before material customer journey launch, and after every critical accessibility or assisted-channel defect 2027-02-08 to 2027-03-25 | effective Residual risk: low Line: second_line | inclusive-access-control-table /officer/dignity#inclusive-customer-access-governance 366a1e48a990...54130487 | Evidence supports effective design and operating posture. Owner: conduct risk, accessibility lead, customer operations, privacy office, product governance, and technology risk / due none | b41af06e5750...be4c8d25 |
No representative rows on read outage Live data trust / Situ fail-closed operating standard | 1L: product engineering 2L: data governance 3L: internal audit audit and risk committee | quarterly 2027-02-11 to 2027-03-28 | effective Residual risk: low Line: second_line | test_frontend_auth_hardening.py /officer/admin/op-readiness#world-class-benchmark aab17e90518e...67609973 | Evidence supports effective design and operating posture. Owner: data governance / due none | 0599814867db...3b141a3c |
Tamper-evident examiner and operator evidence Live data trust / Examiner-grade auditability | 1L: examiner platform 2L: data governance 3L: internal audit audit and risk committee | quarterly 2027-02-14 to 2027-03-31 | effective Residual risk: low Line: second_line | control-evidence-package-hash /officer/admin/op-readiness#control-evidence-manifest 107d025d42a6...d60ccb09 | Evidence supports effective design and operating posture. Owner: data governance / due none | 4b13ab804046...ca5434a9 |
Blocked action states for synthetic or unavailable data Live data trust / Customer harm prevention | 1L: customer operations 2L: data governance 3L: internal audit audit and risk committee | quarterly 2027-02-17 to 2027-04-03 | effective Residual risk: low Line: second_line | blocked-action-state-ci /officer/admin/op-readiness#world-class-benchmark ed0ab7b91b73...f090fc5f | Evidence supports effective design and operating posture. Owner: data governance / due none | beed7403a4a1...850d0b36 |
| Change | Service | Approvals | Evidence | Status | Hash |
|---|---|---|---|---|---|
Origination scorecard threshold refresh credit risk, model risk, and platform engineering / critical | underwriting decision engine | 4/4 approvals 96h lead / emergency no | risk ready / customer ready SoD ready / PIR ready | within | 191cbc2d84fd...b733d7de |
M-Pesa retry and reversal handling change payments engineering and treasury operations / critical | payment orchestration | 4/4 approvals 84h lead / emergency no | risk ready / customer ready SoD ready / PIR ready | within | 2dfce168001e...5d6930bf |
Customer notice template and complaint routing update customer operations, legal control, and conduct risk / material | communications and redress | 3/3 approvals 72h lead / emergency no | risk ready / customer ready SoD ready / PIR ready | within | a26986ed0f49...196f7d2b |
Ledger close reconciliation and suspense threshold change finance control and platform engineering / critical | GL and finance close | 4/4 approvals 96h lead / emergency no | risk ready / customer ready SoD ready / PIR ready | within | 7d13958b2a08...ad6e240c |
Security patch with same-day deployment and post-review security operations and platform engineering / critical | identity and API edge | 3/3 approvals 12h lead / emergency yes | risk ready / customer ready SoD ready / PIR ready | within | 880a734db99b...a885dc06 |
| Release | Gates | Controls | Status | Hash |
|---|---|---|---|---|
LMS operational governance release train 2026.07.1 / changes 3/3 | tests 100% / security pass performance pass / freeze yes | canary ready / flag ready rollback ready / monitoring ready | within | 6f02916d0174...520215cc |
Payments settlement resilience release train 2026.07.2 / changes 2/2 | tests 100% / security pass performance pass / freeze yes | canary ready / flag ready rollback ready / monitoring ready | within | 1dd648b973ed...0cda0759 |
API edge identity and partner protection release train 2026.07.3 / changes 1/1 | tests 100% / security pass performance pass / freeze yes | canary ready / flag ready rollback ready / monitoring ready | within | 80059d37afa1...97751b8a |
| Baseline | Drift | Controls | Status | Hash |
|---|---|---|---|---|
API edge, authentication, and rate-limit configuration api-edge-secure-baseline-2026.07 | 0/0 drift / 100% | backup yes / secrets rotated access reviewed / export ready | within | 96405410280c...8a8e2b3b |
Payment rail retry, reversal, and settlement configuration payments-baseline-2026.07 | 0/0 drift / 100% | backup yes / secrets rotated access reviewed / export ready | within | 0054c11f698c...f18af348 |
Credit policy, scorecard threshold, and affordability configuration underwriting-baseline-2026.07 | 0/0 drift / 100% | backup yes / secrets rotated access reviewed / export ready | within | 979ef8dd1c3c...636c9657 |
GL posting, suspense, close, and reconciliation configuration finance-close-baseline-2026.07 | 0/0 drift / 100% | backup yes / secrets rotated access reviewed / export ready | within | 8722b10956c1...00113f8e |
| Artifact | Repository | Integrity | Status | Hash |
|---|---|---|---|---|
situ-lms-web standalone build artifact platform engineering | apps/lms | SBOM yes / provenance yes signed yes / critical vulns 0 | within | 8ac62f25c9c7...370fcfe4 |
situ-read-api service image platform engineering and API owner | services/situ-read-api | SBOM yes / provenance yes signed yes / critical vulns 0 | within | 0a10a690a4d2...7f3f8e94 |
payment settlement worker image payments engineering | services/payment-settlement | SBOM yes / provenance yes signed yes / critical vulns 0 | within | 53a1e6ceb63d...66f25029 |
| Deployment | Health | Review | Status | Hash |
|---|---|---|---|---|
LMS officer and admin surfaces lms-2026-07-release / release manager and platform engineering | burn 4% / rollback 8m P0 0 / harm 0 | PIR ready / telemetry linked | within | 0240741992ef...0b8a836f |
Payment settlement and retry worker payments-2026-07-release / payments engineering and treasury operations | burn 5% / rollback 10m P0 0 / harm 0 | PIR ready / telemetry linked | within | acbdb330c1dd...3fd6dad1 |
API edge and identity service api-edge-2026-07-release / security operations and API platform owner | burn 3% / rollback 6m P0 0 / harm 0 | PIR ready / telemetry linked | within | fd805e8149ac...a54ab3f1 |
| Domain | Manifest | Evidence | Status | Hash |
|---|---|---|---|---|
Change intake, risk assessment, approvals, and segregation of duties approval / release management, enterprise risk, and control assurance | 4/4 mapped | Production changes carry risk tier, business justification, customer/data impact assessment, approvals, SoD, lead time, and PIR evidence. coverage 100% / findings 0 | within | 685c912985f5...397ba452 |
Release gate, testing, canary, feature flag, monitoring, and rollback governance release / release manager, platform engineering, and SRE | 4/4 mapped | Release trains have linked changes, test pass evidence, security and performance gates, canary, feature flags, rollback, monitoring, and freeze compliance. coverage 100% / findings 0 | within | 8dd68ebe43c6...0b09645a |
Security-focused configuration baseline and drift governance configuration / security operations, platform engineering, and service owners | 4/4 mapped | Critical assets have approved baselines, zero drift, secure configuration score, backups, secret rotation, access review, and evidence export. coverage 100% / findings 0 | within | 824e02c0f405...128ba996 |
Secure software supply-chain, SBOM, provenance, vulnerability, license, signature, and reproducible build governance supply_chain / security engineering, platform engineering, and procurement risk | 4/4 mapped | Build artifacts have SBOMs, provenance, dependency scan, license review, artifact signatures, reproducibility, and zero critical vulnerabilities. coverage 100% / findings 0 | within | bcc86ee9acb5...2709c2dd |
Post-release health, error-budget, rollback, incident, customer-harm, and remediation governance deployment / SRE, customer operations, release management, and enterprise remediation | 4/4 mapped | Deployments have release health telemetry, rollback time, error-budget burn, customer-harm tickets, P0 incident counters, post-release review, and remediation links. coverage 100% / findings 0 | within | 4ee4c52f9fa7...d16e3d9c |
| Control | Metric | Current | Limit | Status | Hash |
|---|---|---|---|---|---|
Change intake, risk assessment, approval, and segregation readiness Critical change governance gaps require Technology Committee and Board Risk Committee escalation. | Production changes with justification, risk/customer/data review, approvals, lead time, SoD, and post-implementation review | 100% | 100% | within | ed31494e1aed...3854fbf5 |
Release gate, testing, canary, feature flag, rollback, and monitoring readiness Release gate failures are escalated through release management and operational risk. | Release trains with linked approved changes, test pass, security/performance gates, rollback, monitoring, and freeze compliance | 100% | 100% | within | 86d5ccc0877d...64ab71b2 |
Configuration baseline and drift control Configuration drift on critical services is escalated to security and technology governance. | Critical assets with approved secure baselines, zero drift, backups, secret rotation, access review, and evidence export | 100% | 100% | within | 4b3fd6c73231...f5bbb8b2 |
Software supply-chain integrity and vulnerability gate Supply-chain gate failures require security and third-party risk escalation. | Artifacts with SBOM, provenance, dependency scan, license review, signature, reproducibility, and zero critical vulnerabilities | 100% | 100% | within | e7fda91b22c7...690dc3e1 |
Deployment health, rollback, incident, and customer-harm control Customer-harming deployment issues require conduct, crisis, and board reporting. | Deployments within error-budget, rollback-time, P0 incident, customer-harm, telemetry, and post-release review limits | 100% | 100% | within | 758db2978a8f...9d9001e9 |
Emergency change discipline Emergency-change spikes enter operational risk and technology committee reports. | Emergency production changes as a share of all production changes | 20% | 25% | within | 2bc0bae8d7ce...c0bc4e16 |
Change-release domain assurance Domain assurance gaps block technology-risk attestation. | Change, release, configuration, supply-chain, deployment, and custody domains with full coverage and zero findings | 100% | 100% | within | 6ba142b9fd02...fad34029 |
Change-release manifest coverage Manifest gaps block release evidence package sign-off. | Change-release artifacts with enterprise control manifest mappings | 100% | 100% | within | 314c6fbaa7f2...9b368cd8 |
Change-release evidence custody and package integrity Custody gaps block examiner-ready change package export. | Change-release evidence objects with SHA-256 custody hashes | 100% | 100% | within | 340ccd0dbc44...4bc583cd |
| Action | Status | Evidence | Owner | Deadline | Hash |
|---|---|---|---|---|---|
| No change, release, or configuration action packs are required for the current evidence set. | |||||
Key lifecycle, FIPS module boundary, custodian attestation, dual control, rotation, escrow, destruction, incident, recovery, manifest, and custody evidence for sensitive financial data and payment operations.
| Key | Boundary | Cryptoperiod | Custody controls | Status | Hash |
|---|---|---|---|---|---|
Borrower PII field encryption key data encryption key / data platform security borrower profile, KYC, and credit bureau stores | cloud KMS HSM-backed key ring FIPS-140-3-L3-KMS-2026-PII AES-256-GCM / production | 180/365d / rotate in 42d | dual yes / escrow yes / logs yes access yes / residency yes / incident yes | within | 7ac259ceec95...6bc2d317 |
Payment tokenization master key tokenization key encryption key / payments security wallet, card, and payment rail tokenization | payment HSM cluster FIPS-140-3-L3-PAY-HSM-2026-02 AES-256-KW / production | 120/180d / rotate in 28d | dual yes / escrow yes / logs yes access yes / residency yes / incident yes | within | 93b1630acff6...8a04106a |
Open-finance consent token signing key asymmetric signing key / identity platform open-finance consent and API gateway | API gateway KMS signing boundary FIPS-140-3-L2-API-KMS-2026-01 ECDSA P-256 / production | 90/180d / rotate in 21d | dual yes / escrow yes / logs yes access yes / residency yes / incident yes | within | 4cbbcb34a0f9...8dd25ee8 |
Examiner evidence custody signing key evidence package signing key / control assurance board, audit, and supervisory evidence manifests | offline signing enclave FIPS-140-3-L2-EVIDENCE-2026-01 Ed25519 / production | 365/730d / rotate in 96d | dual yes / escrow yes / logs yes access yes / residency yes / incident yes | within | 56c150aa021b...82393bcb |
Immutable backup archive encryption key backup encryption key / platform reliability immutable backup, cold archive, and restore drills | backup KMS split-region escrow FIPS-140-3-L2-BACKUP-KMS-2026-01 AES-256-GCM / production | 365/730d / rotate in 120d | dual yes / escrow yes / logs yes access yes / residency yes / incident yes | within | 2f2f8f26a023...44b59d02 |
Partner webhook HMAC secret ring message authentication secret / API platform partner webhooks and event delivery | API platform secrets manager FIPS-140-3-L2-SECRETS-2026-API HMAC-SHA-256 / production | 90/180d / rotate in 18d | dual yes / escrow yes / logs yes access yes / residency yes / incident yes | within | ead43e7a1dfb...ebdd2011 |
| Custodian | Attestation | Review | Status |
|---|---|---|---|
Data platform security lead primary data encryption key custodian | CKC-ACK-2026-001 training yes / dual yes / SoD yes | 18/90d break-glass yes / owner CISO | within |
Payments security lead payment HSM key ceremony custodian | CKC-ACK-2026-002 training yes / dual yes / SoD yes | 14/90d break-glass yes / owner Head of payments risk | within |
Identity platform lead signing and token key custodian | CKC-ACK-2026-003 training yes / dual yes / SoD yes | 21/90d break-glass yes / owner Technology risk officer | within |
Control assurance evidence owner offline evidence-signing custodian | CKC-ACK-2026-004 training yes / dual yes / SoD yes | 25/90d break-glass yes / owner Board secretariat | within |
| Event | Key | Evidence | Status |
|---|---|---|---|
KEY-ROT-2026-Q2-PAY-001 rotation / payments security | payment-tokenization-master-key | 21/90d / dual yes / ticket yes export yes / review yes / customer yes | within |
KEY-CREATE-2026-API-014 creation / identity platform | open-finance-token-signing-key | 34/180d / dual yes / ticket yes export yes / review yes / customer yes | within |
KEY-REC-2026-EVIDENCE-003 recovery_test / control assurance | evidence-custody-signing-key | 16/180d / dual yes / ticket yes export yes / review yes / customer yes | within |
KEY-DESTROY-2026-WH-009 destruction / API platform | webhook-hmac-secret-ring | 12/90d / dual yes / ticket yes export yes / review yes / customer yes | within |
| Control | Metric | Observed | Expectation | Status | Action |
|---|---|---|---|---|---|
| Cryptographic key inventory, ownership, classification, and approved algorithms | Key assets with complete owner, class, system, environment, algorithm, module boundary, and custody evidence | 100.0% / 100.0% | Critical cryptographic material should be inventoried, classified, owned, and constrained to approved algorithms and use contexts. | within | Register missing keys, assign owners, document use limits, and attach module and custody evidence. 45b359d2cdf1...ae951db7 |
| FIPS validated cryptographic module boundary | Critical keys linked to FIPS 140-3 module validation or approved compensating evidence | 100.0% / 100.0% | Cryptographic operations protecting sensitive financial data should run in approved and documented cryptographic module boundaries. | within | Attach module validation references or approved compensating controls before production use. c82ea6289675...7903387b |
| Custodian attestation, dual control, separation of duties, and break-glass readiness | Custodians with current acknowledgement, training, dual-control role, access review, break-glass, and segregation evidence | 100.0% / 100.0% | Key custodians should understand duties, operate under dual control, and not bypass separation-of-duties or emergency-access controls. | within | Refresh custodian acknowledgements, training, access reviews, and break-glass evidence. 27db6c02b0d1...d6a53dd6 |
| Dual-control key operations | Critical keys with dual-control generation, activation, escrow, rotation, or destruction controls | 100.0% / 100.0% | High-impact key operations should require accountable two-person or equivalent dual-control approval. | within | Disable single-custodian key ceremonies or privileged changes until dual-control evidence is current. 0617d7630bc6...adc8c728 |
| Cryptoperiod and rotation readiness | Critical keys inside cryptoperiod with automated rotation before expiry | 100.0% / 100.0% | Keys should be rotated before cryptoperiod expiry and before unmanaged exposure creates customer or operational risk. | within | Rotate overdue keys, reconcile dependent services, and attach post-rotation evidence. e9da5f605a5d...b675d43a |
| Secure storage, escrow, and recovery testing | Critical keys with backup escrow, recovery test, and incident playbook evidence | 100.0% / 100.0% | Critical cryptographic services should survive key loss, provider outage, and recovery events without unmanaged data loss or customer harm. | within | Refresh escrow, recovery tests, incident playbooks, and customer-impact review. 5f1171ab2009...0b3290d3 |
| Least-privilege access review and key-use logging | Critical keys with access reviews and usage logging active | 100.0% / 100.0% | Key use and administration should be logged, monitored, and restricted to least-privilege access paths. | within | Review access, revoke stale paths, enable usage logs, and preserve evidence exports. 6ef0fe224adb...802f80c6 |
| Key lifecycle event evidence integrity | Creation, rotation, revocation, destruction, recovery, and incident events with dual approval, ticket, export, and review evidence | 100.0% / 100.0% | Key lifecycle events should be auditable, approved, linked to tickets, exported, and reviewed for customer impact. | within | Attach missing event approvals, tickets, evidence exports, post-event reviews, and customer-impact reviews. 1bb24694953f...9f10b4fe |
| Enterprise manifest and domain-control coverage | Cryptographic key controls mapped to enterprise evidence manifest and source controls | 100.0% / 100.0% | Cryptographic controls should be traceable to cyber, identity, privacy, payments, open finance, resilience, change, assurance, and board evidence. | within | Map cryptographic controls to manifest rows, source routes, owners, export packages, and board routes. f8ec6eb89ab4...aadb436f |
| Cryptographic evidence custody and reproducibility | Key, custodian, event, control, action, and manifest evidence with SHA-256 custody hashes | 100.0% / 100.0% | Cryptographic key governance should be reproducible for internal audit, board, and supervisory review. | within | Regenerate custody hashes and export package evidence before formal review. 013931073627...3929acbb |
| Trigger | Status | Evidence | Owner | Action | Deadline |
|---|---|---|---|---|---|
| No cryptographic key inventory, FIPS boundary, custodian, rotation, event, manifest, or custody action packs are open. | |||||
| Critical function | Fallback / export | RTO / RPO | Notice / harm | Status | Hash |
|---|---|---|---|---|---|
Digital origination and credit decisioning chief credit officer and product engineering / loan-origination | manual committee queue with frozen strategy version and cached bureau evidence /officer/admin/op-readiness#operational-continuity-exit-governance | 4h / 6h tolerance RPO 5m / tested 20d ago | CBK operational incident and material outsourcing notice pack responsible-lending-affordability-governance-pack | within | af5a3b98d90a...6dff69e4 |
Loan servicing and repayment allocation servicing operations and finance control / loan-servicing | servicing continuity queue with payment suspense reconciliation and customer notice hold /officer/loans#servicing-export | 3h / 4h tolerance RPO 5m / tested 24d ago | CBK operational incident and customer harm update conduct-outcomes-monitoring | within | 4b934ecdddd5...29fd319d |
M-Pesa, bank, and wallet settlement treasury operations and payments engineering / payment-settlement | rail switch, disbursement throttle, suspense ledger, and manual treasury release /officer/treasury/recon#payment-export | 2h / 3h tolerance RPO 2m / tested 18d ago | NPS/CBK payment incident route and customer redress pack payment-error-resolution-governance-pack | within | 056cdfa3b889...aa264cb6 |
Collections, forbearance, and repossession controls collections operations and conduct risk / collections | hardship-first queue freeze, field action hold, and complaints triage desk /officer/collections#exit-export | 6h / 8h tolerance RPO 15m / tested 27d ago | CBK conduct and customer redress update collections-forbearance-governance-pack | within | fc2021e8d148...ed3dd5f0 |
Regulatory reporting and examiner evidence regulatory operations and data governance / regulatory-reporting | static signed regulatory pack with BCBS 239 lineage and custody hashes /officer/admin/reports#supervisory-export | 8h / 12h tolerance RPO 30m / tested 21d ago | supervisory response and regulatory commitments pack records-data-lifecycle-governance-pack | within | 93363bc7434b...7cdbb00d |
Customer notices, complaints, and redress communications customer operations, legal control, and compliance / customer-communications | multi-channel notice switch with approved scripts and acknowledgement tracking /officer/dignity#communications-export | 4h / 6h tolerance RPO 15m / tested 22d ago | customer harm and conduct outcome escalation customer-outcomes-redress-governance-pack | within | 08a2e0953ca0...a1ba2f6e |
| Provider | Rights | Concentration | Status | Hash |
|---|---|---|---|---|
M-Pesa Daraja disbursement, collection, reversal, and wallet settlement APIs | terminate 30d / return 2d step-in yes / alternate yes | 32% / 45% | within | 8ac39c44354c...34f8995f |
Credit bureau adapters Metropol and TransUnion credit-file pull and dispute routes | terminate 45d / return 5d step-in yes / alternate yes | 28% / 40% | within | cd1728809c33...8200048a |
Cloud platform and object storage compute, storage, key custody, backup, and evidence archive | terminate 60d / return 3d step-in yes / alternate yes | 38% / 45% | within | f05a68a99156...77224a74 |
Customer communications providers SMS, WhatsApp, email, and in-app notification delivery | terminate 30d / return 1d step-in yes / alternate yes | 25% / 40% | within | 36271847e566...07100f6b |
Identity and KYC verification providers identity verification, sanctions screening, and customer onboarding controls | terminate 45d / return 5d step-in yes / alternate yes | 30% / 40% | within | 543b136b3ad1...70dca151 |
Ledger and report generation stack GL posting, trial balance, close, statutory evidence, and board packs | terminate 60d / return 3d step-in yes / alternate yes | 34% / 45% | within | c0d6298e8ba7...ca633f91 |
| Dataset | Export | Integrity | Status | Hash |
|---|---|---|---|---|
Loan book, schedules, arrears, and repayment allocation servicing operations and finance control | CSV + JSON schema + hash manifest loan-book-exit-v3 / age 8h | enc yes / hash yes lineage yes / consent yes | within | 13ad62b6460d...da5a38f5 |
Customer profile, consent, privacy, complaints, and redress records data protection officer and customer operations | JSONL + field-level consent boundary manifest customer-consent-exit-v2 / age 6h | enc yes / hash yes lineage yes / consent yes | within | 216b8dcff443...796ece16 |
Payment transactions, reversals, suspense, and settlement reconciliation treasury operations and payment control | ISO-like payment event CSV + reconciliation hashes payment-settlement-exit-v4 / age 2h | enc yes / hash yes lineage yes / consent yes | within | c7496c23b893...1d120c55 |
Collateral registry, valuation evidence, custody chain, and release conditions collateral operations and legal control | PDF/A evidence bundle + JSON custody index collateral-custody-exit-v2 / age 10h | enc yes / hash yes lineage yes / consent yes | within | 56b4c33e56f2...b2c4a95a |
Regulatory returns, board packs, risk data, and control assurance evidence regulatory operations and board secretariat | signed XLSX + PDF + JSON custody manifest supervisory-evidence-exit-v5 / age 9h | enc yes / hash yes lineage yes / consent yes | within | 8088e70ac1e4...b507e214 |
| Transition | Target | Readiness | Status | Hash |
|---|---|---|---|---|
Switch collections and disbursements away from a degraded primary rail payments engineering and treasury operations | bank file rail, suspense ledger, and throttled wallet release M-Pesa Daraja | 17d / 100% pass rollback yes / authority yes | within | 1cc7be2bbeab...77a73e74 |
Switch bureau pulls and dispute evidence to alternate bureau path credit risk and integrations | alternate CRB adapter plus manual affordability evidence queue primary bureau adapter | 26d / 100% pass rollback yes / authority yes | within | c0cae4373b8d...e54d13a2 |
Restore critical services and evidence archive in alternate cloud region platform engineering and security operations | alternate region with restored keys, storage, queues, and evidence manifest primary compute and object storage region | 19d / 100% pass rollback yes / authority yes | within | 0cb9772975bf...c8524521 |
Move customer notices to alternate channel provider with approved scripts customer operations and legal control | alternate SMS, WhatsApp, email, and in-app notice tree primary SMS and WhatsApp provider | 28d / 100% pass rollback yes / authority yes | within | 12b8342fe9fd...89dbd8f7 |
Pause new originations and preserve servicing continuity during solvent wind-down enterprise risk, credit, servicing, and board secretariat | origination stop, borrower notice, servicing-only mode, and board minute pack credit decisioning and origination channels | 23d / 100% pass rollback yes / authority yes | within | 23fc24675437...08c983b5 |
| Wind-down module | Runway | Notices | Status | Hash |
|---|---|---|---|---|
New origination stop and approved product freeze credit policy, product governance, and board secretariat / BRC-RRP-2026-06-01 | KES 0m 90d liquidity / 18m servicing | customer ready / regulator ready redress ready | within | 083cd6f62d3f...786679ae |
Servicing-only mode for active borrowers servicing operations and customer operations / BRC-RRP-2026-06-02 | KES 7800m 92d liquidity / 18m servicing | customer ready / regulator ready redress ready | within | 1a09d41fb9a9...95968a43 |
Collateral custody release, transfer, and customer protection collateral operations and legal control / BRC-RRP-2026-06-03 | KES 3600m 85d liquidity / 18m servicing | customer ready / regulator ready redress ready | within | ff0d074c210d...ed8cf93e |
Supervisory reporting, audit file, and evidence custody continuity regulatory operations, audit liaison, and data governance / BRC-RRP-2026-06-04 | KES 0m 95d liquidity / 18m servicing | customer ready / regulator ready redress ready | within | 4818e764fba6...13114a4d |
| Domain | Manifest | Evidence | Status | Hash |
|---|---|---|---|---|
Critical function mapping, impact tolerance, and exit test evidence critical_function / operational resilience and enterprise risk | 4/4 mapped | Critical functions have named owners, tolerances, fallback modes, exit tests, customer harm controls, and regulator routes. coverage 100% / findings 0 | within | 6b82cfdcfc5a...2460c2af |
Provider exit, step-in, audit, data-return, escrow, and concentration controls provider_exit / vendor risk, legal control, and technology | 4/4 mapped | Critical providers have contractual exit rights, step-in routes, audit rights, data return, escrow, alternate providers, and concentration limits. coverage 100% / findings 0 | within | cc3548f635d5...9da28825 |
Data portability, lineage, encryption, consent boundary, and checksum custody data_portability / data governance, privacy, and platform engineering | 4/4 mapped | Exit datasets have open export formats, schema versions, freshness limits, encryption, checksums, lineage, and consent boundaries. coverage 100% / findings 0 | within | e61eee1a689d...2dd0798b |
Transition runbook rehearsal, rollback, staffing, authority, and communication readiness transition / operational resilience and crisis management team | 4/4 mapped | Provider switches and wind-down transitions are rehearsed within tolerance, pass dry runs, and carry rollback, staffing, authority, and customer communication evidence. coverage 100% / findings 0 | within | 9b043d5e7b29...c4a75065 |
Solvent wind-down, servicing continuity, customer redress, regulator notice, and board minutes wind_down / enterprise risk, CFO, legal control, and board secretariat | 4/4 mapped | Wind-down modules carry runway, servicing continuity, customer/regulator notice, complaints and redress, portfolio coverage, and board minute evidence. coverage 100% / findings 0 | within | b49c701d0fb1...980d7d26 |
| Control | Metric | Current | Limit | Status | Hash |
|---|---|---|---|---|---|
Critical function continuity and exit test coverage Critical function exit gaps block operational continuity attestation. | Critical functions with mapped exit route, fallback mode, tolerance fit, customer harm control, and regulator route | 100% | 100% | within | d17bf2092fe9...c6a847e5 |
Exit test and portability rehearsal currency Stale exit testing is escalated to Technology Committee and Board Risk Committee. | Maximum age of critical function exit test evidence | 27d | 180d | within | f885a48a3c3b...add91566 |
Provider exit contractual readiness and substitutability Material provider exit gaps require Vendor Risk Committee and Board Risk Committee escalation. | Critical providers with termination, data-return, step-in, audit, escrow, alternate provider, subprocessor, and concentration evidence | 100% | 100% | within | 1a0673c3f718...2f513213 |
Data portability, integrity, lineage, and privacy boundary readiness Data portability gaps block provider exit and wind-down attestation. | Datasets with fresh exports, open format, encryption, checksums, lineage, and consent boundary controls | 100% | 100% | within | ee060ca3ff35...8a0cbc70 |
Transition runbook rehearsal and rollback readiness Transition rehearsal failures enter crisis management and operational resilience action logs. | Transition runbooks with current rehearsal, pass rate, rollback, staffing, authority, and communication evidence | 100% | 100% | within | 01db3d388ec1...f932e9ce |
Solvent wind-down and servicing continuity readiness Wind-down gaps block recovery and resolution plan approval. | Wind-down modules with liquidity runway, servicing continuity, notices, redress, and board evidence | 100% | 100% | within | 2fecc0b78afe...a2dd758b |
Wind-down liquidity and servicing runway Runway shortfalls require CFO, ALCO, and Board Risk Committee action. | Minimum liquidity runway days across wind-down modules | 85d | 60d | within | 63549fb19da6...0c318977 |
Servicing continuity runway Servicing runway shortfalls require customer harm and board escalation. | Minimum servicing continuity months across wind-down modules | 18 | 12 | within | 91c3f356f030...d0ed34eb |
Exit governance manifest coverage Manifest gaps block exit-portability package sign-off. | Exit artifacts with complete enterprise control manifest mappings | 100% | 100% | within | 949a5f2414ed...aaa7c9fd |
Customer and regulator communication readiness Communication gaps require legal, compliance, and board secretary remediation. | Critical functions, transition runbooks, and wind-down modules with customer/regulator notice evidence | 100% | 100% | within | 4630427fe41d...5829a710 |
Exit domain control assurance Exit domain assurance gaps are escalated to Audit Committee and Board Risk Committee. | Exit domains with full evidence coverage and zero open findings | 100% | 100% | within | 67a57186cf49...f465308f |
Exit evidence custody and package integrity Custody gaps block examiner-ready exit package export. | Exit evidence objects with SHA-256 custody hashes | 100% | 100% | within | 4390f3e3a095...ee94d5b9 |
| Action | Status | Evidence | Owner | Deadline | Hash |
|---|---|---|---|---|---|
| No operational continuity, exit, or portability action packs are required for the current evidence set. | |||||
| Event | Triggers | Command | Operations | Status | Hash |
|---|---|---|---|---|---|
Payment rail disruption with pending borrower disbursements payments operations and treasury control / high | 3/3 mapped | commander yes / war room yes decision log open / declared 14m | treasury-disbursement, loan-servicing-ledger INC-2038 / op risk linked | within | c0d7cbee2471...45df5d88 |
Privileged identity compromise with critical vulnerability exposure security operations and identity platform / critical | 3/3 mapped | commander yes / war room yes decision log open / declared 11m | officer-queue-triage, loan-servicing-ledger CYB-2026-07-critical-vuln-closure / op risk linked | within | 18700b8c3dcd...752af74b |
Liquidity stress and wallet safeguarding run scenario treasury risk, ALCO, and finance control / critical | 3/3 mapped | commander yes / war room yes decision log open / declared 18m | treasury-disbursement, loan-servicing-ledger ALCO-2026-07-liquidity-watch / op risk linked | within | 4305bfa68135...b8ff79d9 |
Supervisory request during crisis management and ad hoc risk reporting regulatory operations and data governance / high | 3/3 mapped | commander yes / war room yes decision log open / declared 20m | officer-queue-triage REG-2026-07-response-pack / op risk linked | within | 5adc815a4abf...820d9b31 |
Customer harm, pricing, hardship, and redress crisis conduct risk and customer dignity operations / high | 3/3 mapped | commander yes / war room yes decision log open / declared 22m | collections-promises, credit-decisioning DIGNITY-2026-07-redress-review / op risk linked | within | 3c6817fe1137...73f0b0ca |
| Command cell | Events | Coverage | Authority | Status | Hash |
|---|---|---|---|---|---|
Enterprise crisis management team chief operating officer / alternate chief risk officer | 3/3 mapped single accountable incident commander and severity declaration authority | 24h / 15m SLA drill current | runbook ready / contact tree ready authority ready | within | 3d7954bb397e...c2513ddf |
Operations incident command cell platform operations lead / alternate site reliability manager | 2/2 mapped critical operation continuity, fallback mode, and recovery bridge execution | 24h / 10m SLA drill current | runbook ready / contact tree ready authority ready | within | 6c0fb12fa317...0c652df2 |
Legal, regulatory, and board communications cell general counsel / alternate board secretary | 3/3 mapped single-message approval, regulator notice, legal privilege, and board decision trail | 24h / 20m SLA drill current | runbook ready / contact tree ready authority ready | within | 650dadeac456...fd58e1ab |
Customer harm, hardship, and conduct cell chief customer officer / alternate conduct risk lead | 2/2 mapped customer notice, hardship routing, vulnerable-customer review, and redress decisioning | 18h / 20m SLA drill current | runbook ready / contact tree ready authority ready | within | 68f3365849f8...3b94f967 |
Provider, cyber, and security liaison cell security governance lead / alternate vendor risk lead | 2/2 mapped third-party escalation, cyber containment, provider exit, and regulator evidence support | 24h / 15m SLA drill current | runbook ready / contact tree ready authority ready | within | 985079c931e4...990d9551 |
| Communication | Events | Approvals | Notice / receipt | Status | Hash |
|---|---|---|---|---|---|
Board Risk Committee emergency decision pack board / board secretary | 3/3 mapped | script approved / legal ready privacy ready / single source yes | regulator ready / customer ready 30m window / ack tracked | within | 40d05d541dec...259de44e |
CBK, ODPC, FRC, and payment-system regulator notice route regulator / regulatory operations | 3/3 mapped | script approved / legal ready privacy ready / single source yes | regulator ready / customer ready 45m window / ack tracked | within | b0fae3ba650d...6396b7a6 |
SMS, push, branch script, and complaint escalation notice customer / customer operations and conduct risk | 2/2 mapped | script approved / legal ready privacy ready / single source yes | regulator ready / customer ready 60m window / ack tracked | within | 5b9ab454724f...d182d89a |
Officer, branch, collections, teller, and contact-center playbook brief staff / people operations and branch operations | 3/3 mapped | script approved / legal ready privacy ready / single source yes | regulator ready / customer ready 45m window / ack tracked | within | 42c134a075c2...ae11d797 |
Critical provider escalation, exit, step-in, and data-return notice provider / vendor risk and security operations | 2/2 mapped | script approved / legal ready privacy ready / single source yes | regulator ready / customer ready 30m window / ack tracked | within | cbd1cb1fed30...c58711bc |
| Recovery bridge | Evidence | Status | Hash |
|---|---|---|---|
provider-failover-liquidity-protection payment-rail-disruption-crisis / treasury-disbursement | fallback ready / provider exit ready harm reviewed / closure ready | within | 5e7ecb5f3f4c...2b56cb87 |
provider-failover-liquidity-protection cyber-identity-incident-crisis / officer-queue-triage | fallback ready / provider exit ready harm reviewed / closure ready | within | 2bdfc665ac9d...b34cdac2 |
contingency-funding-drawdown liquidity-run-crisis / treasury-disbursement | fallback ready / provider exit ready harm reviewed / closure ready | within | 3c64bd23e12b...90d46326 |
board-and-regulator-communications supervisory-data-request-crisis / officer-queue-triage | fallback ready / provider exit ready harm reviewed / closure ready | within | f536a40fafa4...667d5863 |
customer-communication-and-hardship-controls conduct-harm-redress-crisis / collections-promises | fallback ready / provider exit ready harm reviewed / closure ready | within | 48fb60888438...ecaf4cce |
| After-action | Closure | Status | Hash |
|---|---|---|---|
payment-rail-disruption-crisis-postmortem-2026-07 payment-rail-disruption-crisis / BRC-2026-07-crisis-lessons | root cause ready / lessons linked harm closed / recurrence ready | within | a6b20086edc3...9eda5dd9 |
cyber-identity-incident-crisis-postmortem-2026-07 cyber-identity-incident-crisis / BRC-2026-07-crisis-lessons | root cause ready / lessons linked harm closed / recurrence ready | within | c77511d49b8b...d6441994 |
liquidity-run-crisis-postmortem-2026-07 liquidity-run-crisis / BRC-2026-07-crisis-lessons | root cause ready / lessons linked harm closed / recurrence ready | within | a8ebb63855e0...d7721310 |
supervisory-data-request-crisis-postmortem-2026-07 supervisory-data-request-crisis / BRC-2026-07-crisis-lessons | root cause ready / lessons linked harm closed / recurrence ready | within | 6b00a390138e...5e077d71 |
conduct-harm-redress-crisis-postmortem-2026-07 conduct-harm-redress-crisis / BRC-2026-07-crisis-lessons | root cause ready / lessons linked harm closed / recurrence ready | within | 2d68f3cfc6f8...e0f74630 |
| Domain control | Manifest | Evidence | Status | Hash |
|---|---|---|---|---|
Crisis trigger severity, declaration, and operational-risk event control trigger / enterprise crisis management team and operational risk | 3/3 mapped | Event records prove trigger controls, critical operations, severity, declaration timing, incident IDs, operational-risk event links, and decision log custody. coverage 100% / findings 0 | within | 3bcf81b25ac1...f34c6a03 |
War-room command authority, shift coverage, and contact tree control command / chief operating officer, chief risk officer, and incident commander | 3/3 mapped | Command cells prove lead, alternate, shift coverage, escalation SLA, runbook, contact tree, and decision authority evidence. coverage 100% / findings 0 | within | 75d53a6efb42...1616da57 |
Single-message regulator, customer, staff, provider, and board communications control communications / general counsel, regulatory operations, customer operations, and board secretary | 4/4 mapped | Communication records prove approved scripts, legal and privacy review, notice readiness, translation, acknowledgement tracking, and single-message source control. coverage 100% / findings 0 | within | 81bbdd179734...644b55f3 |
Recovery option, impact tolerance, provider exit, customer harm, and remediation bridge control recovery / operational resilience, recovery planning, vendor risk, and control assurance | 4/4 mapped | Recovery bridge records link crisis events to recovery options, impact tolerances, fallback modes, provider exit readiness, customer harm review, accepted recovery decisions, and closure evidence. coverage 100% / findings 0 | within | f06b69f0cced...798e347f |
After-action, lessons learned, recurrence monitoring, internal-audit reliance, and custody control after_action / control assurance, internal audit liaison, and records manager | 15/15 mapped | After-action records prove root cause, customer-harm closure, remediation ownership, recurrence monitoring, internal-audit readiness, board minute reference, manifest mapping, and package hash custody. coverage 100% / findings 0 | within | 6431cab02a6f...86ce5342 |
| Control | Metric | Current | Limit | Status | Hash |
|---|---|---|---|---|---|
Crisis event declaration and command readiness Undeclared or uncommanded material events require same-cycle board escalation. | Events with mapped triggers, incident IDs, critical operations, declaration SLA, commander, war room, decision log, and operational-risk event linkage | 100% | 100% | within | 932bd432f289...79a860cf |
Crisis command cell coverage Command-cell gaps require executive crisis management escalation. | Command cells with mapped events, leads, alternates, shift coverage, escalation SLA, runbooks, contact trees, decision authority, and drills | 100% | 100% | within | a8e26ffb7031...ab8e3915 |
Crisis communications approval control Unreviewed crisis communications require legal and board secretary escalation. | Communications with mapped events, approved scripts, legal and privacy review, notice readiness, single-message source, translation, acknowledgement tracking, and send-window discipline | 100% | 100% | within | f861ec46f77a...bc0a9d98 |
Regulator, customer, and board communication readiness Gaps in board, regulator, or customer communication readiness block crisis closure. | Board, regulator, and customer communications ready for material crisis events | 100% | 100% | within | 85e2d2c8ba87...02fd939f |
Crisis recovery bridge readiness Events without recovery bridges require Board Risk Committee escalation. | Events linked to recovery options, impact tolerances, remediation actions, fallback mode, provider exit, customer-harm review, accepted decisions, and closure evidence | 100% | 100% | within | 671d3a1c0df4...68df9b7e |
After-action and recurrence control Unvalidated crisis closure requires audit and board risk committee review. | Events with postmortems, root cause, lessons, customer-harm closure, remediation owners, recurrence monitoring, internal audit readiness, and board minute refs | 100% | 100% | within | 3925b36b5a50...c29c88a7 |
Material event declaration SLA Declaration SLA breaches require crisis management and board risk committee review. | Maximum detection-to-declaration minutes across crisis events | 22m | 30m | within | df0a4bc4090e...e52e8def |
Synthetic and unavailable-source crisis blocking Synthetic or unavailable crisis evidence blocks closure claims. | Events, command cells, communications, recovery bridges, and after-actions blocked unless evidence is live, linked, and not synthetic | 100% | 100% | within | dae918f1ec28...3182ddaf |
Enterprise manifest traceability for crisis command Missing manifest traceability blocks crisis package export. | Crisis domain controls mapped to enterprise control evidence manifest rows | 100% | 100% | within | 3566186ed780...d1fcd094 |
Crisis evidence custody Missing custody hashes block crisis closure claims. | Event, command, communication, recovery, after-action, domain-control, and package evidence with SHA-256 custody hashes | 100% | 100% | within | e7ef0a600b17...80f8470f |
| Action | Status | Evidence | Owner | Deadline | Hash |
|---|---|---|---|---|---|
| No crisis command or communications action packs are required for the current evidence set. | |||||
| Source action | Control / owner | Closure | Impact | Status | Hash |
|---|---|---|---|---|---|
Portfolio appetite breach owner remediation queue Attach ALCO decision, capital planning note, covenant action, and owner remediation evidence to the portfolio-risk pack. | portfolio-risk-appetite-stress Portfolio risk governance / enterprise risk management | closed / due 18d mapped yes / evidence linked | high customer/regulatory yes / board yes | within | ab8bdb6bf194...1aba8874 |
Covenant remediation and workout committee action Route stale covenant, borrower-condition, and workout-review exceptions through credit committee minutes and owner evidence. | credit-lifecycle-governance-pack Credit risk lifecycle governance / enterprise credit risk | closed / due 15d mapped yes / evidence linked | high customer/regulatory yes / board yes | within | b62ea0573004...35af7a39 |
Suspense, reconciliation, close, and audit PBC remediation Bind reconciliation queue, suspense clearance, journal hold, close certification, and audit PBC evidence to finance minutes. | finance-ledger-close-governance-pack Finance ledger and close governance / finance control | closed / due 12d mapped yes / evidence linked | moderate customer/regulatory no / board no | within | b1562e0b96dc...7efea430 |
Fair-value, fee-rule, disclosure, redress, and launch-gate remediation Attach fair-value assessment, fee cap, disclosure fix, redress queue, and product-governance minute evidence before repricing. | product-pricing-fair-value-governance-pack Product pricing and fair-value governance / product governance | closed / due 10d mapped yes / evidence linked | high customer/regulatory yes / board yes | within | 1781265c7635...6fad9771 |
Supervisory response finding and commitment delivery action Close legal review, response approval, finding validation, commitment update, and signed board minute evidence before regulator update. | regulatory-supervisory-response-governance-pack Supervisory response and regulatory commitments / regulatory operations | closed / due 8d mapped yes / evidence linked | critical customer/regulatory yes / board yes | within | 87c56454d7c2...aae4b4d3 |
Critical vulnerability, identity, backup, and incident lesson remediation Attach vulnerability closure, privileged-access review, restore evidence, incident lesson, and cyber-risk committee minute evidence. | cyber-resilience-governance-pack Cybersecurity governance / security governance risk and compliance | closed / due 6d mapped yes / evidence linked | high customer/regulatory yes / board yes | within | b64d962773a6...436c24c2 |
Risk-data lineage, reconciliation, ad hoc reporting, and board sign-off action Reconcile source lineage, custody hash coverage, reporting SLA, ad hoc stress reporting, and data council sign-off. | bcbs239-risk-data-governance-pack Risk data aggregation and reporting / data governance | closed / due 14d mapped yes / evidence linked | moderate customer/regulatory no / board no | within | 8cba4d99888f...7ac245ba |
Board decision execution to owner queue and signed minutes archive Bind board decisions to owner queues, due dates, signed minute archive, and assurance validation evidence. | board-risk-attestation-pack Governance assurance / board secretariat | closed / due 5d mapped yes / evidence linked | high customer/regulatory yes / board yes | within | 9b13e089d8a4...7c1ffb04 |
| Owner queue | Actions | SLA | Accountability | Status | Hash |
|---|---|---|---|---|---|
Enterprise risk and portfolio remediation enterprise risk management | 2/2 mapped | oldest 7d / SLA 20d overdue 0 / blocked 0 / unassigned 0 | 1L ready / 2L ready route ready / SLA 100% | within | bbf1ef448e32...1d932370 |
Credit lifecycle, conduct, and fair-value remediation enterprise credit risk and product governance | 2/2 mapped | oldest 9d / SLA 15d overdue 0 / blocked 0 / unassigned 0 | 1L ready / 2L ready route ready / SLA 100% | within | 633a0247de24...433e9d68 |
Ledger close, suspense, audit, and reporting remediation finance control | 1/1 mapped | oldest 5d / SLA 12d overdue 0 / blocked 0 / unassigned 0 | 1L ready / 2L ready route ready / SLA 100% | within | 80a1efb65805...3c95c2e8 |
Supervisory, cyber, and regulator-impact remediation regulatory operations and security governance | 2/2 mapped | oldest 3d / SLA 10d overdue 0 / blocked 0 / unassigned 0 | 1L ready / 2L ready route ready / SLA 100% | within | 4fdd4be6c0de...5cb16f15 |
Board decision execution and signed-minute archive board secretariat | 1/1 mapped | oldest 1d / SLA 7d overdue 0 / blocked 0 / unassigned 0 | 1L ready / 2L ready route ready / SLA 100% | within | c96f601ed80b...e5eb9ed1 |
| Board decision | Minute | Actions | Execution | Status | Hash |
|---|---|---|---|---|---|
Approve portfolio appetite, credit lifecycle, and fair-value remediation closure Board Risk Committee / board secretariat | BRC-2026-07-07-04 2026-07-07 | 3/3 mapped | signed yes / notified yes due accepted yes / Board Risk Committee action tracker | within | f44888af0acf...db8a020e |
Approve ledger suspense clearance and BCBS 239 lineage remediation evidence Audit Committee / Data Council / CFO and data governance chair | AUD-DATA-2026-07-06-02 2026-07-06 | 2/2 mapped | signed yes / notified yes due accepted yes / Audit Committee action tracker | within | 2927f2c0021e...214d3073 |
Approve supervisory response, regulatory commitment, and cyber remediation closure Risk and Compliance Committee / legal control and board secretariat | RCC-2026-07-05-03 2026-07-05 | 2/2 mapped | signed yes / notified yes due accepted yes / Risk and Compliance Committee action tracker | within | c512f57ca1ae...739f3e63 |
Approve enterprise board-action ledger, owner notifications, and signed-minute archive linkage Board Risk Committee / board secretariat | BRC-2026-07-07-09 2026-07-07 | 1/1 mapped | signed yes / notified yes due accepted yes / Board Risk Committee action tracker | within | c56ae17b493a...9e0e2e72 |
| Validation | Evidence | Effectiveness | Reliance | Status | Hash |
|---|---|---|---|---|---|
independent closure, customer/regulatory impact, and recurrence validation portfolio-appetite-breach-remediation / enterprise risk control assurance | ALCO-2026-07-portfolio-action / BRC-2026-07-risk-minute / custody hash linked. / validation attestation complete. | design ready / operating ready remediation ready | harm closed / recurrence ready audit reliance ready | within | abb674af8241...03123014 |
independent closure, customer/regulatory impact, and recurrence validation credit-lifecycle-covenant-remediation / enterprise risk control assurance | CRC-2026-07-covenant-pack / workout owner sign-off / assurance validation attached. / validation attestation complete. | design ready / operating ready remediation ready | harm closed / recurrence ready audit reliance ready | within | f58799c81b81...f4aaca00 |
independent closure and recurrence validation finance-ledger-suspense-clearance / finance control assurance | AUD-2026-Q3-PBC-12 / CFO-CERT-2026-07 / suspense cleared evidence linked. / validation attestation complete. | design ready / operating ready remediation ready | harm closed / recurrence ready audit reliance ready | within | 17d9302ac455...b5b9328e |
independent closure, customer/regulatory impact, and recurrence validation product-pricing-fair-value-remediation / conduct risk and product control | PGC-2026-07-fair-value-pack / redress queue closed / pricing approval custody hash. / validation attestation complete. | design ready / operating ready remediation ready | harm closed / recurrence ready audit reliance ready | within | ec30b4d923ba...b1d4c928 |
independent closure, customer/regulatory impact, and recurrence validation supervisory-response-commitment-remediation / compliance assurance and legal control | REG-2026-07-response-pack / legal privilege review / BRC signed minute attached. / validation attestation complete. | design ready / operating ready remediation ready | harm closed / recurrence ready audit reliance ready | within | 957beb99940a...ec5ff967 |
independent closure, customer/regulatory impact, and recurrence validation cyber-vulnerability-sla-remediation / security governance risk and compliance | CYB-2026-07-critical-vuln-closure / restore test / risk technology committee custody hash. / validation attestation complete. | design ready / operating ready remediation ready | harm closed / recurrence ready audit reliance ready | within | 88094923a356...4951804a |
independent closure and recurrence validation risk-data-lineage-remediation / enterprise risk control assurance | DATA-COUNCIL-2026-07 / BCBS239-lineage export / board risk reporting sign-off. / validation attestation complete. | design ready / operating ready remediation ready | harm closed / recurrence ready audit reliance ready | within | 9e1b38c2fbf6...800523ce |
independent closure, customer/regulatory impact, and recurrence validation board-minute-owner-queue-execution / board secretariat and internal audit liaison | BRC-2026-07-action-ledger / signed minutes archive / owner notifications sent. / validation attestation complete. | design ready / operating ready remediation ready | harm closed / recurrence ready audit reliance ready | within | 9802f9d837b2...9fc4900c |
| Domain control | Stage / owner | Manifest | Evidence | Status | Hash |
|---|---|---|---|---|---|
Enterprise action register source traceability Unmapped remediation actions block board action-ledger sign-off. | source enterprise risk and control assurance | 3/3 mapped | Action records trace source control, source pillar, trigger, owner, evidence, status, due date, and custody hash. coverage 100% / findings 0 | within | 4e5a3d8d7488...bd07bda9 |
Owner queue accountability and SLA control Unassigned, blocked, or overdue actions require board route escalation. | queue first-line owners and second-line control assurance | 2/2 mapped | Owner queues prove assigned actions, accepted due dates, SLA posture, second-line challenge, and escalation routes. coverage 100% / findings 0 | within | 43812c1a04f9...d3deb298 |
Board decision execution and signed-minutes custody Unsigned minutes or missing owner notifications block board evidence closure. | board board secretariat | 3/3 mapped | Board decision records bind source actions to signed minutes, owner notifications, due-date acceptance, and escalation route. coverage 100% / findings 0 | within | 8b280012e66a...6900bfdc |
Independent validation and recurrence monitoring Unvalidated material closures require audit and board risk committee review. | validation control assurance and internal audit liaison | 3/3 mapped | Validation records prove design effectiveness, operating effectiveness, customer-harm closure, recurrence monitoring, and internal audit reliance readiness. coverage 100% / findings 0 | within | 50b1f4f67479...c16719a4 |
Remediation evidence custody, export, and retention control Missing remediation custody evidence blocks board and supervisory closure claims. | custody records manager, data governance, and board secretariat | 10/10 mapped | Enterprise action ledger, owner queues, board decisions, validation evidence, manifest mappings, signed minutes, and package hashes are retained for audit and supervision. coverage 100% / findings 0 | within | e4599f7667bf...51cfd63b |
| Remediation control | Metric | Current | Limit | Status | Evidence |
|---|---|---|---|---|---|
Source action traceability and closure Unmapped or unclosed material actions require board route escalation. | Source actions mapped to controls, due dates, evidence, closure disposition, live reads, and synthetic-action blocking | 100% | 100% | within | Management actions should trace to source controls, owners, due dates, evidence, status, closure evidence, and custody hashes. eadba0d51cc1...69049042 |
Owner remediation queue accountability Unassigned, blocked, or overdue remediation queues require board action tracking. | Owner queues with mapped actions, accepted due dates, no overdue or blocked items, first-line accountability, second-line challenge, and escalation route | 100% | 100% | within | Action owners should hold accountable queues with due dates, SLA discipline, second-line challenge, and escalation routes. a9168a822018...ab92d95b |
Board decision execution and signed minutes Unsigned or unnotified board decisions block board-attestation closure. | Board decisions linked to source actions, signed minutes, owner notification, due-date acceptance, and escalation routes | 100% | 100% | within | Board decisions should be signed, archived, linked to actions, communicated to owners, and traceable to due-date acceptance. 96fd4eca6bc0...bff081f3 |
Independent validation before closure Unvalidated closure requires audit and board risk committee review. | Actions with remediation evidence, design effectiveness, operating effectiveness, customer-harm closure, recurrence monitoring, and internal audit reliance readiness | 100% | 100% | within | Material action closure should be independently validated and ready for internal audit reliance. 15812bc0a721...f75fd219 |
Overdue critical action governance Critical or overdue unresolved actions require same-cycle board escalation. | Critical/high unclosed, overdue, or blocked remediation items | 0 | 0 | within | Critical, high, overdue, and blocked actions should be escalated immediately and not remain unresolved. f7ec43bbd139...232f85a9 |
Customer and regulatory impact closure Unclosed customer/regulatory impact actions block conduct and supervisory attestations. | Customer/regulatory impact actions closed with owner evidence and board route where required | 100% | 100% | within | Actions with customer or regulatory impact should prove remediation, owner sign-off, and board escalation where material. 607d1799ae37...3cc4e9e7 |
Recurrence monitoring after remediation Material actions without recurrence monitoring remain open for board reporting. | Validated actions with recurrence monitoring active | 100% | 100% | within | Remediated issues should include recurrence monitoring to prove the fix remains effective. b372ff4a3072...f367503b |
Synthetic and unavailable-source action blocking Synthetic or unavailable remediation evidence blocks closure claims. | Actions, queues, decisions, and validations blocked unless source evidence is live, linked, and not synthetic | 100% | 100% | within | Remediation actions and board decisions should fail closed on synthetic, unavailable, or unlinked source evidence. e9a841e06bcd...600e84c4 |
Enterprise manifest traceability for remediation Missing manifest traceability blocks remediation package export. | Domain remediation controls mapped to enterprise control evidence manifest rows | 100% | 100% | within | Remediation evidence should trace to enterprise controls, source routes, retention, export packages, and custody hashes. 9554e7a1b7b0...d31623a9 |
Remediation evidence custody Missing custody hashes block remediation closure claims. | Action, queue, board decision, validation, domain control, and package evidence with SHA-256 custody hashes | 100% | 100% | within | Remediation and board-decision evidence should be reproducible for audit, supervision, and board attestations. 879207d4efca...de11bb9a |
| Action | Status | Evidence | Owner | Deadline | Hash |
|---|---|---|---|---|---|
| No enterprise remediation or board-decision action packs are required for the current evidence set. | |||||
| Service | Status | Latency p99 | Uptime | Last incident |
|---|---|---|---|---|
| API gateway | green | 184ms | 99.98% | None in 30d |
| M-Pesa Daraja | green | 410ms | 99.91% | Retry spike 2026-06-29 |
| Metropol CRB | yellow | 690ms | 99.42% | Score pull delay 2026-07-03 |
| NTSA | green | 820ms | 98.94% | None in 14d |
| GL engine | green | 96ms | 99.99% | None in 30d |
| Notification service | green | 240ms | 99.87% | SMS vendor lag 2026-06-27 |
| Report engine | yellow | 1.8s | 98.76% | CBK report queue 2026-07-04 |
| Auth service | green | 72ms | 99.99% | None in 30d |
| File storage | green | 130ms | 99.95% | None in 30d |
| Background jobs | green | 2.1s | 99.80% | CRB batch retry 2026-07-01 |
| Websocket | red | 4.8s | 96.20% | Open incident INC-2041 |
| CDN | green | 55ms | 99.99% | None in 30d |
| Control | Pillar | Standard | Evidence | Owner | Status | Next action |
|---|---|---|---|---|---|---|
| Critical operation and dependency map | Operational resilience | BCBS operational resilience | Operational resilience matrix maps critical operations to dependencies, impact tolerances, fallback modes, and game-day evidence. | platform ops | exceeds | Push impact-tolerance breach events into live incident automation. |
| Impact tolerance and recovery drill coverage | Operational resilience | BCBS operational resilience | Admin readiness records RTO/RPO tolerances, recovery drills, live SLO telemetry signals, generated impact-tolerance ticket routes, and custody hashes for critical lending operations. | site reliability | exceeds | Attach generated ticket IDs to incident queue exports and recovery-review workpapers. |
| Third-party service substitutability | Operational resilience | BCBS third-party dependency management | Third-party exit evidence packs cover payment, bureau, notification, and storage providers with alternate providers, tested runbooks, signed contract clauses, regulator-notice routes, and custody hashes. | vendor risk | exceeds | Include signed provider exit packs in quarterly board resilience attestations. |
| Operational risk RCSA, loss-event, KRI, scenario, remediation, and board reporting evidence packs | Operational risk management | BCBS Principles for the Sound Management of Operational Risk / BCBS operational resilience / CBK Risk Management Guidelines | Admin readiness derives operational risk controls from the custody manifest, mapping Basel operational risk event categories, RCSA processes, control testing, residual risk appetite, loss-event and near-miss capture, gross and net loss recovery, customer remediation, KRI thresholds, scenario analysis, board reporting routes, action packs, custody hashes, and package hashes. | operational risk management, control assurance, and first-line process owners | exceeds | Wire operational risk action packs into RCSA workflow, loss-event register, KRI alerting, and Board Risk Committee operational risk minutes. |
| Third-party lifecycle, due diligence, contract rights, subcontractor, concentration, SLA, incident, cyber, data protection, exit, and evidence-custody packs | Third-party and outsourcing risk governance | Interagency Guidance on Third-Party Relationships: Risk Management / EBA outsourcing arrangements / EU DORA ICT third-party risk / FFIEC cyber and outsourcing risk governance / BCBS operational resilience third-party dependency management | Admin readiness joins material provider inventory, criticality, lifecycle stage, due diligence, audit and exit rights, subcontractor inventory, concentration exposure, SLA and incident monitoring, cyber and financial review recency, resilience and exit test evidence, data residency, critical operation dependencies, monitoring signals, risk-control mappings, action packs, custody hashes, and package hashes. | vendor risk, procurement, legal control, operational resilience, security governance, privacy, payments operations, credit operations, and enterprise risk | exceeds | Wire third-party risk action packs into provider onboarding, renewal approvals, contract remediation, concentration exceptions, exit tests, cyber reviews, and board third-party risk attestations. |
| Model inventory, validation, and governance controls | Model risk and fair lending | SR 11-7 model risk management | Risk model validation page renders production model inventory attestations with independent validation sign-off refs, challenger model evidence, deployment gates, custody hashes, and package hashes. | model risk | exceeds | Export model validation attestation packs to model risk committee and internal audit workpapers. |
| Ongoing monitoring and back-testing | Model risk and fair lending | SR 11-7 model risk management | Risk model governance derives automated breach tickets from PSI, override-rate, governance, evidence, approval-gate, and read-unavailable thresholds. | credit risk | exceeds | Wire breach ticket creation to case-management workflow and alerting. |
| Specific adverse-action reason generation | Model risk and fair lending | CFPB complex-algorithm adverse action | Risk model governance exposes adverse-action notice previews with specific principal reason language, evidence fields, and dispatch quality gates; live officer reject and counter-offer submissions now carry structured decision-governance packets with reason codes, borrower-safe copy, counterfactual guidance, checklist acknowledgements, quality gates, and custody hashes; recorded decision-governance hashes now feed borrower notice dispatch custody, adverse-action archives, fair-lending export package hashes, notice QA sampling, applicant appeal custody, board fair-lending committee attestations, signed board-minute custody, complaint SLA posture, examiner-ready evidence packs, supervisory response workflow routes, internal audit reliance packs, adverse-impact monitoring exceptions, live regulatory response work queues, audit workpaper exports, model lifecycle adverse-impact exception closure, named regulatory task assignment, audit evidence-file delivery, closure attestations, board model-risk follow-up minutes, model-risk committee calendar scheduling, regulatory submission packages, internal-audit issue tracking, overdue escalation alerts, calendar provider delivery receipts, regulator portal receipt hashes, internal-audit remediation closure, and SLA breach notification delivery proof. | fair lending | exceeds | Connect receipt-bearing adverse-action handoffs to live provider APIs, automated remediation SLA timers, regulator delivery reconciliation, and board exception dashboards. |
| Model lifecycle, development data, independent validation, challenger, fair-lending, drift, override, retirement, and evidence-custody packs | Model risk and fair lending | Revised Interagency Guidance on Model Risk Management (2026) / NIST AI RMF / CFPB complex-algorithm adverse action / ECOA fair-lending lifecycle governance | Risk model governance joins production model inventory, development dataset lineage, independent validation attestations, champion-challenger evidence, adverse-impact and specific-reason fair-lending reviews, PSI drift, override monitoring, governance calendar, breach tickets, model change approval workflow, validation committee minutes, adverse-action QA workflow, challenger promotion evidence, override remediation workflow, model incident closure, retirement workflow, board model-risk attestations, change-ticket receipts, committee calendar receipts, signed-minute receipts, adverse-action QA samples, challenger registry receipts, incident case receipts, retirement runbook receipts, board portal signature receipts, live provider webhook ingestion routes, provider webhook verification, signature headers, replay windows, idempotency keys, schema refs, append-only JSONL transcript ledger, raw payload storage refs, replay decision refs, restart-safe duplicate checks, signature-validation transcripts, durable storage ratios, operator-visible ingestion SLO panel, operational replay-cache SLO dashboards, operator replay job dry-runs, replay SLO alert execution dry-runs, managed WORM/object-lock custody vault, KMS-backed provider secret-rotation evidence, object-lock API confirmations, custody object version receipts, KMS rotation jobs, dual-control KMS operation refs, cloud custody operation controls, normalized external receipt intake, CloudEvents-style receipt metadata, duplicate receipt detection, external receipt package-hash binding, signed external receipt ledger records, append-only external receipt JSONL persistence, HMAC-SHA-256 receipt signatures, hash-chain receipt records, receipt signature verification, durable receipt replay controls, receipt ledger integrity audit, tamper finding triage, sequence gap detection, critical finding controls, audit finding remediation queue, owner-routed receipt ledger remediation, critical receipt finding closure controls, no-exception remediation attestations, receipt remediation closure monitor, critical receipt escalation queue, receipt remediation closure receipts, examiner-ready receipt ledger assurance verdict, receipt assurance evidence links, blocked receipt evidence prevention, encrypted receipt assurance export bundle, immutable receipt assurance export retention, blocked-verdict export hold controls, receipt assurance export reconciliation ledger, delivery acknowledgement reconciliation, critical assurance export exception controls, blocked delivery reconciliation exceptions, receipt assurance export exception work queue, owner-routed export reconciliation exceptions, critical export exception closure controls, regulator export manifests, encrypted export artifacts, receipt-bearing regulator/internal-audit/board delivery acknowledgements, export delivery reconciliation checks, manifest and custody hash matching, acknowledgement SLA controls, reconciliation exception queues, owner-routed reconciliation work items, no-exception attestations, closure evidence controls, supervisory submission monitors, destination acknowledgement lag tracking, owner workflow closure receipts, monitoring package integrity controls, retention locks, enterprise manifest mappings, action packs, custody hashes, and package hashes. | model risk, fair lending, credit risk, data governance, conduct risk, change management, and board secretariat | exceeds | Wire signed receipt ledger records, audit findings, remediation items, closure monitors, escalation queues, assurance verdicts, encrypted export bundles, export reconciliation ledgers, and export work queues to live EventBridge, Event Grid, HSM signing keys, supervisory portal callbacks, owner workflow webhooks, and incident queues. |
| Credit bureau consent, data furnishing, negative-listing notice, dispute investigation, correction, cure reporting, privacy, retention, synthetic-action, and evidence-custody packs | Model risk and fair lending | Kenya Banking Credit Reference Bureau Regulations 2020 / CFPB Regulation V FCRA furnisher accuracy and direct dispute duties / World Bank General Principles for Credit Reporting / credit-information consent, data furnishing, negative-listing notice, dispute investigation, correction, privacy, retention, and evidence-custody governance | Underwriting bureau page joins consent journeys, purpose limitation, named bureau evidence, withdrawal routes, privacy notices, retention links, portfolio furnishing files, CRB bureau destinations, source ledgers, exposure, furnishing timeliness, customer identity match, account-status and arrears mappings, negative-listing pre-notices, right-to-dispute and cure routes, vulnerable-customer review, model reason traces, notice of dispute, investigation, source-record trace, correction/deletion, bureau update, customer response, regulator escalation, live-read and synthetic-action blocking, enterprise manifest mappings, action packs, custody hashes, and package hashes. | underwriting operations, credit operations, credit risk, data governance, privacy office, collections conduct, customer dignity operations, regulatory operations, control assurance, and board secretariat | exceeds | Wire credit bureau action packs into bureau pull approvals, furnishing file holds, negative-listing notice suppression, dispute correction workflow, CRB update proof, and board credit reporting minutes. |
| Income verification, expense reasonableness, obligation completeness, DSR/PTI/residual-income, stress affordability, vulnerable-customer, manual-exception, decline, synthetic-action, and evidence-custody packs | Responsible lending and affordability governance | EBA Guidelines on loan origination and monitoring creditworthiness assessment / World Bank responsible lending and over-indebtedness consumer protection / FCA Consumer Duty and borrower financial-difficulty outcomes / Kenya Financial Consumer Protection Framework affordability and fair-treatment expectations / income verification, expense reasonableness, obligation completeness, debt-service capacity, stress affordability, vulnerable-customer safeguards, exception, decline, and evidence-custody governance | Underwriting DSR page joins verified income sources, recency, confidence, documentary evidence, bank statements, tax and payroll traces, M-Pesa cashflow, volatility, consent, privacy, retention, expense benchmarks, essential-expense buffers, household needs, obligations, bureau links, internal ledger links, off-balance commitments, duplicate suppression, priority debts, hardship checks, DSR/PTI/residual-income limits, stressed installments, vulnerable-customer review, hardship history, manual override approval, adverse-action and decline notices, explainability, cooling-off and customer choice, enterprise domain mappings, action packs, custody hashes, and package hashes. | underwriting operations, credit policy, credit risk, conduct risk, model risk, privacy office, data governance, control assurance, and board secretariat | exceeds | Wire responsible lending affordability action packs into underwriting approval holds, affordability exception workflow, adverse action and decline notices, conduct reviews, and board credit-risk minutes. |
| AI operator tool-agency, approval, confidence, provenance, prompt-injection, privacy, incident, and evidence-custody packs | AI operator governance | NIST AI RMF / NIST AI 600-1 Generative AI Profile / OWASP LLM Top 10 2025 / ISO/IEC 42001 AI management system | AI operator page joins role lanes, tool registry health, high-risk tool approvals, confidence triage, prompt-injection and excessive-agency controls, fail-closed source-read provenance, redacted execution inputs, privacy and fair-lending links, AI incident loops, governance action packs, custody hashes, and package hashes. | AI governance council, model risk, AI security, privacy, and operations risk | exceeds | Wire AI operator action packs into model-risk review, tool allow-list changes, security incident review, and board AI governance attestations. |
| Financial-grade API authentication, consent scope, sandbox, partner, quota, webhook, release-assurance, and evidence-custody packs | API platform governance | OpenID FAPI 2.0 Security Profile / OWASP API Security Top 10 2023 / NIST SP 800-204A microservices security / NIST SP 800-218 SSDF / consumer-permissioned financial data rights | API platform page joins endpoint auth, OAuth/mTLS/HMAC posture, request and response schema contracts, deterministic sandbox payloads, consent-scoped borrower and bureau fields, always-auth partner routes, rate-limit and back-pressure tiers, partner security reviews, webhook signing, emitted event evidence, governance action packs, custody hashes, and package hashes. | API platform, identity platform, application security, privacy, partner operations, and operational risk | exceeds | Wire API platform action packs into partner onboarding, API security review, quota changes, privacy launch gates, release assurance, and board API governance attestations. |
| Open-finance consent journey, data-access grant, revocation, portability, restriction, deletion, data-recipient, reconciliation, live-read, synthetic-action, and evidence-custody packs | API platform governance | CFPB Personal Financial Data Rights Rule 12 CFR Part 1033 / eCFR Regulation 1033 / Open Banking Standard consent and data management good practice / EBA PSD2 strong customer authentication and common secure communication / FCA open banking and open finance consumer protection / Kenya Financial Consumer Protection Framework consent, privacy, digital finance, complaint, and redress expectations / consumer-permissioned data sharing, scope minimization, revocation, portability, recipient oversight, reconciliation, and evidence-custody governance | API platform page joins consent journeys, plain-language disclosures, purpose and category scopes, partner and duration evidence, revocation routes, customer notices, live-read and synthetic-action blocking, customer authentication, token binding, least privilege, data minimization, refresh reviews, access logs, revocation, portability, restriction, deletion, partner notification, customer confirmations, DSAR links, data recipient due diligence, contract data-use limits, onward-sharing prohibitions, breach notice, deletion certificates, consent-ledger-to-token reconciliation, scope-to-field reconciliation, recipient-contract-to-sharing reconciliation, enterprise mappings, action packs, custody hashes, and package hashes. | API platform, privacy office, data governance, identity platform, security governance, partner operations, vendor risk, legal control, conduct risk, records manager, customer outcomes operations, control assurance, and board secretariat | exceeds | Wire open-finance consent action packs into consent capture, partner access grants, token revocation, DSAR portability, recipient remediation, API release gates, and board technology-risk minutes. |
| Fraud typology, alert, case, disbursement hold, vulnerable-customer, loss recovery, signal validation, and evidence-custody packs | Fraud and scam risk governance | FFIEC authentication and access risk management / FATF risk-based financial-crime controls / CFPB elder financial exploitation response / NIST CSF 2.0 Detect-Respond-Recover / operational risk fraud loss governance | Fraud management page joins live fraud case reads, alert queue typologies, identity mismatch, velocity, device, CRB, and Fuliza signals, high-risk score thresholds, disbursement holds, fraud lead escalation, SAR/STR financial-crime triage, vulnerable-customer and elder financial exploitation response, reimbursement readiness, fraud loss recovery, model-signal validation, fail-closed source reads, action packs, custody hashes, and package hashes. | fraud operations, financial crime compliance, application security, credit operations, conduct risk, model risk, and operational risk | exceeds | Wire fraud risk action packs into fraud case management, disbursement holds, SAR/STR review, vulnerable-customer redress, fraud model monitoring, loss-event capture, and board fraud-risk attestations. |
| Authorized payment scam and unauthorized-transfer intake, liability, reimbursement, victim-care, receiving-party recovery, fraud reporting, live-read, synthetic-action, and evidence-custody packs | Fraud and scam risk governance | PSR APP scam reimbursement protections and compliance monitoring / EBA PSD2 fraud reporting / CFPB Regulation E unauthorized transfer and error-resolution controls / Kenya Financial Consumer Protection Framework and CBK fraud safety / World Bank financial consumer protection complaints and redress good practices | AML compliance page joins scam and unauthorized-transfer cases, claim amount, intake acknowledgement, payment trace, customer interview, provider or police references, liability assessment, exception review, vulnerable-customer override, maker-checker approval, customer explanation, GL posting, redress link, reimbursement clock, freeze, recall, provider dispute, mule escalation, financial-crime link, settlement reconciliation, victim support route, safe contact, hardship and language support, fraud statistics, regulator and CBK packs, root-cause links, enterprise mappings, action packs, custody hashes, and package hashes. | fraud operations, payment error resolution, payments operations, MLRO, customer outcomes, conduct risk, finance control, regulatory operations, privacy office, and board secretariat | exceeds | Wire scam reimbursement action packs into fraud victim intake, reimbursement approval holds, freeze and recall queues, provider disputes, vulnerable-customer support, fraud statistics, CBK response packs, GL postings, root-cause remediation, and board conduct minutes. |
| Portfolio risk appetite, concentration, and stress evidence packs | Portfolio risk governance | BCBS 239 risk data aggregation / Basel credit risk principles / CBK risk management guidelines | Risk stress workbench joins live concentration limits, forward NPA scenarios, macro product impacts, portfolio VaR, covenant early warnings, appetite limits, management actions, board escalation deadlines, custody hashes, and package hashes. | enterprise risk management | exceeds | Wire appetite breach packs into ALCO, Board Risk Committee, capital planning, and owner remediation queues. |
| Credit policy, granting, collateral, monitoring, early-warning, workout, write-off, and recovery evidence packs | Credit risk lifecycle governance | BCBS Principles for the Management of Credit Risk / CBK Risk Management Guidelines / CBK PG/04 Risk Classification and Provisioning | Risk stress workbench joins credit lifecycle stages, delegated authority and policy evidence, underwriting and affordability controls, model challenge, adverse-action QA, collateral valuation and LTV controls, covenant and borrower-condition monitoring, risk classification, ECL and provisioning links, problem-credit workout books, restructure cure rates, write-off recovery postmortems, board reporting routes, action packs, custody hashes, and package hashes. | enterprise credit risk, credit operations, special assets, and finance control | exceeds | Wire credit lifecycle action packs into underwriting policy changes, collateral review queues, covenant remediation, workout committee minutes, and board credit-risk attestations. |
| Co-lending partner eligibility, loan participation, allocation fairness, risk retention, settlement waterfall, servicing disclosure, concentration, live-read, synthetic-action, and evidence-custody packs | Credit risk lifecycle governance | Basel Committee Principles for the Management of Credit Risk / Basel large exposures and securitisation risk-transfer framework / EBA loan origination and monitoring / IFRS 9 financial asset transfer and derecognition controls / CBK Risk Management Guidelines / Kenya Financial Consumer Protection Framework / World Bank financial consumer protection good practices / co-lending, loan participation, allocation fairness, risk retention, partner due diligence, settlement, servicing, concentration, live-read, and evidence-custody governance | Co-lending page joins live facility projections with partner due diligence, financial review, contract and audit rights, credit approval, risk-share documentation, collateral and covenant mapping, exit plans, borrower disclosure and consent, eligibility coverage, risk retention, adverse-selection blocking, pricing parity, exception review, explainability, waterfall matching, partner-share reconciliation, borrower and GL posting, suspense clearance, participant statements, servicing reports, borrower and delinquency notices, hardship protocols, complaint handoffs, privacy and records controls, counterparty/product/geography/sector concentration limits, stressed exposure, early-warning, capital impact, board escalation, enterprise mappings, action packs, custody hashes, and package hashes. | co-lending operations, partner operations, enterprise credit risk, credit policy, structured credit, syndication desk, treasury reconciliation, finance control, loan servicing operations, conduct risk, vendor risk, legal control, data governance, privacy office, control assurance, and board secretariat | exceeds | Wire co-lending action packs into partner onboarding, allocation holds, risk-retention attestations, settlement remittance holds, servicing report certification, concentration remediation, risk transfer, and board credit-risk minutes. |
| Capital markets issuance approval, investor suitability, bookbuilding allocation fairness, subscription settlement, secondary trading surveillance, ongoing disclosure, funding concentration, live-read, synthetic-action, and evidence-custody packs | Liquidity and funding risk | IOSCO Objectives and Principles of Securities Regulation / IOSCO Principles for Ongoing Disclosure and Material Development Reporting / IOSCO suitability requirements for complex financial products / IOSCO international debt disclosure principles / Kenya Capital Markets Authority issuer, corporate bond, collective investment, custody, and market-conduct expectations / Basel large exposures and securitisation framework / CPMI-IOSCO PFMI settlement finality / IFRS 7 and IFRS 9 disclosure and financial instrument controls | Capital markets page joins live funding, bond, covenant, investor-reporting, and secondary-trade reads with issuer board approval, current prospectus, legal review, regulator filing, credit rating, trustee, custodian, use-of-proceeds, listing approvals, investor eligibility, KYC, AML, suitability, risk disclosure, appropriateness, concentration, cooling-off, complaint routes, order compliance, allocation fairness, price discovery, conflict checks, insider restrictions, audit trails, settlement matching, segregated funds, CSD instructions, refunds, GL posting, investor statements, trade verification, price exceptions, late reports, best execution, market abuse surveillance, settlement finality, ongoing disclosure, covenant reporting, material development reporting, ECL and portfolio metrics, data lineage, redaction, board signoff, funding concentration, liquidity impact, refinancing plans, enterprise mappings, action packs, custody hashes, and package hashes. | capital markets desk, investor relations, treasury risk, settlement operations, market surveillance, finance control, legal control, conduct risk, financial crime compliance, custodian oversight, regulatory operations, data governance, control assurance, and board secretariat | exceeds | Wire capital markets action packs into issuance launch holds, subscription suppression, allocation fairness review, settlement break remediation, trade surveillance queues, investor-report certification, funding concentration remediation, and board capital-markets minutes. |
| Structured credit loan-pool eligibility, true-sale, derecognition, SPV tranche, cashflow waterfall, servicer continuity, investor reporting, capital relief, risk retention, live-read, synthetic-action, and evidence-custody packs | Structured credit and securitisation governance | Basel securitisation framework / IOSCO disclosure principles for public offerings and listings of asset-backed securities / IFRS 9 financial asset transfer and derecognition / IFRS 7 transferred financial asset disclosures / EBA simple, transparent and standardised securitisation and risk-retention expectations / Kenya Capital Markets Authority asset-backed securities expectations | Capital markets page joins structured-credit pools, transfers, tranches, waterfalls, servicer continuity, investor reports, capital relief, domain controls, action packs, custody hashes, and package hashes with loan-pool eligibility coverage, concentration and delinquency limits, data tape readiness, customer notice and consent evidence, adverse-selection blocking, live-read and synthetic-action gates, derecognition assessment, true-sale legal opinion, originator isolation, servicing transfer notice, accounting memo, tax review, board approval, regulator notice, SPV tranche enhancement, reserve and liquidity support, trustee/custodian readiness, investor suitability, offering circular, collection matching, waterfall reconciliation, trigger monitoring, segregated accounts, GL posting, backup servicer, data escrow, borrower communication, complaint handoff, investor reporting, material development disclosure, RWA before/after, significant risk transfer, risk retention, cleanup call control, implicit-support blocking, stress impact, finance reconciliation, enterprise mappings, and evidence custody. | structured credit, capital markets desk, treasury risk, capital planning, finance control, legal control, investor relations, loan servicing operations, conduct risk, data governance, privacy office, control assurance, ALCO, capital committee, audit committee, and board secretariat | exceeds | Wire structured-credit action packs into pool cut-off holds, transfer recognition holds, tranche offer approvals, waterfall distribution holds, servicer-continuity remediation, investor-report certification, capital-relief recognition, risk-retention attestations, and board structured-credit minutes. |
| External data-room room approval, recipient access, legal basis, redaction, privilege review, package integrity, watermark, activity audit, revocation, live-read, synthetic-export blocking, and evidence-custody packs | External disclosure and data-room governance | NIST CSF 2.0 Govern-Protect-Detect-Respond / NIST SP 800-53 Rev. 5 access, audit, media protection, and privacy controls / ISO/IEC 27001 information security management / EU GDPR data minimisation and security of processing / Kenya Data Protection Act and ODPC data sharing safeguards / IOSCO disclosure and investor-protection principles | Capital markets page joins investor, regulator, auditor, partner, and board data-room rooms, export packages, recipients, disclosure reviews, activity audits, revocation incidents, domain controls, action packs, custody hashes, and package hashes with NDA coverage, legal basis, purpose limitation, board or deal approval, expiry, watermark and download controls, redaction, classification, privilege review, PII scan, disclosure index, retention, source-read provenance, synthetic-export blocking, MFA, KYC/accreditation, least privilege, access review, materiality review, selective-disclosure guards, legal and privacy review, version control, Q&A log, regulator route, anomaly monitoring, alert route, watermark trace, legal hold, revocation SLA, regulator notice route, root cause, enterprise mappings, and evidence custody. | data room operations, investor relations, regulatory operations, legal control, privacy office, security governance, data governance, records manager, finance control, board secretariat, control assurance, and board risk | exceeds | Wire external data-room action packs into room activation holds, recipient approval, package publication gates, disclosure review, Q&A control, anomaly triage, revocation and leak response, legal hold, regulator notification, and board data-room minutes. |
| Market abuse surveillance, insider and restricted list governance, market sounding control, best execution evidence, communications surveillance, regulatory reporting decisioning, live-read, synthetic-action blocking, and custody packs | Market conduct surveillance governance | IOSCO Objectives and Principles of Securities Regulation / EU Market Abuse Regulation insider dealing, unlawful disclosure, and market manipulation controls / ESMA suspicious transaction and order reporting expectations / Kenya Capital Markets Act and CMA conduct-of-business expectations / best execution, insider list, market sounding, communications surveillance, STOR, live-read, synthetic-action blocking, and evidence-custody governance | Capital markets page joins market abuse surveillance scenarios, critical alert disposition, trade-order linkage, price-volume benchmarks, insider lists, restricted and watch lists, wall crossings, personal-account dealing review, market sounding consent, disclosure packs, recordings, cleanse notices, best execution benchmark reviews, venue and cost disclosures, communications capture, lexicon hits, escalation closure, retention, STOR and regulator-route decisions, domain controls, action packs, custody hashes, and package hashes. | market surveillance, trading oversight, compliance surveillance, conduct risk, legal control, investor relations, regulatory operations, records manager, data governance, control assurance, and board secretariat | exceeds | Wire market conduct action packs into alert queues, trade holds, wall-crossing freezes, PA dealing suppression, sounding approval holds, best-execution exception review, STOR escalation, communications surveillance remediation, and board conduct minutes. |
| Sustainable finance taxonomy eligibility, use-of-proceeds allocation, impact-claim measurement, target calibration, verification assurance, social safeguard, greenwashing, live-read, synthetic-action, and evidence-custody packs | Climate financial risk and disclosure | ICMA Green Bond Principles / ICMA Social Bond Principles / ICMA Sustainability-Linked Bond Principles / ICMA Sustainability Bond Guidelines / Kenya Green Finance Taxonomy / IFRS S1 and IFRS S2 sustainability and climate disclosures / UNDP SDG Impact Standards / UNEP FI climate target-setting for banks / sustainable-finance taxonomy eligibility, use-of-proceeds, impact-claim, greenwashing, social-safeguard, assurance, target-setting, live-read, and evidence-custody governance | Risk stress workbench joins taxonomy criteria, climate objectives, DNSH, minimum safeguards, exclusions, eligible allocation, unallocated proceeds, escrow reconciliation, invoices, borrower consent, refinancing lookback, impact target achievement, verification variance, measurement method, data lineage, beneficiary evidence, double-counting controls, negative-impact review, disclosure approval, sustainability target KPI calibration, penalty mechanism, external benchmark, board approval, independent verification, assurance scope, sample coverage, public report, safeguard screening, unresolved grievance tolerance, vulnerable-customer review, community consent, privacy, no-harm, redress, enterprise mappings, action packs, custody hashes, and package hashes. | sustainable finance, climate risk, impact measurement, treasury reconciliation, finance control, conduct risk, privacy office, data governance, control assurance, legal control, and board secretariat | exceeds | Wire sustainable finance action packs into green-label holds, use-of-proceeds reporting, investor impact reporting, sustainability-linked pricing approvals, assurance refreshes, safeguard remediation, greenwashing review, and board sustainable-finance minutes. |
| Collateral valuation, LTV, lien perfection, registry search, custody, insurance, repossession, dispute, synthetic-action, and evidence-custody packs | Collateral valuation and custody governance | Basel Principles for the Management of Credit Risk / CBK Risk Management Guidelines / EBA loan origination and monitoring collateral valuation expectations / IFRS 13 fair value measurement / legal enforceability, custody, insurance, repossession, dispute, and evidence-custody governance | Collateral command center joins vehicle logbooks, title deeds, equipment debentures, crop NDVI security, and market-security pledges with independent valuation, fair-value method evidence, forced-sale value, LTV limits, revaluation cadence, registry searches, perfected charges, priority and consent checks, fraud/caveat clearance, release controls, custody evidence, insurance cover, lender-interest notation, claim routes, recovery legal notices, vulnerable-customer review, approved repossession agents, sale valuation, shortfall disclosure, live-read and synthetic-action blocking, enterprise manifest mappings, action packs, custody hashes, and package hashes. | collateral operations, credit risk, legal control, recoveries, insurance operations, records manager, fraud operations, conduct risk, and board secretariat | exceeds | Wire collateral action packs into credit renewals, margin calls, lien perfection queues, custody vault checks, insurance renewal, repossession approvals, dispute holds, impairment overlays, and board credit-risk attestations. |
| Collections conduct, hardship forbearance, promise-to-pay, repossession, write-off, recovery, and borrower-outcome evidence packs | Collections and forbearance governance | CBK Risk Management Guidelines / Kenya Financial Consumer Protection Framework / World Bank Good Practices for Financial Consumer Protection / FCA Consumer Duty borrower difficulty protections | Collections command center joins DPD segments, strategy rules, consent-aware contact controls, hardship screening, forbearance offer coverage, vulnerable-customer review, promise-to-pay integrity, legal and repossession readiness, write-off recovery, board reporting routes, action packs, custody hashes, and package hashes. | collections operations, conduct risk, special assets, legal control, and credit risk finance control | exceeds | Wire collections conduct action packs into hardship queues, PTP remediation, repo/legal holds, write-off postmortems, and board customer-outcomes reporting. |
| Loan statement accuracy, repayment waterfall allocation, payoff and settlement quote, waiver, reversal, refund, notice, dispute, reconciliation, live-read, synthetic-action, and evidence-custody packs | Loan servicing and repayment governance | CFPB Regulation Z periodic statement, payoff statement, and payment allocation expectations / World Bank financial consumer protection servicing and disclosure good practices / FCA Consumer Duty borrower support and fair treatment / Kenya Financial Consumer Protection Framework servicing, disclosure, complaint, redress, and fair-treatment expectations / loan statement accuracy, repayment waterfall, payoff quote, waiver, reversal, refund, notice, dispute, reconciliation, and evidence-custody governance | Loan waterfall page joins borrower statements, amount due arithmetic, principal/interest/fee splits, due date and arrears evidence, delivery channels, dispute routes, language and accessibility, retention links, payment rails, paid amount, allocated amount, suspense, principal/interest/fee/charge components, waterfall order, fee-cap checks, borrower instructions, overpayment handling, GL posting, schedule updates, payoff quote SLA, principal balance, accrued interest, fees, rebate or waiver credits, good-through dates, per-diem, collateral release, waiver, reversal, refund, notice, redress, root cause, payment rail-to-ledger reconciliation, statement-to-ledger reconciliation, payoff-to-ledger reconciliation, live-read and synthetic-action blocking, enterprise mappings, action packs, custody hashes, and package hashes. | loan servicing operations, payments operations, finance control, treasury reconciliation, customer outcomes operations, conduct risk, special assets, collateral operations, data governance, records manager, control assurance, and board secretariat | exceeds | Wire loan servicing repayment action packs into statement publication holds, waterfall posting holds, payoff quote workflow, waiver and reversal approvals, refund and redress queues, GL reconciliation breaks, and board servicing minutes. |
| IFRS 9 staging, allowance adequacy, loan-level evidence, and impairment action packs | Allowance and impairment governance | IFRS 9 expected credit loss impairment / Basel credit risk and ECL guidance / CBK provisioning comparison | Officer ECL page joins Stage 1, Stage 2, and Stage 3 allowance buckets, SICR exposure, credit-impaired exposure, CBK provision shortfalls, top-loan ECL concentration, loan-level EAD/PD/LGD/ECL evidence, recomputation recency, action packs, board escalation deadlines, custody hashes, and package hashes. | CFO, credit risk, and impairment committee | exceeds | Wire ECL action packs into reporting-close workflow, impairment committee minutes, finance overlays, and external-audit workpapers. |
| Capital adequacy, ICAAP, stress capital, and leverage evidence packs | Capital adequacy and ICAAP | Basel III capital framework / Basel leverage ratio / CBK PG/04 capital adequacy | Executive capital adequacy page joins CAR, Tier 1, RWA density, capital buffer headroom, stress CAR floors, lending-book leverage proxy, NPL capital triggers, provenance events, CFO action packs, board escalation deadlines, custody hashes, and package hashes. | CFO and enterprise risk | exceeds | Wire ICAAP action packs into capital committee minutes, board capital plans, and regulator-ready return workpapers. |
| Climate financial risk, scenario, financed-emissions, and disclosure evidence packs | Climate financial risk and disclosure | BCBS climate-related financial risk principles / CBK Climate-Related Risk Management / IFRS S2 / TCFD | Risk stress workbench joins transition exposure, physical risk exposure, stressed climate loss uplift, financed-emissions intensity proxies, green finance opportunity tracking, scenario coverage, methodology evidence, covenant triggers, disclosure action packs, board escalation deadlines, custody hashes, and package hashes. | enterprise risk, CFO, and sustainability | exceeds | Replace proxy financed-emissions factors with borrower-level emissions, collateral resilience, and transition-plan attestations. |
| Liquidity risk appetite and contingency funding evidence packs | Liquidity and funding risk | BCBS sound liquidity risk management / Basel III LCR / CBK Basel III liquidity standards | ALM workbench joins live liquidity ladder, current cash, LCR, survival horizon, cumulative liquidity gaps, duration gaps, NII-at-risk shocks, funding concentration, contingency funding actions, board escalation deadlines, custody hashes, and package hashes. | treasury risk and ALCO | exceeds | Wire contingency funding actions into treasury execution queues, ALCO minutes, and Board Risk Committee liquidity attestations. |
| FX open-position, hedge, revaluation, stress, KRI, and market-risk evidence packs | Market and foreign exchange risk | Basel market risk framework / BCBS Minimum capital requirements for market risk / CBK Foreign Exchange Exposure Limits / CBK Risk Management Guidelines | Treasury FX page joins monitored currency exposures, board and prudential net-open-position limits, Tier 1 capital ratios, hedge coverage, independent rate-source freshness, revaluation integrity, stressed FX losses, counterparty and settlement evidence, ALCO action packs, custody hashes, and package hashes. | treasury risk, ALCO, payments risk, and finance control | exceeds | Wire market-risk action packs into hedge execution, ALCO limit approvals, independent price verification, and board market-risk attestations. |
| IRRBB earnings, EVE, repricing, basis-risk, optionality, and ALM governance evidence packs | Interest rate risk and ALM governance | Basel IRRBB standards / Basel Framework SRP31-SRP98 / CBK Risk Management Guidelines | ALM workbench joins duration buckets, NII shock scenarios, funding mix, IRRBB source completeness, scenario coverage, NII earnings-at-risk, EVE shock proxy, repricing gap concentration, duration gap limit, basis risk, largest-source optionality, ALCO action packs, board escalation deadlines, custody hashes, and package hashes. | treasury risk, ALCO, and finance control | exceeds | Wire IRRBB action packs into ALCO limit monitoring, hedge/repricing approvals, capital planning, and Board Risk Committee rate-risk attestations. |
| Payment settlement finality, rail resilience, and exception evidence packs | Payments and settlement risk | CPMI-IOSCO PFMI / CPMI ISO 20022 harmonisation / Kenya National Payment System risk controls | Disbursement workbench joins live batch history, pending disbursement exposure, payment rail health, configured rail coverage, latency, settlement finality, ISO 20022 reference completeness, exception actions, oversight deadlines, custody hashes, and package hashes. | payments operations and treasury control | exceeds | Wire settlement exception packs into provider incident workflows, payment retry/reversal queues, and Board Risk Committee payment-system attestations. |
| Payment error intake, unauthorized-transfer, investigation, provisional-credit, reversal, refund, provider-dispute, reconciliation, notice, redress, live-read, synthetic-action, and evidence-custody packs | Payments and settlement risk | CFPB Regulation E Electronic Fund Transfer Act error-resolution and unauthorized-transfer expectations / World Bank financial consumer protection complaints, disclosure, and redress good practices / CPMI-IOSCO PFMI payment finality and operational-risk expectations / Kenya Financial Consumer Protection Framework fair-treatment, complaint, redress, and digital-finance expectations / payment error intake, unauthorized transfer, investigation, provisional credit, reversal, refund, provider dispute, reconciliation, notice, redress, and evidence-custody governance | Treasury reconciliation page joins oral and written error notices, customer identity, account, transaction, amount, acknowledgement, liability assessment, investigations, transaction traces, ledger traces, provider traces, customer interviews, written explanations, correction decisions, provisional credits, reversals, refunds, root cause, maker-checker approval, rail reversal, GL correction, customer notices, redress, provider tickets, callbacks, settlement files, customer impact links, payment error reconciliations, live-read and synthetic-action blocking, enterprise mappings, action packs, custody hashes, and package hashes. | payment error resolution, payments operations, treasury reconciliation, finance control, customer outcomes operations, conduct risk, privacy office, data governance, vendor risk, operational risk, control assurance, and board secretariat | exceeds | Wire payment error resolution action packs into error intake, provisional credit, refund, reversal, provider dispute, GL correction, redress, and board payment-risk minutes. |
| Deposit product, wallet float, customer-fund safeguarding, liquidity run, dormant balance, synthetic-action, and evidence-custody packs | Deposits and wallet safeguarding | Basel Core Principles for effective banking supervision / CBK prudential and deposit-taking microfinance guidance / EBA payment services and e-money safeguarding / FCA payment and e-money safeguarding requirements / customer-fund segregation, liquidity, dormant balance, and run-protection governance | Deposits command center joins savings, term deposit, merchant float, agent float, and repayment wallet products with customer disclosures, rate-change notices, dormancy and complaint routes, safeguarding account mappings, liquidity buffers, withdrawal SLA controls, live-read and synthetic-action blocking, segregated customer-fund accounts, trustee acknowledgements, no-commingling and insolvency-remoteness evidence, wallet-float reconciliation freshness, deposit-run scenarios, dormant and unclaimed-balance controls, enterprise manifest mappings, action packs, custody hashes, and package hashes. | deposit operations, treasury risk, payments finance control, records manager, conduct risk, ALCO, and board secretariat | exceeds | Wire deposits and wallet safeguarding action packs into ALCO, treasury liquidity runbooks, wallet-float reconciliation, dormant balance workflows, customer-disclosure governance, and board risk attestations. |
| Insurance product, Cap17 gate, premium trust-fund, claims fairness, reinsurance, synthetic-action, and evidence-custody packs | Insurance and protection governance | IAIS Insurance Core Principles / Kenya insurance conduct and licensing controls / Cap17 trust-pool segregation / IFRS 17 insurance contract evidence / customer outcome, claims fairness, and reinsurance governance | Insurance command center joins motor MGA, trade credit, repo protection, and mutual aid protection products with approved wordings, pricing and eligibility review, customer outcomes, complaints route, Cap17 gate state, live-read and synthetic-action controls, unearned premium and member-fund segregation, trust/bank reconciliation, no-direct-insert controls, claims SLA, coverage decisions, fraud screening, payout approvals, reinsurance and concentration evidence, enterprise manifest mappings, action packs, custody hashes, and package hashes. | insurance operations, Cap17 control, conduct risk, finance control, claims operations, reinsurance risk, and board secretariat | exceeds | Wire insurance protection action packs into product governance, Cap17 gate review, premium trust reconciliation, claims queues, reinsurance renewal, and board conduct-risk attestations. |
| Agent onboarding, fit-and-proper, training, liquidity, teller cash reconciliation, commission payout, fraud/AML, conduct, synthetic-action, and evidence-custody packs | Agent network and cash operations governance | CBK prudential and agency banking guidance / Basel operational risk and resilience principles / FATF risk-based AML/CFT financial inclusion guidance / GSMA mobile money agent network and safeguarding practices / agent liquidity, cash reconciliation, commission, conduct, and evidence-custody governance | Agent network command center joins regional clusters, captains, fit-and-proper review, training completion, liquidity float, cash-out SLA, complaints route, fraud monitoring, AML screening, geofence controls, live-read and synthetic-action blocking, teller tills, physical cash count, variance, dual control, supervisor approval, CCTV or audit trail, safe limits, commission attestation, tax withholding, clawback, dispute windows, payout rails, failed-payout handling, agent fraud/AML/complaint/cash-variance incidents, enterprise manifest mappings, action packs, custody hashes, and package hashes. | agent network operations, cash operations, treasury risk, payments finance control, fraud operations, MLRO, conduct risk, operational risk, agent finance control, and board secretariat | exceeds | Wire agent network and cash action packs into cluster activation, field liquidity replenishment, teller day-close, commission payout approvals, fraud/AML case management, customer redress, and board operational-risk attestations. |
| Proactive regulatory obligation radar | Regulatory operations | CBK/ODPC/FRC regulatory horizon management | Regulatory workbench maps Central Bank of Kenya, Office of the Data Protection Commissioner, Financial Reporting Centre, and National Payment System obligations to owners, triggers, evidence routes, due dates, escalation owners, next actions, export packs, package hashes, and missing-artifact checks. | regulatory operations | exceeds | Wire horizon changes to owner alerts, regulator-ready evidence-pack exports, and board conduct-risk reporting. |
| Regulatory return inventory, source reconciliation, validation-rule, maker-checker, CFO, compliance, API-submission, acknowledgement, amendment, prudential-capital, board-route, live-read, and evidence-custody packs | Regulatory operations | CBK Digital Credit Provider data submission testing / CBK Risk Management Guidelines reliable regulatory reporting / BCBS 239 risk data aggregation and risk reporting / Basel Core Principles supervisory reporting | CBK regulatory reporting page joins live submission and capital-component reads with DCP API data submission testing, return inventory, owner and cadence evidence, source-system and dataset reconciliation, validation rule inventories, validation exceptions, data-quality issue tracking, maker-checker approval, CFO and compliance officer attestations, regulator acknowledgement refs, amendment controls, capital component trial-balance tie-outs, board pack refs, enterprise control mappings, action packs, custody hashes, and package hashes. | regulatory reporting, finance control, compliance assurance, data governance, API platform, board secretariat, and control assurance | exceeds | Wire regulatory return action packs into CBK filing workflow, API submission testing, validation exception queues, CFO certification, board reporting, amendment approvals, and regulator acknowledgement monitoring. |
| Regulatory perimeter, licence, registration, authorization, key-person, fit-and-proper, ownership, third-party notice, change-control, product launch, country expansion, synthetic-action, and evidence-custody packs | Regulatory operations | CBK Digital Credit Providers Regulations 2022 / CBK Digital Credit Provider licensing procedures / National Payment System Regulations 2014 and PSP authorisation procedures / ODPC Data Controller and Processor registration guidance / Capital Markets licensing requirements / POCAMLA AML-CFT-CPF reporting institution obligations | Regulatory workbench joins regulated activity classifications, authorities, licence and registration references, renewal windows, key-person fit-and-proper filings, source-of-funds evidence, ownership and third-party change triggers, payment, data-protection, AML, capital-markets, insurance, pricing, live-read product gates, country-expansion no-objection routes, enterprise control mappings, action packs, custody hashes, and package hashes. | legal control, regulatory operations, company secretary, privacy office, financial crime compliance, payments operations, capital markets desk, insurance governance, product governance, platform expansion, and board secretariat | exceeds | Wire regulatory perimeter action packs into product-launch, partner onboarding, country expansion, ownership-change, renewal, key-person appointment, no-objection, and signed board/regulator evidence workflows. |
| Supervisory exam request, regulator response, finding remediation, commitment tracking, board escalation, and legal evidence-custody packs | Supervisory response and regulatory commitments | Basel Core Principles for Effective Banking Supervision / BCBS Compliance and the compliance function in banks / BCBS corporate governance principles for banks / CBK Risk Management Guidelines | Regulatory workbench joins CBK, ODPC, and FRC supervisory requests with intake, scope, due-date, owner, legal privilege, confidentiality, evidence route, board route, live-read, and synthetic-action controls; response packs with artifacts, QA, legal review, redaction, approval, submission, acknowledgement, and single-message scripts; supervisory findings with root cause, customer-harm review, remediation evidence, independent validation, board reporting, and closure posture; regulatory commitments with milestones, mapped enterprise controls, board approval, second-line review, audit notice, regulator updates, dependency clearance, action packs, custody hashes, and package hashes. | regulatory operations, compliance assurance, legal control, enterprise risk, privacy office, financial crime compliance, payments risk, records manager, and board secretariat | exceeds | Wire supervisory response action packs into exam request intake, legal review, evidence collection, response approval, finding remediation, commitment delivery, regulator update scripts, and board risk committee minutes. |
| Tax obligation registration, iTax filing calendar, KRA VAT/PAYE/WHT/corporate tax remittance, SHA/SHIF, NSSF, housing levy, NITA, eTIMS, ledger reconciliation, transfer-pricing, stamp-duty, audit-query, live-read, synthetic-action, and evidence-custody packs | Tax and statutory compliance governance | OECD Tax Control Framework and co-operative compliance / COSO Internal Control Integrated Framework / Kenya Revenue Authority iTax, eTIMS, VAT, PAYE, withholding tax, corporate income tax, transfer-pricing, affordable housing levy, and statutory payment expectations / Social Health Authority employer contribution expectations / NSSF employer contribution expectations / tax obligation registration, return preparation, payment, filing calendar, payroll statutory contribution, ledger reconciliation, tax-position, live-read, synthetic-action, and evidence-custody governance | Operational readiness joins KRA, SHA/SHIF, NSSF, payroll statutory, iTax, eTIMS, portal, payment, certificate, filing, and ledger evidence with registration currency, return preparation, payment slips, portal acknowledgements, bank proof, certificates, employee population matching, statutory deduction calculation, employer contribution calculation, remittance files, payslip disclosures, source-ledger-to-return-to-payment reconciliation, open item ageing, tax technical memos, legal basis, external advisor reviews, provision approvals, disclosure assessment, board visibility, enterprise mappings, action packs, custody hashes, and package hashes. | tax operations, CFO tax control, payroll tax, people operations, finance control, treasury reconciliation, legal control, compliance assurance, privacy office, records manager, control assurance, and board secretariat | exceeds | Wire tax statutory action packs into iTax filing holds, payroll close, statutory remittance approvals, eTIMS reconciliation, tax payable suspense clearance, transfer-pricing support, audit-query remediation, and board audit minutes. |
| Privacy impact and high-risk processing launch gates | Data protection and privacy | ODPC Data Protection Act / NIST Privacy Framework / NIST AI RMF | Consent workbench maps high-risk automated decisioning, consent and DSAR processing, third-party processor sharing, cross-border transfers, and retention/deletion operations to DPIA, Data Commissioner consultation, lawful-basis, processor, retention, evidence, and launch-blocker gates. | privacy engineering | exceeds | Wire privacy gate status into product launch approval, model release, and processor onboarding workflows. |
| Records inventory, retention schedule, legal hold, DSAR disposition, immutable archive, backup propagation, and evidence-custody packs | Data protection and privacy | NIST Privacy Framework data processing lifecycle / ISO 15489 records management / Kenya Data Protection Act storage limitation and data-subject rights / regulator, AML, dispute, tax, and audit evidence retention | Operational readiness joins material lending, payment, AML, dispute, consent, DSAR, backup, and archive records with owner, system, PII inventory, retention rule, statutory basis, active legal/regulator/AML/dispute holds, deletion and restriction workflow evidence, portability export readiness, archive immutability, backup alignment, enterprise control mappings, action packs, custody hashes, and package hashes. | records manager, privacy office, legal control, MLRO, platform reliability, and data governance | exceeds | Wire records lifecycle action packs into DSAR queues, legal hold release, archive disposal, backup propagation, audit workpapers, and board privacy attestations. |
| AML typology surveillance and STR evidence packs | Financial crime compliance | FATF risk-based AML/CFT/CPF / Kenya FRC suspicious transaction reporting / CBK AML supervision | AML workbench derives typology surveillance and suspicious transaction report evidence from persisted screenings and monitoring alerts, mapping sanctions, PEP, structuring, high-risk counterparty, velocity, and cross-border typologies to MLRO actions, FRC report posture, filing deadlines, custody hashes, and package hashes. | MLRO and financial crime compliance | exceeds | Wire MLRO dispositions into case management, goAML export preparation, and board financial-crime reporting. |
| Financial-crime KYC, CDD, beneficial ownership, EDD, screening, monitoring, STR/SAR, no-tipping-off, goAML, risk-control, and evidence-custody packs | Financial crime compliance | FATF Recommendations risk-based AML/CFT/CPF / FinCEN customer due diligence and beneficial ownership / Kenya FRC suspicious and unusual transaction reporting / sanctions, PEP, adverse media, and STR governance | AML workbench joins customer risk rating, CDD, expected activity, beneficial ownership, sanctions, PEP and adverse-media screening, high-risk enhanced due diligence, periodic review age, monitoring enablement, reportable alerts, investigator ownership, STR/SAR filing deadline, no-tipping-off attestation, goAML readiness, enterprise manifest mappings, action packs, custody hashes, and package hashes. | MLRO, KYC operations, financial crime compliance, screening operations, model risk, data governance, and board secretariat | exceeds | Wire financial-crime action packs into onboarding holds, CDD refresh queues, beneficial ownership remediation, screening disposition, STR/SAR reporting, no-tipping-off controls, goAML export preparation, and board financial-crime attestations. |
| Business-network KYB, merchant, supplier, anchor-buyer, dealer-importer, relationship exposure, marketplace abuse, renewal, action, and evidence-custody packs | Business network and KYB governance | FATF Recommendations risk-based CDD and ongoing monitoring / FATF Recommendation 24 beneficial ownership of legal persons / Kenya beneficial ownership and digital credit provider controls / OECD responsible business conduct due diligence / World Bank integrity compliance and IFC due diligence | Soko marketplace joins merchants, suppliers, anchor buyers, dealer importers, logistics partners, RFQ, SCF invoice, RBF, vehicle import, and group procurement relationships with registration, tax PIN, beneficial ownership, ownership-register recency, sanctions, PEP, adverse media, bank account, permit or license, privacy notice, expected activity, velocity, duplicate invoice, settlement account, concentration, activity-review, enterprise manifest, action pack, custody hash, and package hash evidence. | marketplace operations, MLRO, financial crime compliance, fraud operations, credit risk, payments operations, vendor risk, data governance, and board secretariat | exceeds | Wire business-network KYB action packs into merchant and supplier onboarding holds, RFQ award gates, SCF invoice purchase holds, RBF drawdown approvals, vehicle import dealer review, group procurement concentration checks, renewal queues, fraud triage, and board marketplace-risk attestations. |
| Cross-domain risk data lineage, quality, timeliness, adaptability, reconciliation, and board reporting evidence packs | Risk data aggregation and reporting | BCBS 239 risk data aggregation and risk reporting / CBK Risk Management Guidelines | Admin readiness derives BCBS 239 controls from the custody manifest, grouping credit, impairment, capital, treasury, payments, compliance, conduct, resilience, cybersecurity, live-data, assurance, and board domains into source lineage, artifact, export package, custody hash, reporting SLA, ad hoc stress reporting, reconciliation cadence, board route, action packs, and package hashes. | data governance, enterprise risk, and control assurance | exceeds | Wire risk data action packs into data council workflow, supervisory information requests, and board risk reporting sign-off. |
| Finance ledger, posting-rule, reconciliation, suspense, period-close, financial-reporting, audit, synthetic-action, and evidence-custody packs | Finance ledger and close governance | IFRS Conceptual Framework and IFRS financial reporting discipline / COSO Internal Control Integrated Framework / Basel corporate governance principles for banks / CBK Risk Management Guidelines / ledger integrity, period-close, reconciliation, suspense, adjustment, and audit-evidence custody governance | GL command center joins cash, bank, M-Pesa, payment settlement, loan, deposit, wallet, ECL, treasury, FX, fee, commission, agent payout, insurance, tax, and expense ledger domains with account ownership, posting rules, subledger tie-outs, trial-balance links, reconciliation SLA, suspense limits, double-entry journal integrity, maker-checker approval, dual approval, reversal routes, manual adjustment governance, close milestones, IFRS financial statement support, CBK regulatory return mapping, external audit PBC packs, board finance packs, live-read and synthetic-action blocking, enterprise manifest mappings, action packs, custody hashes, and package hashes. | CFO, finance control, risk finance, treasury finance control, reconciliation operations, tax, regulatory reporting, audit liaison, control assurance, and board secretariat | exceeds | Wire finance ledger action packs into reconciliation queues, suspense clearance, journal posting holds, period-close certification, audit PBC workflows, regulatory-return sign-off, CFO certification, and board finance minutes. |
| Product fair-value, pricing, total-cost-of-credit, fee transparency, target-market, disclosure, lifecycle, complaints, redress, synthetic-action, and evidence-custody packs | Product pricing and fair-value governance | FCA Consumer Duty price and value outcome / EBA product oversight and governance for retail banking products / Kenya Financial Consumer Protection Framework / World Bank Good Practices for Financial Consumer Protection / fair-value, fee-transparency, suitability, disclosure, product lifecycle, and evidence-custody governance | Pricing workbench joins MSME Working Capital Plus, Boda Logbook Refinance, Chama Group Credit, Merchant Inventory Float, and Green Agri Equipment products with APR ceilings, cost stack, expected loss, funding cost, operating cost, target margin, fee caps, complaint-rate thresholds, fair-value assessments, total-cost-of-credit evidence, key facts statements, affordability, vulnerable-customer paths, target-market definitions, distributor training, conduct monitoring, fee triggers, waiver and reversal routes, tax treatment, language and channel disclosure coverage, readability, rate-change notices, digital consent receipts, launch lifecycle gates, GL and fee mapping, rollback plans, post-launch reviews, retirement notices, live-read and synthetic-action blocking, enterprise manifest mappings, action packs, custody hashes, and package hashes. | product governance, pricing committee, conduct risk, credit policy, product finance control, digital product, agent conduct control, regulatory operations, control assurance, and board secretariat | exceeds | Wire product pricing action packs into pricing approvals, fair-value assessments, fee-rule changes, disclosure remediation, launch gates, post-launch outcome reviews, redress queues, regulatory sign-off, and board product-governance minutes. |
| Product launch queue, regulatory perimeter linkage, product-pricing linkage, manifest coverage, approval-route, live-read, upstream-action, post-launch review, synthetic-action, and evidence-custody packs | Product pricing and fair-value governance | Product launch regulatory readiness / regulatory perimeter licensing governance / product pricing fair-value governance / privacy, AML, responsible-lending, live-read, board approval, and evidence-custody launch controls | Product launch workbench composes MSME Working Capital Plus, Boda Logbook Refinance, Chama Group Credit, Merchant Inventory Float, and Green Agri Equipment launch candidates with product-pricing/fair-value rows, regulatory perimeter product gates, required enterprise control mappings, board and regulator notice routes, legal, operations, training, communications, rollback, live-read, post-launch review, upstream action-pack clearance, custody hashes, and package hashes. | product governance, regulatory operations, legal control, conduct risk, pricing committee, credit policy, privacy office, financial crime compliance, payments operations, and board secretariat | exceeds | Wire product launch readiness actions into product-create/save flows, launch approvals, regulator notices, go-live holds, post-launch reviews, board minutes, and owner work queues. |
| Risk-adjusted profitability, funds-transfer-pricing, RAROC hurdle, cost-stack, stressed return, attribution, customer-outcome, and evidence-custody packs | Risk-adjusted profitability and FTP governance | Interagency FTP guidance for funding and contingent liquidity risk / BCBS sound liquidity risk management / OCC lending and loan portfolio risk management / OCC earnings quality / EBA loan origination and monitoring loan pricing / Basel Core Principles risk governance / World Bank financial consumer protection | Pricing workbench joins MSME working-capital, logbook refinance, invoice discounting, green agri equipment, and merchant inventory segments with approved RAROC hurdles, FTP curves, funding, liquidity, contingent-liquidity, expected-loss, capital, operating, acquisition, tax and levy, and customer-redress cost stacks, expected-loss and capital model lineage, stressed funding, credit, redress, and growth-frontier scenarios, GL/subledger/portfolio/board attribution, customer-outcome gates, enterprise manifest mappings, action packs, custody hashes, and package hashes. | pricing committee, treasury risk, ALCO, risk finance, product finance control, conduct risk, enterprise risk, and board secretariat | exceeds | Wire RAROC and FTP action packs into pricing approvals, ALCO FTP curve review, capital planning, product launch and repricing, customer-outcome review, and board profitability minutes. |
| Production-change, release-gate, configuration-baseline, software-supply-chain, deployment-health, emergency-change, rollback, synthetic-action, and evidence-custody packs | Change, release, and configuration governance | FFIEC Development, Acquisition, and Maintenance change management / FFIEC Architecture, Infrastructure, and Operations configuration management / NIST SP 800-128 security-focused configuration management / NIST SP 800-218 Secure Software Development Framework / NIST CSF 2.0 Govern and Protect / CBK Risk Management and Business Continuity guidance | Admin readiness joins production changes, risk tiers, business justifications, customer and data impact reviews, approvals, segregation-of-duties checks, emergency-change discipline, post-implementation reviews, release trains, linked changes, test pass rates, security and performance gates, canaries, feature flags, rollback plans, monitoring, deployment-freeze evidence, secure configuration baselines, drift counts, secret rotation, access reviews, SBOMs, provenance, dependency scans, license reviews, signed artifacts, reproducible builds, vulnerability gates, deployment health, error-budget burn, rollback time, P0 incidents, customer-harm tickets, domain assurance, manifest mappings, action packs, custody hashes, and package hashes. | release management, platform engineering, security operations, service owners, enterprise risk, vendor risk, data governance, customer operations, control assurance, internal audit liaison, and board secretariat | exceeds | Wire change-release action packs into CAB approvals, release trains, deployment holds, configuration drift queues, vulnerability gates, rollback drills, customer-harm review, remediation queues, and board technology-risk minutes. |
| Recovery trigger, recovery option, solvent wind-down, communication, and board escalation evidence packs | Recovery and resolution planning | FSB Key Attributes recovery and resolution planning / BCBS operational resilience / CBK Risk Management Guidelines | Admin readiness derives recovery and resolution controls from capital, liquidity, IRRBB, payment, resilience, conduct, risk data, board, and control assurance evidence, joining quantitative triggers, recovery options, capital and liquidity restoration capacity, critical operation continuity, provider substitutability, solvent wind-down readiness, regulator and customer communication routes, board escalation trails, action packs, custody hashes, and package hashes. | enterprise risk, treasury risk, CFO, operational resilience, and board secretariat | exceeds | Wire recovery action packs into crisis management workflow, ALCO, capital committee, regulator notice packs, and board decision minutes. |
| Critical-function exit, provider substitutability, data-portability, transition-runbook, solvent wind-down, communication, and evidence-custody packs | Recovery and resolution planning | BCBS operational resilience critical operation mapping and testing / EBA outsourcing exit strategies / EU DORA ICT third-party risk / PRA SS2/21 outsourcing and third-party risk / CBK Risk Management and Business Continuity guidance | Admin readiness joins critical operations, provider exits, data export schemas, transition rehearsals, wind-down modules, customer and regulator communication routes, provider step-in and data-return rights, alternate-provider readiness, concentration limits, escrow, subprocessor inventories, portable datasets, checksum and encryption evidence, lineage and privacy boundaries, rollback and decision authority, servicing-only runway, board minutes, manifest mappings, action packs, custody hashes, and package hashes. | operational resilience, vendor risk, legal control, data governance, privacy, platform engineering, treasury operations, customer operations, enterprise risk, control assurance, and board secretariat | exceeds | Wire exit-portability action packs into provider renewal gates, transition rehearsals, data export jobs, wind-down runbooks, customer/regulator notices, and board recovery planning minutes. |
| Crisis command, war-room, regulator/customer communications, recovery bridge, after-action, recurrence-monitoring, and evidence-custody packs | Crisis command and communications governance | BCBS operational resilience incident management and business continuity testing / BCBS corporate governance board oversight / FSB Key Attributes crisis management and resolution planning / FFIEC business continuity crisis management communications / regulator, customer, staff, provider, board, recovery, after-action, and evidence-custody governance | Admin readiness joins payment, cyber, liquidity, supervisory, and customer-harm crisis events with trigger controls, incident IDs, critical operations, declaration SLA, incident commander assignment, war-room evidence, decision logs, operational-risk event links, command cells, contact trees, decision authorities, regulator, customer, staff, provider, and board communications, approved scripts, legal and privacy review, single-message source control, acknowledgement tracking, recovery options, impact tolerances, provider exit, customer harm review, remediation actions, postmortems, root cause, lessons learned, recurrence monitoring, internal-audit readiness, board minute refs, manifest mappings, action packs, custody hashes, and package hashes. | enterprise crisis management team, operational resilience, legal control, regulatory operations, customer operations, vendor risk, security operations, control assurance, internal audit liaison, and board secretariat | exceeds | Wire crisis command packs into live incident severity declaration, emergency contact tree testing, regulator notice workflows, customer communication dispatch, recovery option activation, after-action lessons, and board crisis minutes. |
| Enterprise risk appetite statement, risk-limit, KRI, breach, exception, committee-challenge, tolerance-use, and evidence-custody packs | Enterprise risk appetite and limit governance | FSB Principles for an Effective Risk Appetite Framework / BCBS corporate governance principles for banks / Basel Core Principles for effective banking supervision / OCC Corporate and Risk Governance / COSO ERM Integrating with Strategy and Performance / ISO 31000 risk management guidelines | Admin readiness joins board-approved appetite statements, risk capacity, appetite, tolerance, early-warning thresholds, breach thresholds, limit utilization, KRIs, breach cases, exceptions, second-line challenge, committee decisions, signed minutes, customer-impact assessments, manifest mappings, custody hashes, and package hashes across credit, liquidity, capital, operational resilience, conduct, cyber, technology, and model risk. | board risk committee, enterprise risk, CRO, ALCO, conduct risk, technology risk, operational risk, risk data governance, and board secretariat | exceeds | Wire appetite actions into board appetite refresh, limit breach workflows, exception expiry reviews, second-line challenge, committee minutes, supervisory evidence packs, and owner remediation queues. |
| Enterprise-wide scenario inventory, severe-but-plausible design, reverse stress, model and data lineage, capital-liquidity-profit-customer impact, management action, board challenge, and evidence-custody packs | Enterprise stress testing governance | BCBS Stress testing principles / EBA Guidelines on institutions' stress testing / Federal Reserve SR 12-7 stress testing guidance / PRA SS31/15 ICAAP and SREP / ISO 31000 risk management guidelines | Risk stress workbench joins macro-credit, liquidity-run, cyber-outage, climate-agri, market-FX-rate, and reverse-stress scenarios with severity narratives, review SLAs, board approvals, model coverage, data lineage, customer-impact assessments, stressed credit loss, capital headroom, liquidity survival, funding concentration, operational outage loss, customer redress, climate loss uplift, market loss, model validation, challenger evidence, reconciliation, sensitivity analysis, owner sign-off, credible management actions, legal and operational feasibility, dependency clearance, reverse-stress failure points, early-warning triggers, recovery options, signed committee minutes, enterprise manifest mappings, action packs, custody hashes, and package hashes. | enterprise risk, CRO, capital planning, treasury risk, ALCO, risk analytics, model risk, operational resilience, conduct risk, climate risk, risk data governance, and board secretariat | exceeds | Wire enterprise stress actions into ICAAP, ILAAP and liquidity contingency, ALCO, capital committee, operational resilience exercises, customer-harm review, board challenge minutes, and supervisory information requests. |
| Three-lines control assurance and board escalation | Governance assurance | NIST CSF 2.0 Govern / IIA Three Lines Model / Basel corporate governance principles | Admin readiness derives one assurance review per world-class control from the custody manifest, routing first-line owners, second-line reviewers, third-line internal audit, board committees, residual risk, findings, custody hashes, assurance hashes, and package hashes. | risk and compliance assurance | exceeds | Export signed assurance packs to board risk committee and internal audit workpapers. |
| Internal audit charter, independence, risk-based audit universe, annual plan, engagement, issue-validation, QAIP, external-assessment, audit committee, synthetic-action, and evidence-custody packs | Governance assurance | IIA 2024 Global Internal Audit Standards / Basel Committee internal audit function in banks / OCC internal and external audit handbook / CBK Risk Management Guidelines and Risk Based Supervisory Framework | Admin readiness joins internal audit universe, critical-risk coverage, audit committee approvals, independence attestations, data access, annual audit plan, resources, skills, analytics, QAIP links, engagement scope, RCM, sample coverage, working paper review, reports, management responses, issue handoff, validation, recurrence monitoring, external assessment, enterprise mappings, action packs, custody hashes, and package hashes. | chief audit executive, board audit committee, internal audit operations, control assurance, enterprise risk, data governance, records manager, and board secretariat | exceeds | Wire internal audit action packs into audit planning, engagement workflow, issue validation, QAIP review, audit committee minutes, remediation queues, and examiner evidence packs. |
| Board charter, reserved matters, fit-and-proper directors, composition, independence, committee, meeting, conflict, related-party, policy, evaluation, succession, disclosure, stakeholder, synthetic-action, and evidence-custody packs | Governance assurance | Basel Committee Corporate governance principles for banks / OCC Corporate and Risk Governance / CBK Prudential Guideline on Corporate Governance / G20-OECD Principles of Corporate Governance | Admin readiness joins board charter and reserved matters, delegated authority, director fit-and-proper and CBK filings, independence, non-executive ratios, CPD, attendance, tenure, succession, committee mandates, quorum, minutes, board packs, related-party exposure, recusal, independent review, policy approvals, risk appetite, management accountability, board evaluation, disclosures, stakeholder channels, enterprise mappings, action packs, custody hashes, and package hashes. | board chair, company secretary, board secretariat, nominations and governance committee, legal control, enterprise risk, compliance assurance, internal audit, records manager, and board committee chairs | exceeds | Wire corporate board governance action packs into board portal workflows, director onboarding, committee calendars, conflict pre-clearance, related-party approvals, policy review, disclosure production, supervisory response, and signed-minute archives. |
| Board risk committee evidence pack and decision trail | Governance assurance | NIST CSF 2.0 Govern / BCBS corporate governance principles / IIA Three Lines Model | Board pack composes world-class control evidence, three-lines assurance, resilience automation, model validation attestations, privacy and regulatory packs, governing-body questions, decision requests, committee routes, custody hashes, and package hashes. | board secretariat and enterprise risk | exceeds | Wire board decisions back into owner work queues and signed minutes archive. |
| Enterprise remediation source-action, owner-queue, board-decision, independent-validation, recurrence-monitoring, and signed-minute evidence packs | Enterprise remediation and board decision execution | BCBS corporate governance principles for banks / BCBS Principles for the Sound Management of Operational Risk / COSO Internal Control monitoring and deficiency remediation / IIA Three Lines Model / board decision execution, owner accountability, independent validation, issue closure, signed minutes, and evidence-custody governance | Admin readiness joins portfolio, credit lifecycle, finance close, product pricing, supervisory response, cyber, risk-data, and board-minute actions with source-control mappings, owner queues, SLA posture, board decisions, signed minutes, owner notifications, due-date acceptance, independent validation, customer/regulatory impact closure, recurrence monitoring, synthetic-action blocking, manifest mappings, action packs, custody hashes, and package hashes. | enterprise risk, control assurance, board secretariat, records manager, data governance, first-line owners, and internal audit liaison | exceeds | Wire remediation owner queues into live workflow assignment, signed-minute archive retention, internal-audit reliance packs, recurrence monitoring, and board risk committee follow-up attestations. |
| Cyber resilience governance, asset exposure, privileged access, vulnerability, detection, incident, ransomware recovery, and evidence-custody packs | Cybersecurity governance | NIST CSF 2.0 Govern-Identify-Protect-Detect-Respond-Recover / CIS Critical Security Controls v8.1 / ISO/IEC 27001:2022 ISMS / FFIEC cyber risk management and self-assessment guidance | Admin readiness joins cyber control domains across NIST CSF 2.0 functions, asset and attack-surface inventory, privileged access MFA and secrets rotation, critical vulnerability SLA telemetry, EDR and SIEM detection coverage, immutable backup and restore evidence, phishing simulation signal, ransomware and API-abuse exercises, customer-harm review, regulator-notice readiness, action packs, custody hashes, and package hashes. | security governance, security operations, identity platform, application security, platform reliability, vendor risk, privacy, and operational risk | exceeds | Wire cyber resilience action packs into SOC case management, vulnerability exceptions, access reviews, backup restore drills, incident regulator notices, and board cyber-risk attestations. |
| Identity inventory, MFA, phishing-resistant authentication, least privilege, segregation-of-duties, access review, privileged event, service account, break-glass, and evidence-custody packs | Cybersecurity governance | NIST CSF 2.0 PR.AA identity management, authentication, and access control / CIS Controls v8.1 account and access control management / FFIEC Architecture, Infrastructure, and Operations identity and privileged access governance | Admin readiness joins workforce, privileged, service-account, customer-support, and break-glass principals with owner, system, MFA, phishing-resistant factor, role target, actual roles, review age, stale-account flag, JML automation, SoD conflict, session policy, access events, privilege grants, break-glass use, key rotation, approvals, expiry, reviewer, revocation, risk-control mappings, action packs, custody hashes, and package hashes. | identity platform, security governance, security operations, application security, platform reliability, control assurance, and board secretariat | exceeds | Wire identity access action packs into access-request approvals, stale account revocation, MFA upgrades, SoD remediation, service credential rotation, break-glass review, and board cyber-risk attestations. |
| Cryptographic key and secrets custody governance | Cybersecurity governance | NIST SP 800-57 key management / NIST SP 800-130 CKMS design / NIST SP 800-152 CKMS profile / FIPS 140-3 validated cryptographic modules / NIST CSF 2.0 data security / FFIEC AIO cryptographic operations / PCI DSS 4.0.1 key management | Key inventory, FIPS module boundary, custodian attestation, dual-control ceremony, cryptoperiod, rotation, revocation, destruction, recovery, incident, manifest, and evidence-custody packs join borrower PII, payment tokenization, open-finance signing, evidence-signing, backup archive, and webhook keys with FIPS module validation references, custodian attestations, training, access reviews, break-glass, and separation-of-duties evidence, key lifecycle events, customer-impact reviews, enterprise manifest mappings, action packs, custody hashes, and package hashes. | security governance, application security, platform reliability, payments security, identity platform, data governance, privacy office, control assurance, and board secretariat | exceeds | Wire KMS/HSM ceremonies, rotation pipelines, access recertification, incident response, backup recovery drills, evidence signing, and board cyber-risk minutes. |
| Governance, risk ownership, and policy evidence | Cybersecurity governance | NIST CSF 2.0 Govern | Admin readiness exposes a machine-readable control evidence manifest with owners, evidence sources, retention, export packages, and custody hashes. | security governance | exceeds | Sign manifest exports with release attestation before regulator handoff. |
| Incident detection, response, and recovery visibility | Cybersecurity governance | NIST CSF 2.0 Detect/Respond/Recover | Operational readiness links incidents to postmortems, matching game-day recovery evidence, customer-harm reviews, closure readiness, evidence routes, and custody hashes. | security operations | exceeds | Push closure-ready incident links into SOC evidence exports and board risk reporting. |
| Session-bound access and secret isolation | Cybersecurity governance | NIST CSF 2.0 Protect | Officer, examiner, and agent routes use server session tokens and same-origin proxy writes. | identity platform | exceeds | Keep direct browser bearer-token and public-token checks in CI. |
| Customer outcome, vulnerable-customer, and fair-value monitoring | Customer outcomes and conduct | CBK consumer protection / FCA Consumer Duty / World Bank financial consumer protection | Dignity hub derives conduct outcome controls from complaint evidence, including resolution SLA breaches, vulnerable-customer support signals, fair-value and product-suitability flags, root-cause clusters, board escalation routes, custody hashes, and package hashes. | customer dignity operations | exceeds | Wire conduct outcome remediation into product governance minutes and board customer-outcomes reporting. |
| Complaint intake, fair handling, vulnerable-customer support, redress calculation, dispute escalation, root-cause remediation, recurrence monitoring, third-party accountability, synthetic-action, and evidence-custody packs | Customer outcomes and conduct | World Bank financial consumer protection complaints handling and dispute resolution / FCA Consumer Duty consumer support and vulnerable-customer outcomes / CBK Prudential Guideline on Consumer Protection complaint procedures / G20-OECD financial consumer protection complaints handling and redress / complaint intake, fair handling, vulnerable-customer support, redress, dispute escalation, root-cause remediation, third-party accountability, and evidence-custody governance | Dignity hub joins complaint cases, intake source traces, acknowledgements, SLA clocks, owner assignments, impartial reviews, vulnerable-customer needs assessments, adjusted communications, hardship reviews, redress eligibility and calculation evidence, maker-checker approvals, payout/correction and GL mappings, tax and fee treatment, internal appeal, ombudsman/CBK and regulator routes, legal review, approved customer scripts, third-party accountability, root-cause remediation, customer-harm assessment, recurrence metrics, independent validation, board minutes, enterprise manifest mappings, action packs, custody hashes, and package hashes. | customer dignity operations, conduct risk, customer remediation finance control, regulatory operations, legal control, control assurance, data governance, records manager, and board secretariat | exceeds | Wire customer outcomes and redress action packs into complaint case management, vulnerable-customer support queues, redress payout/correction workflow, ombudsman and CBK escalation packs, root-cause recurrence monitoring, and board customer-outcomes minutes. |
| Accessible, plain-language, translated, assisted-channel, USSD, low-bandwidth, financial education, comprehension, defect remediation, and evidence-custody packs | Inclusive customer access and capability governance | WCAG 2.2 accessibility / W3C cognitive accessibility / UN CRPD accessible information and communications / G20-OECD financial consumer protection / World Bank financial consumer protection / CGAP responsible digital credit / GSMA mobile money customer treatment / Kenya consumer protection and financial consumer protection | Dignity hub joins loan application, repayment, complaint, collections, marketplace, mobile money, and USSD journeys with WCAG critical checks, keyboard, screen reader, focus, error prevention, timeout, color contrast, low-bandwidth, translated disclosure, plain-language score, comprehension testing, assisted support, USSD fallback, call center, agent, field officer, consent, transcript, privacy script, vulnerability handoff, complaint route, education modules, numeracy examples, cost-of-credit, data-use, redress education, knowledge checks, defect remediation, enterprise manifest mappings, action packs, custody hashes, and package hashes. | accessibility lead, product engineering, conduct risk, customer dignity operations, customer education, mobile channel operations, data governance, control assurance, and board secretariat | exceeds | Wire inclusive access action packs into product launch gates, disclosure reviews, translation QA, accessibility defect blockers, assisted-channel drills, USSD fallback tests, financial education refresh, customer-harm triage, and board customer-outcomes minutes. |
| No representative rows on read outage | Live data trust | Situ fail-closed operating standard | Frontend hardening suite verifies LMS, examiner, agent, superapp, and mobile surfaces hide fallback rows. | product engineering | exceeds | Extend the no-demo invariant to every newly added product surface. |
| Tamper-evident examiner and operator evidence | Live data trust | Examiner-grade auditability | Control evidence manifest surfaces SHA-256 custody hashes and package hashes for examiner-ready export bundles. | examiner platform | exceeds | Store signed manifest exports alongside examiner evidence packs. |
| Blocked action states for synthetic or unavailable data | Live data trust | Customer harm prevention | Trade-credit, mobile credit, payroll, title-deed, and agent shell surfaces block actions on synthetic or missing reads. | customer operations | exceeds | Add automated UX snapshots for every blocked action state. |
| ID | Service | Impact | Owner | Status |
|---|---|---|---|---|
| INC-2041 | Websocket | Officer queue refresh delayed in Kisumu branch | Lilian Achieng | Mitigating |
| INC-2038 | Report engine | CBK liquidity pack generated 18 minutes late | Peter Mwangi | Resolved |
| INC-2034 | Metropol CRB | Bureau checks retried for 212 applications | Fatuma Ali | Resolved |
| Window | Primary | Secondary | Escalation |
|---|---|---|---|
| Today 07:00-19:00 | Lilian Achieng | Peter Mwangi | CTO desk |
| Today 19:00-07:00 | Fatuma Ali | David Kiprono | Ops director |
| Tomorrow 07:00-19:00 | John Mutua | Mercy Wairimu | Platform lead |