Loading officer dashboard…
Loading officer dashboard…
Loading officer dashboard…
Executive KPI summary · monthly board report · portfolio health
| Agenda item | Board question |
|---|
| Decision request |
|---|
| Evidence packs |
|---|
| Assurance |
|---|
| Package hash |
|---|
Enterprise risk oversight and control maturity NIST CSF 2.0 Govern oversight / Board Risk Committee | Do management evidence and independent assurance prove the control environment remains ahead of benchmark? | Approve the signed control assurance pack and retain custody hash with board minutes. | control-assurance-pack, examiner-custody-pack, governance-evidence-pack 3 controls / 2 routes | ready 3 assurance reviews / 0 open questions | d86af42492dc...24c13408 |
Enterprise risk appetite, limits, breaches, exceptions, and board challenge governance FSB Principles for an Effective Risk Appetite Framework / BCBS corporate governance principles for banks / OCC Corporate and Risk Governance / COSO ERM / ISO 31000 / Board Risk Committee / ALCO / Conduct Committee / Technology Risk Committee / Audit Committee | Can management prove the risk profile remains within risk capacity, appetite, and tolerance, with timely breach remediation, controlled exceptions, independent challenge, and reproducible evidence? | Approve the board appetite statement, risk capacity, tolerance thresholds, KRIs, limit utilization, breach remediation, exceptions, second-line challenge, signed minutes, owner actions, and evidence custody package. | capital-icaap-evidence-pack, control-assurance-pack, customer-outcomes-redress-governance-pack, cyber-resilience-governance-pack, enterprise-risk-appetite-limit-governance-pack, operational-risk-governance-pack, portfolio-risk-appetite-pack, risk-data-aggregation-governance-pack, treasury-liquidity-risk-pack 9 controls / 9 routes | ready 9 assurance reviews / 0 open questions | 62deaa0b07e6...dfeb2ce4 |
Enterprise stress testing, reverse stress, management action, and board challenge governance BCBS Stress testing principles, EBA Guidelines on institutions' stress testing, Federal Reserve SR 12-7 stress testing guidance, PRA SS31/15 ICAAP and SREP, and ISO 31000 / Board Risk Committee / ALCO / Capital Committee / Operational Risk Committee / Conduct Committee / Audit Committee | Can management prove the platform remains viable under severe but plausible stress, knows the reverse-stress failure points, has credible actions, protects customers, and preserves reproducible evidence for supervisors? | Approve the enterprise scenario inventory, severe-but-plausible assumptions, reverse-stress failure points, model validation, challenger evidence, data lineage, capital and liquidity impacts, customer-harm safeguards, credible management actions, signed committee minutes, and custody evidence package. | capital-icaap-evidence-pack, climate-risk-disclosure-pack, control-assurance-pack, cyber-resilience-governance-pack, enterprise-risk-appetite-limit-governance-pack, enterprise-stress-testing-governance-pack, market-fx-risk-governance-pack, operational-risk-governance-pack, portfolio-risk-appetite-pack, risk-adjusted-profitability-ftp-governance-pack, risk-data-aggregation-governance-pack, treasury-liquidity-risk-pack 12 controls / 12 routes | ready 12 assurance reviews / 0 open questions | 23802f4b469f...5ce97e1e |
Operational resilience and third-party exit readiness BCBS operational resilience and third-party dependency management / Board Risk Committee / Technology Committee | Are critical operations, incidents, and outsourced providers inside impact tolerance with tested substitutes? | Ratify resilience automation evidence and provider exit packs for the quarterly board attestation. | incident-recovery-pack, operational-resilience-automation-pack, operational-resilience-pack, third-party-exit-evidence-pack 4 controls / 2 routes | ready 4 assurance reviews / 0 open questions | 6e150bdee8af...dfee42af |
Crisis command, war-room, regulator/customer communication, recovery activation, and after-action governance BCBS operational resilience incident management, FSB crisis management and resolution planning, FFIEC crisis communications, and corporate governance board oversight / Crisis Management Team / Board Risk Committee / Audit Committee | Do crisis controls prove material events are declared quickly, commanded by accountable leaders, communicated consistently, bridged to tested recovery options, closed with lessons learned, and reproducible for supervisors? | Approve crisis event declaration, incident commander assignment, war-room evidence, decision logs, operational-risk event links, command cells, regulator/customer/staff/provider communications, legal and privacy review, recovery option bridges, customer-harm reviews, after-action lessons, recurrence monitoring, internal-audit readiness, board minutes, and custody package evidence before closing material crisis events. | crisis-command-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | e854c582fae9...3022e12d |
Operational risk RCSA, loss events, KRIs, and scenario governance BCBS Principles for the Sound Management of Operational Risk and CBK Risk Management Guidelines / Operational Risk Committee / Board Risk Committee / Audit Committee | Do RCSAs, loss events, KRIs, scenarios, remediation trails, and custody hashes prove operational risk is identified, measured, monitored, controlled, and board-challenged? | Approve RCSA category coverage, residual risk appetite, control testing, operational loss and near-miss capture, KRI thresholds, scenario analysis, remediation closure, board reporting, and evidence custody packs. | operational-risk-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | bbdac5f49b90...82676c07 |
Enterprise remediation, owner queue, signed-minute, validation, and recurrence governance BCBS corporate governance principles for banks, BCBS operational risk principles, COSO internal control monitoring, IIA Three Lines Model, and remediation evidence custody / Audit Committee / Board Risk Committee / Internal Audit | Do remediation controls prove source actions are assigned, decisions are signed, owners notified, validations complete, recurrence monitored, and evidence reproducible? | Approve the enterprise remediation action ledger, source-control mappings, owner queues, signed minutes, owner notifications, due-date acceptance, independent validation, customer/regulatory impact closure, recurrence monitoring, manifest mappings, action packs, and evidence custody before management closes material actions. | enterprise-remediation-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 250ce53a7cbf...f42f6644 |
Internal audit charter, risk-based audit universe, annual plan, engagement quality, issue validation, and QAIP governance IIA 2024 Global Internal Audit Standards, Basel Committee internal audit function in banks, OCC internal and external audit handbook, and CBK Risk Management Guidelines / Audit Committee / Board Risk Committee / Internal Audit | Do internal audit controls prove independence, risk-based coverage, engagement quality, issue validation, QAIP, committee oversight, and examiner-ready custody evidence are complete and board-accountable? | Approve the internal audit charter, independence attestations, risk-based audit universe, critical-risk coverage, annual plan resources, engagement scope, RCM, sample coverage, working paper review, report issuance, management responses, issue validation, recurrence monitoring, QAIP, external assessment readiness, audit committee reporting, manifest mappings, action packs, and custody evidence before issuing the annual audit committee reliance pack. | control-assurance-pack, cyber-resilience-governance-pack, enterprise-remediation-governance-pack, examiner-custody-pack, finance-ledger-close-governance-pack, internal-audit-governance-pack, model-lifecycle-fair-lending-governance-pack, operational-risk-governance-pack, records-data-lifecycle-governance-pack, regulatory-supervisory-response-governance-pack, risk-data-aggregation-governance-pack, third-party-risk-governance-pack 12 controls / 12 routes | ready 12 assurance reviews / 0 open questions | 5bdd448f50d1...68a47901 |
Corporate board governance, director suitability, committee, conflict, related-party, policy, evaluation, and disclosure governance Basel Committee corporate governance principles for banks, OCC Corporate and Risk Governance, CBK Prudential Guideline on Corporate Governance, and G20-OECD Principles of Corporate Governance / Board / Audit Committee / Board Risk Committee / Nominations and Governance Committee | Do corporate board controls prove the board is fit, independent, informed, conflict-controlled, committee-supported, policy-accountable, transparent, evaluated, and supported by reproducible evidence? | Approve board charter, reserved matters, delegated authority, director fit-and-proper filings, independence and non-executive ratios, CPD, attendance, tenure, succession, committee mandates, quorum, minutes, related-party exposure controls, recusal, independent review, policy approvals, risk appetite, management accountability, board evaluation, disclosures, stakeholder channels, enterprise mappings, action packs, and custody evidence before issuing the annual corporate governance attestation. | board-risk-committee-pack, control-assurance-pack, corporate-board-governance-pack, enterprise-remediation-governance-pack, enterprise-risk-appetite-limit-governance-pack, examiner-custody-pack, finance-ledger-close-governance-pack, internal-audit-governance-pack, privacy-impact-pack, records-data-lifecycle-governance-pack, regulatory-supervisory-response-governance-pack, risk-data-aggregation-governance-pack, tax-statutory-obligation-governance-pack, third-party-risk-governance-pack 14 controls / 14 routes | ready 14 assurance reviews / 0 open questions | b065731bfeba...06264327 |
Third-party lifecycle, outsourcing, concentration, and exit risk governance Interagency Guidance on Third-Party Relationships, EBA outsourcing arrangements, EU DORA ICT third-party risk, FFIEC cyber and outsourcing risk governance, and BCBS operational resilience third-party dependency management / Vendor Risk Committee / Technology Committee / Board Risk Committee | Do third-party controls prove critical providers are risk-assessed, contractually controlled, continuously monitored, substitutable, exit-ready, data-safe, and board-accountable throughout the relationship lifecycle? | Approve material provider inventory, criticality, lifecycle stage, due diligence, audit and exit rights, subcontractor inventory, concentration exposure, SLA and incident monitoring, cyber and financial review recency, resilience and exit tests, data residency, and custody evidence before renewing or expanding critical providers. | third-party-risk-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 50a3f54c2694...30335b56 |
Recovery, resolution, and solvent wind-down readiness FSB Key Attributes recovery and resolution planning, BCBS operational resilience, and CBK Risk Management Guidelines / Crisis Management Team / ALCO / Capital Committee / Board Risk Committee | Do triggers, recovery options, continuity routes, communication plans, board authorities, and custody hashes prove the platform can recover or wind down in an orderly way under severe stress? | Approve trigger thresholds, recovery options, capital and liquidity restoration capacity, critical operation continuity, provider substitutability, solvent wind-down readiness, regulator and customer communication routes, board escalation trails, and recovery action evidence packs. | recovery-resolution-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 4ab83502907c...9476e92c |
Change, release, configuration, software supply-chain, deployment health, and rollback governance FFIEC Development, Acquisition, and Maintenance change management, FFIEC Architecture Infrastructure and Operations configuration management, NIST SP 800-128, NIST SP 800-218 SSDF, NIST CSF 2.0, and CBK Risk Management and Business Continuity guidance / Change Advisory Board / Technology Committee / Audit Committee / Board Risk Committee | Do change and release controls prove production changes are approved, tested, reversible, securely built, drift-controlled, monitored, and customer-safe before and after deployment? | Approve production-change risk tiers, business and customer impact reviews, approvals, segregation of duties, release gates, security and performance tests, canary and feature-flag controls, rollback plans, configuration baselines, supply-chain artifacts, deployment health, customer-harm counters, remediation links, and evidence custody before high-risk releases proceed. | api-platform-governance-pack, change-release-configuration-governance-pack, control-assurance-pack, cyber-resilience-governance-pack, identity-access-governance-pack, operational-risk-governance-pack 6 controls / 6 routes | ready 6 assurance reviews / 0 open questions | d465fa281ccc...08197d19 |
Operational continuity, exit portability, provider substitutability, and wind-down execution readiness BCBS operational resilience, EBA outsourcing exit strategies, EU DORA ICT third-party risk, PRA SS2/21 outsourcing and third-party risk, and CBK Risk Management and Business Continuity guidance / Vendor Risk Committee / Technology Committee / Crisis Management Team / Board Risk Committee | Do exit and portability controls prove critical functions can be transferred, substituted, exported, communicated, and wound down without avoidable customer harm or evidence loss? | Approve critical-function exit tests, provider data-return and step-in rights, alternate-provider readiness, concentration limits, portable dataset exports, transition rehearsals, solvent wind-down modules, communication routes, board minutes, action packs, and custody evidence before material provider renewal or recovery plan attestation. | crisis-command-governance-pack, operational-continuity-exit-governance-pack, recovery-resolution-governance-pack, risk-data-aggregation-governance-pack, third-party-risk-governance-pack 5 controls / 5 routes | ready 5 assurance reviews / 0 open questions | 87c6ca3b7c7a...ce6634ba |
Model lifecycle, challenger evidence, fair lending, and adverse-action governance Revised Interagency Guidance on Model Risk Management (2026), NIST AI RMF, CFPB complex-algorithm adverse action, and fair-lending adverse action / Model Risk Committee / Board Risk Committee | Do lifecycle evidence, data lineage, validation sign-offs, challenger results, fair-lending reviews, breach tickets, notice gates, and custody hashes support continued automated decisioning? | Approve model lifecycle evidence, development data lineage, validation attestations, challenger evidence, fair-lending reviews, drift and override monitoring, adverse-action quality gates, model change and retirement controls, and custody package evidence for production use. | fair-lending-pack, model-lifecycle-fair-lending-governance-pack, model-risk-pack, model-validation-attestation-pack 4 controls / 3 routes | ready 4 assurance reviews / 0 open questions | 77375e2f1cea...aafb9aec |
Credit bureau furnishing, CRB dispute, correction, and adverse reporting governance Kenya Banking Credit Reference Bureau Regulations 2020, CFPB Regulation V FCRA furnisher duties, World Bank General Principles for Credit Reporting, and credit-information evidence custody / Credit Risk Committee / Conduct Committee / Risk and Compliance Committee / Board Risk Committee | Do bureau controls prove credit information is consented, accurate, complete, timely, disputed records are investigated and corrected, negative listings are notice-controlled, and evidence is reproducible for customers, CRBs, board, and supervisors? | Approve bureau consent, purpose limitation, named-bureau evidence, withdrawal route, privacy notice, retention link, portfolio furnishing timeliness, identity match, account-status and arrears mappings, negative-listing pre-notices, right-to-dispute and cure routes, vulnerable-customer review, adverse reason traces, notice of dispute, investigation, source-record trace, correction/deletion, bureau update, customer response, regulator escalation, synthetic-action blocking, custody hashes, and board credit reporting evidence. | credit-bureau-furnishing-governance-pack, fair-lending-pack 2 controls / 2 routes | ready 2 assurance reviews / 0 open questions | bb6dedbd76c6...930831ee |
AI operator tool agency, approval, provenance, and safety governance NIST AI RMF, NIST AI 600-1 Generative AI Profile, OWASP LLM Top 10 2025, and ISO/IEC 42001 / AI Governance Council / Model Risk Committee / Board Risk Committee | Are AI operator actions bounded, evidence-backed, human-approved for high-impact use, auditable, and safe under prompt attack or source outage? | Approve tool registry health, high-impact approval gates, confidence triage, prompt-injection and excessive-agency controls, redacted execution inputs, live-source provenance, privacy and fair-lending links, incident loops, and custody evidence before expanding AI operator autonomy. | ai-operator-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 267abd2ab29b...d4c59d1b |
Cyber resilience threat, vulnerability, identity, backup, and incident governance; cryptographic key custody governance NIST CSF 2.0, CIS Critical Security Controls v8.1, ISO/IEC 27001:2022 ISMS, and FFIEC cyber risk management and self-assessment guidance; NIST key management guidance, FIPS 140-3, and PCI DSS key management / Cyber Risk Committee / Technology Committee / Board Risk Committee | Do cyber controls prove the platform can govern, identify, protect, detect, respond, and recover from material cyber threats with reproducible evidence and board-ready accountability? Do cyber and cryptographic controls also prove recovery from key-compromise threats? | Approve cyber risk governance, attack-surface inventory, cryptographic key inventory, FIPS module boundaries, key custodian attestations, dual-control ceremonies, key rotation, escrow, destruction, privileged access MFA, secrets rotation, critical vulnerability SLA, EDR and SIEM coverage, ransomware recovery, customer-harm review, regulator-notice readiness, third-party compromise drills, action packs, and custody evidence before signing cyber-risk attestations. | cryptographic-key-custody-governance-pack, cyber-resilience-governance-pack 2 controls / 2 routes | ready 2 assurance reviews / 0 open questions | 1fb2fcef6157...32acfd2f |
Identity access, privileged account, service account, and break-glass governance NIST CSF 2.0 PR.AA identity management, authentication, and access control, CIS Controls v8.1 account and access control management, and FFIEC Architecture, Infrastructure, and Operations identity governance / Cyber Risk Committee / Technology Committee / Board Risk Committee | Do identity controls prove every privileged, service, support, and emergency access path is owned, strongly authenticated, least-privileged, reviewed, time-bound, revoked when expired, and reproducible for audit? | Approve identity inventory, MFA and phishing-resistant authentication, least privilege, segregation-of-duties controls, access review recertification, privileged event approval, service account rotation, break-glass review, session policy, and custody evidence before expanding privileged or sensitive access. | identity-access-governance-pack, security-control-pack 2 controls / 2 routes | ready 2 assurance reviews / 0 open questions | 2b0550943f65...88852d9c |
API platform security, consent, partner, quota, and resilience governance OpenID FAPI 2.0, OWASP API Security Top 10 2023, NIST SP 800-204A, NIST SP 800-218, and consumer-permissioned financial data rights / API Governance Council / Technology Committee / Board Risk Committee | Do partner APIs prove strong authentication, scoped consent, object authorization, throttling, webhook integrity, release assurance, and reproducible evidence before production use? | Approve financial-grade API authentication, OAuth/mTLS/HMAC controls, consent-scoped borrower-data access, deterministic sandbox contracts, partner security review, rate limits, webhook signing, release assurance, and custody evidence before expanding partner API access. | api-platform-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 9b71edcf6f35...3382eb3a |
Open-finance consent, data rights, recipient oversight, and revocation governance CFPB Personal Financial Data Rights Rule 12 CFR Part 1033, eCFR Regulation 1033, Open Banking Standard consent and data management good practice, EBA PSD2 strong customer authentication and common secure communication, FCA open banking and open finance consumer protection, Kenya Financial Consumer Protection Framework, and evidence custody / Technology Committee / Conduct Committee / Privacy Governance Forum / Board Risk Committee | Do open-finance controls prove customer data sharing is permissioned, specific, revocable, portable, recipient-controlled, reconciled, fail-closed on synthetic data, and reproducible for customers, partners, board, and supervisors? | Approve plain-language consent journeys, purpose-specific scopes, data category limits, bounded duration, revocation routes, customer notices, customer authentication, token binding, least privilege, data minimization, refresh reviews, access logs, revocation, portability, restriction, deletion, partner notification, customer confirmation, DSAR linkage, recipient due diligence, contract data-use limits, onward-sharing prohibition, breach notice, deletion certificate, reconciliation, live-read, synthetic-action blocking, and custody evidence before expanding open-finance data sharing. | api-platform-governance-pack, open-finance-consent-governance-pack, privacy-impact-pack, records-data-lifecycle-governance-pack 4 controls / 4 routes | ready 4 assurance reviews / 0 open questions | 2d9f3a53f344...32aa6c39 |
Fraud and scam risk alert, case, hold, redress, and evidence governance FFIEC authentication and access risk management, FATF risk-based financial-crime controls, CFPB elder financial exploitation response, NIST CSF 2.0 Detect/Respond/Recover, and operational-risk fraud loss governance / Fraud Risk Committee / Financial Crime Committee / Board Risk Committee | Do fraud controls prevent disbursement and customer harm, preserve evidence, escalate suspicious activity, recover losses, validate signals, and reproduce the decision trail for board and supervisory review? | Approve fraud typology monitoring, high-risk alert escalation, disbursement holds, identity/device/velocity/CRB/Fuliza signals, vulnerable-customer and elder financial exploitation response, reimbursement readiness, fraud loss recovery, model-signal validation, and evidence custody before expanding automated disbursement release. | fraud-risk-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 26cbcba4e1fe...613b19ce |
Scam reimbursement, fraud victim care, receiving-party recovery, and fraud reporting governance PSR APP scam reimbursement protections and compliance monitoring, EBA PSD2 fraud reporting, CFPB Regulation E unauthorized transfer and error-resolution controls, Kenya Financial Consumer Protection Framework, CBK fraud safety, and World Bank complaints and redress good practices / Fraud Risk Committee / Financial Crime Committee / Payments Risk Committee / Conduct Committee / Board Risk Committee | Do scam reimbursement controls prove victims are acknowledged, assessed, reimbursed or explained, supported, protected from recurrence, and backed by recovery, reporting, redress, and tamper-evident evidence? | Approve scam and unauthorized-transfer intake, reimbursement liability decisions, vulnerable-customer support, customer explanations, reimbursement clocks, GL postings, receiving-party freezes, payment recalls, provider disputes, mule escalation, fraud statistics, CBK/regulator packs, root-cause remediation, and custody hashes before expanding instant-payment or automated recovery workflows. | aml-str-evidence-pack, customer-outcomes-redress-governance-pack, finance-ledger-close-governance-pack, financial-crime-governance-pack, fraud-risk-governance-pack, payment-error-resolution-governance-pack, payment-settlement-assurance-pack, scam-reimbursement-governance-pack 8 controls / 8 routes | ready 8 assurance reviews / 0 open questions | 1aa15f0d0a3b...dfb24f23 |
Financial-crime KYC, CDD, beneficial ownership, screening, and reporting governance FATF Recommendations risk-based AML/CFT/CPF, FinCEN customer due diligence and beneficial ownership, Kenya FRC suspicious and unusual transaction reporting, and sanctions/PEP/adverse-media governance / Financial Crime Committee / Risk and Compliance Committee / Board Risk Committee | Do KYC/CDD, beneficial ownership, EDD, screening, transaction monitoring, suspicious report filing, no-tipping-off controls, goAML readiness, and custody hashes prove financial-crime risk is controlled and board-accountable? | Approve customer risk rating, CDD, expected activity, beneficial ownership, sanctions, PEP, adverse-media screening, high-risk EDD, ongoing monitoring, STR/SAR filing readiness, no-tipping-off controls, goAML evidence, and custody hashes before expanding onboarding or product limits. | aml-str-evidence-pack, financial-crime-governance-pack 2 controls / 2 routes | ready 2 assurance reviews / 0 open questions | 7f5228baaa67...fc06ef79 |
Business network KYB, merchant, supplier, anchor-buyer, marketplace, and exposure-gate governance FATF risk-based CDD and ongoing monitoring, FATF Recommendation 24 beneficial ownership, Kenya beneficial ownership and digital credit provider controls, OECD responsible business conduct due diligence, World Bank integrity compliance, IFC due diligence, and marketplace evidence custody / Risk and Compliance Committee / Credit Risk Committee / Fraud Risk Committee / Board Risk Committee | Do business-network KYB controls prove legal entity counterparties are verified, beneficial owners current, screening clear, settlement and permits controlled, marketplace abuse triaged, exposure gates enforced, renewals current, and evidence reproducible for board and supervisors? | Approve merchant, supplier, anchor-buyer, dealer-importer, and logistics-partner KYB evidence, registration and tax PIN checks, beneficial ownership verification, ownership-register recency, sanctions, PEP, adverse media, bank-account and permit evidence, privacy notices, expected activity profiles, velocity monitoring, duplicate-invoice screening, settlement-account matching, concentration limits, relationship activity reviews, action packs, custody hashes, and board marketplace-risk evidence before expanding RFQ awards, SCF invoice purchases, RBF drawdowns, vehicle import dealer limits, or group procurement exposure. | business-network-kyb-governance-pack, credit-lifecycle-governance-pack, financial-crime-governance-pack, fraud-risk-governance-pack, payment-settlement-assurance-pack, privacy-impact-pack, records-data-lifecycle-governance-pack, third-party-risk-governance-pack 8 controls / 8 routes | ready 8 assurance reviews / 0 open questions | 688d15a5b253...0fdc7493 |
Portfolio concentration, stress, and capital appetite BCBS 239 risk data aggregation, Basel credit risk principles, and CBK risk management guidelines / ALCO / Board Risk Committee | Do concentration limits, forward NPA, macro shocks, VaR, and covenant early warnings remain inside approved appetite with hashed owner evidence? | Approve concentration breaches, forward NPA paths, macro stress product impacts, VaR exceptions, covenant actions, and capital appetite evidence packs. | portfolio-risk-appetite-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | a52254cd93da...41c3f870 |
Credit lifecycle, collateral, early warning, and workout governance BCBS Principles for the Management of Credit Risk, CBK Risk Management Guidelines, and CBK PG/04 Risk Classification and Provisioning / Credit Risk Committee / Special Assets Committee / Board Risk Committee | Do lifecycle stages, policy controls, collateral, monitoring, early-warning, workout, write-off, and custody evidence prove credit risk is controlled from origination through recovery? | Approve credit policy discipline, granting controls, affordability and model challenge, adverse-action QA, collateral valuation and LTV controls, covenant and early-warning actions, classification and provisioning links, workout cure rates, restructuring controls, write-off recovery postmortems, and credit lifecycle custody evidence. | credit-lifecycle-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | fadabc90eb80...bd7ae616 |
Responsible lending, affordability, creditworthiness, and borrower outcome governance EBA Guidelines on loan origination and monitoring creditworthiness assessment, World Bank responsible lending and over-indebtedness consumer protection, FCA Consumer Duty borrower difficulty protections, Kenya Financial Consumer Protection Framework, and responsible-lending evidence custody / Credit Risk Committee / Conduct Committee / Model Risk Committee / Board Risk Committee | Do affordability controls prove credit is granted only when income, expenses, obligations, stress capacity, vulnerable-customer safeguards, exceptions, notices, customer choice, and custody evidence are complete and reproducible? | Approve income verification, source recency, confidence, documentary, bank-statement, tax/payroll, M-Pesa cashflow, volatility, consent, privacy, retention, expense reasonableness, essential-expense protection, obligation completeness, DSR, PTI, residual income, stress affordability, vulnerable-customer safeguards, hardship history, manual exception approval, decline and adverse-action notices, explainability, customer choice, synthetic-action blocking, and custody evidence before expanding automated or manual credit approvals. | credit-lifecycle-governance-pack, fair-lending-pack, responsible-lending-affordability-governance-pack 3 controls / 3 routes | ready 3 assurance reviews / 0 open questions | 6a851538de8a...2876980f |
Co-lending partner, participation, allocation, settlement, servicing, and concentration governance Basel Committee credit-risk principles, Basel large exposures and securitisation risk-transfer framework, EBA loan origination and monitoring, IFRS 9 financial asset transfer controls, CBK Risk Management Guidelines, Kenya Financial Consumer Protection Framework, World Bank financial consumer protection practices, and evidence custody / Credit Risk Committee / Vendor Risk Committee / Audit Committee / Conduct Committee / Board Risk Committee | Do co-lending controls prove partner risk, borrower fairness, allocation discipline, risk transfer, cashflow settlement, servicing, concentration appetite, and custody evidence are complete, fair, reconciled, and reproducible? | Approve co-lending partner eligibility, due diligence, financial review, contract and audit rights, credit approval, risk-share documentation, covenant mapping, exit plans, borrower disclosure, consent, allocation eligibility, risk retention, adverse-selection blocking, pricing parity, exception review, explainability, settlement waterfall match, partner-share reconciliation, borrower and GL posting, suspense clearance, participant statements, servicing reports, borrower and delinquency notices, hardship protocols, complaint handoffs, concentration limits, stressed exposure, early-warning, capital impact, live-read, synthetic-action blocking, and custody evidence before expanding co-lending or participation programmes. | co-lending-participation-governance-pack, credit-lifecycle-governance-pack, finance-ledger-close-governance-pack, payment-settlement-assurance-pack, third-party-risk-governance-pack 5 controls / 5 routes | ready 5 assurance reviews / 0 open questions | aff6843a1605...7042115a |
Capital markets issuance, investor protection, bookbuilding, settlement, trading, disclosure, and funding concentration governance IOSCO securities regulation objectives and ongoing disclosure principles, IOSCO suitability and international debt disclosure expectations, Kenya Capital Markets Authority issuer and market-conduct expectations, Basel large exposures and securitisation framework, CPMI-IOSCO PFMI settlement finality, IFRS 7 and IFRS 9 financial instrument controls, and evidence custody / ALCO / Conduct Committee / Audit Committee / Capital Markets Committee / Board Risk Committee | Do capital markets controls prove issuance, investor suitability, allocation fairness, settlement integrity, market conduct, disclosure timeliness, funding concentration, and custody evidence are complete, fair, live-read backed, and reproducible for investors, trustees, custodians, auditors, board, and supervisors? | Approve issuer board approval, prospectus currency, legal review, regulator filing, credit rating, trustee appointment, custodian readiness, use-of-proceeds, listing approval, investor eligibility, KYC, AML, suitability, risk disclosure, appropriateness, concentration cap, cooling-off, complaint route, order compliance, allocation fairness, price discovery, conflict checks, insider restrictions, audit trails, settlement matching, segregated funds, CSD instruction, refund route, GL posting, investor statements, trade verification, price exception monitoring, late-report monitoring, best execution, market-abuse surveillance, settlement finality, ongoing disclosure, covenant reporting, material development reporting, ECL and portfolio metrics, data lineage, redaction, board signoff, funding concentration, liquidity impact, refinancing plans, live-read, synthetic-action blocking, and custody evidence before launching or expanding capital markets programmes. | capital-markets-issuance-governance-pack, finance-ledger-close-governance-pack, financial-crime-governance-pack, market-fx-risk-governance-pack, payment-settlement-assurance-pack, product-pricing-fair-value-governance-pack, treasury-liquidity-risk-pack 7 controls / 7 routes | ready 7 assurance reviews / 0 open questions | 190d04063ec1...33ee2718 |
Structured credit securitisation, true-sale, capital relief, risk retention, and investor reporting governance Basel securitisation framework, IOSCO ABS disclosure principles, IFRS 9 financial asset transfer and derecognition, IFRS 7 transferred financial asset disclosures, EBA STS and risk-retention expectations, Kenya Capital Markets Authority asset-backed securities expectations, and evidence custody / ALCO / Capital Committee / Audit Committee / Conduct Committee / Board Risk Committee | Do structured credit controls prove loan pools are eligible, true sale and derecognition are supportable, tranches and waterfalls are controlled, servicers are substitutable, investor reports are current, capital relief is backed by significant risk transfer and retention, and evidence is reproducible for investors, auditors, board, and supervisors? | Approve loan-pool eligibility, data tape, concentration, delinquency, customer notice, consent or disclosure, adverse-selection blocking, true-sale legal opinion, derecognition assessment, originator isolation, servicing transfer notices, accounting and tax memos, board and regulator notice, SPV tranche enhancement, reserve and liquidity support, trustee and custodian readiness, investor suitability, offering circulars, collection waterfalls, trigger monitoring, segregated accounts, GL posting, servicer continuity, backup servicing, data escrow, complaint handoff, investor reporting, material development disclosure, RWA before and after, significant risk transfer, risk retention, cleanup call control, implicit-support blocking, stress impact, finance reconciliation, live-read, synthetic-action blocking, and custody evidence before approving securitisation launch, sale recognition, investor distribution, or capital relief. | capital-icaap-evidence-pack, capital-markets-issuance-governance-pack, co-lending-participation-governance-pack, control-assurance-pack, credit-lifecycle-governance-pack, customer-outcomes-redress-governance-pack, enterprise-risk-appetite-limit-governance-pack, enterprise-stress-testing-governance-pack, finance-ledger-close-governance-pack, loan-servicing-repayment-governance-pack, payment-settlement-assurance-pack, portfolio-risk-appetite-pack, responsible-lending-affordability-governance-pack, risk-adjusted-profitability-ftp-governance-pack, risk-data-aggregation-governance-pack, structured-credit-securitisation-governance-pack 16 controls / 16 routes | ready 16 assurance reviews / 0 open questions | 55f58e2de4b5...39c9592f |
External data-room, investor due-diligence, regulator, audit, partner, and board disclosure governance NIST CSF 2.0, NIST SP 800-53 access, audit, media protection, and privacy controls, ISO/IEC 27001 information security management, EU GDPR, Kenya Data Protection Act and ODPC Data Sharing Code, IOSCO disclosure and investor-protection principles, and evidence custody / Board Risk Committee / Audit Committee / Technology Committee / Conduct Committee / Capital Markets Committee | Do external data-room controls prove every investor, regulator, auditor, partner, and board disclosure room is lawful, purpose-bound, least-privilege, redacted, privilege-reviewed, watermarked, audited, revocable, live-read backed, and reproducible for board and supervisory review? | Approve room purpose, legal basis, purpose limitation, recipient approval, NDA coverage, board or deal approval, expiry, watermarking, download controls, export scope, redaction, classification, privilege review, PII scan, disclosure index, retention policy, source-read provenance, synthetic-export blocking, MFA, KYC or accreditation, least privilege, access review, materiality review, selective-disclosure guard, legal review, privacy review, version control, Q&A log, regulator route, activity logging, anomaly monitoring, alerting, revocation SLA, recipient notice, watermark trace, legal hold, regulator notice route, root cause, live-read, synthetic-action blocking, and custody evidence before opening, expanding, or certifying external data rooms. | board-risk-committee-pack, capital-markets-issuance-governance-pack, control-assurance-pack, cyber-resilience-governance-pack, external-data-room-governance-pack, finance-ledger-close-governance-pack, identity-access-governance-pack, privacy-impact-pack, records-data-lifecycle-governance-pack, regulatory-supervisory-response-governance-pack, risk-data-aggregation-governance-pack, structured-credit-securitisation-governance-pack 12 controls / 12 routes | ready 12 assurance reviews / 0 open questions | 38aead238eae...47aff648 |
Market conduct, market abuse surveillance, insider-list, market-sounding, best-execution, communications, and regulatory reporting governance IOSCO Objectives and Principles of Securities Regulation, EU Market Abuse Regulation, ESMA STOR expectations, Kenya Capital Markets Act, CMA conduct-of-business expectations, and evidence custody / Conduct Committee / Capital Markets Committee / Audit Committee / Technology Committee / Board Risk Committee | Do market conduct controls prove trading, sounding, insider-list, best-execution, communications, and regulatory-reporting evidence is complete, timely, fair, live-read backed, and reproducible for investors, regulators, auditors, board committees, and supervisors? | Approve market-abuse scenario coverage, alert disposition, critical-alert closure, trade-order linkage, price-volume benchmark, restricted list, watch list, wall-crossing log, MNPI room, personal-account-dealing review, market-sounding consent, approved script, disclosure pack, recording, cleanse notice, best-execution benchmark, venue policy, cost disclosure, price challenge, communications capture, lexicon review, escalation closure, retention, case linkage, STOR decisioning, regulator route, filing SLA, live-read, synthetic-action blocking, and custody evidence before launching, expanding, or certifying capital-markets conduct activities. | board-risk-committee-pack, capital-markets-issuance-governance-pack, control-assurance-pack, external-data-room-governance-pack, finance-ledger-close-governance-pack, financial-crime-governance-pack, market-conduct-surveillance-governance-pack, market-fx-risk-governance-pack, payment-settlement-assurance-pack, privacy-impact-pack, product-pricing-fair-value-governance-pack, records-data-lifecycle-governance-pack, regulatory-supervisory-response-governance-pack, risk-data-aggregation-governance-pack, structured-credit-securitisation-governance-pack 15 controls / 15 routes | ready 15 assurance reviews / 0 open questions | 7043689412e3...202aa6ef |
Sustainable finance taxonomy, use-of-proceeds, impact claims, target calibration, verification, safeguards, and greenwashing governance ICMA Green Bond Principles, ICMA Social Bond Principles, ICMA Sustainability-Linked Bond Principles, ICMA Sustainability Bond Guidelines, Kenya Green Finance Taxonomy, IFRS S1 and IFRS S2, UNDP SDG Impact Standards, UNEP FI climate target-setting for banks, and sustainable-finance evidence custody / Sustainable Finance Committee / Conduct Committee / Audit Committee / ALCO / Board Risk Committee | Do sustainable finance controls prove every green, social, sustainability, and sustainability-linked claim is taxonomy-eligible, proceeds-reconciled, impact-measured, target-calibrated, independently assured, no-harm reviewed, live-read backed, and reproducible for customers, investors, assurers, board, and supervisors? | Approve taxonomy criteria, climate objective mapping, DNSH, minimum safeguards, exclusion screening, use-of-proceeds allocation, unallocated proceeds limits, escrow and invoice reconciliation, borrower consent, refinancing lookback, impact measurement method, data lineage, beneficiary evidence, double-counting blocks, negative-impact review, disclosure approval, sustainability target materiality, KPI calibration, penalty mechanism, external benchmark, board approval, independent verification, assurance scope, sample coverage, public reporting, safeguard screening, grievance resolution, vulnerable-customer review, community consent, privacy, no-harm, redress, live-read, synthetic-action blocking, greenwashing suppression, and custody evidence before sustainable labels, investor impact reports, or sustainability-linked pricing expand. | capital-markets-issuance-governance-pack, climate-risk-disclosure-pack, customer-outcomes-redress-governance-pack, product-pricing-fair-value-governance-pack, risk-data-aggregation-governance-pack, sustainable-finance-impact-governance-pack 6 controls / 6 routes | ready 6 assurance reviews / 0 open questions | 7113b2622630...ee20e92e |
Collateral valuation, lien perfection, custody, insurance, recovery, and asset disposition governance Basel Principles for the Management of Credit Risk, CBK Risk Management Guidelines, EBA loan origination and monitoring collateral valuation expectations, IFRS 13 fair value measurement, and legal enforceability evidence custody / Credit Risk Committee / Recoveries Committee / Conduct Risk Committee / Board Risk Committee | Do collateral controls prove assets are independently valued, legally enforceable, custodied, insured, dispute-controlled, fair in recovery, fail-closed on synthetic data, and reproducible for board and supervisory review? | Approve independent valuation, fair-value method evidence, forced-sale values, LTV limits, registry searches, perfected liens, priority and consent checks, fraud/caveat clearance, document custody, insurance cover, lender-interest notation, claim routes, recovery notices, vulnerable-customer review, approved repossession agents, sale valuation, shortfall disclosure, synthetic-action blocking, and custody evidence before expanding collateral-backed credit or enforcing security. | collateral-valuation-custody-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | c95fb83050e5...7907afa9 |
Collections conduct, hardship forbearance, repossession, and write-off governance CBK Risk Management Guidelines, Kenya Financial Consumer Protection Framework, World Bank Financial Consumer Protection Good Practices, and FCA Consumer Duty borrower difficulty protections / Collections Conduct Committee / Special Assets Committee / Board Risk Committee | Do collections, forbearance, repo/legal, write-off, and borrower-outcome controls prove that recovery activity is effective, fair, and evidence-backed? | Approve DPD strategy controls, consent-aware contact discipline, hardship screening, forbearance offers, vulnerable-customer review, promise-to-pay integrity, legal and repossession holds, write-off recovery, customer-outcome postmortems, and collections custody evidence. | collections-forbearance-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 15f4a0284259...b6a3deb1 |
Loan servicing statement, repayment allocation, payoff, refund, dispute, and reconciliation governance CFPB Regulation Z periodic statement, payoff statement, and payment allocation expectations, World Bank financial consumer protection servicing and disclosure good practices, FCA Consumer Duty borrower support and fair treatment, Kenya Financial Consumer Protection Framework, and servicing evidence custody / Conduct Committee / Credit Risk Committee / Audit Committee / Board Risk Committee | Do servicing controls prove borrower-visible balances, statements, payment allocation, payoff quotes, exceptions, disputes, redress, reconciliations, and custody evidence are accurate, fair, timely, and reproducible? | Approve statement accuracy, amount due arithmetic, principal/interest/fee splits, due date and arrears evidence, delivery channels, dispute routes, accessibility, repayment waterfall order, payment allocation balance, suspense handling, fee-cap checks, borrower instructions, overpayment handling, GL posting, schedule updates, payoff quote SLA, good-through dates, per-diem, fee itemization, waiver credits, collateral release, waiver, reversal, refund, notice, redress, root cause, payment rail-to-ledger reconciliation, statement-to-ledger reconciliation, payoff-to-ledger reconciliation, synthetic-action blocking, and custody evidence before expanding loan servicing automation. | customer-outcomes-redress-governance-pack, finance-ledger-close-governance-pack, loan-servicing-repayment-governance-pack, payment-settlement-assurance-pack 4 controls / 4 routes | ready 4 assurance reviews / 0 open questions | bf53517aebb1...41fc05a2 |
Payment error, unauthorized transfer, provisional credit, refund, redress, and reconciliation governance CFPB Regulation E Electronic Fund Transfer Act error-resolution and unauthorized-transfer expectations, World Bank financial consumer protection complaints and redress good practices, CPMI-IOSCO PFMI payment finality and operational-risk expectations, Kenya Financial Consumer Protection Framework, and payment error evidence custody / Payments Risk Committee / Conduct Committee / Audit Committee / Board Risk Committee | Do payment error controls prove unauthorized transfers, incorrect transfers, omitted transfers, refunds, provisional credits, provider disputes, redress, reconciliations, and custody evidence are fair, timely, accurate, customer-visible, and reproducible? | Approve oral and written payment error notice intake, customer identity, account, transaction, amount, acknowledgement, consumer liability assessment, investigation SLA, transaction trace, ledger trace, provider trace, customer interview, written explanation, correction decision, provisional credit, reversal control, refund, root cause, maker-checker approval, rail reversal, GL correction, customer notice, redress, provider ticket, callback, settlement file, customer impact, reconciliation, live-read, synthetic-action blocking, and custody evidence before expanding payment error automation. | customer-outcomes-redress-governance-pack, finance-ledger-close-governance-pack, payment-error-resolution-governance-pack, payment-settlement-assurance-pack 4 controls / 4 routes | ready 4 assurance reviews / 0 open questions | 4287a90d1651...d9b43ec5 |
Customer outcomes, complaint handling, vulnerable support, redress, and dispute escalation governance World Bank financial consumer protection complaints handling and dispute resolution, FCA Consumer Duty consumer support and vulnerable-customer outcomes, CBK Prudential Guideline on Consumer Protection complaint procedures, and G20-OECD financial consumer protection complaints handling and redress / Conduct Committee / Risk and Compliance Committee / Audit Committee / Board Risk Committee | Do customer outcomes controls prove complaints are accessible, fair, timely, vulnerable-customer aware, redress-ready, externally escalatable, root-cause remediated, third-party accountable, and reproducible for board and supervisory review? | Approve complaint intake source traces, acknowledgement and SLA clocks, owner assignment, impartial review, vulnerable-customer needs assessments, adjusted communication, hardship review, redress eligibility, calculation, maker-checker approval, payout/correction and ledger mapping, tax and fee treatment, internal appeal, ombudsman/CBK and regulator routes, legal review, approved customer scripts, third-party accountability, root-cause remediation, recurrence monitoring, independent validation, board minutes, synthetic-action blocking, custody hashes, and board customer-outcomes package evidence. | conduct-outcomes-pack, customer-outcomes-redress-governance-pack 2 controls / 2 routes | ready 2 assurance reviews / 0 open questions | c4eb076d7576...48139fe4 |
Inclusive customer access, accessibility, language, comprehension, assisted-channel, and financial capability governance WCAG 2.2 accessibility, W3C cognitive accessibility, UN CRPD accessible information and communications, G20-OECD financial consumer protection, World Bank financial consumer protection, CGAP responsible digital credit, GSMA mobile money customer treatment, and Kenya consumer protection expectations / Customer and Conduct Committee / Technology Committee / Product Governance Committee / Board Risk Committee | Do inclusive access controls prove customers can understand, access, compare, consent, complain, get help, use fallback channels, and build financial capability without avoidable exclusion or evidence loss? | Approve WCAG critical journey evidence, keyboard and screen-reader readiness, focus visibility, error prevention, timeout extension, color contrast, plain-language scores, translated disclosures, comprehension testing, assisted-channel authentication, consent, transcripts, privacy scripts, vulnerable-customer handoffs, complaint routes, USSD and low-bandwidth fallback, financial education modules, numeracy examples, cost-of-credit and data-use explanations, knowledge checks, defect remediation, synthetic-action blocking, action packs, custody hashes, and board inclusive-access evidence before expanding customer journeys or growth campaigns. | conduct-outcomes-pack, customer-harm-pack, customer-outcomes-redress-governance-pack, inclusive-customer-access-governance-pack, open-finance-consent-governance-pack, privacy-impact-pack, product-pricing-fair-value-governance-pack, responsible-lending-affordability-governance-pack 8 controls / 8 routes | ready 8 assurance reviews / 0 open questions | f75e03256687...35dbc676 |
IFRS 9 ECL staging, allowance adequacy, and impairment governance IFRS 9 expected credit loss impairment, Basel ECL guidance, and CBK provisioning comparison / Impairment Committee / Audit and Risk Committee / Board Risk Committee | Do staging, provision adequacy, loan-level EAD/PD/LGD/ECL, recomputation evidence, and custody hashes support reporting-close allowance sign-off? | Approve Stage 1, Stage 2, Stage 3, SICR, credit-impaired exposure, CBK shortfall, top-loan concentration, loan-level evidence, recomputation recency, and allowance action evidence packs. | ifrs9-ecl-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | ede145792ef5...7bf9f551 |
Capital adequacy, ICAAP, and stress capital readiness Basel III capital framework, Basel leverage ratio, and CBK PG/04 capital adequacy / Capital Committee / Board Risk Committee | Do capital ratios, stress scenarios, RWA composition, leverage proxy, NPL triggers, and provenance hashes support planned growth and regulator-ready returns? | Approve CAR, Tier 1, RWA density, stress capital floor, leverage proxy, NPL trigger, provenance, and ICAAP action evidence packs. | capital-icaap-evidence-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 94e1cdd8e17d...58fb38d3 |
Climate financial risk and disclosure readiness BCBS climate-related financial risk principles, CBK Climate-Related Risk Management, IFRS S2, and TCFD / Board Risk Committee / Sustainability Committee | Do climate scenarios, classified exposures, emissions proxies, covenant triggers, methodology, and disclosure hashes prove climate risk is governed, measured, and board-challenged? | Approve transition exposure, physical exposure, stressed climate loss uplift, financed-emissions proxy, green finance opportunity, scenario coverage, methodology, and disclosure action evidence packs. | climate-risk-disclosure-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 6c957fac7a3a...c5717765 |
Liquidity, funding concentration, and contingency funding readiness BCBS liquidity risk principles, Basel III LCR, and CBK Basel III liquidity standards / ALCO / Board Risk Committee | Do liquidity ladder, LCR, ALM shocks, funding sources, and contingency actions prove the platform can survive stressed outflows? | Approve LCR, survival-horizon, liquidity-gap, duration-gap, NII-at-risk, funding concentration, and contingency funding evidence packs. | treasury-liquidity-risk-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | a9048903e16c...742f0836 |
Market and FX open-position risk governance Basel market risk framework, BCBS Minimum capital requirements for market risk, CBK Foreign Exchange Exposure Limits, and CBK Risk Management Guidelines / ALCO / Board Risk Committee / Audit Committee | Do exposure limits, hedge controls, independent valuation, stress scenarios, KRIs, and custody hashes prove market and FX risk is measured, controlled, escalated, and board-challenged? | Approve FX open-position limits, prudential net-open-position ratios, hedge coverage, independent rate-source freshness, revaluation integrity, market stress losses, KRI thresholds, counterparty settlement controls, ALCO action packs, and custody evidence. | market-fx-risk-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | f51246382d85...a3f685cf |
Interest rate risk in the banking book and ALM governance Basel IRRBB standards, Basel Framework SRP31-SRP98, and CBK Risk Management Guidelines / ALCO / Board Risk Committee | Do earnings, economic-value, repricing, basis-risk, and behavioral optionality controls prove rate risk is inside board appetite with hashed evidence? | Approve source completeness, shock scenario coverage, NII earnings-at-risk, EVE proxy, repricing gap, duration limit, basis risk, optionality, and ALCO action evidence packs. | irrbb-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | d6301eb4eb3e...23c93d03 |
Payment settlement finality, rail resilience, and exception recovery CPMI-IOSCO PFMI, CPMI ISO 20022 harmonisation, and Kenya National Payment System risk controls / Payments Risk Committee / Board Risk Committee | Do payment batches, rails, references, provider health, retry/reversal actions, and custody hashes prove safe settlement under degraded rail conditions? | Approve settlement finality, pending exposure, rail resilience, latency, rail configuration, ISO 20022 reference, and exception recovery evidence packs. | payment-settlement-assurance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 3483a0ff5e00...573a7eb6 |
Deposits, wallet safeguarding, liquidity, dormant balance, and run-protection governance Basel Core Principles for effective banking supervision, CBK prudential and deposit-taking microfinance guidance, EBA payment services and e-money safeguarding, FCA payment and e-money safeguarding requirements, and customer-fund segregation governance / ALCO / Payments Risk Committee / Conduct Risk Committee / Board Risk Committee | Do deposits and wallet controls prove customer funds are segregated, reconciled, liquidity-backed, disclosure-ready, dormancy-controlled, fail-closed on synthetic data, and reproducible for board and supervisory review? | Approve savings, term-deposit, merchant float, agent float, and repayment wallet product governance, customer disclosures, rate-change notices, safeguarding account mappings, segregated customer-fund and wallet-float accounts, trustee acknowledgements, no-commingling controls, wallet-float reconciliation, liquidity run scenarios, dormant and unclaimed-balance controls, synthetic-action blocking, and custody evidence before expanding deposits or wallet balances. | deposits-wallet-safeguarding-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 6acbe56a4e58...a24c9c92 |
Insurance protection, claims fairness, premium trust, and reinsurance governance IAIS Insurance Core Principles, Kenya insurance conduct and licensing controls, Cap17 trust-pool segregation, IFRS 17 insurance contract evidence, and customer outcome governance / Insurance Governance Committee / Conduct Risk Committee / Board Risk Committee | Do insurance controls prove protection products are licensed or gated, fair-value reviewed, fund-segregated, claims-fair, reinsured, fail-closed on synthetic data, and reproducible for board and supervisory review? | Approve motor MGA, trade credit, repo protection, and mutual aid product governance, Cap17 gate evidence, premium trust and member-fund segregation, claims SLA and fairness controls, reinsurance and concentration cover, synthetic-action blocking, and custody evidence before expanding protection products. | insurance-protection-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 4fd7e0bb0795...7c5682ff |
Agent network, teller cash, commission payout, fraud, AML, and conduct governance CBK prudential and agency banking guidance, Basel operational risk and resilience principles, FATF risk-based AML/CFT financial inclusion guidance, GSMA mobile money agent network and safeguarding practices, and cash-operation evidence custody / Operational Risk Committee / Financial Crime Committee / ALCO / Conduct Risk Committee / Board Risk Committee | Do agent network and cash controls prove field operations are fit-and-proper, trained, liquid, reconciled, dual-controlled, fraud/AML routed, customer-redress ready, fail-closed on synthetic data, and reproducible for board and supervisory review? | Approve agent cluster fit-and-proper review, training completion, captain oversight, field liquidity, cash-out SLA, teller cash reconciliation, variance, dual control, supervisor approval, audit trail, safe limits, commission attestation, tax withholding, clawback, dispute windows, payout rails, fraud and AML incident routing, customer redress, synthetic-action blocking, and custody evidence before expanding agent coverage or commission campaigns. | agent-network-cash-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | d8d4c684912a...ed78bfc4 |
Regulatory, privacy, records lifecycle, and financial-crime governance CBK/ODPC/FRC horizon management, data protection, records management, and FATF AML/CFT/CPF / Conduct Risk Committee / Board Risk Committee | Are new regulatory obligations, CBK returns, DPIAs, processor controls, retention schedules, legal/regulator/AML/dispute holds, DSAR disposition evidence, archive custody, AML typologies, STR evidence packs, and launch blockers owned with regulator-ready evidence? | Approve regulator-ready evidence packs, CBK return inventory, API data-submission testing, source reconciliation, validation-rule inventories, maker-checker and officer attestations, acknowledgements, amendment controls, privacy launch gates, records retention and hold evidence, DSAR disposition workflows, archive disposal proofs, and AML STR evidence packs for high-risk processing changes. | aml-str-evidence-pack, privacy-impact-pack, records-data-lifecycle-governance-pack, regulatory-horizon-pack, regulatory-return-production-governance-pack 5 controls / 5 routes | ready 5 assurance reviews / 0 open questions | 3af3b6c808d5...14f8cbe3 |
Regulatory perimeter, licensing, key-person, change-control, product approval, and country expansion governance CBK Digital Credit Providers Regulations 2022, CBK DCP licensing procedures, National Payment System Regulations 2014, ODPC registration guidance, CMA licensing requirements, POCAMLA AML-CFT-CPF obligations, and regulatory perimeter evidence custody / Risk and Compliance Committee / Legal Control / Product Governance Committee / Board Risk Committee | Do perimeter controls prove every regulated activity is classified, licensed or registered, key persons are filed, material changes are held until notice or no-objection, and product or country launches are blocked until regulator-ready evidence exists? | Approve regulated activity classifications, licence and registration currentness, renewal windows, key-person fit-and-proper filings, source-of-funds evidence, ownership and third-party notice triggers, payment/data/AML/CMA/insurance gates, product launch holds, country expansion no-objection evidence, enterprise mappings, action packs, and custody evidence before regulated activities launch or change. | capital-markets-issuance-governance-pack, control-assurance-pack, corporate-board-governance-pack, financial-crime-governance-pack, insurance-protection-governance-pack, payment-settlement-assurance-pack, privacy-impact-pack, product-pricing-fair-value-governance-pack, records-data-lifecycle-governance-pack, regulatory-horizon-pack, regulatory-perimeter-licensing-governance-pack, regulatory-return-production-governance-pack, regulatory-supervisory-response-governance-pack, third-party-risk-governance-pack 14 controls / 14 routes | ready 14 assurance reviews / 0 open questions | f41af8a2bdf8...692d34ce |
Supervisory exam response, finding remediation, and regulatory commitment governance Basel Core Principles for Effective Banking Supervision, BCBS compliance function, BCBS corporate governance principles, CBK Risk Management Guidelines, and supervisory evidence custody / Risk and Compliance Committee / Legal Control / Board Risk Committee | Do supervisory response controls prove requests are triaged, responses are complete and approved, findings are remediated and validated, commitments are delivered, regulator communications are controlled, and evidence is reproducible for supervision? | Approve supervisory request intake, scope, due-date, owner assignment, legal privilege, confidentiality, evidence routes, response artifacts, QA, redaction, management approval, regulator submission and acknowledgement, single-message scripts, finding root-cause and customer-harm review, independent validation, commitment milestone delivery, regulator updates, synthetic-action blocking, custody hashes, and board escalation evidence. | regulatory-supervisory-response-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | ff70cbe2ae7d...3af46399 |
Tax and statutory obligation, payroll contribution, filing, reconciliation, and tax-position governance OECD Tax Control Framework and co-operative compliance, COSO internal control, Kenya Revenue Authority iTax, eTIMS, VAT, PAYE, withholding tax, corporate income tax, transfer-pricing, affordable housing levy, Social Health Authority, NSSF, and statutory evidence custody / Audit Committee / Risk and Compliance Committee / ALCO / Board Risk Committee | Do tax statutory controls prove obligations are registered, returns are prepared and filed, payments are remitted and reconciled, payroll deductions are complete and disclosed, tax positions are supported and provisioned, audit queries are remediated, and evidence is reproducible for auditors, board, and regulators? | Approve KRA obligation registration, iTax return preparation, payment slips, portal acknowledgements, bank payment proof, tax certificates, VAT, PAYE, withholding tax, corporate tax, affordable housing levy, SHA/SHIF, NSSF, NITA, employee population matching, deduction and employer contribution calculations, remittance files, payslip disclosures, eTIMS invoice controls, source-ledger-to-return-to-payment reconciliations, suspense clearance, tax technical memos, legal basis, external advisor review, provision approval, disclosure assessment, board visibility, audit-query remediation, live-read, synthetic-action blocking, and custody evidence before statutory filing, payroll close, or board audit signoff. | finance-ledger-close-governance-pack, payment-settlement-assurance-pack, regulatory-horizon-pack, regulatory-supervisory-response-governance-pack, risk-data-aggregation-governance-pack, tax-statutory-obligation-governance-pack 6 controls / 6 routes | ready 6 assurance reviews / 0 open questions | 0b35d44d576b...f713d429 |
Risk data aggregation, lineage, and supervisory reporting BCBS 239 risk data aggregation and risk reporting and CBK Risk Management Guidelines / Data Council / Board Risk Committee / Audit and Risk Committee | Do source lineage, data quality, timeliness, adaptability, reconciliation, and board risk reporting controls prove risk reports are complete, accurate, useful, and decision-ready? | Approve domain lineage, custody hash coverage, reporting SLA, ad hoc stress reporting, supervisory information requests, reconciliation cadence, board report route, and BCBS 239 action evidence packs. | risk-data-aggregation-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 76ee09bc44ff...06dbc105 |
Finance ledger, reconciliation, suspense, period close, audit, and reporting governance IFRS financial reporting discipline, COSO internal control, Basel corporate governance principles for banks, CBK Risk Management Guidelines, and ledger-close evidence custody / Audit Committee / ALCO / Impairment Committee / Board Risk Committee | Do finance controls prove ledger domains are reconciled, journals are balanced and approved, suspense is cleared, close milestones are complete, reports are audit-ready, and board finance evidence is reproducible? | Approve ledger domain ownership, posting rules, subledger tie-outs, reconciliation SLA, suspense tolerances, double-entry journal integrity, maker-checker approvals, reversal routes, manual adjustment controls, period-close milestones, IFRS reporting support, CBK regulatory return mapping, external audit PBC evidence, CFO certification, synthetic-action blocking, custody hashes, and board finance package evidence. | finance-ledger-close-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | bd91af4ec2d1...93367454 |
Product pricing, fair value, fee transparency, disclosure, lifecycle, and redress governance FCA Consumer Duty price and value outcome, EBA product oversight and governance, Kenya Financial Consumer Protection Framework, World Bank financial consumer protection good practices, and product evidence custody / Product Governance Committee / Conduct Committee / Credit Risk Committee / Audit Committee / Board Risk Committee | Do product controls prove prices and fees are fair-value assessed, understandable, suitable, disclosed, complaint-monitored, redress-ready, lifecycle-controlled, fail-closed on synthetic data, and reproducible for board and supervisory review? | Approve product fair-value assessments, total cost of credit, APR ceilings, cost-stack evidence, fee caps, fee waivers, reversals, tax treatment, complaint routes, redress controls, target-market definitions, affordability, vulnerable-customer paths, key facts statements, language and channel disclosure coverage, readability, rate-change notices, digital consent receipts, distributor training, launch gates, GL and fee mapping, post-launch reviews, rollback and retirement notices, synthetic-action blocking, custody hashes, and board product evidence before launch or repricing. | product-pricing-fair-value-governance-pack 1 controls / 1 routes | ready 1 assurance reviews / 0 open questions | 75707b668a7d...299c41e1 |
Product launch regulatory readiness, perimeter linkage, approval route, and go-live hold governance Product launch regulatory readiness, regulatory perimeter licensing governance, product pricing fair-value governance, privacy, AML, responsible-lending, live-read, board approval, and evidence custody / Product Governance Committee / Risk and Compliance Committee / Conduct Committee / Board Risk Committee | Do product launch controls prove every candidate is pricing-ready, perimeter-cleared, manifest-mapped, approval-routed, live-read backed, post-launch reviewed, and blocked when upstream regulatory or pricing actions remain open? | Approve product launch candidates, pricing and fair-value linkage, regulatory perimeter product gates, required enterprise manifest mappings, legal approval, operations readiness, training, customer communications, rollback plans, regulator notices, board decisions, live-read controls, post-launch review scheduling, upstream action clearance, custody hashes, and go-live holds before pilot or full launch. | board-risk-committee-pack, financial-crime-governance-pack, live-data-trust-pack, privacy-impact-pack, product-launch-regulatory-readiness-pack, product-pricing-fair-value-governance-pack, records-data-lifecycle-governance-pack, regulatory-perimeter-licensing-governance-pack, responsible-lending-affordability-governance-pack 9 controls / 9 routes | ready 9 assurance reviews / 0 open questions | 69bccb93d34e...37d8c799 |
Risk-adjusted profitability, funds-transfer-pricing, RAROC, and unit economics governance Interagency FTP guidance for funding and contingent liquidity risk, BCBS sound liquidity risk management, OCC lending and loan portfolio risk management, OCC earnings quality, EBA loan origination and monitoring loan pricing, Basel Core Principles risk governance, and World Bank financial consumer protection / ALCO / Product Governance Committee / Capital Committee / Conduct Committee / Board Risk Committee | Do FTP curves, liquidity-cost allocation, RAROC hurdles, cost stack, expected loss, economic capital, stressed return, profitability attribution, and customer-outcome gates prove growth is profitable, capital-aware, fair, reconciled, and reproducible for ALCO, board, and supervisors? | Approve RAROC hurdle evidence, FTP curves, funding-cost and liquidity-premium allocation, contingent-liquidity charges, expected-loss and capital model lineage, full product cost stack, stressed funding and credit scenarios, customer-redress and fee-waiver sensitivities, GL/subledger/portfolio/board attribution reconciliation, customer-outcome gates, action packs, custody hashes, and board profitability evidence before material launch, repricing, growth, or profitability claims. | capital-icaap-evidence-pack, customer-outcomes-redress-governance-pack, finance-ledger-close-governance-pack, ifrs9-ecl-governance-pack, product-pricing-fair-value-governance-pack, risk-adjusted-profitability-ftp-governance-pack, risk-data-aggregation-governance-pack, treasury-liquidity-risk-pack 8 controls / 8 routes | ready 8 assurance reviews / 0 open questions | 23ac2617b8de...bf5952d2 |
Live data trust, cybersecurity protection, and customer harm prevention NIST CSF Protect and customer outcome protection / Technology Committee / Customer and Conduct Committee | Do auth isolation, no-fallback data invariants, conduct outcome controls, and blocked action states prevent customer harm under degraded or unfair journeys? | Ratify fail-closed data trust, conduct-outcome monitoring, and customer harm controls before approving any new product launch. | conduct-outcomes-pack, customer-harm-pack, live-data-trust-pack, security-control-pack 4 controls / 2 routes | ready 4 assurance reviews / 0 open questions | 413806e16850...b327541a |
Cyber resilience threat, vulnerability, cryptographic key custody, identity, backup, and incident governance ISO 27001 / NIST CSF / CBK Cybersecurity Guidance / NIST key management guidance, FIPS 140-3, PCI DSS key management / Technology Committee / Audit and Risk Committee | Are HSM key ceremonies, rotation schedules, access entitlements, backup encryption, and incident run-books board-approved and independently validated? | Ratify cryptographic key custody controls, threat/vulnerability management, identity governance, and incident response readiness. | cryptographic-key-custody-governance-pack, cyber-resilience-governance-pack 2 controls / 2 routes | ready 2 assurance reviews / 0 open questions | 8e0a2abe5fd2...5b56bef6 |
ECL summary read is unavailable.
All recipients receive AES-256 encrypted PDF with individual watermarks.
No scheduled board pack distribution. Set up monthly auto-distribution:
Schedule monthly