The bank has an operational risk management framework and operational resilience approach considering its risk profile, appetite, business environment, tolerance for disruption to critical operations and emerging risks, with strategies, policies, procedures, systems and controls to identify, assess, evaluate, monitor, report and control or mitigate operational risk (loss from failed processes, people, systems or external events, including legal risk) and to identify and protect against threats, respond, adapt, recover and learn from disruptions so critical operations keep being delivered. The board approves and periodically reviews operational risk management for all material products, activities, processes and systems (including operational risk appetite) and the resilience approach (including tolerance for disruption), and oversees implementation; functions identify internal and external threats on an ongoing basis. The bank identifies its critical operations and maps the people, technology, processes, data, facilities, third parties and intragroup entities and their interdependencies; implements and continuously improves incident response and recovery plans; runs business continuity exercises under severe but plausible scenarios, including service provider and payment system disruption; operates a robust ICT and cyber security framework with board oversight and senior management evaluation, and resilient ICT whose protection, detection, response and recovery are regularly tested with situational awareness of vulnerabilities; monitors operational risk profiles, collects internal and, where feasible, external loss data and reports to the board, management, risk function and business units; reports developments and incidents disrupting critical operations, with severity, to the supervisor; manages service providers through due diligence, sound contract structuring (data ownership and confidentiality, termination rights), ongoing monitoring including financial condition, a register of outsourced activities with metrics, dependency management, contingency and exit strategies with substitutability assessed, clear contracts and service levels, and rights of inspection and supervisory access; and runs a resourced change management process assessing effects on critical operations.
This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.