The principles apply to systemically important banks at both group and solo level, to all risk management data, to key internal models including Pillar 1 and Pillar 2 capital models and value-at-risk, and to outsourced processes (SRP36.4 to SRP36.8). They cover governance and infrastructure (Principles 1 and 2), aggregation capabilities (Principles 3 to 6: accuracy and integrity, completeness, timeliness, adaptability), reporting (Principles 7 to 11: accuracy, comprehensiveness, clarity and usefulness, frequency, distribution) and supervisory review (Principles 12 to 14) (SRP36.9, SRP36.18). The bank should meet all principles at once, with trade-offs only in exceptional ad hoc situations and never where they materially affect decisions (SRP36.11). The board must approve the group framework, ensure resources and oversee senior management's delivery within a timeframe agreed with supervisors (SRP36.12, SRP36.20). Capabilities must be fully documented and independently validated by staff with IT, data and reporting expertise, separate from audit, considered in acquisitions and new products, and unaffected by group structure (SRP36.21). Senior management must know the limitations on aggregation and fold remediation into the IT strategy (SRP36.22). Data must be aggregated largely automatically, available by business line, legal entity, asset type, industry and region, and reports reconciled and validated, with frequency set by the board and increased in stress (SRP36.18). Reporting must be forward-looking with early warning of limit breaches (SRP36.14).
This control maps to 11 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 11 it maps to, and the evidence behind each claim, over MCP and REST.