An FMI identifies plausible internal and external sources of operational risk and mitigates them with systems, policies, procedures and controls. The board defines responsibilities and endorses the framework, with systems and controls reviewed, audited and tested periodically and after significant change. It sets operational reliability objectives, has scalable capacity for stress volumes, maintains comprehensive physical and information security policies, and keeps a business continuity plan covering wide-scale disruption with a secondary site, recovery of critical IT within two hours and completion of settlement by end of day even in extreme circumstances, tested regularly. It also manages risks from key participants, other FMIs and service and utility providers, and the risks it poses to other FMIs.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.