FFIEC IT Examination Handbook
FFIEC IT Examination Handbook: Third-Party Risk Management

FFIEC IT Examination Handbook FFIEC-18: Ongoing monitoring and assessment

Ongoing monitoring and assessment. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Third-Party Risk Management.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 171 controls across 84 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SASB Standards · 4 controls

  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement

ISO 27005 · 3 controls

ISO 31000 · 3 controls

ISO/IEC 23894:2023 · 3 controls

Japan AI Guidelines · 3 controls

  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-30 · 3 controls

  • NISTSP30-1 Risk Management Strategy and Risk Assessment Programme Establishment
  • NISTSP30-2 Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System)
  • NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF

NIST SP 800-53 Rev 5 · 3 controls

PCI P2PE · 3 controls

PCI PIN Security · 3 controls

PCI SSF · 3 controls

Solvency II · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls

IEEE 7000 · 2 controls

ISO/IEC 27003:2017 · 2 controls

  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management

NIST SP 800-37 · 2 controls

  • NISTSP37-1 RMF Prepare Step: Organisation-Level and System-Level Preparation
  • NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation

NIST SP 800-39 · 2 controls

  • NISTSP39-4 Risk Responding: Identify, Evaluate, Decide, Implement
  • NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • OCCHS-3 Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols
  • OCCHS-7 Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 2 controls

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OSFIB13-4 Third-Party Risk Management and Cloud

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs

API 1164 · 1 control

  • API1164-21 TSA Pipeline Security Directive Alignment
  • SPS220-28 Annual Board Risk Management Declaration
  • CJIS-19 Supply Chain Risk Management

GLBA · 1 control

HKMA SPM · 1 control

IEC 62443 · 1 control

  • IEC62443-21 Supply chain risk management for critical components

IEEE 1686 · 1 control

ISO 22320:2018 · 1 control

ISO 27019 · 1 control

  • ISO27019-21 Supply chain risk management for critical components

MTCS (Singapore) · 1 control

NERC CIP · 1 control

  • NERCCIP-8 Supply Chain Risk Management (CIP-013)
  • NIS2I-2 Policy, Risk Management, and Roles + Responsibilities

NIST SP 1800-32 · 1 control

  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation
  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • ORSA-S1 ORSA Manual Section 1: Description of Insurer's Risk Management Framework
  • PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration
  • SSAE18-CC9.2 CC9.2 - Vendor and Business Partner Risk Management
  • AIGF-1.1 Risk Management and Internal Controls

South Korea ISMS-P · 1 control

  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in FFIEC IT Examination Handbook: Third-Party Risk Management

Query this from an agent

The graph holds this control, the 171 it maps to, and the evidence behind each claim, over MCP and REST.