HKMA SPM implementation roadmap + AI compliance + supervisory dialogue. ORGANIZATIONAL ROLES at AI: (a) BOARD + RISK COMMITTEE - SPM governance oversight + module-by-module compliance + sectoral risk integration + reporting; (b) CHIEF EXECUTIVE OFFICER (CEO) - executive accountability + supervisory engagement + tone-from-the-top; (c) CHIEF RISK OFFICER (CRO) + HEAD OF OPERATIONAL RISK - SPM module compliance lead + integrated risk management; (d) CHIEF FINANCIAL OFFICER (CFO) + TREASURER - Basel + capital + liquidity + ICAAP + regulatory reporting; (e) CHIEF COMPLIANCE OFFICER + MLRO - AML/CFT + AMLO + supervisory engagement + regulatory reporting + sanctions; (f) CHIEF INFORMATION SECURITY OFFICER (CISO) + TECHNOLOGY RISK OFFICER - TM module compliance + C-RAF + sectoral cybersecurity (verified separately); (g) GENERAL COUNSEL + LEGAL - Banking Ordinance + sub-regulations + module interpretation + HKMA supervisory dialogue; (h) INTERNAL AUDIT (3rd line) - AC-G + module-by-module audit + HKMA review + remediation tracking; (i) BUSINESS LINE OWNERS - 1st-line accountability + module-by-module + business risk integration; (j) HUMAN RESOURCES - CG-5 remuneration + CG-6 competence + workforce + sectoral training; (k) DATA PROTECTION OFFICER (DPO) - PDPO Cap. 486 + privacy compliance. SUPERVISORY DIALOGUE: ongoing HKMA dialogue + on-site examinations + thematic reviews + horizontal reviews + module-by-module assessment + remediation + escalation procedures; HKMA may impose remedial action plans + restrictions + sanctions + supervisory letters + monetary penalties under Banking Ordinance. SECTORAL ENGAGEMENT: HKAB (Hong Kong Association of Banks) + DTCAHK (DTC Association) + HKFTU + industry associations + thematic working groups + sectoral cybersecurity exercises (Cyber Wargames + Tabletop) + HKCERT + JFIU + cross-agency engagement. PROGRAM ELEMENTS: (1) SPM Module Inventory + applicability assessment; (2) Module-by-module compliance assessment + gap analysis + remediation roadmap; (3) Ongoing supervisory dialogue + thematic reviews + on-site examinations; (4) Module updates + version tracking + transition implementation; (5) Cross-module integration + holistic risk management; (6) Sectoral coordination + industry forums + HKMA Quarterly Bulletins; (7) International framework alignment + Basel + IOSCO + FSB + cross-border. TOOLING: (a) GRC platforms (ServiceNow GRC + Archer + LogicGate + RSA + others); (b) Regulatory reporting platforms (Wolters Kluwer + Vermeg + Vermeg + AxiomSL + others); (c) Risk management (Sphera + EHS Insight + LogicManager); (d) AML/CFT platforms (NICE Actimize + Oracle FCCM + FIS + Refinitiv + Pelican); (e) Stress testing + ICAAP + capital management; (f) Internal audit + assurance platforms; (g) Sectoral cybersecurity tools (per C-RAF separately tracked). METRICS: SPM module compliance status + remediation closure + Basel compliance + Pillar 3 disclosures + supervisory engagement frequency + thematic review findings + audit + assurance outcomes.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.