HKMA TM-G-1
TM-G-1 Governance: Board + Senior Mgmt + Tech Risk Framework + Roles + Responsibilities

HKMA TM-G-1 HKMA-TMG1-Governance-Board-Framework-Roles: TM-G-1 Governance - Board + Senior Mgmt Oversight + Technology Risk Management Framework + Roles

HKMA TM-G-1 Governance of Technology Risk. (1) BOARD AND SENIOR MANAGEMENT OVERSIGHT OF TECHNOLOGY RISK (TM-G-1.2.1) - Board approval of IT strategy + technology risk appetite + risk tolerance; senior management accountability + governance structure; reporting + escalation; Board IT/cyber literacy + training; risk-committee oversight; ongoing supervisory dialogue; HKMA fitness and propriety expectations; (2) TECHNOLOGY RISK MANAGEMENT FRAMEWORK (TM-G-1.2.2) - documented + Board-approved Technology Risk Management Framework integrating IT + cyber + business continuity + operational resilience; risk taxonomy + identification + assessment + measurement + mitigation + monitoring + reporting; ERM integration; 3-lines-of-defense + risk-committee + Board oversight; periodic review + Framework update; (3) ROLES AND RESPONSIBILITIES (TM-G-1.2.3) - clearly defined roles for Board + senior management + CISO + Technology Risk Officer + IT operations + business-line cyber-risk owners + 3-lines-of-defense + segregation of duties + accountability + RACI; ongoing review + workforce planning + capability development + sectoral PDP integration. KEY EVIDENCE: Board-approved Framework + minutes + committees + RACI + roles charters + risk-committee reports + supervisory communications.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.