OCC Heightened Standards (12 CFR Part 30, Appendix D)
Risk Governance Framework

OCC Heightened Standards (12 CFR Part 30, Appendix D) OCCHS-2: Risk Governance Framework: Three Lines of Defense, Scope, and Charter

Establish and maintain a Risk Governance Framework per 12 CFR Part 30 Appendix D Sections II.A and II.B. The Framework must (a) be a written articulation of the covered banks risk management framework with documented charter and approval by the Board, (b) cover comprehensively the risk areas of credit + interest rate + liquidity + price + operational + compliance + strategic + reputation risk + additional risks as warranted by the covered banks risk profile, (c) be tailored to the covered banks risk profile + size + complexity + nature of activities + scope of operations, (d) align with the three-lines-of-defense model per Section II.C: front line units (Section II.C.1) own and manage risk in their activities + independent risk management (Section II.C.2) provides oversight + internal audit (Section II.C.3) provides independent assurance, (e) be reviewed and approved by the Board at least annually and after significant change, (f) be communicated to all relevant personnel + integrated with business operations + supported by training + measurement + reporting. The Framework must integrate with the Strategic Plan (Section II.D) + Risk Appetite Statement (Section II.E) + Risk Limits (Section II.F) + Compensation and Performance Management (Section II.M).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.