OCC Heightened Standards (12 CFR Part 30, Appendix D)
Risk Data, Talent, Compensation, Strategy

OCC Heightened Standards (12 CFR Part 30, Appendix D) OCCHS-7: Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning

Operate Risk Data Aggregation and Reporting + Talent Management + Compensation + Strategic Planning per 12 CFR Part 30 Appendix D Sections II.J + II.L + II.M + II.D. Risk Data Aggregation and Reporting per Section II.J must (a) provide the Board + senior management + Independent Risk Management with timely + accurate + comprehensive + consistent + relevant risk information across business lines + risk categories + with appropriate granularity, (b) align with BCBS 239 Principles for Effective Risk Data Aggregation and Risk Reporting as supervisory expectation for global systemically important banks, (c) integrate technology + data governance + data quality + reconciliation processes + capability to produce risk reports under stress conditions. Strategic Plan per Section II.D must (a) be a written multi-year strategy covering business objectives + risk objectives + capital + liquidity + earnings + growth + with consideration of macroeconomic + regulatory + competitive environment, (b) be aligned with Risk Appetite Statement + Risk Governance Framework, (c) be reviewed and approved annually by the Board. Talent Management per Section II.L must (a) attract + develop + retain personnel with the skills + experience + risk management capability + ethical standards required to operate the covered bank, (b) include succession planning for key roles + leadership development + diversity + inclusion considerations. Compensation and Performance Management per Section II.M must (a) align compensation + performance management with risk-taking decisions + risk outcomes + risk culture, (b) avoid excessive risk-taking incentives + balance short-term and long-term performance + integrate clawback + malus provisions + Board oversight of significant compensation arrangements.

What else in your programme already covers this

This control maps to 76 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning

Japan AI Guidelines · 3 controls

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-30 · 3 controls

  • NISTSP30-1 Risk Management Strategy and Risk Assessment Programme Establishment
  • NISTSP30-2 Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System)
  • NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls
  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management

NIST SP 800-37 · 2 controls

  • NISTSP37-1 RMF Prepare Step: Organisation-Level and System-Level Preparation
  • NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation

NIST SP 800-39 · 2 controls

  • NISTSP39-4 Risk Responding: Identify, Evaluate, Decide, Implement
  • NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model

API 1164 · 1 control

  • API1164-21 TSA Pipeline Security Directive Alignment
  • CJIS-19 Supply Chain Risk Management

IEC 62443 · 1 control

  • IEC62443-21 Supply chain risk management for critical components

MTCS (Singapore) · 1 control

NERC CIP · 1 control

  • NERCCIP-8 Supply Chain Risk Management (CIP-013)
  • NIS2I-2 Policy, Risk Management, and Roles + Responsibilities
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • PSPF24-1 Security Culture, Governance, Risk Management
  • AIGF-1.1 Risk Management and Internal Controls

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 76 it maps to, and the evidence behind each claim, over MCP and REST.