The risk and control environment is strong and challenged. Baseline: a risk management framework with board-approved appetites and tolerances guiding decisions and a plan to reach the desired risk culture; risks recorded in a register with owners for risks and controls, assessed, monitored and mitigated or accepted with rationale; a proportionate framework to quantify impact and probability; qualitative and quantitative risk and control assessments; monitoring of the internal and external environment and emerging risks; the ORSA in line with Solvency II; accessible incident reporting; separation of front line and independent assurance; centralised risk, compliance and audit with controlled outsourcing; risk-based internal audit; direct access of compliance and risk to staff and records; audit actions implemented; audits after significant change. Higher levels add front-line ownership, comparison of modelled and framework risks, quantified emerging risks and a no-blame culture.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.