Regulatory and financial crime exposure and appetite are understood and challenged. Financial crime risk assessment: an annual, scoped and resourced assessment compared with appetite, identifying inherent and residual risk by service, jurisdiction, customer type, transaction complexity and volume and distribution channel, informing controls; at higher levels a documented methodology covering Lloyd's six risk types (fraud, anti-money laundering, sanctions, market abuse, bribery and corruption, facilitation of tax evasion), associated persons risk-rated and a control library. Governance: a board-endorsed framework with escalation criteria and reporting lines, responsibility defined under SM&CR, senior commitment, a compliance function with authority and resources, and suspicious activity escalation to experienced staff. Monitoring and assurance: independent audit with compensating controls and root cause remediation, routine testing, adequate coverholder controls. Regulatory: regulatory risk monitored through appetite and reported to the board, high-risk jurisdictions given focus, audits used to improve and actions tracked.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.