Regulatory·Regulators
Live

Intelligence generated by AI from public regulatory sources. Not investment or regulatory advice. Verify before relying on any output.

Regulators

Framework mappings for ICAAP, ORSA, and supervisory submissions

Clause-level detail — each pack maps specific regulatory clauses to risk themes and scenarios, with relevance narratives for evidence preparation. For a high-level view of framework obligations without clause detail, see Alignment.

6

Regulators

34

Mapped Clauses

10

Linked Themes

5

Jurisdictions

CPS 230APRA · v1

APRA CPS 230 Operational Risk Management Alignment Pack

APRA Prudential Standard CPS 230 Operational Risk Management

6

Clauses

2

Themes

APRA Prudential Standard CPS 230, effective 1 July 2025 (with transitional arrangements for service provider arrangements until 1 July 2026), consolidates and substantially uplifts operational risk management expectations for all APRA-regulated entities — ADIs, general and life insurers, private health insurers, and RSE licensees. CPS 230 supersedes CPS 231 (Outsourcing) and CPS 232 (Business Continuity Management), introducing three integrated pillars: operational risk management, business continuity, and management of service provider arrangements. The Standard is unambiguous that the Board is ultimately accountable for operational risk management and must approve the entity's operational risk profile, tolerance levels, business continuity plan, and service provider management policy. A central innovation is the requirement to identify 'critical operations' — processes which, if disrupted beyond tolerance levels, would have a material adverse impact on depositors, policyholders, beneficiaries, or financial system stability — and establish quantitative tolerance levels expressed as maximum disruption duration, maximum data loss, and minimum service levels. APRA's supervisory approach, articulated in CPG 230 (Prudential Practice Guide), emphasises end-to-end mapping including upstream and downstream dependencies, scenario testing under severe-but-plausible conditions, and rigorous management of material service providers including the so-called 'fourth parties'. APRA has signalled intensive thematic review activity through 2025-26, with deep-dive reviews of critical operations identification, tolerance level calibration, and material service provider registers expected.

Op ResilienceBoard PackRisk CommitteeSupervisoryThematic ReviewRisk Appetite
Clause Mapping

Paragraph 13-18

Establishes Board and senior management roles and responsibilities. The Board must approve the operational risk management framework, oversee its implementation, and ensure operational risk is managed within risk appetite. Senior management is accountable for day-to-day operational risk management and must provide the Board with comprehensive, accurate and timely information.

Paragraph 23-29

Requires identification, assessment and management of operational risks across all business activities, including the maintenance of an operational risk profile, comprehensive risk and control self-assessment processes, monitoring of key risk and control indicators, and timely escalation of incidents and control weaknesses to the Board.

+4 more clauses

BCBS-CRFRBCBS · v1

BCBS Principles for the Effective Management and Supervision of Climate-Related Financial Risks Alignment Pack

Basel Committee on Banking Supervision — Principles for the Effective Management and Supervision of Climate-Related Financial Risks (June 2022)

5

Clauses

2

Themes

The BCBS Principles, published in June 2022, establish 18 principles (12 for banks, 6 for supervisors) that set the global baseline for integrating climate-related financial risks into existing Basel prudential frameworks rather than creating a parallel regime. National implementation is now well advanced: the ECB's Guide on climate and environmental risks, the PRA's SS3/19, OSFI's Guideline B-15, MAS Guidelines on Environmental Risk Management, and APRA's CPG 229 all trace their design to these Principles. For internationally-active banks, the Principles are the touchstone against which supervisors assess whether climate risk is genuinely embedded in governance, strategy, risk appetite, capital and liquidity adequacy assessments (ICAAP/ILAAP), credit underwriting, and stress-testing. The 2024–2025 supervisory cycle has focused on quantification: supervisors are challenging banks to move beyond qualitative narrative disclosures to demonstrate that climate risk drivers are translated into credit rating overrides, sector concentration limits, counterparty engagement plans, and Pillar 2 capital considerations. Physical risk modelling for property portfolios and transition risk pathways for high-emitting sectors (oil & gas, power, cement, steel, agriculture, real estate) are being tested through both regulator-run exercises and firm-led scenario analysis. For CROs, the Principles now underpin the emerging supervisory expectation that climate is a driver of existing risk categories — credit, market, operational, liquidity, legal — and that quantitative integration into ICAAP is no longer aspirational but expected within the current supervisory review cycle.

ICAAPORSABoard PackRisk CommitteeRisk AppetiteSupervisoryScenario Design
Clause Mapping

Principle 1 (Corporate Governance)

Establishes the board's ultimate accountability. Supervisors expect documented board training, climate expertise in board composition, and explicit board challenge in minutes on climate strategy and transition planning.

Principle 5 (Capital and Liquidity Adequacy)

This is the operative Pillar 2 hook. Supervisors are now testing whether materiality assessments are honest and whether quantified impacts flow into ICAAP capital demand. Absence of a Pillar 2 add-on where climate is deemed material is itself a supervisory finding.

+3 more clauses

DORAEBA · v1

EU DORA Digital Operational Resilience Alignment Pack

Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector

6

Clauses

2

Themes

The Digital Operational Resilience Act (DORA), which became fully applicable on 17 January 2025, establishes a unified, directly-binding ICT risk management regime across all EU regulated financial entities — banks, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, and crowdfunding platforms. DORA elevates ICT risk from an operational sub-discipline to a board-level prudential concern, requiring management bodies to bear ultimate responsibility for ICT risk management frameworks, approve digital operational resilience strategies, and allocate appropriate budget. The Regulation is supplemented by a suite of Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) developed jointly by the ESAs, covering ICT risk management tools, incident classification, threat-led penetration testing (TLPT), and third-party risk management. A defining feature is the Oversight Framework for Critical ICT Third-Party Service Providers (CTPPs), under which the ESAs designate and directly supervise systemically important providers — including hyperscale cloud platforms — with powers to issue recommendations, conduct on-site inspections, and impose periodic penalty payments. Supervisory expectations centre on: demonstrable board engagement; granular mapping of ICT assets supporting critical or important functions; rigorous contractual provisions with ICT third parties using the mandatory Register of Information; severity-tiered incident classification with 4-hour initial notification for major incidents; and triennial advanced TLPT for significant institutions. Non-compliance carries reputational, supervisory, and pecuniary consequences, with national competent authorities empowered to impose administrative penalties calibrated to firm size and breach severity.

Op ResilienceBoard PackRisk CommitteeSupervisoryScenario Design
Clause Mapping

Article 5

Establishes governance and organisation requirements: the management body bears ultimate responsibility for ICT risk management, must approve and oversee implementation of the ICT risk management framework, allocate appropriate budget, and maintain active engagement through regular training. Boards cannot delegate accountability and must demonstrate ICT literacy.

Article 6

Mandates a comprehensive, documented and regularly reviewed ICT risk management framework covering strategies, policies, procedures, ICT protocols and tools necessary to protect information and ICT assets. Requires annual internal audit review and post-incident framework updates.

+4 more clauses

PS22/9FCA · v1

FCA Consumer Duty (PS22/9) & AI Governance Alignment Pack

FCA Policy Statement PS22/9 — A New Consumer Duty (FCA Handbook PRIN 2A) and Related AI Governance Expectations

6

Clauses

1

Themes

The FCA Consumer Duty, in force for open products since 31 July 2023 and for closed products since 31 July 2024, imposes a Principle 12 higher standard of care requiring firms to act to deliver good outcomes for retail customers. It is enforced through four outcomes (products and services, price and value, consumer understanding, consumer support) and cross-cuts every stage of the customer journey. The Duty is deliberately outcomes-based and evidence-driven, requiring firms to produce a board-approved annual Consumer Duty report supported by robust data on outcomes actually delivered, not just processes followed. The FCA's 2024 Dear CEO letters and multi-firm reviews have made clear that supervisors will test whether outcomes monitoring is granular enough to identify foreseeable harm to vulnerable customers and specific customer segments. This is increasingly intersecting with the FCA's AI and machine learning discussion paper (DP5/22) and the 2024 joint BoE/FCA AI Survey findings: where firms deploy AI or algorithmic decisioning in pricing, credit, fraud screening, or customer communications, the Duty imposes a de facto explainability and fairness requirement. Supervisors expect firms to demonstrate that models do not systematically disadvantage protected or vulnerable groups, that model outputs are challengeable by customers, and that governance around model development, validation, monitoring and decommissioning is proportionate to consumer impact. For CROs, the Duty has become the primary conduct risk lens in the UK and the practical vehicle through which AI governance expectations are being enforced ahead of any dedicated AI regulation.

Board PackRisk CommitteeSupervisoryThematic ReviewRisk Appetite
Clause Mapping

PRIN 2A.1 (The Consumer Principle)

Principle 12 sets a higher standard than the previous Principle 6 'treating customers fairly'. It is proactive ('act to deliver') and outcomes-focused, meaning process compliance is insufficient — firms must evidence outcomes actually achieved.

PRIN 2A.2 (Cross-cutting Rules)

The 'avoid foreseeable harm' rule is the most operationally demanding. It requires firms to identify harms before they crystallise, which for AI-driven decisioning implies pre-deployment bias testing and ongoing outcomes monitoring by customer segment.

+4 more clauses

SS1/21PRA · v1

FCA/PRA Operational Resilience Policy (PS21/3 & SS1/21) Alignment Pack

PRA Supervisory Statement SS1/21 and FCA Policy Statement PS21/3 — Operational Resilience: Impact Tolerances for Important Business Services

5

Clauses

2

Themes

The joint PRA/FCA operational resilience framework, in force since 31 March 2022 with a transitional runway to 31 March 2025, requires banks, building societies, PRA-designated investment firms, insurers and FMIs to identify their important business services (IBS), set impact tolerances expressed as maximum tolerable disruption, and demonstrate through severe-but-plausible scenario testing that they can remain within those tolerances by the end of the transition period. As of March 2025, supervisors have moved decisively out of the design phase and into active challenge: firms are being asked to evidence that mapping is granular enough to identify single points of failure, that impact tolerances are calibrated against consumer harm and financial stability rather than internal appetite, and that lessons learned from real incidents (CrowdStrike, Synapse, ION Markets, and repeated cloud outages) have been fed back into resilience planning. The PRA's Dear CEO letters through 2024 have highlighted persistent weaknesses in third-party mapping, concentration risk in cloud and market data providers, and insufficient testing of substitutability assumptions. Boards are expected to own the self-assessment document, and internal audit is expected to provide independent assurance. For CROs, the framework is now the primary operational risk supervisory lens in the UK, sitting alongside the incoming Critical Third Parties regime under FSMA 2023 sections 312L–312S, which extends direct supervisory reach to designated CTPs such as hyperscale cloud providers.

Op ResilienceBoard PackRisk CommitteeSupervisoryScenario DesignThematic Review
Clause Mapping

SS1/21 §2.1–2.6

Identification is the foundational obligation. Firms must apply externally-focused criteria rather than internal materiality; supervisors have criticised firms that catalogue too many or too few IBS. The register must be reviewed when the business model changes and defended against consumer harm and market integrity yardsticks.

SS1/21 §3.1–3.9

Impact tolerances must be expressed in time and other measurable dimensions (e.g. transaction volumes, number of affected consumers). They are hard external thresholds — not appetite statements — and boards must approve them. Supervisors expect calibration papers linking tolerances to specific harm scenarios.

+3 more clauses

SS1/23PRA · v1

PRA SS1/23 Model Risk Management Principles Alignment Pack

PRA Supervisory Statement SS1/23 — Model Risk Management Principles for Banks

6

Clauses

1

Themes

PRA Supervisory Statement SS1/23, effective 17 May 2024, establishes the UK's first comprehensive cross-cutting expectations for model risk management (MRM) at banks, building societies, and PRA-designated investment firms. SS1/23 articulates five core principles covering model identification and risk classification, governance, development and implementation, validation, and risk mitigants for models with deficiencies. Critically, SS1/23 adopts an expansive definition of 'model' that explicitly includes deterministic quantitative methods and — through PRA's Dear CEO letter follow-up — captures artificial intelligence and machine learning systems used in credit decisioning, financial crime, capital, pricing, and operational decision-making. This brings AI/ML governance squarely within prudential supervisory scope. The PRA expects firms to maintain a comprehensive model inventory with risk-tiering, robust independent validation functions reporting to the CRO or equivalent, and senior accountability anchored under the Senior Managers and Certification Regime (typically SMF4 Chief Risk Officer). The Statement explicitly addresses third-party and vendor models, requiring firms to apply the same MRM standards regardless of model origin — a particularly acute challenge for off-the-shelf AI tools, foundation models, and externally-procured scoring engines. The PRA has integrated SS1/23 compliance into routine supervision and Periodic Summary Meetings; firms self-assessed against the principles in 2024 and material gaps must be remediated under board-monitored plans. Supervisory expectations are intensifying as generative AI and agentic systems proliferate in regulated workflows.

ICAAPBoard PackRisk CommitteeSupervisoryThematic Review
Clause Mapping

Principle 1 (Paragraphs 2.1-2.12)

Model identification, model risk classification and model inventory. Firms must adopt a broad model definition encompassing quantitative methods, AI/ML, and deterministic rule-based systems, maintain a complete inventory, and apply a risk-tiering framework reflecting materiality, complexity and uncertainty — driving proportionate governance intensity.

Principle 2 (Paragraphs 3.1-3.18)

Governance: requires board accountability for model risk strategy and appetite, clear three-lines-of-defence roles, an SMF holder accountable for the MRM framework (typically the CRO under SMF4), and robust policies covering the model lifecycle including challenger and benchmark practices.

+4 more clauses