The Data Technical Standards for Control, Risk & Process
Purpose of this document
CUBE creates and maintains Process, Risk, and Control Taxonomies and Indices to facilitate its unique approach to Non-Financial Risk (NFR) data. This Data Technical Standards (DTS) document defines the data constructs to facilitate this approach. Additionally, it defines the methodologies by which CUBE Processes, CUBE Risks, and CUBE Controls should each be constructed, to enable identification, comparability, and integration across diverse customer data.
Thus, the purpose of this document is to provide a single source definition of these standards and to promote uniformity and efficiency for the financial services industry.
What are the Data Technical Standards (DTS)?
The DTS framework defines, articulates, and applies Control, Risk, and Process. The framework for Control is broader than that for Risk and Process in this document because control has more variability across customers and more complexity.
Early Development of the DTS
The DTS framework was developed collaboratively with the CUBE Network of customers and refined through testing against the CUBE Network of Risks and Controls. The guiding principle for DTS research and analysis is to produce clear, concise, and simple outcomes.
The DTS and CUBE
CUBE's DTS are integral to its services, digitizing non-financial risk management for the financial industry. Customers receive network-driven data insights, horizon scanning, and benchmarking through CUBE Indices, which group controls, risks, and processes based on commonality observed across customer data. The CUBE Group Control Index is divided into Divisional Control Indices, which are further divided into Control Indices reflecting functions within a division. CUBE Risk Indices and Processes are both network-driven taxonomies of identified risks and processes. A full list of CUBE Indices can be found in the Appendix.
- CIB > Global Markets > Credit
- CIB > Securities Services > Compliance
- Retail > Credit Cards
Through CUBE's Industry Calibration, customers can identify weaknesses and risk exposures for which they can prioritise remediation and identify opportunities for rationalisation and cost reduction.
What Problem does the Data Technical Standards Solve?
The financial services industry, particularly investment banking firms, dedicate significant time and resources to managing non-financial risk (NFR). However, due to their siloed approach, each firm has developed different NFR management methods. CUBE aims to bridge this knowledge gap by creating an industry-standard for control, risk, and process definition and articulation. This standardization allows firms to reduce the burden of maintaining different methodologies, frameworks, and datasets. CUBE's process, risk, and control data construction follows the standard, allowing it to serve as a central hub and information exchange through a network-driven dataset. The DTS enables customers to calibrate their data against the CUBE Network, identify weaknesses and risk exposures, and prioritize remediation. Customers can also identify opportunities for rationalization and cost reduction through CUBE's Industry Calibration.
Customer Value
The DTS framework offers the opportunity for industry connectivity, allowing CUBE to statistically assess the completeness of firms' data. By comparing their controls against the CUBE Controls, which are constructed using the DTS framework and associated analytics from CUBE's Industry Calibration benchmarking, customers can take a more informed, evidence-based approach to NFRM instead of relying on a traditional, inward-looking, and judgment-based approach.
Customers who join CUBE and use the DTS framework can benefit from:
- Greater efficiency in managing NFRM frameworks
- Reduced risk and control administration time
- A more effective NFRM framework.
- CUBE's network provides insights from a range of firms, making it easier to identify vulnerabilities and remediate non-controls and upgrade controls.
- The DTS framework encourages more effective and proactive interaction across the 1st and 2nd Lines of defence and with regulators.
Processes, Risks, and Controls
The DTS framework provides more detailed information on control articulation compared to risks and processes. CUBE focuses on controls because firms use them to mitigate risks, making control the critical data point to address. Therefore, this document begins with an analysis of how the DTS applies to controls.
However, it is essential to understand the order in which these elements manifest in customer businesses. Customers operate processes that incur risks, which must be mitigated by controls.