Skip to main content

Control Construction

CUBE Controls comprise three components: Control Objective, Control Description, and Control Attributes.

Controls can be identified by the risks they aim to mitigate (Control Objective) and the methods they use to achieve this (Control Description).

Control Objective: is the control mitigating a risk?

Controls mitigate risks. The Control Objective field links Control Type with CUBE Level 3 Risks. The CUBE Risk Taxonomy is a list of Risk Events. The Control Objective lists L3 risk events separated by commas, and the penultimate and ultimate risks are separated by an oxford comma and the word 'and'.

info

To prevent the risk(s) of Insider trading (personal account or personal gain), Insider trading (on firm's account), and Inappropriate access to accounts, data or systems

Control Description: The Review section

The Control Description outlines the control activities that mitigate the risks stated in the Control Objective. The 'Review' section of the Control Description specifies what is being monitored (typically and intra-day control) or reviewed (typically daily or less frequent) in that control activity.

An example of a 'Review' section is:

  • Review the details of supervisory reports relating to cancelled or amended trades

Customer data is generalized in CUBE control wording to avoid specific customer elements.

Control Description: The Identify section

The 'Identify' section specifies what the control operator looks for during the review/monitoring step. It starts with the phrase 'Identify one or more of the following:' followed by bullet points. These elements are informed by Customer controls and are drafted to be applicable across Customers. Customer-specific elements are avoided in CUBE Control wording by generalizing information derived from customer data.

An example of an 'Identify' section is (Identify one or more of the following):

  • Cancel or amend activity that is indicative of unauthorised, fraudulent or manipulative behaviour
  • Cancels or amends requested by front office staff, or support function, where correct procedures were not followed or there is insufficient supporting evidence
  • Complex trade amendments which do not reconcile to source documentation or the formal change request
  • Cancel and amend activity performed by unauthorised personnel

Control Description: The Action section

The 'Action' section in the Control Description specifies necessary actions based on the findings of the Review and Identify steps. CUBE uses a standardized set of actions to describe the completion of the control and finding elements from the Identify section. Bespoke actions can be drafted if needed. Control actions are sequentially numbered for logical order and typically include up to five actions selected from the table provided.

 #Action
1Amend inaccurate / incomplete or stale data or documentation
2Complete and / or request completion of outstanding tasks or approvals
3Determine circumstance of suspicious and / or irregular activity
4Determine circumstance of breach or deviation
5Provide sign-off that review has been performed, logs /documentation / systems are updated, and issue is resolved with evidence as necessary
6Define next steps with relevant parties
7Investigate rationale for any late, missing or incomplete tasks
8Agree timeframe for completion with relevant parties
9Inform supervisor(s) and / or relevant governance function(s) and, or body as appropriate
10Confirm exception(s) have a valid and recorded justification and are monitored as required
11Ensure relevant individuals are aware of restrictions on their role and responsibilities until requirements are completed
12Resolve trade irregularity e.g. unwind, amend or exit trade
13Ensure conduct issue is handled appropriately e.g. disciplinary action, inform regulator
14Halt trading or further business until all approvals are obtained
15Ensure regulatory registration / license / waiver /disclaimer is in place as required
16Ensure closure of inappropriate customer account, trading book, chatroom or subject of this control
17Ensure Supervisor is comfortable with mitigating actions andmresidual risk
18Inform counterparty on the other side of the trade
19Inform customer of the circumstances of the event or issue
20Perform root cause analysis
21Resolve IT alert e.g. abort job, restart job, restart service
22Determine circumstance of IT alert or failure