Skip to main content

Controls

Elements of a Control

The Data Technical Standards (DTS) framework is a comprehensive methodology that outlines how a control should be written to facilitate rules-based comparability of data across firms. A control includes the following information:

  • A Control Code (i.e. a unique identifier)
  • Control Objective
  • Control Description (with 3 sub-sections i) Review, ii) Identify and iii) Action)
  • Control Attributes (Name, Owner, Type, Frequency, Automation, Theme, Products)
  • Mapping to Risks
  • Mapping to Processes

The CUBE Control

The diagram below shows how the CUBE Control fields are interconnected.

Guiding Principles

CUBE follows a set of guiding principles when constructing controls to ensure consistency and comparability across firms.

  • Data field values should be small to ensure greater clarity and comparability.
  • Default data or rules-based constructs are preferred over free text.
  • Controls should be simple and not overly complicated.
  • Controls should be specific to the risk they are mitigating and relevant to the industry.
    • CUBE focuses on the "what" and "why" of controls. Details about how a control is performed are specific to each firm and not captured in the DTS. For example, which team an input comes from, which role performs the control, and on which system it is performed.
  • CUBE-specific terminology and methodologies should be capitalized to facilitate their identification and distinguish them from external terminology.

'Key' Controls

CUBE does not differentiate between controls and "key" controls. Instead, it includes processes, risks, and controls in its Indices when two or more customers operate the same process, risk, or control. The goal is to allow the industry to define which controls are important based on their prevalence across multiple customers.

CUBE adapts the minimum number of controls required based on the size of the network. Currently, this is referred to as the "two or more" rule, which is explained in detail later in the document. As a result, CUBE does not use the term "key" control because all controls in the index are considered "key" due to their prevalence in customer data.