Glossary
CUBE Control Index - The lowest level of control grouping made by CUBE. It is the controls found in 2 or more customers in business lines scoped against that index area. This is the revenue generating or Front Office areas (eg Credit, FX, Agency Services etc) and their support functions (e.g. Compliance, Finance etc).
CUBE Division Control Index - The aggregation of all Indices within the Division.
CUBE Group Control Index - The aggregation of all Divisional Indices.
CUBE Network - the collection of firms who have shared their risk and control data with CUBE.
Division - a specialized unit within a financial institution that is responsible for providing a range of financial services to corporations, governments, and other organizations.
Group - a collection of investment banking divisions within a financial institution that are focused on providing financial services to customers in a particular market segment or industry.
Industry Calibration (Calibrate) - the alignment of customer data with CUBE data at both the risk and control level. This activity includes the review of every customer control and establishing the relationship with CUBE data, a data quality assessment and a gap analysis.
Clarification Comments - The CUBE analysis methodology automatically assesses every Customer control for quality. Every control assesses as an 'Unclear Control' receives a Clarification Comment, which is a short explanation of the nature of the lack of clarity. Both matched and unmatched controls can have a Clarification Comment.
Control Quality - The CUBE control quality score provides an independent assessment of the clarity of a control description. The results are produced using proprietary machine learning models which are trained on thousands of controls from across the industry and reference the CUBE Data Technical Standards in their assessment of control description clarity
Unclear Control - and Unclear Control is a Customer control that the CUBE Control Quality Models have identified as being unclear. This can be for a variety of reasons which are captured in the 'Clarification Comment' (see above).
Control Matching - Control matching is the process of reviewing all customer controls for quality and their relationship (or not) with CUBE controls. The activity assigns every customer control in a scoped dataset with a Control Insight Code.
Risk Matching - Risk matching is the process of reviewing all customer risks to identify their relationship (or not) with CUBE risks. The activity assigns every customer risk in a scoped dataset with a Risk Insight Code.
Divisional Risk Matching - CUBE match CUBE risks aggregated to the widest level of customer risk taxonomy available. This could be a Division (e.g. Global Markets, Securities Services).
Group Risk Matching - If the highest level of risks provided by the customer is at Group level then risks will be matched at that level and divided later based on controls and businesses aligned with each Division and then CUBE Index.
Control - In the context of risk management, a control is a measure or action that is put in place to mitigate or reduce the likelihood or impact of a risk event.
Risk - the potential for losses or negative outcomes associated with an activity or process.
Risk Event - A risk event is a specific incident or occurrence that has the potential to cause negative consequences or losses for an individual, company, or organization.Â
CUBE Control Attributes - elements of CUBE Controls that capture control details outside of the Control Description.
Data Evaluation - the process that involves reviewing the customer dataset to ensure it contains the expected data coverage and the minimum data fields required for the product purchased from CUBE.
Index Alignment (aka 'scoping') - the review of Customer business lines and selection of the most appropriate CUBE Indices to connect that data with.
Risk Insight Codes - Risk Insight Codes are tags applied by CUBE to customer risks and CUBE risks to categorise the relationship between the datasets
Control Insight Codes - Control Insight Codes are tags applied by CUBE to customer controls and CUBE controls to categorise the relationship between the datasets
Mapping - creating a link, but not establishing compatibility, between one data element and another data element
Matching - creating a relationship between a comparable CUBE Control and a Customer control or CUBE Risk and Customer risk
Network Driven - the utilisation of Customer data to inform and create CUBE Risks, Controls and Processes. The principal being that CUBE will only create data points if sufficient numbers of customers (two or more) are using that data point, and if there is conflict between Customer data, the majority value is used.
Network Signal Strength - Our Network Signal Strength (NSS) tells you how many of your peers have a match to (i.e. operate) that particular CUBE control. A higher NSS shows that the control is more commonly operated and documented by the industry.
Normalised Signal Strength - The normalised signal strength was developed to provide Network Signal Strength insights independent of the CUBE Index, and as such, there is a unique score per index control. This insight is used when displaying information at a firm or business line level.
Non-Financial Risk - the potential risks faced by a financial institution that are not directly related to financial loss or gain. These risks can include things like operational risks, reputational risks, legal risks, strategic risks, and regulatory risks.
Non-Financial Risk Management - the process of identifying, assessing, and managing these non-financial risks to minimize their potential impact on the institution's operations, reputation, and overall performance. NFRM involves developing policies and procedures that address these risks, as well as implementing controls and processes that mitigate their potential impact.
Process - a series of activities or steps that are undertaken to achieve a specific objective or goal.
Risk Threat - a potential factor or condition that can increase the likelihood or impact of a negative outcome or event.
Risk Consequence - the potential negative outcome or impact that may result from a particular risk event or exposure.
Data Scoping - the alignment of Customer and CUBE data to allow for effective comparison, benchmarking, calibration and other analysis. It uses the DTS fields and knowledge of the customer to align customer businesses with the appropriate CUBE Indices. It comprises two processes: Data Evaluation and Index Alignment.
Shadow List - a list of unique, unmatched customer controls that have not qualified to be drafted into a CUBE control according to the 'two or more' rule. Therefore, they are a set of customer controls that are not yet sufficiently common and therefore, not surfaced by CUBE in an Index.
SMEs - CUBE individuals (Subject Matter Experts) who possess specialized knowledge and expertise in various aspects of non-financial risk management.
2 or more rule - the rule that two or more customers must operate the same control, risk, process, attribute etc in the same index for it to be added to CUBE.
Risk Taxonomy - a hierarchical classification system that is used to categorize and organize various types of risks based on their characteristics, causes, and potential impacts.
Process Taxonomy - a hierarchical classification system that is used to categorize and organize various types of business processes based on their characteristics, objectives, and outcomes.
Risk Intelligence - CUBE's horizon scanning product which maps CUBE Risk and Controls to announcements and markets events. Through these risk and control mappings and the results of Industry Calibration, each Risk Intelligence publication shows a bespoke view of how a customer may be exposed to the event.