Matching of regulatory controls to Index Controls
Regulatory controls will be matched to CUBE Index controls using the same mapping model which is used to match customer controls to CUBE Index controls. The advantage of having regulatory controls already restated in the CUBE Index control statement is that this format is already known and understood by these models.
Matching logic
There may be a one-to-one or one-to-many relationship between regulatory controls and CUBE Index controls.
Matching of regulatory controls to CUBE Index controls will be performed using the CUBE proprietary AI matching engine, making use of the data attributes in Table 3.6 to arrive at the most accurate match.
Table 3.6 Attributes used for matching regulatory controls to CUBE Index Controls
| Regulatory Control | Risk | Process | CUBE Index Control |
|---|---|---|---|
| RegControl Name | Level 3 Risk Name | Level 2 Process Name | Control Objective |
| RegControl Description | - | Control Description |
Exception handling
There may be instances where a regulatory obligation cannot be matched to a CUBE Index control. These reasons include:
- Controls for that obligation are needed but are concerned with governance and are directive by nature (rather than detective/preventative) and as such are unlikely to be included in control libraries and the RCSA. Examples include obligations which require the establishment of departments / teams / committees, general organizational arrangements, authorisations etc.
- Erroneous inclusion of elements of regulatory text that should have been filtered out or are at a lower level of granularity and are therefore embedded in a regulatory obligation.
- Controls for that obligation are required but do not appear in any CUBE index controls OR unique to customer controls
In the event that a regulatory obligation cannot be matched to a CUBE index control, the process in Figure 3.4 will be followed.
Table 3.7 Regulatory Control CUBE Index Controls Mapping Codes###
| High Level Codes | Reason Code Labels | Definition |
|---|---|---|
| Matched | Direct Match | Regulatory control (and therefore byndefinition Reference Regulatory Obligation) matched to CUBE Index Control on one-to-one basis |
| Matched | One to many | Regulatory control (and therefore by definition Reference Regulatory Obligation) matched to CUBE Index Controls on one-to-many basis |
| Matched | Partial match | Partially matches one or more CUBE Index Controls but requires SME review |
| No match to Cube Index Control | Governance control required | Obligation requires a governance control |
| No match to Cube Index Control | No match - Reg Control | Regulatory control (and therefore by definition Reference Regulatory Obligation) does not match to any CUBE Index Controls or unique to customer controls |