Skip to main content

Matching of regulatory controls to Index Controls

Regulatory controls will be matched to CUBE Index controls using the same mapping model which is used to match customer controls to CUBE Index controls. The advantage of having regulatory controls already restated in the CUBE Index control statement is that this format is already known and understood by these models.

Matching logic

There may be a one-to-one or one-to-many relationship between regulatory controls and CUBE Index controls.

Matching of regulatory controls to CUBE Index controls will be performed using the CUBE proprietary AI matching engine, making use of the data attributes in Table 3.6 to arrive at the most accurate match.

Table 3.6 Attributes used for matching regulatory controls to CUBE Index Controls

Regulatory ControlRiskProcessCUBE Index Control
RegControl NameLevel 3 Risk NameLevel 2 Process NameControl Objective
RegControl Description-Control Description

Exception handling

There may be instances where a regulatory obligation cannot be matched to a CUBE Index control. These reasons include:

  • Controls for that obligation are needed but are concerned with governance and are directive by nature (rather than detective/preventative) and as such are unlikely to be included in control libraries and the RCSA. Examples include obligations which require the establishment of departments / teams / committees, general organizational arrangements, authorisations etc.
  • Erroneous inclusion of elements of regulatory text that should have been filtered out or are at a lower level of granularity and are therefore embedded in a regulatory obligation.
  • Controls for that obligation are required but do not appear in any CUBE index controls OR unique to customer controls

In the event that a regulatory obligation cannot be matched to a CUBE index control, the process in Figure 3.4 will be followed.

Table 3.7 Regulatory Control CUBE Index Controls Mapping Codes###

High Level CodesReason Code LabelsDefinition
MatchedDirect MatchRegulatory control (and therefore byndefinition Reference Regulatory Obligation) matched to CUBE Index Control on one-to-one basis
MatchedOne to manyRegulatory control (and therefore by definition Reference Regulatory Obligation) matched to CUBE Index Controls on one-to-many basis
MatchedPartial matchPartially matches one or more CUBE Index Controls but requires SME review
No match to Cube Index ControlGovernance control requiredObligation requires a governance control
No match to Cube Index ControlNo match - Reg ControlRegulatory control (and therefore by definition Reference Regulatory Obligation) does not match to any CUBE Index Controls or unique to customer controls