Processes
This section defines the Processes that CUBE has identified from Customer data and industry standards. By including the Process dimension, CUBE and customers can perform analyses from a broader perspective that spans risks and business functions. This approach enables customers to identify risks' root causes and design effective control measures. All businesses conduct processes as part of their daily operations, which inevitably incur risk. To mitigate these risks, companies impose controls.
Process Definition
CUBE has created a 3-level Process Taxonomy based on extensive research into Customer process taxonomies and industry data. The aim is to reflect the commonality observed across those data sets. The definition of CUBE Process follows the overarching principles of the DTS: clarity, conciseness, and simplicity.
The Level 3 Processes developed by CUBE adhere to the following guidelines:
- Process names must be concise (2 - 6 words), and unambiguous.
- Process names must include a noun, for example
- Data Collection
- Sanctions Screening and Monitoring
- Trade Capture
- Level 3 Process descriptions must be short but accurately convey what the process does
- Level 2 Processes are SME-driven aggregations of L3 Processes
- Level 1 Processes are SME-driven aggregations of L2 Processes.
By adhering to these guidelines, CUBE ensures that their Process Taxonomy is easy to understand, universally applicable, and promotes consistency in risk management across financial institutions.
Process Mapping
The effective alignment of Process, Risk and Control is crucial to deriving value from the Process element. CUBE align Process to Risk to Control by leveraging Customer data and SME industry knowledge.
Processes are mapped to Risk Events and Controls separately.