Skip to main content

Reference regulatory obligations and risks

Relationship between reference regulatory obligations and risks

All regulatory obligations should be focused on preventing or detecting a particular risk which arises from the business process. As per section 3.4.3, these risks will be identified when reference regulatory obligations are extracted from the regulatory text. The risks will focus on the Risk Event i.e. what went wrong or what could go wrong that the regulation is trying to detect or prevent.

Mapping of reference regulatory obligations to the CUBE Risk Taxonomy

Based on the identification of these risks, reference regulatory obligations will be mapped to the CUBE Risk Taxonomy at the most granular level -- Level 3.

CUBE Index controls are already mapped to the Risk Taxonomy and therefore this facilitates the accuracy of the matching of reference regulatory obligations to CUBE controls and makes use of the existing relationships in the data model.

For each regulatory obligation, there can only be a one-to-one or one-to-many relationship between reference regulatory obligations and Level 3 risks in the CUBE risk taxonomy.

The focus of the mapping will be the Risk Event aspect of the CUBE Level 3 risks.