Control Matrix

Builds the named-row risk-control matrix that maps obligations to control objectives, control activities, owners, frequency, evidence pointers, test methods, last-test results, and open issues. Foundational primitive: compliance-testing samples against it, vendor-diligence and exit-plan reference it, exam-brief reads it, model-card-builder pulls its controls section from it. Risk function and compliance function both consume the same matrix. Best for: - Standing up the matrix for a process, product, or function (lending, vendor lifecycle, model lifecycle, risk-data and risk reporting, cyber-disclosure governance, consumer-compliance management). - Refreshing an existing matrix after a regulatory change, an MRA, an audit finding, an incident, or a process redesign. - Translating a freshly mapped obligation set into the row structure that downstream testing and review will run against. Not the right tool when: - The obligations have not been extracted yet. Run `obligation-mapping` first; the matrix consumes its

anotb d640540 13 files · 109.3 KB Updated

File contents

anotb/second-line-financial-services/tree/main/plugins/capability-plugins/risk-compliance-core/skills/control-matrix commit d6405409fe

Frequently asked questions

npx skillmds@latest add anotb/control-matrix