Purpose

Maintain the governance structure, ownership and review rhythm for the COTS acceptance framework.

Scope

This procedure applies to board oversight, management review, owner assignment and governance reporting for COTS acceptance.

Steps

#ActionDetailsEvidence
1Confirm COTS governance baselineConfirm the current COTS manual, CBCS source mapping, risk appetite and accountable owners.Governance record
2Confirm Board oversightConfirm the Board reviews COTS-related risk exposure at least annually and that management provides adequate people, tools and test environments.Board review note
3Obtain independent CORF challengeObtain independent CORF challenge of material product, ICT, legal and compliance risks and acceptance results.CORF challenge record
4Confirm Internal Audit reviewConfirm Internal Audit periodically assesses compliance with the manual and the minimum TMMi Level 2, training and security-testing expectations.Internal Audit report
5Record decisions and exceptionsRecord decisions, exceptions and remediation actions in the approved evidence repository and BCMS.Evidence repository entry
6Escalate governance gapsRaise unresolved governance or independence gaps as issues and track them to closure.Issue or remediation record

Evidence

  • governance record
  • board or management review note
  • issue or remediation record where applicable

Relationships

Implementation

  • Implementation state: current under the approved COTS Acceptance and Testing Manual version 1.0
  • Execution evidence: retained for each governance cycle

History

  • 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
  • 2026-07-26: Created from the approved COTS manual and mapped to CBCS-derived IT requirements.