Purpose
Maintain the operating steps for safe and sound electronic banking arrangements. Systems supporting client authentication, transaction execution, wallet interaction, and digital onboarding must operate in a secure and controlled manner.
Scope
This procedure applies to e-banking risk identification, countermeasures, internal control, customer security and transparency records. Where such systems interface with AML/CTF/CPF or sanctions controls, specific security and compliance requirements apply.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Confirm e-banking owner and control expectations | Verify systems supporting client authentication, transaction execution, wallet interaction, and digital onboarding operate in a secure and controlled manner. | e-banking risk review |
| 2 | Confirm customer and privileged access controls | Verify controls are appropriately designed where e-banking systems interface with AML/CTF/CPF or sanctions controls. | customer-security or transparency record |
| 3 | Verify encryption of onboarding and screening data | Confirm sensitive onboarding and screening data is encrypted and protected. | encryption and access control evidence |
| 4 | Verify anomalous activity monitoring and escalation | Confirm anomalous activity is monitored and escalated. | anomalous activity monitoring and escalation record |
| 5 | Confirm transaction controls support sanctions and monitoring | Verify transaction controls support sanctions and monitoring requirements where applicable. | e-banking risk review |
| 6 | Assess outage or control failure compliance impact | Verify outages or control failures affecting digital channels are assessed for compliance and regulatory impact. | outage or control failure compliance impact assessment |
| 7 | Review risk assessments and internal controls | Review risk assessments, user-facing security measures and internal controls. Record changes, incidents or customer-security issues and assign actions. | customer-security or transparency record |
| 8 | Retain evidence of review, approval and follow-up | Retain evidence of review, approval and follow-up. | e-banking risk review |
| 9 | Escalate cross-border or customer-protection gaps | Escalate cross-border or customer-protection gaps where needed. | escalation or remediation log |
Evidence
- e-banking risk review
- customer-security or transparency record
- encryption and access control evidence for onboarding and screening data
- anomalous activity monitoring and escalation record
- outage or control failure compliance impact assessment
- escalation or remediation log where relevant
Relationships
- Requirement: REQ-IT-004 Maintain Safe and Sound Electronic Banking
- Policy: POL-IT-001 IT and Cybersecurity Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-IT-004 Ensure Safe and Sound Electronic Banking Is Maintained
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved IT and Cybersecurity Manual version 1.1
History
- 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
- 2026-07-26: Created from REQ-IT-004.