Purpose

Maintain the operating steps for safe and sound electronic banking arrangements. Systems supporting client authentication, transaction execution, wallet interaction, and digital onboarding must operate in a secure and controlled manner.

Scope

This procedure applies to e-banking risk identification, countermeasures, internal control, customer security and transparency records. Where such systems interface with AML/CTF/CPF or sanctions controls, specific security and compliance requirements apply.

Steps

#ActionDetailsEvidence
1Confirm e-banking owner and control expectationsVerify systems supporting client authentication, transaction execution, wallet interaction, and digital onboarding operate in a secure and controlled manner.e-banking risk review
2Confirm customer and privileged access controlsVerify controls are appropriately designed where e-banking systems interface with AML/CTF/CPF or sanctions controls.customer-security or transparency record
3Verify encryption of onboarding and screening dataConfirm sensitive onboarding and screening data is encrypted and protected.encryption and access control evidence
4Verify anomalous activity monitoring and escalationConfirm anomalous activity is monitored and escalated.anomalous activity monitoring and escalation record
5Confirm transaction controls support sanctions and monitoringVerify transaction controls support sanctions and monitoring requirements where applicable.e-banking risk review
6Assess outage or control failure compliance impactVerify outages or control failures affecting digital channels are assessed for compliance and regulatory impact.outage or control failure compliance impact assessment
7Review risk assessments and internal controlsReview risk assessments, user-facing security measures and internal controls. Record changes, incidents or customer-security issues and assign actions.customer-security or transparency record
8Retain evidence of review, approval and follow-upRetain evidence of review, approval and follow-up.e-banking risk review
9Escalate cross-border or customer-protection gapsEscalate cross-border or customer-protection gaps where needed.escalation or remediation log

Evidence

  • e-banking risk review
  • customer-security or transparency record
  • encryption and access control evidence for onboarding and screening data
  • anomalous activity monitoring and escalation record
  • outage or control failure compliance impact assessment
  • escalation or remediation log where relevant

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved IT and Cybersecurity Manual version 1.1

History

  • 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
  • 2026-07-26: Created from REQ-IT-004.