Skip to content

Evidence request lists

CFTC System Safeguards (17 CFR 37, 38, 39, 49)

Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CFTC System Safeguards: Business Continuity and Disaster Recovery

CFTC-SS-10
Geographic Dispersal of Backup Infrastructure and Personnel

Where subject to the critical entity requirements, maintain infrastructure and personnel sufficient to meet the same day recovery objective that are located outside the relevant area and do not depend on the same critical transportation, telecommunications, power, water or other infrastructure components relied on for normal activities.

Artefacts an auditor will ask for
  • Site location analysis showing separation of the primary and backup sites
  • Dependency analysis for transportation, telecommunications, power and water at each site
  • Evidence that recovery personnel live and work outside the relevant area
  • Wide scale disruption test results
Where this commonly fails
  • Backup site in the same metropolitan area sharing utilities
  • Personnel dispersal not addressed at all
  • Dependency analysis limited to telecommunications
CFTC-SS-11
Testing and Review of Business Continuity and Disaster Recovery Capabilities

Conduct regular periodic testing and review of business continuity and disaster recovery capabilities, using protocols adequate to establish that backup resources are sufficient to meet the recovery requirements, and retain the results.

Artefacts an auditor will ask for
  • Recovery test plan and schedule
  • Test reports with scenario, scope, results and issues raised
  • Evidence that backup resources were exercised rather than assumed
  • Records of the results made available to the Commission on request
Where this commonly fails
  • Tabletop exercises only with no technical failover
  • Backup resources not exercised
  • Test issues not tracked to closure
  • Results not retained
CFTC-SS-24
Periodic Update of the Recovery Plan and Emergency Procedures

Update the business continuity and disaster recovery plan and emergency procedures at a frequency determined by an appropriate risk analysis and no less frequently than annually.

Artefacts an auditor will ask for
  • Version history of the plan showing at least annual update
  • Risk analysis determining the update frequency
  • Approval record for each updated version
  • Change log describing what was updated
Where this commonly fails
  • Plan reissued annually with no substantive change and no review record
  • Update frequency not derived from a risk analysis
  • Approval of the updated plan not recorded
CFTC-SS-25
Same Day Recovery Time Objective for Critical Entities

Where determined by the Commission to be a critical financial market or a critical swap data repository, maintain a recovery plan and resources sufficient to achieve a same day recovery time objective even in a wide scale disruption.

Artefacts an auditor will ask for
  • Record of the Commission determination of critical status
  • Same day recovery time objective documented in the plan
  • Test evidence demonstrating same day recovery
  • Resource plan supporting same day recovery in a wide scale disruption
Where this commonly fails
  • Critical status determined but the plan still carries a next business day objective
  • Same day recovery never tested against a wide scale disruption scenario
  • Resource plan does not distinguish local from wide scale events
CFTC-SS-26
Own Resources or Contractual Arrangements to Meet the Recovery Objective

Satisfy the recovery requirement either through infrastructure and personnel resources of the registrant own, or through contractual arrangements with another registrant or a disaster recovery service provider sufficient to ensure continued fulfilment of all responsibilities and obligations.

Artefacts an auditor will ask for
  • Statement of which route is relied on
  • Contracts with recovery service providers including the service levels
  • Evidence that the contracted arrangement covers all responsibilities and obligations
  • Provider capability verification and test participation
Where this commonly fails
  • Contractual route relied on without confirming the provider can meet the recovery objective
  • Contract covers infrastructure but not the regulatory obligations
  • Provider never included in recovery testing
CFTC-SS-27
Coordination of the Recovery Plan with Members and Market Participants

To the extent practicable, coordinate the business continuity and disaster recovery plan with those of the members, clearing members and other market participants on whom the registrant depends, so that activity can effectively resume following a disruption.

Artefacts an auditor will ask for
  • Register of members and participants on whom the registrant depends
  • Evidence of coordination such as shared recovery assumptions or joint planning documents
  • Communication procedures for a disruption
  • Assessment where coordination was judged impracticable
Where this commonly fails
  • No identification of the participants the registrant depends on
  • Coordination asserted with no supporting record
  • Impracticability claimed without assessment
CFTC-SS-28
Synchronised Testing with Members and Market Participants

To the extent practicable, initiate and coordinate periodic synchronised testing of the business continuity and disaster recovery plan with the plans of the members, clearing members and other market participants on whom the registrant depends.

Artefacts an auditor will ask for
  • Schedule of industry wide or member facing recovery tests
  • Participation records for members and participants
  • Test reports and the issues raised
  • Follow up records with participants who did not take part
Where this commonly fails
  • Testing performed internally only
  • Member participation not tracked
  • Issues raised by participants not followed up
CFTC-SS-29
Recovery Plan Accounts for Essential Service Providers

To the extent practicable, ensure the business continuity and disaster recovery plan takes into account the plans of telecommunications, power, water and other essential service providers.

Artefacts an auditor will ask for
  • Register of essential service providers per site
  • Evidence of the provider continuity arrangements obtained
  • Assessment of single points of failure across providers
  • Contract terms covering provider continuity
Where this commonly fails
  • Provider continuity assumed from the service contract with no evidence
  • Single points of failure across providers not analysed
  • Water and physical services omitted
CFTC-SS-30
Outsourcing with Retention of Complete Responsibility

Where required resources are maintained through a contractual outsourcing arrangement, retain complete responsibility for any failure to meet the program and recovery requirements and employ personnel with the expertise necessary to supervise the provider delivery of the services.

Artefacts an auditor will ask for
  • Register of outsourced system safeguards resources
  • Contracts reflecting the retained responsibility
  • Evidence of the in house expertise supervising each provider
  • Provider performance and service review records
Where this commonly fails
  • Reliance on provider assurance reports with no in house supervisory capability
  • Contracts transfer responsibility in substance
  • Provider reviews not documented
CFTC-SS-31
Testing Covers Outsourced Resources and Tester Independence from Providers

Apply the required testing to all resources whether owned or outsourced, verify that they work together effectively, and where independent testing is required engage a contractor independent of both the registrant and any outside service provider used to design, develop or maintain the resources being tested.

Artefacts an auditor will ask for
  • Test scope statements showing outsourced resources are included
  • End to end test evidence covering combined own and outsourced resources
  • Independence declarations from testing contractors covering the service providers
  • Procurement records evidencing the independence check
Where this commonly fails
  • Testing scoped to internally hosted systems only
  • Independence assessed against the registrant but not against the service provider
  • No end to end verification that own and outsourced resources work together
CFTC-SS-8
Business Continuity and Disaster Recovery Plan and Resources

Maintain a business continuity and disaster recovery plan, emergency procedures, backup facilities and physical, technological and personnel resources sufficient to enable timely recovery and resumption of operations and of the ongoing fulfilment of the registrant responsibilities and obligations following any disruption.

Artefacts an auditor will ask for
  • Current business continuity and disaster recovery plan
  • Emergency procedures and call trees
  • Inventory of backup facilities and standby resources
  • Mapping from each regulatory obligation to the recovery capability supporting it
  • Personnel succession and standby arrangements
Where this commonly fails
  • Plan covers technology recovery only and omits regulatory obligations such as market surveillance and audit trail
  • Personnel resources not addressed
  • Plan not linked to the specific responsibilities of the registrant category
CFTC-SS-9
Next Business Day Recovery Time Objective

Maintain the capability to resume operations and the ongoing fulfilment of responsibilities and obligations during the next business day following a disruption, unless determined to be a critical entity subject to the more stringent same day objective.

Artefacts an auditor will ask for
  • Documented recovery time objective and the analysis supporting it
  • Test results demonstrating the objective is achievable
  • Resource plan supporting the objective
  • Record of the entity critical or non critical determination
Where this commonly fails
  • Recovery objective stated but never demonstrated by test
  • Objective set for technology only and not for the regulatory obligations
  • Critical determination status not recorded

CFTC System Safeguards: Cybersecurity Testing

CFTC-SS-13
Vulnerability Testing

Conduct vulnerability testing of a scope sufficient to satisfy the scope requirement, at a frequency determined by an appropriate risk analysis and no less frequently than quarterly for covered entities, including automated vulnerability scanning following generally accepted best practices.

Artefacts an auditor will ask for
  • Vulnerability scan reports covering the required scope
  • Scanning schedule evidencing the frequency achieved
  • Risk analysis supporting the frequency
  • Evidence the scanning method follows accepted practice
  • Covered entity determination where the minimum frequency applies
Where this commonly fails
  • Scanning limited to external addresses
  • Quarterly minimum missed for a covered entity
  • Authenticated scanning not used so findings understate exposure
  • Scan findings not fed to the remediation register
CFTC-SS-14
External Penetration Testing

Conduct external penetration testing of a scope sufficient to satisfy the scope requirement, at a frequency determined by an appropriate risk analysis and no less frequently than annually for covered entities, with the required annual test performed by independent contractors for covered entities.

Artefacts an auditor will ask for
  • External penetration test reports with scope and methodology
  • Engagement letters evidencing contractor independence for the required annual test
  • Frequency risk analysis
  • Retest or closure evidence for findings
Where this commonly fails
  • Annual external test performed by internal staff at a covered entity
  • Scope narrower than the scope requirement demands
  • Findings not retested after remediation
CFTC-SS-15
Controls Testing

Conduct controls testing covering each control included in the program of risk analysis and oversight, at a frequency determined by an appropriate risk analysis, with key controls tested no less frequently than every three years for covered entities and the key control testing performed by independent contractors for covered entities.

Artefacts an auditor will ask for
  • Control inventory drawn from the program with the key control designation
  • Risk analysis identifying which controls are key controls
  • Testing schedule showing the rolling coverage of every control
  • Independent contractor reports for key control testing
  • Test results per control
Where this commonly fails
  • Controls testing covers a sample with no plan to reach full coverage
  • Key controls not identified
  • Rolling three year cycle asserted but coverage not tracked
  • Key control testing performed in house at a covered entity
CFTC-SS-16
Security Incident Response Plan and Testing

Maintain a written security incident response plan covering the definition and classification of security incidents, reporting policies and procedures, internal and external communication and information sharing, and hand off and escalation points, and test it at a frequency determined by an appropriate risk analysis and no less frequently than annually for covered entities.

Artefacts an auditor will ask for
  • Security incident response plan containing each required element
  • Test records with the method used and the participants
  • Post test improvement actions
  • Evidence of the definition and classification scheme in use
  • Escalation and hand off matrix
Where this commonly fails
  • Plan lacks the classification scheme or the escalation points
  • Testing limited to a walkthrough every few years
  • External communication and information sharing not addressed
  • Test findings not used to update the plan
CFTC-SS-17
Enterprise Technology Risk Assessment

Conduct a written enterprise technology risk assessment analysing threats and vulnerabilities in the context of mitigating controls and identifying, estimating and prioritising risks to operations, assets, market participants and others arising from impairment of data confidentiality, integrity and availability or of system reliability, security or capacity, at a frequency determined by an appropriate risk analysis and no less frequently than annually for covered entities.

Artefacts an auditor will ask for
  • Written enterprise technology risk assessment
  • Threat and vulnerability analysis set against the mitigating controls
  • Risk prioritisation covering effects on market participants and third parties
  • Evidence of annual refresh or documented update of the previous assessment
Where this commonly fails
  • Assessment covers internal impact only and omits market participants
  • Threats listed without reference to mitigating controls
  • Assessment not refreshed annually at a covered entity
CFTC-SS-18
Independence of Testers

Perform the required testing either by engaging independent contractors or by using employees who are not responsible for the development or operation of the systems or capabilities being tested, and engage independent contractors where the rules require it.

Artefacts an auditor will ask for
  • Independence declaration for each test engagement
  • Organisation chart or role evidence showing testers are not responsible for the systems tested
  • Procurement records for independent contractor engagements
  • Assessment of contractor independence from any outside service provider involved
Where this commonly fails
  • Testing performed by the operating team
  • Independence claimed on the basis of a separate reporting line within the same function
  • Contractor independence from the service provider not assessed
CFTC-SS-33
Regular Periodic Objective Testing and Review of Automated Systems

Conduct regular, periodic and objective testing and review of automated systems to establish that they are reliable, secure and have adequate scalable capacity, covering all of the required types of testing.

Artefacts an auditor will ask for
  • Testing programme covering all required test types with their frequencies
  • Risk analysis determining each testing frequency
  • Test calendar and completion tracking
  • Evidence of objectivity in how testing is commissioned and reported
Where this commonly fails
  • Testing programme covers penetration testing only
  • Frequencies set by convention rather than risk analysis
  • Completion against the calendar not tracked
CFTC-SS-34
Internal Penetration Testing

Conduct internal penetration testing of a scope sufficient to satisfy the scope requirement, at a frequency determined by an appropriate risk analysis and no less frequently than annually for covered entities, performed by independent contractors or by employees not responsible for development or operation of the systems tested.

Artefacts an auditor will ask for
  • Internal penetration test reports with scope and methodology
  • Evidence that testers are independent of development and operation of the tested systems
  • Frequency risk analysis
  • Findings tracked to closure
Where this commonly fails
  • Internal testing omitted entirely because external testing is performed
  • Testing performed by the team that operates the systems
  • Annual minimum missed for a covered entity
CFTC-SS-35
Scope of Testing and Assessment

Set the scope of all system safeguards testing and assessment broadly enough to include the automated systems and controls that the program and the current cybersecurity threat analysis indicate are necessary to identify risks and vulnerabilities that could enable an intruder, unauthorised user or insider to interfere with operations or regulatory responsibilities, impair reliability, security or capacity, alter or exfiltrate regulated activity data, or take other unauthorised action.

Artefacts an auditor will ask for
  • Documented scoping rationale for each test referencing the program and the threat analysis
  • Current cybersecurity threat analysis
  • Systems and controls in scope and the justification for any exclusion
  • Evidence the four risk outcomes in the rule were considered in scoping
Where this commonly fails
  • Scope carried forward year on year without reference to the threat analysis
  • Exclusions undocumented
  • Insider risk outcomes not considered in scoping
CFTC-SS-36
Internal Reporting and Review by Senior Management and the Board

Ensure that both senior management and the board receive and review reports setting out the results of the required testing and assessment, and establish and follow procedures for remediation of the issues identified and for evaluating the effectiveness of the testing and assessment protocols.

Artefacts an auditor will ask for
  • Board and senior management papers presenting the testing and assessment results
  • Minutes evidencing review and any decisions taken
  • Documented remediation procedure
  • Records of the evaluation of the effectiveness of the testing protocols
Where this commonly fails
  • Results presented to management only and not to the board
  • Reports tabled but no evidence of review or challenge
  • No periodic evaluation of whether the testing protocols are effective

CFTC System Safeguards: Notification, Records and Remediation

CFTC-SS-19
Prompt Notification to the Commission

Notify Commission staff promptly of electronic trading halts and significant systems malfunctions, hardware or software malfunctions, security incidents or targeted threats that jeopardise or are likely to jeopardise system operation, reliability, security or capacity, and of any activation of the business continuity and disaster recovery plan.

Artefacts an auditor will ask for
  • Notification procedure naming the trigger events, the recipient division and the timeframe
  • Log of notifications made with timestamps
  • Assessment records for events judged not notifiable
  • Escalation path and out of hours arrangements
Where this commonly fails
  • Notification triggers not defined so events are assessed case by case
  • Notifications made by informal contact with no record
  • No record of the assessment for events judged not notifiable
  • Plan activation not treated as a notifiable event
CFTC-SS-20
Production of System Safeguards Books and Records

Provide to the Commission promptly on request the current business continuity and disaster recovery plans and other emergency procedures, all assessments of operational risks or system safeguards related controls, all reports concerning system safeguards testing and assessment whether by independent contractors or employees, and all other books and records requested in connection with system safeguards oversight.

Artefacts an auditor will ask for
  • Records inventory covering each listed category
  • Retention schedule meeting the recordkeeping rules
  • Evidence records can be produced promptly, such as a prior production log
  • Records of testing performed by employees as well as contractors
Where this commonly fails
  • Contractor test reports retained but employee performed testing not documented
  • Records held by individuals rather than a managed repository
  • Retention shorter than the applicable recordkeeping period
CFTC-SS-21
Remediation of Vulnerabilities and Deficiencies

Identify and document the vulnerabilities and deficiencies revealed by the required testing and assessment, analyse and document the risks they present in order to decide and document whether to remediate or accept the risk, and remediate in a timely manner given the nature and magnitude of the risk.

Artefacts an auditor will ask for
  • Findings register capturing every vulnerability and deficiency from testing
  • Risk analysis for each finding with the remediate or accept decision and its approver
  • Remediation timescales tied to the risk rating
  • Evidence of closure and of risk acceptances being revisited
Where this commonly fails
  • Findings tracked without a documented risk analysis
  • Risk acceptances granted with no owner, rationale or expiry
  • Remediation timescales not linked to risk magnitude
  • Findings from employee performed testing not entered in the register
CFTC-SS-32
Timely Advance Notice of Material Planned Changes

Give Commission staff timely advance notice of all material planned changes to automated systems that may affect their reliability, security or adequate scalable capacity, and of material planned changes to the program of risk analysis and oversight.

Artefacts an auditor will ask for
  • Change management procedure identifying which changes require advance notice
  • Register of notices given with dates relative to the change
  • Materiality criteria for change notification
  • Notices covering changes to the program itself
Where this commonly fails
  • Materiality criteria undefined
  • Notices given after implementation
  • Changes to the program of risk analysis and oversight never notified

CFTC System Safeguards: Registrant Specific Requirements

CFTC-SS-37
Protection of Swap Data Repository Data

A swap data repository must, with respect to all data in its custody, maintain the program of risk analysis and oversight, maintain emergency procedures, backup facilities and a recovery plan allowing timely recovery and resumption of its duties, and periodically test that backup resources are sufficient to continue fulfilling all of its statutory and regulatory duties.

Artefacts an auditor will ask for
  • Inventory of the data held in custody and its criticality
  • Recovery plan mapped to the specific duties of a swap data repository
  • Backup sufficiency test results referenced to those duties
  • Access and integrity controls over the repository data
Where this commonly fails
  • Recovery plan written for the platform rather than for the data duties
  • Backup testing does not demonstrate the duties can continue to be met
  • Data in custody not inventoried
CFTC-SS-38
Production of Annual Total Trading Volume

A designated contract market must provide its annual total trading volume to the Commission for each calendar year by the prescribed date, the figure that determines whether it is a covered designated contract market subject to the minimum testing frequency and independent contractor testing requirements.

Artefacts an auditor will ask for
  • Annual total trading volume submission records with the date submitted
  • Calculation basis for the volume figure
  • Record of the percentage returned by the Commission
  • Determination of covered status and its effect on the testing programme
Where this commonly fails
  • Submission made late or not evidenced
  • Covered status never determined so the enhanced testing frequencies are not applied
  • Calculation basis undocumented
CFTC-SS-39
Critical Financial Market Designation Obligations

Where the Commission has determined the registered entity to be a critical financial market, comply with the additional obligations governing maintenance and geographic dispersal of disaster recovery resources sufficient to meet a same day recovery time objective in a wide scale disruption.

Artefacts an auditor will ask for
  • Record of the Commission determination and the date it took effect
  • Compliance assessment against the additional obligations
  • Evidence of the geographic dispersal and same day capability
  • Notification and reporting records arising from the designation
Where this commonly fails
  • Designation status not tracked
  • Additional obligations assumed to be met by the standard recovery plan
  • No assessment against the specific requirements that follow the designation

CFTC System Safeguards: Risk Analysis and Oversight Program

CFTC-SS-1
Program of Risk Analysis and Oversight

Establish and maintain a program of risk analysis and oversight covering operations and automated systems, to identify and minimise sources of operational risk through appropriate controls and procedures and through systems that are reliable, secure and have adequate scalable capacity.

Artefacts an auditor will ask for
  • Written program of risk analysis and oversight approved by the board
  • Mapping of the program to each prescribed category
  • Board and senior management approval records
  • Annual review record of the program
Where this commonly fails
  • Program exists as separate policies with no single documented program
  • Not all prescribed categories addressed
  • No evidence of board approval or review
CFTC-SS-12
Capacity and Performance Planning Category

Address capacity and performance planning within the program, including controls for monitoring systems to ensure adequate scalable capacity and testing, monitoring and analysis of current and projected capacity and performance and of possible degradation from planned system changes.

Artefacts an auditor will ask for
  • Capacity monitoring configuration and thresholds
  • Capacity and performance trend reporting
  • Projected capacity analysis against expected volumes
  • Assessment of capacity impact for planned changes
Where this commonly fails
  • Capacity monitored reactively with no projection
  • Change assessments omit capacity impact
  • No documented capacity thresholds
CFTC-SS-2
Enterprise Risk Management and Governance Category

Address enterprise risk management and governance within the program, covering assessment, mitigation and monitoring of security and technology risk, security and technology capital planning and investment, board and management oversight, technology audit and controls assessments, and remediation of deficiencies.

Artefacts an auditor will ask for
  • Technology and security risk register with assessment and monitoring evidence
  • Technology capital plan and investment approvals
  • Board technology and security oversight papers
  • Internal audit reports on technology and controls
  • Deficiency remediation tracker
Where this commonly fails
  • Technology risk not represented in the enterprise risk register
  • No technology capital planning tied to security
  • Board oversight limited to incident reporting
CFTC-SS-22
Business Continuity and Disaster Recovery Planning Category

Address business continuity and disaster recovery planning and resources within the program, including regular periodic testing and review of those capabilities and the controls described in the recovery paragraphs of the section.

Artefacts an auditor will ask for
  • Program section covering business continuity and disaster recovery
  • Testing and review schedule for continuity capabilities
  • Linkage from the program to the recovery plan and resources
Where this commonly fails
  • Continuity treated as a separate plan not represented in the program
  • Testing schedule absent from the program
  • Program references the plan without describing the controls
CFTC-SS-23
Resources Sufficient to Fulfil Obligations

Establish and maintain resources that allow each obligation and responsibility to be fulfilled, including daily processing, clearing and settlement of transactions, in light of any risk to operations and automated systems, and periodically verify that those resources are adequate.

Artefacts an auditor will ask for
  • Resource assessment covering personnel, infrastructure and capacity
  • Periodic verification of resource adequacy with dates and outcomes
  • Link from the assessment to the daily processing obligations
Where this commonly fails
  • Resource adequacy assumed rather than verified
  • Verification performed without a documented outcome
  • Personnel resources not covered
CFTC-SS-3
Information Security Category

Address information security within the program, covering access to systems and data with least privilege, separation of duties and account monitoring, user and device identification and authentication, security awareness training, audit log maintenance and analysis, media protection, personnel security and screening, system and communications protection, system and information integrity, vulnerability management, penetration testing and security incident response.

Artefacts an auditor will ask for
  • Information security policy set covering each listed element
  • Access control and privileged access review records
  • Authentication standards for users and devices
  • Security awareness training records
  • Audit log configuration, retention and review evidence
  • Vulnerability management and remediation reporting
  • Security incident response plan and incident records
Where this commonly fails
  • One or more listed elements absent, commonly media protection and personnel screening
  • Least privilege stated but not evidenced by access reviews
  • Audit logs collected but not analysed
CFTC-SS-4
Systems Operations Category

Address systems operations within the program, covering system maintenance, configuration management including baseline configuration, configuration change and patch management, least functionality and inventory of authorised and unauthorised devices and software, and event and problem response and management.

Artefacts an auditor will ask for
  • Configuration baselines and compliance reporting
  • Patch management records with timescales
  • Asset inventory covering authorised and unauthorised devices and software
  • Event and problem management records
Where this commonly fails
  • Inventory covers authorised assets only
  • Baselines defined but conformance not measured
  • Problem management not distinguished from incident handling
CFTC-SS-5
Systems Development and Quality Assurance Category

Address systems development and quality assurance within the program, covering requirements development, pre production and regression testing, change management procedures and approvals, outsourcing and vendor management, and training in secure coding practices.

Artefacts an auditor will ask for
  • Software development lifecycle procedure
  • Pre production and regression test evidence
  • Change approval records
  • Vendor management procedure for development suppliers
  • Secure coding training records
Where this commonly fails
  • Emergency changes bypass approval with no retrospective record
  • Regression testing not evidenced
  • Secure coding training absent
CFTC-SS-6
Physical Security and Environmental Controls Category

Address physical security and environmental controls within the program, covering physical access and monitoring, power, telecommunication and environmental controls, and fire protection.

Artefacts an auditor will ask for
  • Physical access control and monitoring records for data centres and technical areas
  • Environmental and power system maintenance and test records
  • Fire detection and suppression test records
  • Access list reviews
Where this commonly fails
  • Colocation and cloud facilities excluded on the basis that they are third party managed
  • Environmental system tests not retained
  • Access lists not reviewed
CFTC-SS-7
Generally Accepted Standards and Best Practices

In addressing the prescribed categories, follow generally accepted standards and best practices with respect to the development, operation, reliability, security and capacity of automated systems.

Artefacts an auditor will ask for
  • Statement of the standards and frameworks adopted
  • Mapping from the program to the adopted standard
  • Gap assessment against the adopted standard and its remediation plan
  • Evidence the standard version in use is current
Where this commonly fails
  • Standards named but no mapping to the program
  • Gap assessment performed once and never repeated
  • Adopted standard version out of date
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the CFTC System Safeguards (17 CFR 37, 38, 39, 49) framework page.