Skip to content

Evidence request lists

HKMA Cyber Resilience Assessment Framework (C-RAF)

Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

HKMA C-RAF Domain 1-2: Governance + Identification (Cyber Strategy, Risk Mgmt, Asset Mgmt, Threat Assessment)

HKMA-CRAF-Domain1-2-Governance-Identification
HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment

HKMA C-RAF Domain 1 GOVERNANCE + Domain 2 IDENTIFICATION. DOMAIN 1 GOVERNANCE (5 sub-areas): (1) CYBER RISK GOVERNANCE - board + senior management oversight + governance structure + reporting lines + delegation; board cyber-risk literacy + training; cyber-risk-committee or board-committee oversight + minutes + escalation; (2) CYBER RISK STRATEGY - documented + board-approved cyber strategy + alignment with business strategy + risk appetite + 3-5 year roadmap + investment + resource planning; (3) CYBER RISK CULTURE - tone-from-the-top + cyber-aware culture + accountability + non-punitive reporting + cross-business engagement + customer-protection orientation; (4) ROLES + RESPONSIBILITIES - clearly-defined cyber roles including CISO + Cyber Risk Officer + business-line cyber-risk owners + 3-lines-of-defense; (5) CYBER RISK REPORTING - regular + risk-based reporting to board + senior manage

Artefacts an auditor will ask for
  • Governance documents + board records
  • Asset inventory + dependency mapping
  • Threat-landscape monitoring evidence
Where this commonly fails
  • Governance documents incomplete
  • Asset inventory gaps
  • Threat assessment weak

HKMA C-RAF Domain 3-4: Protection + Detection (Access, Data, Infrastructure, Application, Monitoring, Testing)

HKMA-CRAF-Domain3-4-Protection-Detection
HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel

HKMA C-RAF Domain 3 PROTECTION + Domain 4 DETECTION. DOMAIN 3 PROTECTION (6 sub-areas): (1) ACCESS CONTROL - identity + access management + privileged access (PAM) + MFA + zero trust + just-in-time access + role-based access + access reviews + offboarding; (2) DATA SECURITY - data classification + encryption at rest + in transit + key management + DLP + tokenisation + de-identification + secure-data-destruction; (3) INFRASTRUCTURE SECURITY - network segmentation + firewall + IDS/IPS + endpoint protection + patch management + secure configuration + cloud security + hybrid + zero-trust network architecture; (4) APPLICATION SECURITY - secure SDLC + DevSecOps + code review + SAST + DAST + SCA + container + API + cloud-native security + WAF + bot protection; (5) SECURITY AWARENESS + TRAINING - workforce training + role-based + phishing simulation + awareness campaigns + cyber-skill developmen

Artefacts an auditor will ask for
  • Protection control evidence per sub-area
  • SIEM + SOC + threat-intel coverage
  • Pen-test + red team reports + remediation
Where this commonly fails
  • Protection gaps
  • Detection coverage weak
  • Testing program inadequate

HKMA C-RAF Domain 5-6: Response & Recovery + Situational Awareness (IR, Recovery, Threat Intel, Info Sharing)

HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness
HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing

HKMA C-RAF Domain 5 RESPONSE AND RECOVERY + Domain 6 SITUATIONAL AWARENESS. DOMAIN 5 RESPONSE AND RECOVERY (3 sub-areas): (1) INCIDENT RESPONSE PLANNING - documented IR plan + playbooks + runbooks + RACI + escalation criteria + decision trees + communication plan including HKMA cyber-incident reporting (24-hour + 48-hour SLAs per HKMA Circulars) + customer + media + regulatory communications + legal + law-enforcement + 3rd-party partner integration + retainer + tabletop exercises; (2) INCIDENT RESPONSE EXECUTION - SOC-coordinated detection + triage + containment + eradication + recovery + post-incident review + lessons learned + remediation + sharing learnings with sector via CISP + maintaining forensic chain of evidence + working with HKCERT + HK Police + threat-intel sharing + cross-jurisdiction coordination; (3) RECOVERY AND RESILIENCE - business continuity + DR + RTO/RPO + IT continu

Artefacts an auditor will ask for
  • IR plan + playbooks + tabletop exercises
  • BCP/DR + RTO/RPO + recovery testing
  • CISP/HKCERT/FS-ISAC participation
Where this commonly fails
  • IR plan weak + not tested
  • Recovery procedures untested
  • Threat-intel sharing not done

HKMA C-RAF: Coordination with HKMA SPM TM-G-1, Sectoral Coordination, 2024-2025 Pipeline

HKMA-CRAF-2024-2025-AI-Quantum-Cloud-Ransomware-DORA
HKMA C-RAF 2024-2025 Pipeline - AI, Quantum-Resistant Cryptography, Cloud Security, Ransomware, EU DORA Coordination

HKMA C-RAF 2024-2025 pipeline + emerging risks + sectoral cybersecurity evolution. KEY 2024-2025 INITIATIVES: (1) AI + MACHINE LEARNING + GENERATIVE AI CYBER GOVERNANCE - AIs deploying AI/ML for fraud detection + AML + customer service + lending + risk management; emerging governance + bias + transparency + adversarial ML + AI-specific attack vectors (prompt injection + model extraction + data poisoning); HKMA supervisory communications on AI cyber risk. (2) QUANTUM-RESISTANT CRYPTOGRAPHY READINESS - NIST FIPS 203 (ML-KEM) + FIPS 204 (ML-DSA) + FIPS 205 (SLH-DSA) finalized 2024; cryptographic asset inventory + crypto-agility + transition planning + 'harvest now decrypt later' threat mitigation; HKMA supervisory expectations + sectoral working groups. (3) CLOUD + MULTI-CLOUD + HYBRID SECURITY - increased cloud adoption + sovereign cloud requirements + outsourcing risk + sub-processor visi

Artefacts an auditor will ask for
  • Pipeline tracking + impact assessment
  • Emerging risk readiness + roadmap
  • Multi-jurisdictional + DORA coordination
Where this commonly fails
  • Pipeline not tracked
  • Emerging risk readiness gaps
  • Multi-jurisdictional coordination weak
HKMA-CRAF-Coord-SPM-TM-G-1-Singapore-UK-Sectoral
HKMA C-RAF Coordination with HKMA SPM TM-G-1, Singapore MAS TRMG, UK FCA Operational Resilience and Sectoral Cybersecurity

HKMA C-RAF coordination with HKMA SPM Modules + international banking sectoral cybersecurity + 2024-2025 pipeline. HKMA SUPERVISORY POLICY MANUAL (SPM) MODULES: (a) TM-G-1 General Principles for Technology Risk Management (verified separately) - foundational technology risk management expectations + 7 modules; (b) GS-1 General Principles for Risk Management - enterprise-wide risk management; (c) TM-G-3 General Principles for Information Technology Risk Management - earlier TI module; (d) IC-1 Risk-Based Approach to Inspection - supervisory approach; (e) other SPM Modules covering BCM + operational risk + AML + outsourcing + cloud. SINGAPORE MAS TRMG (Technology Risk Management Guidelines, June 2021) - parallel framework for Singapore-licensed financial institutions; similar 7-pillar structure + maturity assessment + mandatory + supervisory oversight; cross-Asia banking coordination. UK F

Artefacts an auditor will ask for
  • Multi-framework alignment + crosswalk
  • Sectoral cybersecurity engagement
  • 2024-2025 emerging risk readiness
Where this commonly fails
  • Multi-framework alignment ad-hoc
  • Sectoral engagement weak
  • Emerging risk readiness gap
HKMA-CRAF-Implementation-Roles-Tooling-Assurance
HKMA C-RAF Implementation Roadmap, Organizational Roles, Tooling and Assurance

HKMA C-RAF implementation roadmap. ORGANIZATIONAL ROLES at AI: (a) BOARD + RISK COMMITTEE - C-RAF governance oversight + cyber-strategy + risk appetite + reporting; (b) CHIEF INFORMATION SECURITY OFFICER (CISO) - operational ownership + C-RAF program lead + Maturity Assessment + IRA + remediation; (c) CHIEF RISK OFFICER (CRO) / HEAD OF OPERATIONAL RISK - 2nd-line oversight + cyber-risk integration + reporting + Board engagement; (d) CHIEF TECHNOLOGY OFFICER (CTO) / CIO - IT + cloud + infrastructure + DevSecOps + asset management; (e) HEAD OF INTERNAL AUDIT (3rd line) - cyber audit + 3-year independent review oversight; (f) COMPLIANCE - HKMA supervisory relations + regulatory reporting; (g) BUSINESS LINE CYBER-RISK OWNERS - 1st-line accountability + cyber-risk acceptance; (h) HUMAN RESOURCES - cyber training + workforce + culture; (i) PROCUREMENT + 3rd-PARTY MANAGEMENT - vendor cyber risk

Artefacts an auditor will ask for
  • Role inventory + RACI
  • Tooling adoption + integration
  • Annual + 3-year cycle execution
  • Workforce certifications
Where this commonly fails
  • Roles undefined
  • Tooling fragmented
  • Program execution gaps
  • Workforce gaps
HKMA-CRAF-Status-Industry-Adoption-FutureRoadmap
HKMA C-RAF Status, Industry Adoption, Hong Kong Banking Sector and Future Roadmap

HKMA C-RAF status + Hong Kong banking sector adoption. ADOPTION: ALL ~150+ HKMA AUTHORISED INSTITUTIONS (AIs) mandated to participate in CFI + C-RAF + complete annual self-assessment + 3-year independent review + ongoing supervisory dialogue; major participants include local banks (HSBC + Hang Seng Bank + Standard Chartered Hong Kong + Bank of China Hong Kong + DBS Hong Kong + Citi + UBS + Goldman Sachs + Morgan Stanley + many more); RLBs + DTCs + foreign banks operating in Hong Kong; ~100 percent participation as mandated. CYBER MATURITY PROGRESS: significant industry maturity improvement since 2016 launch; most AIs at Intermediate (Level 3) or higher maturity; HIGH-inherent-risk AIs typically Intermediate-to-Advanced (Level 3-4); v2.0 raised maturity expectations + added iCAST requirement. iCAST EXECUTION: significant industry experience executing iCAST + remediation; sectoral lessons

Artefacts an auditor will ask for
  • AI participation + maturity evidence
  • CISP + PDP engagement
  • Supervisory dialogue + roadmap
Where this commonly fails
  • Adoption monitoring weak
  • CISP + PDP gaps
  • Supervisory engagement weak

HKMA C-RAF: Cybersecurity Fortification Initiative (CFI), 3 Pillars (C-RAF + PDP + CISP), Mandatory Scope

HKMA-CRAF-CFI-3Pillars-Scope-Mandatory
HKMA CFI 3 Pillars (C-RAF + PDP + CISP), Mandatory Scope and Supervisory Framework

HKMA CYBERSECURITY FORTIFICATION INITIATIVE (CFI) - announced May 2016 + ongoing evolution + C-RAF v2.0 issued 6 May 2020 (Circular 20200506e1a1). CFI 3 PILLARS: (1) CYBER RESILIENCE ASSESSMENT FRAMEWORK (C-RAF) - mandatory tiered self-assessment of cybersecurity maturity vs inherent risk; (2) PROFESSIONAL DEVELOPMENT PROGRAMME (PDP) - workforce certifications (Certified Cyber Security Officer CCSO + Cyber Risk Management); (3) CYBER INTELLIGENCE SHARING PLATFORM (CISP) - HKMA-operated sectoral intelligence-sharing platform + threat-intel feeds + IOC distribution + integration with HKCERT + commercial providers. SCOPE: C-RAF applies to ALL HKMA AUTHORISED INSTITUTIONS (AIs) - approximately 150+ entities including (a) LICENSED BANKS (mainstream commercial banks); (b) RESTRICTED LICENCE BANKS (RLBs - investment banks + private banks); (c) DEPOSIT-TAKING COMPANIES (DTCs - finance companies)

Artefacts an auditor will ask for
  • AI status confirmation + scope evidence
  • C-RAF + PDP + CISP participation
  • Supervisory dialogue records
Where this commonly fails
  • Scope unclear
  • CFI 3 Pillars participation gaps
  • Supervisory engagement weak

HKMA C-RAF: Inherent Risk Assessment (IRA), Maturity Assessment (MA), Target Maturity Level, Assessment Cycle

HKMA-CRAF-IRA-Maturity-TargetLevel-Cycle
HKMA C-RAF Inherent Risk Assessment (IRA), Cyber Maturity Assessment (MA), Target Maturity Level, Assessment Cycle

HKMA C-RAF Inherent Risk Assessment (IRA) + Maturity Assessment (MA) methodology + assessment cycle. INHERENT RISK ASSESSMENT (IRA): scoring AI inherent cyber risk based on multiple factors including (a) TECHNOLOGY FOOTPRINT - on-premise + cloud + hybrid + complexity + interconnectivity; (b) ONLINE SERVICES - internet banking + mobile + API + open banking + customer-facing channels; (c) DATA + TRANSACTIONS - volumes + sensitivity + PII + financial + cross-border; (d) THIRD-PARTY DEPENDENCIES - service providers + cloud + outsourcing + sub-processors + interconnectedness; (e) SCALE + DEPOSITS - asset size + customer base + transaction volume + balance sheet size; (f) CYBERSECURITY THREAT-ENVIRONMENT - geopolitical + sectoral + historical incidents + targeted-attack history; (g) SECTORAL ROLE - systemically important + cross-border + interconnection with other AIs. IRA RESULT: LOW + MEDIUM

Artefacts an auditor will ask for
  • IRA submission + validation
  • MA self-assessment + independent review
  • Remediation roadmap tracking + closure
Where this commonly fails
  • IRA methodology unclear
  • MA scoring inconsistent
  • Roadmap not tracked

HKMA C-RAF: iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs

HKMA-CRAF-Crosswalk-NIST-CSF-ISO27001-FFIEC-CBEST-TIBER
HKMA C-RAF Crosswalk to NIST CSF, ISO 27001, FFIEC CAT, CBEST, TIBER-EU and Sectoral Frameworks

HKMA C-RAF crosswalk to international + sectoral cybersecurity frameworks. (a) NIST CYBERSECURITY FRAMEWORK (CSF) 2.0 - the 6 CSF functions (Govern + Identify + Protect + Detect + Respond + Recover) map directly to C-RAF 7 domains; many AIs use NIST CSF as supplementary framework + crosswalk to C-RAF for ease + interoperability. (b) ISO/IEC 27001:2022 (Information Security Management System) + ISO 27002:2022 implementation guide + 27017 (cloud) + 27018 (privacy in cloud) + 27701 (PIMS) + 27036 (supplier relationships) - widely adopted by HK AIs alongside C-RAF; ISO 27001 certified AIs typically map ISO 27001 controls to C-RAF maturity levels. (c) FFIEC CYBERSECURITY ASSESSMENT TOOL (CAT) - similar tiered cyber-maturity assessment used by US banks; C-RAF + FFIEC CAT methodologically aligned + complementary; some HK AIs with US operations use both. (d) FFIEC IT EXAMINATION HANDBOOK - US ba

Artefacts an auditor will ask for
  • Multi-framework crosswalk + certification
  • Sectoral cybersecurity coordination
  • DORA + cross-jurisdictional readiness
Where this commonly fails
  • Multi-framework alignment ad-hoc
  • Sectoral coordination weak
  • Cross-jurisdictional gaps
HKMA-CRAF-iCAST-RedTeam-PurpleTeam-IntelLed
HKMA C-RAF iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs

HKMA C-RAF iCAST (Intelligence-led Cyber Attack Simulation Testing) - mandatory for HIGH inherent risk AIs + optional for medium tier + modeled on UK CBEST + ECB TIBER-EU (verified separately in this corpus) + intelligence-led red team testing methodology. iCAST OBJECTIVES: (a) test AI cyber defenses against realistic + threat-intelligence-informed attack scenarios; (b) assess people + processes + technology resilience against simulated APT + ransomware + insider + supply-chain attacks; (c) provide actionable findings + remediation recommendations; (d) build sectoral threat-intelligence + lessons-learned. iCAST 5 PHASES: (1) SCOPE DEFINITION - critical services + critical functions + scope of testing + risk acceptance + ground rules + RoE + HKMA coordination + executive sponsorship; AI engages Threat Intelligence Provider + Red Team Service Provider both pre-approved by HKMA; (2) THREAT

Artefacts an auditor will ask for
  • iCAST execution + reports + remediation
  • TI + RT provider engagement
  • Sectoral coordination evidence
Where this commonly fails
  • iCAST not done for HIGH AIs
  • Provider selection issues
  • Remediation tracking weak
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the HKMA Cyber Resilience Assessment Framework (C-RAF) framework page.