HKMA TM-G-1
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
TM-G-1 Coordination with HKMA SPM, C-RAF v2.0, Basel III, FSB and 2024-2025 Pipeline
HKMA TM-G-1 coordination + 2024-2025 pipeline. COORDINATION WITH HKMA FRAMEWORKS: (a) HKMA SPM UMBRELLA (separately referenced) - TM-G-1 is one of 60+ SPM modules; SPM provides overall framework + supervisory expectations; (b) HKMA C-RAF v2.0 (verified separately) - HKMA Cybersecurity Fortification Initiative + Cyber Resilience Assessment Framework + IRA + Maturity + iCAST + CISP + PDP; coordinates with TM-G-1 + TM-G-3 (Information Technology Security and Cyber Risk) for cybersecurity-specific expectations; (c) HKMA TM-G-2 (Business Continuity Planning) + TM-G-4 (Public Cloud) + TM-E-1 (e-Banking) + TM-M (Monitoring) + TM-N (New Technology) + TM-S (Supervisory Expectations) - related TM module family; (d) HKMA OR-1 (Operational Risk Management) + OR-2 (Operational Resilience) + RR-1 (Recovery Planning) + SA-2 (Outsourcing) + IC-1 (Risk Management Framework) - adjacent modules; (e) HKMA S
- Multi-framework alignment + crosswalk
- International framework adoption
- Pipeline + emerging risk readiness
- Multi-framework alignment ad-hoc
- International alignment weak
- Pipeline readiness gaps
HKMA TM-G-1 implementation roadmap + status. ORGANIZATIONAL ROLES at AI: (a) BOARD + RISK COMMITTEE - TM-G-1 governance oversight + Technology Risk Management Framework approval + Risk Appetite + Pillar 2; (b) CHIEF INFORMATION SECURITY OFFICER (CISO) - operational ownership + TM-G-1.6 information security + cybersecurity + sectoral expectations; (c) CHIEF TECHNOLOGY OFFICER (CTO) / CIO - IT + cloud + infrastructure + TM-G-1.3-5 strategy + policies + operations; (d) CHIEF RISK OFFICER (CRO) + HEAD OF OPERATIONAL RISK - 2nd-line oversight + Technology Risk Management Framework integration + sectoral reporting; (e) HEAD OF INTERNAL AUDIT (3rd line) - TM-G-1.8 independent audit + sectoral cybersecurity audit + remediation tracking; (f) COMPLIANCE - HKMA supervisory dialogue + regulatory reporting + sectoral cybersecurity coordination; (g) BUSINESS LINE OWNERS - 1st-line accountability + bus
- Role inventory + RACI
- TM-G-1 compliance + remediation
- Supervisory dialogue records
- Roles undefined
- Compliance gaps
- Supervisory engagement weak
TM-G-1 Cyber: Security Monitoring + SIEM + Threat Intel + Cyber IR + Audit + Outsourcing + Cloud
HKMA TM-G-1 Cyber + Audit + Outsourcing + Cloud. (1) SECURITY MONITORING AND SIEM (TM-G-1.7.1) - SIEM + SOC + 24x7 monitoring + log management + correlation + use cases + alert handling + escalation + UEBA + behavior analytics + SOAR automation + threat detection + Splunk + IBM QRadar + Microsoft Sentinel + Elastic Security + ArcSight; (2) CYBER THREAT INTELLIGENCE (TM-G-1.7.2) - tactical + operational + strategic threat intel + IOC management + CISP (HKMA Cyber Intelligence Sharing Platform separately tracked) + commercial threat-intel feeds (Recorded Future + Mandiant + CrowdStrike + Anomali) + threat-modeling + scenario analysis + emerging-threat tracking + sectoral threat-intelligence sharing; (3) CYBER INCIDENT RESPONSE (TM-G-1.7.3) - documented IR plan + playbooks + runbooks + IR team + escalation procedures + breach response retainers (Mandiant + CrowdStrike + Kroll + Coveware + S
- SOC operations + SIEM use cases
- CTI + IOC + sectoral sharing
- IR plans + retainer engagement
- Audit + Outsource + Cloud risk evidence
- SOC + SIEM gaps
- CTI ad-hoc
- IR plans not tested
- Outsourcing + cloud risk weak
TM-G-1 Governance: Board + Senior Mgmt + Tech Risk Framework + Roles + Responsibilities
HKMA TM-G-1 Governance of Technology Risk. (1) BOARD AND SENIOR MANAGEMENT OVERSIGHT OF TECHNOLOGY RISK (TM-G-1.2.1) - Board approval of IT strategy + technology risk appetite + risk tolerance; senior management accountability + governance structure; reporting + escalation; Board IT/cyber literacy + training; risk-committee oversight; ongoing supervisory dialogue; HKMA fitness and propriety expectations; (2) TECHNOLOGY RISK MANAGEMENT FRAMEWORK (TM-G-1.2.2) - documented + Board-approved Technology Risk Management Framework integrating IT + cyber + business continuity + operational resilience; risk taxonomy + identification + assessment + measurement + mitigation + monitoring + reporting; ERM integration; 3-lines-of-defense + risk-committee + Board oversight; periodic review + Framework update; (3) ROLES AND RESPONSIBILITIES (TM-G-1.2.3) - clearly defined roles for Board + senior manageme
- Board records + Framework documentation
- Roles + RACI + organizational charts
- Supervisory engagement evidence
- Board oversight weak
- Framework documentation gaps
- Roles undefined
TM-G-1 IT Operations: Operations Mgmt + Capacity + Performance + Problem + Incident Management
HKMA TM-G-1 IT Operations. (1) IT OPERATIONS MANAGEMENT (TM-G-1.5.1) - 24x7 operations + monitoring + service delivery + ITIL + ITSM + ServiceNow + BMC + others + operations runbooks + procedures + sound operational practices + automation + DevOps + SRE + IT service management metrics + KPI dashboards; (2) CAPACITY AND PERFORMANCE MANAGEMENT (TM-G-1.5.2) - capacity planning + monitoring + alerting + performance baselines + trending + forecast + scaling + cloud autoscaling + DRP + business growth + transaction volume + customer-facing service performance + SLO + SLI + service level management; (3) PROBLEM AND INCIDENT MANAGEMENT (TM-G-1.5.3) - documented incident management + classification + escalation + resolution + post-incident review + lessons learned + remediation + sharing learnings; coordination with cybersecurity incident response + HKMA cyber-incident reporting (24-hour + 48-hou
- Operations runbooks + procedures
- Capacity + performance dashboards
- Incident logs + post-incident reviews
- Operations runbooks missing
- Capacity planning weak
- Incident management ad-hoc
TM-G-1 IT Strategy + Policies + Risk Assessment + Project + System Development + Change Management
HKMA TM-G-1 IT Strategy + Policies + Risk + Development + Change. (1) IT STRATEGY AND PLANNING (TM-G-1.3.1) - documented + Board-approved IT strategy aligned with business strategy + risk appetite + technology innovation + customer experience + investment planning + multi-year roadmap + portfolio prioritization + KPIs + budget; (2) IT POLICIES STANDARDS AND PROCEDURES (TM-G-1.3.2) - comprehensive IT policy framework + standards + procedures + technical baselines + compliance with regulatory + sectoral expectations + periodic review + version control + workforce communication + training; (3) TECHNOLOGY RISK ASSESSMENT (TM-G-1.3.3) - risk identification + assessment + impact + likelihood + risk-treatment + residual-risk acceptance + alignment with TRM Framework + business + change-driven + new technology + cyber threat landscape + supply chain + 3rd party + cloud; ongoing + periodic review
- IT Strategy + Policy documentation
- Risk register + assessment evidence
- Project + SDLC + Change records
- IT Strategy weak
- Policy framework incomplete
- Risk assessment ad-hoc
TM-G-1 Information Security: Programme + Access + PAM + Network + Crypto + DLP + Vulnerability + Endpoint
HKMA TM-G-1 Information Security Programme. Comprehensive technical + administrative + physical security controls. (1) INFORMATION SECURITY PROGRAMME (TM-G-1.6.1) - documented + Board-approved information security programme + governance + roles + ISMS-style alignment with ISO 27001 + sectoral expectations + Cybersecurity Fortification Initiative; CISO leadership + Board reporting + Risk Committee oversight; (2) ACCESS CONTROL + IDENTITY MANAGEMENT (TM-G-1.6.2) - identity + access management + provisioning + de-provisioning + access reviews + role-based + attribute-based + segregation of duties + ZTNA + identity governance; (3) PRIVILEGED ACCESS MANAGEMENT (PAM) (TM-G-1.6.3) - privileged credential vault + just-in-time access + session recording + monitoring + PAM tooling (CyberArk + BeyondTrust + Delinea + others); (4) NETWORK SECURITY (TM-G-1.6.4) - segmentation + firewall + IDS/IPS + W
- ISMS + Information Security policies
- PAM + Access controls implementation
- Network + Crypto + DLP technical controls
- ISMS programme weak
- PAM not implemented
- Network + Crypto + DLP gaps
TM-G-2 BCP + TM-E-1 e-Banking + OR-2 Operational Resilience Adjacent Modules
HKMA TM-G-1 adjacent modules covered in this framework's scope. TM-G-2 BUSINESS CONTINUITY PLANNING: (a) Business Continuity Governance (TM-G-2.2.1) - Board oversight + BCP committee + crisis management + RACI + ownership; (b) Business Impact Analysis (TM-G-2.3.1) - critical process + service identification + dependency mapping + RTO/RPO + financial + operational + customer + reputational impact; (c) Recovery Strategy and Plans (TM-G-2.3.2) - documented recovery strategies per critical service + IT continuity + work area continuity + supplier continuity + alternate site + recovery procedures; (d) Backup and Restoration (TM-G-2.3.3) - data + system backups + retention + offsite + immutable + ransomware-resistant + restoration testing + integrity verification; (e) BCP Testing and Exercising (TM-G-2.4.1) - annual + scenario-based + tabletop + live + sectoral cyber wargames + lessons learned
- BCP plans + testing + ransomware resilience
- E-banking compliance evidence
- OR-2 IBS + Impact Tolerances + Mapping
- BCP weak
- E-banking compliance gaps
- OR-2 Impact Tolerances undefined
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.