Skip to content

Evidence request lists

HKMA TM-G-1

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

TM-G-1 Coordination with HKMA SPM, C-RAF v2.0, Basel III, FSB and 2024-2025 Pipeline

HKMA-TMG1-Coord-SPM-CRAF-Basel-FSB-2024-2025-Pipeline
TM-G-1 Coordination with HKMA SPM, C-RAF v2.0, Basel III, FSB, ISO 27001, NIST CSF and 2024-2025 Pipeline

HKMA TM-G-1 coordination + 2024-2025 pipeline. COORDINATION WITH HKMA FRAMEWORKS: (a) HKMA SPM UMBRELLA (separately referenced) - TM-G-1 is one of 60+ SPM modules; SPM provides overall framework + supervisory expectations; (b) HKMA C-RAF v2.0 (verified separately) - HKMA Cybersecurity Fortification Initiative + Cyber Resilience Assessment Framework + IRA + Maturity + iCAST + CISP + PDP; coordinates with TM-G-1 + TM-G-3 (Information Technology Security and Cyber Risk) for cybersecurity-specific expectations; (c) HKMA TM-G-2 (Business Continuity Planning) + TM-G-4 (Public Cloud) + TM-E-1 (e-Banking) + TM-M (Monitoring) + TM-N (New Technology) + TM-S (Supervisory Expectations) - related TM module family; (d) HKMA OR-1 (Operational Risk Management) + OR-2 (Operational Resilience) + RR-1 (Recovery Planning) + SA-2 (Outsourcing) + IC-1 (Risk Management Framework) - adjacent modules; (e) HKMA S

Artefacts an auditor will ask for
  • Multi-framework alignment + crosswalk
  • International framework adoption
  • Pipeline + emerging risk readiness
Where this commonly fails
  • Multi-framework alignment ad-hoc
  • International alignment weak
  • Pipeline readiness gaps
HKMA-TMG1-Implementation-Roles-Tooling-Status
TM-G-1 Implementation Roadmap, Roles, Tooling, Status and Future

HKMA TM-G-1 implementation roadmap + status. ORGANIZATIONAL ROLES at AI: (a) BOARD + RISK COMMITTEE - TM-G-1 governance oversight + Technology Risk Management Framework approval + Risk Appetite + Pillar 2; (b) CHIEF INFORMATION SECURITY OFFICER (CISO) - operational ownership + TM-G-1.6 information security + cybersecurity + sectoral expectations; (c) CHIEF TECHNOLOGY OFFICER (CTO) / CIO - IT + cloud + infrastructure + TM-G-1.3-5 strategy + policies + operations; (d) CHIEF RISK OFFICER (CRO) + HEAD OF OPERATIONAL RISK - 2nd-line oversight + Technology Risk Management Framework integration + sectoral reporting; (e) HEAD OF INTERNAL AUDIT (3rd line) - TM-G-1.8 independent audit + sectoral cybersecurity audit + remediation tracking; (f) COMPLIANCE - HKMA supervisory dialogue + regulatory reporting + sectoral cybersecurity coordination; (g) BUSINESS LINE OWNERS - 1st-line accountability + bus

Artefacts an auditor will ask for
  • Role inventory + RACI
  • TM-G-1 compliance + remediation
  • Supervisory dialogue records
Where this commonly fails
  • Roles undefined
  • Compliance gaps
  • Supervisory engagement weak

TM-G-1 Cyber: Security Monitoring + SIEM + Threat Intel + Cyber IR + Audit + Outsourcing + Cloud

HKMA-TMG1-Cyber-Monitoring-Threat-Intel-IR-Audit-Outsource-Cloud
TM-G-1 Security Monitoring + SIEM + Threat Intel + Cyber IR + Audit + Outsourcing + Cloud Computing Risk

HKMA TM-G-1 Cyber + Audit + Outsourcing + Cloud. (1) SECURITY MONITORING AND SIEM (TM-G-1.7.1) - SIEM + SOC + 24x7 monitoring + log management + correlation + use cases + alert handling + escalation + UEBA + behavior analytics + SOAR automation + threat detection + Splunk + IBM QRadar + Microsoft Sentinel + Elastic Security + ArcSight; (2) CYBER THREAT INTELLIGENCE (TM-G-1.7.2) - tactical + operational + strategic threat intel + IOC management + CISP (HKMA Cyber Intelligence Sharing Platform separately tracked) + commercial threat-intel feeds (Recorded Future + Mandiant + CrowdStrike + Anomali) + threat-modeling + scenario analysis + emerging-threat tracking + sectoral threat-intelligence sharing; (3) CYBER INCIDENT RESPONSE (TM-G-1.7.3) - documented IR plan + playbooks + runbooks + IR team + escalation procedures + breach response retainers (Mandiant + CrowdStrike + Kroll + Coveware + S

Artefacts an auditor will ask for
  • SOC operations + SIEM use cases
  • CTI + IOC + sectoral sharing
  • IR plans + retainer engagement
  • Audit + Outsource + Cloud risk evidence
Where this commonly fails
  • SOC + SIEM gaps
  • CTI ad-hoc
  • IR plans not tested
  • Outsourcing + cloud risk weak

TM-G-1 Governance: Board + Senior Mgmt + Tech Risk Framework + Roles + Responsibilities

HKMA-TMG1-Governance-Board-Framework-Roles
TM-G-1 Governance - Board + Senior Mgmt Oversight + Technology Risk Management Framework + Roles

HKMA TM-G-1 Governance of Technology Risk. (1) BOARD AND SENIOR MANAGEMENT OVERSIGHT OF TECHNOLOGY RISK (TM-G-1.2.1) - Board approval of IT strategy + technology risk appetite + risk tolerance; senior management accountability + governance structure; reporting + escalation; Board IT/cyber literacy + training; risk-committee oversight; ongoing supervisory dialogue; HKMA fitness and propriety expectations; (2) TECHNOLOGY RISK MANAGEMENT FRAMEWORK (TM-G-1.2.2) - documented + Board-approved Technology Risk Management Framework integrating IT + cyber + business continuity + operational resilience; risk taxonomy + identification + assessment + measurement + mitigation + monitoring + reporting; ERM integration; 3-lines-of-defense + risk-committee + Board oversight; periodic review + Framework update; (3) ROLES AND RESPONSIBILITIES (TM-G-1.2.3) - clearly defined roles for Board + senior manageme

Artefacts an auditor will ask for
  • Board records + Framework documentation
  • Roles + RACI + organizational charts
  • Supervisory engagement evidence
Where this commonly fails
  • Board oversight weak
  • Framework documentation gaps
  • Roles undefined

TM-G-1 IT Operations: Operations Mgmt + Capacity + Performance + Problem + Incident Management

HKMA-TMG1-Operations-Capacity-Problem-Incident
TM-G-1 IT Operations + Capacity + Performance + Problem + Incident Management

HKMA TM-G-1 IT Operations. (1) IT OPERATIONS MANAGEMENT (TM-G-1.5.1) - 24x7 operations + monitoring + service delivery + ITIL + ITSM + ServiceNow + BMC + others + operations runbooks + procedures + sound operational practices + automation + DevOps + SRE + IT service management metrics + KPI dashboards; (2) CAPACITY AND PERFORMANCE MANAGEMENT (TM-G-1.5.2) - capacity planning + monitoring + alerting + performance baselines + trending + forecast + scaling + cloud autoscaling + DRP + business growth + transaction volume + customer-facing service performance + SLO + SLI + service level management; (3) PROBLEM AND INCIDENT MANAGEMENT (TM-G-1.5.3) - documented incident management + classification + escalation + resolution + post-incident review + lessons learned + remediation + sharing learnings; coordination with cybersecurity incident response + HKMA cyber-incident reporting (24-hour + 48-hou

Artefacts an auditor will ask for
  • Operations runbooks + procedures
  • Capacity + performance dashboards
  • Incident logs + post-incident reviews
Where this commonly fails
  • Operations runbooks missing
  • Capacity planning weak
  • Incident management ad-hoc

TM-G-1 IT Strategy + Policies + Risk Assessment + Project + System Development + Change Management

HKMA-TMG1-Strategy-Policies-RiskAssessment-Dev-Change
TM-G-1 IT Strategy + Policies + Risk Assessment + Project Management + System Development + Change Management

HKMA TM-G-1 IT Strategy + Policies + Risk + Development + Change. (1) IT STRATEGY AND PLANNING (TM-G-1.3.1) - documented + Board-approved IT strategy aligned with business strategy + risk appetite + technology innovation + customer experience + investment planning + multi-year roadmap + portfolio prioritization + KPIs + budget; (2) IT POLICIES STANDARDS AND PROCEDURES (TM-G-1.3.2) - comprehensive IT policy framework + standards + procedures + technical baselines + compliance with regulatory + sectoral expectations + periodic review + version control + workforce communication + training; (3) TECHNOLOGY RISK ASSESSMENT (TM-G-1.3.3) - risk identification + assessment + impact + likelihood + risk-treatment + residual-risk acceptance + alignment with TRM Framework + business + change-driven + new technology + cyber threat landscape + supply chain + 3rd party + cloud; ongoing + periodic review

Artefacts an auditor will ask for
  • IT Strategy + Policy documentation
  • Risk register + assessment evidence
  • Project + SDLC + Change records
Where this commonly fails
  • IT Strategy weak
  • Policy framework incomplete
  • Risk assessment ad-hoc

TM-G-1 Information Security: Programme + Access + PAM + Network + Crypto + DLP + Vulnerability + Endpoint

HKMA-TMG1-InfoSec-Access-PAM-Network-Crypto-DLP-Endpoint
TM-G-1 Information Security Programme + Access + PAM + Network + Crypto + DLP + Vulnerability + Endpoint

HKMA TM-G-1 Information Security Programme. Comprehensive technical + administrative + physical security controls. (1) INFORMATION SECURITY PROGRAMME (TM-G-1.6.1) - documented + Board-approved information security programme + governance + roles + ISMS-style alignment with ISO 27001 + sectoral expectations + Cybersecurity Fortification Initiative; CISO leadership + Board reporting + Risk Committee oversight; (2) ACCESS CONTROL + IDENTITY MANAGEMENT (TM-G-1.6.2) - identity + access management + provisioning + de-provisioning + access reviews + role-based + attribute-based + segregation of duties + ZTNA + identity governance; (3) PRIVILEGED ACCESS MANAGEMENT (PAM) (TM-G-1.6.3) - privileged credential vault + just-in-time access + session recording + monitoring + PAM tooling (CyberArk + BeyondTrust + Delinea + others); (4) NETWORK SECURITY (TM-G-1.6.4) - segmentation + firewall + IDS/IPS + W

Artefacts an auditor will ask for
  • ISMS + Information Security policies
  • PAM + Access controls implementation
  • Network + Crypto + DLP technical controls
Where this commonly fails
  • ISMS programme weak
  • PAM not implemented
  • Network + Crypto + DLP gaps

TM-G-2 BCP + TM-E-1 e-Banking + OR-2 Operational Resilience Adjacent Modules

HKMA-TMG1-Adjacent-TMG2-TME1-OR2-BCP-eBanking-Resilience
TM-G-2 BCP + TM-E-1 e-Banking + OR-2 Operational Resilience Adjacent Modules

HKMA TM-G-1 adjacent modules covered in this framework's scope. TM-G-2 BUSINESS CONTINUITY PLANNING: (a) Business Continuity Governance (TM-G-2.2.1) - Board oversight + BCP committee + crisis management + RACI + ownership; (b) Business Impact Analysis (TM-G-2.3.1) - critical process + service identification + dependency mapping + RTO/RPO + financial + operational + customer + reputational impact; (c) Recovery Strategy and Plans (TM-G-2.3.2) - documented recovery strategies per critical service + IT continuity + work area continuity + supplier continuity + alternate site + recovery procedures; (d) Backup and Restoration (TM-G-2.3.3) - data + system backups + retention + offsite + immutable + ransomware-resistant + restoration testing + integrity verification; (e) BCP Testing and Exercising (TM-G-2.4.1) - annual + scenario-based + tabletop + live + sectoral cyber wargames + lessons learned

Artefacts an auditor will ask for
  • BCP plans + testing + ransomware resilience
  • E-banking compliance evidence
  • OR-2 IBS + Impact Tolerances + Mapping
Where this commonly fails
  • BCP weak
  • E-banking compliance gaps
  • OR-2 Impact Tolerances undefined
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.