Systemic Risk
What is Systemic Risk?
The risk of widespread failure in a system, market, or industry that could trigger cascading effects across interconnected organizations.
Terms that appear alongside systemic risk
Each of these is named in at least one of the same controls as systemic risk. The number is how many controls name both.
- audit 4 shared controls
- risk assessment 3 shared controls
- governance 3 shared controls
- compliance 3 shared controls
- transparency 3 shared controls
- cybersecurity 3 shared controls
- policy 3 shared controls
- foundation model 2 shared controls
Frameworks that govern systemic risk
What the standards actually require on systemic risk
Requirements naming systemic risk across 6 standards, quoted from the control text.
Providers of GPAI models with systemic risk shall additionally: perform model evaluation incl adversarial testing; assess and mitigate possible systemic risks;
EUAI-Art.55 · Obligations of providers of GPAI models with systemic risk →Disclose management of systemic risks including financial, technology, and geopolitical risks
SASB-LG-2 · Systemic Risk Management →Identify and address concentration risk and systemic risk where multiple suppliers share common dependencies.
ISO22318-9.1 · Concentration and Systemic Risk Review →VLOPs and VLOSEs shall provide the Digital Services Coordinator of establishment or the Commission, on reasoned request, access to data necessary to monitor compliance, and provide vetted researchers access to data for the sole purpose of researching systemic...
DSA-Art.40 · Data access and scrutiny →The FSA expects financial institutions to implement a comprehensive cybersecurity risk management framework + aligned with NIST CSF 2.0 + FFIEC IT Examination Handbook + ISO/IEC 27001 ISMS + integrated into Enterprise Risk Management (ERM).
JP-FSA-CYB-Risk-Management-NIST-CSF-FFIEC-Aligned-Identify-Protect-Detect-Respond-Recover-Govern-Plan-Do-Check-Act · Japan FSA Cybersecurity Risk Management Framework + NIST CSF 2.0 Aligned + FFIEC Crosswalk + Identify Protect Detect Respond Recover Govern + ISO 27001 ISMS + Plan-Do-Check-Act + Inherent vs Residual Risk + Risk Appetite + Cyber Risk in ERM →Lloyds Cyber Insurance Requirements - Systemic Cyber Risk Aggregation + Catastrophe Modelling. Lloyds Catastrophe Modelling Standards require all managing agents to: (a) Model Cyber Realistic Disaster Scenarios (Cyber RDS) developed by Lloyds + Cambridge Centr...
LLOYDS-CI-Systemic-Cyber-Risk-Aggregation-Cyber-Catastrophe-Modelling-Vendor-Use-RDS-Scenario-Testing · Lloyds Cyber Insurance Systemic Aggregation + Catastrophe Modelling + RDS →Questions people ask about systemic risk
What is Systemic Risk?
Why is Systemic Risk important for compliance?
Which compliance frameworks address Systemic Risk?
Where can I learn more about Systemic Risk?
See how Systemic Risk applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.