|
Order of 3 November 2014 on Internal ControlFrench Government and ACPR
|
Banking, payment and investment entities within the Order’s scope |
Risk measurement, limits, permanent and periodic controls, internal audit, incident records, outsourcing, continuity and management reporting. |
|
Source
|
|
AMF General RegulationAMF
|
Issuers, investment firms, asset managers and other market participants within applicable provisions |
Compliance, internal controls, risk management, conflicts, reporting, control evidence and supervisory remediation. |
|
Source
|
|
Digital Operational Resilience ActEuropean Union and French financial supervisors
|
Financial entities and ICT third-party providers within DORA’s scope |
ICT risk, major incident reporting, resilience testing, third-party registers, recovery and management-body oversight. |
|
Source
|
|
EBIOS Risk Manager MethodANSSI
|
Organisations using the national method to manage digital risk |
Risk scenarios, threat analysis, security objectives, treatment plans, monitoring and governance evidence. |
|
Source
|
|
GDPR and Personal Data Breach NotificationCNIL
|
Controllers and processors handling personal data within the GDPR’s scope |
Privacy accountability, incident assessment, 72-hour notification where required, affected-person communication and remediation records. |
|
Source
|