|
Regulation 242-P on Internal Control in Credit InstitutionsCBR
|
Credit institutions and banking groups within scope |
Internal-control systems, compliance, independent internal audit, control reporting, findings, escalation and corrective-action tracking. |
|
Source
|
|
Ordinance 3624-U on Risk and Capital ManagementCBR
|
Credit institutions and banking groups within scope |
Risk strategy, appetite, material-risk identification, limits, capital planning, monitoring, reporting and independent assessment. |
|
Source
|
|
Regulation 716-P on Operational Risk ManagementCBR
|
Credit institutions and banking groups within scope |
Operational-risk classification, event databases, assessment, controls, key indicators, scenario analysis, reporting and remediation. |
|
Source
|
|
Corporate Governance Code and Public-Company RecommendationsCBR
|
Russian public joint-stock companies and other adopting issuers |
Board and committee oversight, risk management, internal controls, internal audit, governance evaluation and transparent reporting. |
|
Source
|
|
Federal Law 152-FZ Personal Data Incident ReportingRoskomnadzor
|
Personal-data operators within the Law’s scope |
Incident recording, initial regulatory notification, investigation updates, cause analysis, response measures and evidence retention. |
|
Source
|