Bank X · mid-size SAMA-regulated bank (illustrative) · prepared by the Head of Technology Risk (second line)
| Control domain | In scope | Effective | Partial | Not effective | Direction (6 mo.) | What moved |
|---|---|---|---|---|---|---|
| Identity & privileged access | 34 | 26 | 6 | 2 | ▲ Improving | Joiner-leaver revocation moved to same-day. Session recording remains the open gap. |
| Change & release management | 21 | 19 | 2 | 0 | ▶ Stable | Pre-approval control holds. The emergency route is the weak point (KRI-2). |
| Third-party & outsourced hosting | 18 | 11 | 5 | 2 | ▼ Deteriorating | Two attestations lapsed since the Q1 report. No new control failures found. Coverage fell, not performance. |
Scope of this paper: 73 controls across three domains, selected because they sit on the path of the risk above. The full technology control set is reported in the quarterly dashboard.
What it means: Fourteen named administrators can change production on core banking and the payment switch without a reconstructable record. The count rose by three during the Q2 core upgrade: two vendor-support accounts and one database administrator.
What it means: Nearly one production change in ten bypasses pre-approval, and a quarter of those are not documented inside the window. The emergency route is functioning as a bypass, not as an evidence-producing control.
What it means: For seven providers, including the two holding disaster-recovery capacity for the payment switch, the bank is reporting control effectiveness it has not independently confirmed this year.
Approve SAR 1.4m from the approved FY technology contingency (within this Committee's delegated expenditure limit of SAR 2.0m) to close the privileged-access recording gap, with the vendor-support element delivered through the Q4 contract renewals. Target: residual risk 12 → 8 by 15 December 20X1.
Not being asked for: no change to the appetite ceiling; no new tooling procurement (the uplift sits on the existing licence); no permanent headcount (contract resource, time-boxed). Residual at 8 sits at the ceiling, not comfortably below it. Moving it lower depends on the payment-switch network-segmentation work already scheduled in the FY 20X2 plan, which is not part of this decision.
| Accountability | Owner | Date |
|---|---|---|
| Decision | Board Risk Committee | 12 Aug 20X1 (this meeting) |
| Delivery of session recording | Chief Information Officer | 30 Nov 20X1 |
| Audit-rights and recording clauses at renewal | Head of Procurement | At each renewal, latest 15 Dec 20X1 |
| Re-test and residual re-score | Head of Technology Risk (second line) | 15 Dec 20X1 |
| Report back to the Committee | Head of Technology Risk | 20 Jan 20X2 |
| Data point | Source system | As at / period | Prepared & challenged |
|---|---|---|---|
| 212 privileged accounts; 14 unrecorded | Privileged access management console: account export, reconciled to HR joiner-leaver extract | 30 Jun 20X1 | First line (identity ops); second-line reconciliation 9 Jul 20X1 |
| 73 controls; effectiveness split (section 2) | GRC risk register: second-line test results | Quarter ended 30 Jun 20X1 | Second line; sample-based, not full population |
| 457 production changes; 43 emergency | Service management tool: change module | 1 Apr – 30 Jun 20X1 | First line (change management) |
| Retrospective approval 32 of 43 (74%) | Service management tool: all 43 emergency records | Tested 8–12 Jul 20X1 | Second line; full check, no sampling |
| 11 material providers; 4 current attestations; 16-month mean age | Supplier register and contract repository | 30 Jun 20X1 | Vendor management; materiality per outsourcing policy |
| Residual 12, and 8 post-remediation | Risk register scoring model v3.1 (likelihood × impact, 1–25) | Scored 3 Jul; challenged 15 Jul 20X1 | First line scored; second line challenged; no open disagreement |
| SAR 1.4m cost | CIO planning estimate; vendor day-rate card | Rate card dated 2 Jul 20X1 | Planning estimate ±15%; not a tendered price |
Stated limitation: the two lapsed attestations covering disaster-recovery capacity are carried from the providers' prior-year reports. A current attestation is a deliverable of the Q4 renewals, not of this paper.
Illustrative artifact. All data fictional. Structure: Mohammed AlYahya (how I frame technology-risk decisions for a risk committee).