1. Records Retention & Legal Hold advanced

    On 27 September 2022 the SEC and CFTC announced settlements with 15 broker-dealers and one investment adviser totalling over $1.1bn, with individual SEC penalties ranging from $10M to $125M, for failing to preserve business communications conducted on personal messaging apps. What was the architectural failure, and what does it teach about capture obligations generally?

    3 min answer secrecordkeepingcaptureretention
  2. Records Retention & Legal Hold advanced

    Your automated retention job deletes records after seven years. Legal informs you that litigation is anticipated involving accounts from nine years ago. What now?

    2 min answer legal-holdretentionarchitecture
  3. Regulatory & Data Protection Architecture advanced Multiple choice

    A global enterprise application must satisfy different regulatory regimes per market. Where should regulatory logic live?

    1 min answer regulatoryconfigurationpolicy-as-codemulti-jurisdiction
  4. Regulatory & Data Protection Architecture advanced

    How do you make a data residency requirement a structural property rather than a policy?

    2 min answer residencycellscontrol-planeenforcement
  5. Regulatory & Data Protection Architecture beginner

    Marketing has signed with an analytics vendor and the vendor's SDK is due in next week's mobile release. Legal asks whether you are the controller or the processor for what that SDK collects. Why does the answer change the architecture rather than only the paperwork?

    2 min answer controllerprocessorsub-processorssdk
  6. Regulatory Reporting Pipelines advanced

    A regulatory return was submitted three months ago. A reference-data correction arrives showing that a counterparty classification was wrong for 14 months, which changes figures in that return and in the five before it. What happens next, and what must the pipeline have supported for this to be manageable?

    3 min answer regulatory-reportingrestatementbitemporallineage
  7. Regulatory Reporting Pipelines advanced

    A regulatory submission is found to be wrong. You must produce an amended figure and explain the difference. What must the pipeline have supported?

    2 min answer reportinglineagereproducibility
  8. Regulatory Reporting Pipelines advanced

    An insurer must submit regulatory reports whose format and content change periodically. How should the pipeline be designed?

    2 min answer digitreportingmappingreproducibility
  9. Regulatory Reporting Pipelines advanced

    Design a pipeline producing periodic regulatory submissions where every figure must be defensible years later.

    1 min answer regulatory-reportingreproducibilitylineagecontrols
  10. Sector Cloud Rules advanced

    A regulated institution must satisfy sector-specific rules on outsourcing to cloud providers. What does architecture need to demonstrate?

    1 min answer outsourcingcloud-regulationexitoversight
  11. Sector Cloud Rules advanced

    Sector rules require audit rights over providers and a tested exit plan. How does that shape your architecture and supplier choices?

    2 min answer outsourcingaudit-rightsconcentrationexit
  12. Sector Cloud Rules advanced

    The EU's Digital Operational Resilience Act has applied to financial entities since 17 January 2025. It requires a maintained register of every contractual arrangement with an ICT third-party provider, threat-led penetration testing, and brings designated critical providers under direct supervisory oversight. What does an architecture team gain from this, what does it pay, and when does the bill land?

    3 min answer dorathird-party-riskregisterresilience-testing