Continuous Controls Monitoring

Testing controls continuously instead of sampling them once a year.

Nothing written here yet

This topic is part of the curriculum but has no questions, cards or glossary entries so far. The rest of Assurance, Audit & Model Risk may still cover what you are looking for.

Assurance, Audit & Model Risk

Neighbouring topics

Assurance, Audit & Model Risk

General material on assurance, architectural governance and risk oversight.

No content yet

Control Design vs Operation

A control that is well designed and never runs fails exactly like one that is absent.

No content yet

Audit Evidence

Producing durable, tamper-evident proof as a by-product rather than as a project.

No content yet

Certification Impact on Architecture

What SOC 2 and ISO 27001 actually require of a design, and what they do not.

No content yet

Segregation of Duties

Splitting authority so no single actor can both make and approve a change.

No content yet

Change Advisory vs Automated Gates

Replacing a weekly board with evidence a machine produces on every change.

No content yet

Risk Appetite

The stated tolerance that tells you which risks you are allowed to accept.

No content yet

Risk Assessment Methods

Qualitative matrices, FAIR and scenario analysis, and the illusion of a precise score.

No content yet

Security Design Review

Reviewing an architecture for security while changing it is still cheap.

No content yet

Architecture Compliance Checks

Automating conformance to standards so review effort goes to the genuinely novel.

No content yet

Exception & Waiver Management

Time-boxed, owned deviations with a remediation date, rather than permanent silence.

No content yet

Design Authority

How an ARB should decide, what it should not review, and how it avoids becoming a queue.

Three Lines Model

Ownership, oversight and independent assurance, and where architecture sits in it.

No content yet

Model Risk Management

Inventory, validation, monitoring and challenge for models that make consequential decisions.

No content yet

AI Risk Tiering

Classifying a use case by potential harm, and the obligations each tier triggers.

No content yet

Model Documentation

Model cards, intended use, limitations, and the record a regulator will ask for.

No content yet

Model Evaluation & Red-Teaming

Adversarial testing of a probabilistic system with no fixed expected output.

No content yet

Bias & Fairness Controls

Measuring disparate outcomes, choosing a fairness definition, and living with the trade-off.

No content yet

Human-in-the-Loop Design

Meaningful review rather than a rubber stamp, and designing against automation bias.

No content yet