Templates for Risk Management

The Provenix-Insight templates provide structured frameworks for identifying, assessing and managing risks across projects, operations and governance-driven environments.

Each template is aligned with established risk management practices and regulatory expectations, while remaining fully configurable within the Provenix platform. Templates can be adapted to internal risk methodologies, assessment models and reporting requirements.

Different template variants are available to reflect:

  • the size and risk profile of the organisation

  • specific risk categories, scoring models and thresholds

  • integrations with internal data sources or notification channels such as e-mail

These variants can be selected and managed directly within the Profile section of the Provenix software, enabling users to apply risk management structures that best fit their organisational context.

Templates provide a structured foundation and can be further extended using configurable workflows, calculation logic, automation tools and the internal scripting capabilities of Provenix-Insight.

Template CodeDescriptionRegulatory / Legal Frameworks – USARegulatory / Legal Frameworks – UKRegulatory / Legal Frameworks – EU
CONFLIConflict-of-interest declaration, assessment and mitigation workflow (including registers, approvals and periodic attestations)Sarbanes-Oxley (SOX) (listed issuers); SEC disclosure expectations; FCPA (where relevant); state ethics rules where applicableCompanies Act 2006; UK Corporate Governance Code; FCA / PRA expectations (where applicable); Bribery Act 2010EU Corporate Sustainability Due Diligence (proposed/where applicable); national corporate governance codes; anti-corruption frameworks; sector rules where applicable
ETHICSEthics and conduct management: codes of conduct, training, attestations, breaches and escalation handlingSarbanes-Oxley (SOX) (listed issuers); SEC disclosure expectations; FCPA; industry codes where applicableCompanies Act 2006; UK Corporate Governance Code; Bribery Act 2010; FCA/PRA conduct expectations (where applicable)EU Corporate Sustainability Due Diligence (proposed/where applicable); national ethics/compliance frameworks; sector rules where applicable
POLICYPolicy governance: creation, ownership, versioning, review cycles, approvals and dissemination trackingSarbanes-Oxley (SOX) (listed issuers); SEC recordkeeping expectations; industry-specific policy requirementsCompanies Act 2006; FCA / PRA governance expectations (where applicable); recordkeeping expectationsEU GDPR (where policies cover data); sectoral governance requirements; national corporate governance codes
AUDITRInternal audit planning and delivery: audit universe, risk-based plan, fieldwork, findings, remediation and reportingIIA Standards; PCAOB/SEC expectations (public issuers); SOX internal control environmentUK Internal Audit Standards / IIA UK guidance; FCA/PRA expectations (where applicable)ISO 19011 (guidance); national internal audit/financial supervision expectations; EBA/ESMA guidance (where applicable)
GOVSTRGovernance structure risk review: decision rights, committee structures, delegations and governance gapsSOX governance expectations (public issuers); SEC governance disclosures; industry rules where applicableUK Corporate Governance Code; Companies Act 2006; FCA/PRA governance requirements (where applicable)National corporate governance codes; sector governance requirements; EBA governance guidelines (where applicable)
COMPLNCompliance monitoring programme: obligations register, monitoring plans, testing, issue management and reportingSEC/FINRA (where applicable); SOX; industry obligations; state/federal compliance regimesFCA Handbook / PRA Rulebook (where applicable); UK Corporate Governance Code; relevant sector obligationsEU sector obligations (e.g. MiFID II, PSD2, AMLD where applicable); national supervisory expectations
AMLCTFAML/CTF risk framework: risk assessment, controls mapping, monitoring, suspicious activity workflows and reportingBSA/AML; FinCEN regulations; OFAC sanctions; FATF guidance (implemented locally)Money Laundering Regulations; Proceeds of Crime Act; OFSI sanctions; FCA expectations (where applicable)EU AML Directives (AMLD); national AML laws; EU sanctions regimes; EBA AML guidelines
SANCTRSanctions compliance: screening governance, escalation, case handling, audit trail and reportingOFAC sanctions; US export controls (where applicable); FinCEN/industry expectationsOFSI sanctions; UK export controls (where applicable); FCA expectations (where applicable)EU sanctions regimes; national enforcement rules; sector guidance where applicable
PRIVCYPrivacy and data protection risk management: DPIAs, RoPA alignment, incident workflows and controls mappingState privacy laws (e.g. CCPA/CPRA); sector privacy regimes (HIPAA/GLBA where applicable)UK GDPR; Data Protection Act 2018; ICO guidanceEU GDPR; EDPB guidance; national supervisory authority guidance
CYSCRCybersecurity risk framework: controls mapping, risk assessment, treatment plans, monitoring and reportingNIST CSF; SEC cyber disclosure rules (public issuers); sector rules where applicableNCSC guidance; FCA/PRA cyber expectations (where applicable); UK cyber regulations where applicableNIS2 Directive (where applicable); ENISA guidance; sector requirements
THIRDPThird-party / vendor risk management: due diligence, onboarding, monitoring, contract controls and exit managementOCC/FDIC/FRB guidance (financial sector); SEC/FINRA expectations (where applicable); industry best practiceFCA/PRA outsourcing rules (where applicable); UK operational resilience expectationsEBA outsourcing guidelines (financial sector); DORA (where applicable); national supervisory expectations
OPRESLOperational resilience programme: important business services, impact tolerances, mapping, testing and reportingFFIEC guidance (financial sector); industry resilience guidance; state/federal expectations where applicableFCA/PRA operational resilience policy; UK requirements for important business servicesDORA (where applicable); EBA/ESMA resilience expectations; national supervisory guidance
BCPDRBusiness continuity and disaster recovery: BIA, plan development, testing, lessons learned and governance reportingFFIEC BCP guidance; industry BCP expectations; sector regulators where applicableUK operational resilience expectations; industry BCP guidance; FCA/PRA where applicableDORA (where applicable); national BCP expectations; ISO 22301 alignment (best practice)
FRAUDRFraud risk management: fraud risk assessment, controls, case management, reporting and remediationSOX internal controls; SEC expectations; industry fraud frameworks; state/federal statutesFraud Act 2006; Bribery Act 2010 (related); FCA expectations where applicableEU anti-fraud frameworks; sector obligations; national criminal law provisions
WHISTLWhistleblowing programme: intake, triage, investigations, protection measures and reportingDodd-Frank whistleblower provisions (where applicable); SOX reporting channels; industry regimesPublic Interest Disclosure Act; FCA whistleblowing rules (where applicable)EU Whistleblower Protection Directive; national implementation laws
INVESTInvestigation management: case intake, evidence tracking, actions, conclusions and governance reportingSOX/SEC recordkeeping expectations; employment laws; sector rules where applicableEmployment law; FCA/PRA expectations where applicable; recordkeeping standardsNational employment and compliance regimes; GDPR constraints where applicable
RISREGEnterprise risk register: taxonomy, ownership, scoring models, controls, action plans and reporting packCOSO ERM (best practice); SEC risk disclosures; SOX control environmentUK Corporate Governance Code; FCA/PRA risk governance expectations (where applicable)EBA governance/risk guidelines (where applicable); national corporate governance codes
PRJRISProject risk management: project risk register, assessments, mitigations, escalations and reportingPMI/industry best practice; contractual/project governance expectationsUK project governance standards; sector expectations where applicableEU project governance norms; sector requirements where applicable
MODELModel risk management: inventory, validation, monitoring, issues and governance reportingSR 11-7 (Fed); OCC 2011-12; regulatory expectations (financial sector)PRA/FCA model risk expectations (where applicable); industry guidanceEBA model risk expectations; ECB guidance where applicable; national supervisory guidance
ITGCIT general controls (ITGC) framework: control library, testing, issues and remediation trackingSOX ITGC expectations; PCAOB guidance; SEC expectationsUK SOX-style expectations (where applicable); audit standards; sector regulatorsEU audit expectations; national supervisory requirements; ISO 27001 alignment (best practice)
ACCESSAccess management risk framework: identity governance, role reviews, approvals and evidence collectionSOX; NIST; industry security standards; sector rules where applicableNCSC guidance; FCA/PRA expectations (where applicable)NIS2 (where applicable); ISO 27001 alignment; GDPR security principle
CHGCTLChange management controls: change governance, testing requirements, approvals, deployment and audit trailSOX control environment; audit standards; IT governance expectationsAudit and governance expectations; FCA/PRA where applicableEU audit expectations; ISO 27001/ITIL alignment (best practice)
INCIDIncident management and reporting: classification, containment, communications and lessons learned workflowSEC cyber reporting (public issuers); state breach notification laws; sector rulesUK GDPR breach reporting; ICO guidance; NCSC guidanceEU GDPR breach reporting; NIS2 incident reporting (where applicable); national authority guidance
SOCREPSOC/assurance reporting support: evidence collection, control mapping, issue tracking and reporting packAICPA SOC 1/2; SOX; audit standardsISAE 3402; assurance standards; audit expectationsISAE standards; national assurance frameworks; sector expectations
ESGREPESG risk and reporting: data collection, controls, disclosures, governance and audit trailSEC climate disclosure expectations (where applicable); state regimes; voluntary standardsUK TCFD-aligned reporting expectations (where applicable); FCA guidanceCSRD/ESRS (where applicable); EU taxonomy; national implementations
HSEHealth, safety and environment (HSE) risk framework: incident reporting, controls, actions and compliance trackingOSHA requirements; EPA rules where applicable; sector obligationsHSE regulations; industry obligations; reporting requirementsEU OSH directives; national implementations; sector rules
FINRPTFinancial reporting risk controls: close process governance, controls testing, issues and remediationSOX; SEC reporting rules; PCAOB expectationsCompanies Act 2006; audit standards; FCA rules where applicableEU audit expectations; national financial reporting rules; sector supervisors where applicable
TAXRISKTax risk management: risk identification, controls mapping, reporting and governance sign-offIRS compliance regimes; state/federal tax obligations; governance expectationsUK tax governance and compliance expectations; HMRC guidance where applicableEU tax compliance regimes; national tax governance expectations
REGCHARegulatory change management: horizon scanning, impact assessment, implementation tracking and reportingRegulatory obligations management; SEC/FINRA updates where applicable; sector rulesFCA/PRA regulatory change expectations (where applicable); UK obligationsEU regulatory updates (e.g. EBA/ESMA/EIOPA where applicable); national implementations
DORADigital operational resilience (DORA) readiness: ICT risk management, incident reporting, testing and third-party oversightSector resilience expectations; FFIEC guidance; industry regimesUK operational resilience requirements; FCA/PRA expectationsDORA (where applicable); EBA/ESMA guidance; national supervisor expectations
OUTSRCOutsourcing and cloud risk: due diligence, contract controls, ongoing monitoring and exit planningOCC/FDIC/FRB outsourcing guidance (where applicable); sector expectationsFCA/PRA outsourcing requirements (where applicable); UK operational resilienceEBA outsourcing guidelines; DORA (where applicable); national supervisory rules
TRADEMarket / trading conduct risk framework: surveillance governance, incidents, investigations and reportingSEC/FINRA rules; CFTC where applicable; market conduct expectationsFCA market conduct rules; MAR (UK); PRA where applicableMAR (EU); MiFID II conduct obligations (where applicable); national supervision
CONSUMConsumer protection / fair treatment risk: policies, monitoring, complaints and remediation workflowCFPB expectations; state consumer protection laws; sector rulesConsumer Duty (FCA); complaints handling rules; sector obligationsEU consumer protection directives; sector rules; national regulators
COMPLAComplaints management: intake, classification, resolution, root cause analysis and reportingCFPB/industry complaint handling expectations; sector rulesFCA DISP rules; Financial Ombudsman processes; sector rulesEU ADR/ODR frameworks; sector complaint rules; national requirements
KYCKYC / onboarding risk controls: customer due diligence, approvals, screening and periodic review workflowBSA/AML; FinCEN CDD Rule; OFAC screening expectationsMoney Laundering Regulations; FCA expectations (where applicable); OFSI screeningEU AMLD; national CDD rules; sanctions regimes
CREDITCredit risk governance: risk appetite, monitoring, exceptions, approvals and reportingBasel-aligned expectations (where applicable); OCC/FRB guidance; internal governancePRA/FCA credit risk expectations (where applicable); internal governanceCRR/CRD (where applicable); EBA guidelines; national supervisor expectations
LIQUIDLiquidity risk governance: monitoring, stress testing workflow, controls and reportingBasel-aligned expectations; FRB/OCC guidance; internal governancePRA/FCA liquidity requirements (where applicable)CRR/CRD liquidity requirements; EBA guidelines; national supervision
CAPITALCapital adequacy governance: ICAAP/ILAAP workflows, evidence collection and reporting packsBasel/US capital rules; FRB/OCC expectations where applicablePRA ICAAP/ILAAP expectations; FCA where applicableCRR/CRD; ICAAP/ILAAP expectations; EBA guidelines
OPRISKOperational risk framework: RCSA, KRIs, event management, actions and reportingBasel-aligned operational risk expectations; OCC/FRB guidance; industry practicePRA/FCA operational risk expectations (where applicable)EBA operational risk expectations; national supervisor requirements
RCSARisk and Control Self-Assessment (RCSA): methodology, scoring, evidence, action tracking and reportingIndustry practice; internal control expectations; sector supervisors where applicableIndustry practice; FCA/PRA expectations where applicableIndustry practice; EBA/ESMA guidance where applicable
KRIKey Risk Indicators (KRI) framework: KRI catalogue, thresholds, monitoring workflows and escalationsIndustry practice; sector rules where applicableIndustry practice; sector rules where applicableIndustry practice; sector rules where applicable
LOSSLoss event management: event capture, classification, root cause, actions and reportingBasel-aligned operational risk practice; sector supervisor expectationsOperational risk practice; PRA/FCA where applicableOperational risk practice; EBA guidance where applicable
CTRLIBControls library management: control catalogue, mappings, ownership, testing cycles and evidenceSOX control environment; COSO; audit expectationsAudit expectations; UK governance requirementsAudit expectations; ISO alignments (best practice); sector guidance
ISSUEIssue and remediation management: findings, actions, owners, due dates, approvals and reportingSOX remediation expectations; audit standards; sector requirementsAudit remediation expectations; FCA/PRA where applicableAudit remediation expectations; sector supervisors where applicable
TRAINCompliance training and attestations: curricula, completion tracking, reminders and reportingSOX ethics programme expectations; industry compliance expectationsFCA conduct expectations (where applicable); UK governance guidanceEU sector compliance expectations; national supervisory guidance
DISCPLDisciplinary and HR compliance cases: case management, approvals, documentation and reportingEmployment law; compliance programme expectations; recordkeeping normsUK employment law; governance expectations; recordkeeping normsEU labour law frameworks (varies by member state); GDPR constraints where applicable
Scroll to Top