Artefacts

We aim to deliver sectorwide operational resilience improvements to benefit the safety and security of customers through trusted and effective collaboration

Welcome to the CMORG Artefact library

This brings together all CMORG outputs that are accessible to industry participants. You can register to access all of these here, but to receive a response, you must provide an industry email address and be a direct industry participant.

Filter by:

Resilience
Stocktake of Firm-Level Resilience - Report Highlights
This summary presents key findings from a cross-sector survey on how UK financial firms measure resilience.
Resilience
Guidance for Firm Operational Resilience
Following on from the development of the original guidance produced in 2021, this document provides an update to firms on the guidance to implementing operational resilience.
Technology and cyber
AI Baseline Review Guidance
The Cross Market Operational Resilience Group’s (CMORG) AI Taskforce artefact was created in 2024 as a joint initiative of the CIO Forum and Cyber Coordination Group, in response to concerns relating to sector-level risk introduced by the rapid adoption of Generative AI (Gen-AI).
Technology and cyber
Guidance for Post-Quantum Cryptography
This artefact emphasises the urgency of managing quantum risk and aligns with the UK National Cyber Security Centre’s (NCSC) guidance for the financial sector which is transitioning towards quantum-safe cryptographic practice.
Technology and cyber
Cloud-Hosted Data Vaulting Good Practice
This good practice guidance outlines the essential steps and recommendations for creating, maintaining, and securing immutable cloud-hosted data vaults to ensure the availability, integrity, and security of critical data. It takes the key outputs of the CMORG Cloud-Hosted Data Vault Reference Architecture1 and outlines actionable practices for establishing an effective cloud-hosted data vaulting process that meets regulatory requirements and mitigates risks related to data loss, corruption, and unauthorized access.
Third Party
Third Party Exit Plan Template
This artefact was formulated to establish a standardised template and associated guidance for exit strategies concerning material and high-impact suppliers as part of an organisation’s Third Party Risk Management framework and associated Business Continuity and Disaster Recovery measures.
Third Party
Collaborative Scenario Testing of Critical Third Parties
A common approach to scenario testing of critical third parties to address the challenge common providers have of multiple assurance engagements with diverse financial institutions.
Third Party
Third Party Lifecycle Management Guidance
Developed to provide industry expertise on managing resilience risks through the lifecycle of a third-party engagement, optimising the approaches undertaken by larger firms and supporting capability building across the wider sector.