Artefacts

We aim to deliver sectorwide operational resilience improvements to benefit the safety and security of customers through trusted and effective collaboration

Welcome to the CMORG Artefact library

This brings together all CMORG outputs that are accessible to industry participants. You can register to access all of these here, but to receive a response, you must provide an industry email address and be a direct industry participant.

Filter by:

Resilience
Stocktake of Firm-Level Resilience - Report Highlights
This summary presents key findings from a cross-sector survey on how UK financial firms measure resilience.
Resilience
Guidance for Firm Operational Resilience
Following on from the development of the original guidance produced in 2021, this document provides an update to firms on the guidance to implementing operational resilience.
Resilience
Strategic Risk Register 2025 version 3
A refresh of the 2023/4 Strategic Risk Register to capture the most relevant risks facing the financial sector in 2025. The register has reflected the Operational Resilience Collaboration Group's (ORCG) Threat Monitoring Framework, the Dynamic Scenario Library, National Risk Register and the Authorities’ recommendations to provide an informed view of the threat landscape.
Technology and cyber
AI Baseline Review Guidance
The Cross Market Operational Resilience Group’s (CMORG) AI Taskforce artefact was created in 2024 as a joint initiative of the CIO Forum and Cyber Coordination Group, in response to concerns relating to sector-level risk introduced by the rapid adoption of Generative AI (Gen-AI).
Technology and cyber
Guidance for Post-Quantum Cryptography
This artefact emphasises the urgency of managing quantum risk and aligns with the UK National Cyber Security Centre’s (NCSC) guidance for the financial sector which is transitioning towards quantum-safe cryptographic practice.
Technology and cyber
Cloud-Hosted Data Vaulting Good Practice
This good practice guidance outlines the essential steps and recommendations for creating, maintaining, and securing immutable cloud-hosted data vaults to ensure the availability, integrity, and security of critical data. It takes the key outputs of the CMORG Cloud-Hosted Data Vault Reference Architecture1 and outlines actionable practices for establishing an effective cloud-hosted data vaulting process that meets regulatory requirements and mitigates risks related to data loss, corruption, and unauthorized access.
Sector Response
Mortgages Advances and Property Completions Industry Playbook
This document outlines a ‘principles-based’ approach to implementing effective business continuity responses across UK retail firms and which can be referred to during operational disruption, affecting Mortgage advances and property completions.
Third Party
Third Party Exit Plan Template
This artefact was formulated to establish a standardised template and associated guidance for exit strategies concerning material and high-impact suppliers as part of an organisation’s Third Party Risk Management framework and associated Business Continuity and Disaster Recovery measures.
Resilience
CMORG Artefact Library
This is the CMORG Artefact Library as of August 2026.