Artefacts

We aim to deliver sectorwide operational resilience improvements to benefit the safety and security of customers through trusted and effective collaboration

Welcome to the CMORG Artefact library

This brings together all CMORG outputs that are accessible to industry participants. You can register to access all of these here, but to receive a response, you must provide an industry email address and be a direct industry participant.

Filter by:

Sector Response
Sector Response Framework Mapping Template
The updated firm mapping Template helps organisations document how they engage across SRF response groups. It supports clarity, streamlined communication, and enhanced collaboration during disruption. Firms are encouraged to integrate this into their business continuity plans and keep it regularly updated.
Sector Response
Sector Response Framework (SRF) Summary
A simplified overview which provides a quick reference for raising awareness amongst internal stakeholders including C-suite.
Technology and cyber
AI Shared Responsibility Model
This Shared Responsibility Model provides baseline guidance for understanding Artificial Intelligence security responsibilities and how these are managed between client firms and AI service providers.
Technology and cyber
Cloud Control Framework
A cloud framework to support consistent adoption of controls and practices across shared accountability models between FS firms and Cloud Services Providers.
Technology and cyber
Security in the Cloud
This artefact was developed to promote good practice guidance on how to plan and implement security in the Cloud to optimise the approach undertaken by CMORG firms and support capability building across the wider sector.
Resilience
Sector Principles for Service Substitution
The principles in this artefact relate to the substitution of a business service.
Third Party
Collaborative Testing of Third Parties - Effective Practices
This artefact was designed to provide a set of principles and broad expectations of the industry on how scenario testing with third parties should be conducted.

The guidance here is intended to be used by financial firms of all maturities as either a guidance for building a framework for scenario testing with third parties, or to act as a check point for established programs.
Third Party
Third Party Information Security - Supplier Risk Assurance Framework
The Supplier Risk Assurance Framework was designed to develop a third-party assurance scale as a practical tool to help firms assess the cyber security risk of their third parties and ensure appropriate levels of risk-based control.
Third Party
Reconnection Framework
The Reconnection Framework is a voluntary series of steps, common practices, and activities a compromised organisation could consider taking to facilitate reconnection between itself and client organisations following a significant cyber incident.