← Frameworks / PRA SS1/23 / Control Mappings

PRA Supervisory Statement SS1/23 — Model Risk Management

UK Prudential Regulation Authority supervisory statement setting expectations for model risk management at banks, building societies, and PRA-designated investment firms. 5 principles covering model identification and classification, governance (board accountability, model risk committee, independent validation), model development and implementation (documentation, testing, performance monitoring), model use and ongoing monitoring, and risk mitigation and reporting. Effective 17 May 2024 with proportionate application.

AC Access Control

Control Name PRA SS1/23 References
AC-01 Policy and Procedures
P-IT.1
AC-02 Account Management
P2.4P-IT.1
AC-03 Access Enforcement
P3.3P3.6P-IT.1
AC-05 Separation of Duties
P2.2P2.4P4.1P-IT.1
AC-06 Least Privilege
P2.4P3.3P3.6P4.4P-IT.1
AC-17 Remote Access
P-IT.1
AC-24 Access Control Decisions
P-IT.1

AT Awareness and Training

Control Name PRA SS1/23 References
AT-01 Policy and Procedures
P2.3
AT-02 Literacy Training and Awareness
P2.3P3.6
AT-03 Role-based Training
P2.3P3.6

AU Audit and Accountability

Control Name PRA SS1/23 References
AU-01 Policy and Procedures
P-IT.2
AU-02 Event Logging
P3.2P3.4P4.3P4.4P-IT.2
AU-03 Content of Audit Records
P3.2P4.3P4.4P-IT.2
AU-05 Response to Audit Logging Process Failures
P5.3
AU-06 Audit Record Review, Analysis, and Reporting
P3.4P3.6P4.5P5.2P-IT.2
AU-07 Audit Record Reduction and Report Generation
P-IT.2
AU-08 Time Stamps
P-IT.2
AU-09 Protection of Audit Information
P-IT.2
AU-10 Non-repudiation
P3.2P4.4P-IT.2
AU-11 Audit Record Retention
P5.5P-IT.2
AU-12 Audit Record Generation
P3.3P3.4P-IT.2
AU-14 Session Audit
P-IT.2

CA Security Assessment and Authorization

Control Name PRA SS1/23 References
CA-01 Policy and Procedures
P2.2P4.1
CA-02 Control Assessments
P2.2P4.1P4.2
CA-05 Plan of Action and Milestones
P4.5P5.1
CA-06 Authorization
P2.2P3.4
CA-07 Continuous Monitoring
P4.1P5.2
CA-08 Penetration Testing
P4.2P5.4

CM Configuration Management

Control Name PRA SS1/23 References
CM-01 Policy and Procedures
P3.1
CM-02 Baseline Configuration
P3.3P-IT.3
CM-03 Configuration Change Control
P3.3P3.4P4.4P5.5
CM-04 Impact Analyses
P3.3P3.4
CM-05 Access Restrictions for Change
P3.3P3.4
CM-06 Configuration Settings
P3.3P-IT.3
CM-08 System Component Inventory
P1.1P1.3P5.5P-IT.3
CM-09 Configuration Management Plan
P3.3P3.4
CM-12 Information Location
P1.1P3.2
CM-13 Data Action Mapping
P1.1P3.2

CP Contingency Planning

Control Name PRA SS1/23 References
CP-02 Contingency Plan
P-IT.3
CP-04 Contingency Plan Testing
P5.4
CP-07 Alternate Processing Site
P-IT.3
CP-09 System Backup
P-IT.3
CP-10 System Recovery and Reconstitution
P-IT.3

IA Identification and Authentication

Control Name PRA SS1/23 References
IA-02 Identification and Authentication (Organizational Users)
P-IT.1
IA-04 Identifier Management
P-IT.1
IA-05 Authenticator Management
P-IT.1

IR Incident Response

Control Name PRA SS1/23 References
IR-01 Policy and Procedures
P5.3
IR-04 Incident Handling
P5.3
IR-06 Incident Reporting
P5.3

MP Media Protection

Control Name PRA SS1/23 References
MP-06 Media Sanitization
P5.5

PE Physical and Environmental Protection

Control Name PRA SS1/23 References
PE-01 Policy and Procedures
P-IT.3
PE-02 Physical Access Authorizations
P-IT.3
PE-03 Physical Access Control
P-IT.3

PL Planning

Control Name PRA SS1/23 References
PL-01 Policy and Procedures
P2.1P2.3
PL-02 System Security and Privacy Plans
P1.1P1.3P2.3P3.5P5.1
PL-04 Rules of Behavior
P2.3P3.6
PL-08 Security and Privacy Architectures
P1.3P3.1
PL-10 Baseline Selection
P5.1
PL-11 Baseline Tailoring
P5.1

PM Program Management

Control Name PRA SS1/23 References
PM-01 Information Security Program Plan
P2.1P2.2P2.3
PM-02 Information Security Program Leadership Role
P2.1P2.2
PM-03 Information Security and Privacy Resources
P2.1
PM-04 Plan of Action and Milestones Process
P4.5
PM-05 System Inventory
P1.1
PM-06 Measures of Performance
P4.5P5.2
PM-09 Risk Management Strategy
P1.2P2.1P3.5P5.1P5.4
PM-10 Authorization Process
P2.2P2.3
PM-11 Mission and Business Process Definition
P1.2P1.3P3.6
PM-13 Security and Privacy Workforce
P2.1
PM-14 Testing, Training, and Monitoring
P2.3P4.1P5.2P5.3
PM-29 Risk Management Program Leadership Roles
P2.1

PS Personnel Security

Control Name PRA SS1/23 References
PS-01 Policy and Procedures
P2.1P2.4
PS-02 Position Risk Designation
P2.2P2.4
PS-03 Personnel Screening
P2.4
PS-06 Access Agreements
P2.4
PS-07 External Personnel Security
P2.2P2.4
PS-09 Position Descriptions
P2.4

RA Risk Assessment

Control Name PRA SS1/23 References
RA-02 Security Categorization
P1.1P1.2
RA-03 Risk Assessment
P1.2P3.5P5.1P5.4
RA-07 Risk Response
P4.5P5.1
RA-09 Criticality Analysis
P1.1P1.2

SA System and Services Acquisition

Control Name PRA SS1/23 References
SA-03 System Development Life Cycle
P3.1P5.5
SA-04 Acquisition Process
P1.3
SA-05 System Documentation
P3.1P3.5
SA-08 Security and Privacy Engineering Principles
P3.1
SA-10 Developer Configuration Management
P3.1P3.3P3.4
SA-11 Developer Testing and Evaluation
P3.3P4.2P4.3
SA-15 Development Process, Standards, and Tools
P3.1P3.3
SA-16 Developer-provided Training
P3.3
SA-17 Developer Security and Privacy Architecture and Design
P3.1P3.5

SC System and Communications Protection

Control Name PRA SS1/23 References
SC-02 Separation of System and User Functionality
P-IT.3
SC-07 Boundary Protection
P-IT.3
SC-28 Protection of Information at Rest
P-IT.3

SI System and Information Integrity

Control Name PRA SS1/23 References
SI-01 Policy and Procedures
P3.2
SI-04 System Monitoring
P5.2P5.3
SI-05 Security Alerts, Advisories, and Directives
P5.3
SI-06 Security and Privacy Function Verification
P3.2P4.3P5.2
SI-07 Software, Firmware, and Information Integrity
P3.2P4.3
SI-10 Information Input Validation
P3.2P4.3
SI-11 Error Handling
P3.2
SI-12 Information Management and Retention
P3.2P5.5
SI-15 Information Output Filtering
P3.2