Licensed commercial bankSample
One control library for a bank answering to five frameworks
A bank tested overlapping controls separately for each framework. We merged them into a single library traced to the underlying obligations.
The challenge
Compliance, information security and internal audit each maintained their own control lists for supervisory directions, PCI DSS, ISO/IEC 27001 and data protection. The same firewall review was evidenced four times a year, while some obligations had no control at all.
Our approach
- 01Obligations firstLawyers extracted requirements from each source into a single register with citations.
- 02Rationalise controlsDuplicate controls were merged and mapped to every obligation they satisfy.
- 03Automate evidenceIdentity and infrastructure integrations replaced manual screenshots for routine tests.
- 04Report by decisionBoard reporting was rebuilt around exposure, not test counts.
The solution
The bank now runs one control library in ENKAYT Comply, linked to an obligations register in ENKAYT Govern. Horizon flags new directions and proposes the obligations they affect.
- ENKAYT Govern
- ENKAYT Comply
- ENKAYT Horizon
- Microsoft Entra ID
- ServiceNow
Results
Sample- fewer controls after rationalisation
- 41%
- faster evidence retrieval for inspections
- 3×
- of in-scope obligations mapped to a control
- 100%
- Single source of truth across three assurance teams
- Inspection requests answered from the platform
- Gaps surfaced and closed before the next cycle
“For the first time, compliance, security and audit are looking at the same list — and it's traced back to the actual rules.”
Facing something similar?
Tell us where you are today. We'll show you what a comparable programme would look like for your organisation.