TREASURY OPERATIONSREVIEW

The operating record for cash, risk, and control.

2026 research note

Standards-to-treasury workflow crosswalk

A source-linked map from payment, control, resilience, risk, accounting, and security authorities to treasury workflows and buyer questions.

TREASURY OPERATIONS REVIEWStandards-to-treasury workflow crosswalkMethod and limitations included
Executive summary

A source-linked map from payment, control, resilience, risk, accounting, and security authorities to treasury workflows and buyer questions.

The maintained dataset joins 49 organization records, 30 normalized capabilities, 8 operating models, 19 authority records, and 12 operating domains. Counts describe the research corpus; they are not a market-size or quality score.

The authority records

ISO 20022

Global financial messaging communities · Maintained standard and message repository. ISO 20022 provides a common methodology, business model, and message repository for financial communications.

Swift CBPR+

Swift cross-border payment and reporting community · Current operating market practice. Swift's CBPR+ programme applies ISO 20022 messages and market-practice rules to cross-border payments and cash reporting.

Fedwire Funds ISO 20022

Fedwire Funds participants and connected customers · Implemented operating format. The Federal Reserve migrated the Fedwire Funds Service to ISO 20022 messages and maintains implementation resources.

Nacha Operating Rules

ACH network participants and originators under applicable roles · Current maintained operating rules. Nacha maintains operating rules for ACH entries, participants, warranties, authorization, returns, risk, and related processes.

EU Instant Payments Regulation

Payment service providers and users in scope under the regulation · Published with phased obligations. The regulation introduces requirements around sending and receiving instant euro credit transfers, charges, and verification of payee.

DORA

Financial entities and relevant ICT third parties within scope · Applicable regulation. DORA establishes requirements for ICT risk management, incident reporting, resilience testing, third-party risk, and oversight in the financial sector.

FCA operational resilience

FCA-regulated firms in scope · Current supervisory framework. The FCA requires in-scope firms to identify important business services, set impact tolerances, map dependencies, test, and remediate vulnerabilities.

COSO Internal Control

Organizations designing and evaluating internal control · Current framework and guidance. COSO organizes internal control around environment, risk assessment, control activities, information and communication, and monitoring.

ISO 31000:2018

Organizations managing risk · Published and confirmed standard. ISO 31000 provides principles, a framework, and a process for managing risk.

ISO 22301:2019

Organizations establishing a business-continuity management system · Published and confirmed standard. ISO 22301 specifies requirements for a business-continuity management system.

ISO/IEC 27001

Organizations establishing an information-security management system · Current published edition. ISO/IEC 27001 specifies requirements for an information-security management system.

OFAC Framework

Organizations subject to U.S. sanctions requirements or managing related exposure · Current official framework. OFAC describes management commitment, risk assessment, internal controls, testing and auditing, and training as essential components.

IFRS 9

Entities applying IFRS within their reporting requirements · Current issued standard. IFRS 9 addresses classification and measurement, impairment, and hedge accounting for financial instruments.

ASC 815

Entities applying U.S. GAAP to derivatives and hedging · Current codification topic. ASC 815 contains U.S. GAAP requirements for derivatives and hedge accounting.

SEC money-market fund reforms

Registered money-market funds and related participants within scope · Final rule with phased compliance. The SEC adopted reforms concerning liquidity fees, redemption gates, liquidity requirements, reporting, and related money-market fund controls.

BCBS 239

Global systemically important banks and other institutions as applied by supervisors · Current supervisory principles. BCBS 239 sets principles for governance, data architecture, accuracy, integrity, completeness, timeliness, adaptability, reporting, and supervisory review.

PCAOB AS 2201

Audits of issuers when the standard applies · Current auditing standard. AS 2201 establishes requirements for audits of internal control over financial reporting integrated with financial-statement audits.

2021 ISDA Definitions

Parties using the definitions in relevant derivatives documentation · Current published definitions with maintained supplements. The 2021 ISDA Definitions provide standardized terms for interest-rate derivatives documentation.

PCI DSS

Entities storing processing or transmitting payment account data within scope · Current maintained standard. PCI DSS defines technical and operational requirements for protecting payment account data.

The operating-domain lens

Cash positioning and liquidity visibility

The daily control process for knowing which cash, account, currency, legal entity, bank, value date, restriction, and concentration state can support an accountable liquidity decision. The crosswalk links 7 capabilities and 2 authority records.

Cash-flow forecasting and variance governance

The maintained process for projecting cash by entity, currency, horizon, source, driver, scenario, owner, and confidence, then learning from actual-versus-forecast variance. The crosswalk links 8 capabilities and 2 authority records.

Payments, fraud, and release control

The end-to-end control chain from authorized obligation and beneficiary data through payment creation, validation, approval, screening, transmission, bank acceptance, settlement, rejection, return, and reconciliation. The crosswalk links 9 capabilities and 4 authority records.

Bank connectivity and message integrity

The governed transport and transformation layer connecting ERP and treasury records to banks while preserving identity, format, version, data, signature, status, correction, and evidence. The crosswalk links 8 capabilities and 4 authority records.

Bank-account, signatory, and mandate governance

The controlled record of bank accounts, legal owners, purposes, services, signatories, authorities, mandates, fees, documentation, reviews, changes, and closures. The crosswalk links 8 capabilities and 2 authority records.

Liquidity, funding, debt, and investment

The decision system for meeting obligations and deploying surplus cash through facilities, debt, deposits, money-market instruments, investments, and internal liquidity under policy and risk constraints. The crosswalk links 11 capabilities and 3 authority records.

Financial risk and hedging

The governed process for identifying FX, interest-rate, commodity, credit, and liquidity exposures; defining risk appetite; selecting treatment; executing; valuing; monitoring; and preserving accountable evidence. The crosswalk links 12 capabilities and 4 authority records.

Treasury accounting, reconciliation, and close

The evidence chain connecting bank events, treasury deals, valuations, accruals, settlements, classifications, journals, reconciliations, approvals, disclosures, and general-ledger close. The crosswalk links 10 capabilities and 4 authority records.

Intercompany liquidity and in-house banking

The operating structure for centralizing cash, payments, receivables, funding, FX, netting, and internal account relationships across legal entities while preserving legal, tax, accounting, and control boundaries. The crosswalk links 11 capabilities and 3 authority records.

Working capital and cash conversion

The cross-functional decision system connecting receivables, payables, inventory, disputes, terms, financing, forecasts, and operating behavior to liquidity and enterprise value. The crosswalk links 9 capabilities and 2 authority records.

Treasury data models and decision lineage

The governance of accounts, entities, banks, counterparties, instruments, currencies, rates, transactions, forecasts, statuses, transformations, models, overrides, and retained decision evidence. The crosswalk links 10 capabilities and 3 authority records.

Treasury operational resilience and third-party dependency

The capacity to sustain or recover critical cash, payment, funding, risk, and reporting services across banks, networks, vendors, people, facilities, credentials, data, and alternate processes. The crosswalk links 9 capabilities and 4 authority records.

How to use the crosswalk

Determine applicability with qualified owners, identify affected records and workflows, map each expectation to an accountable decision and retained evidence, then use capability and organization pages to frame a technology evaluation. A mapping is editorial navigation—not a conformity or legal conclusion.

Methodology

  1. Define the market boundary, exclusions, operating models, and capability taxonomy before classifying organizations.
  2. Require an approved official source for organization inclusion and each documented capability.
  3. Keep authority sources, provider claims, independent observations, editorial synthesis, and unknowns in separate evidence states.
  4. Use one primary operating model per organization while retaining adjacent scope in the narrative record.
  5. Preserve source URLs, review dates, material changes, limitations, and correction history.

Limitations

  • The maintained population is substantial but not claimed to be a complete global market.
  • Official public documentation may omit available capabilities or lag product and service changes.
  • Documented positioning does not measure product depth, configured availability, independent performance, implementation effort, customer outcome, or commercial terms.
  • Authority mappings are editorial research aids and do not establish buyer-specific applicability or product conformity.
  • No organization may purchase inclusion, classification, finding, or correction outcome.

Reproducibility and updates

The report is reproduced from the provider registry, normalized facts and evidence, authority and domain records, and the publication taxonomy. A material change requires a dated source and editorial explanation. Historical values remain available through the change ledger rather than disappearing when the current record changes.

Research boundary

Treasury Operations Review is not a bank, broker, dealer, payment processor, investment adviser, accounting firm, law firm, tax adviser, sanctions authority, regulator, auditor, cybersecurity assessor, or software provider. Its records support research and operational review; they do not establish legal or regulatory compliance, accounting treatment, tax outcome, sanctions permissibility, payment authorization, fair value, investment suitability, hedge effectiveness, audit sufficiency, security, liquidity, or fitness of any system for a particular organization.