TREASURY OPERATIONSREVIEW

The operating record for cash, risk, and control.

Operating domain

Operating domain: Treasury operational resilience and third-party dependency

The capacity to sustain or recover critical cash, payment, funding, risk, and reporting services across banks, networks, vendors, people, facilities, credentials, data, and alternate processes.

What this domain asks

The capacity to sustain or recover critical cash, payment, funding, risk, and reporting services across banks, networks, vendors, people, facilities, credentials, data, and alternate processes.

The domain should retain its own evidence, decision owner, materiality criteria, exception path, and consequence even when it shares organization identity, workflow, or technology with adjacent domains. Aggregation can support oversight; it should not erase the evidence behind different risks or operating outcomes.

Buyer questions

  • Which treasury services are critical and what impact tolerance applies?
  • Which banks, networks, files, keys, systems, people, and sites are required?
  • What alternate process can actually meet volume and control needs?
  • How are scenarios exercised across parties?
  • Which findings remain open and who owns remediation?

Mapped workflows

Bank Connectivity And Statement Ingestion

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for bank connectivity and statement ingestion within this domain.

Payment Initiation Approval And Release Control

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for payment initiation approval and release control within this domain.

Cash Positioning And Balance Visibility

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for cash positioning and balance visibility within this domain.

Counterparty Credit And Market-Risk Controls

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for counterparty credit and market-risk controls within this domain.

Policy Limits Approvals And Segregation Of Duties

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for policy limits approvals and segregation of duties within this domain.

Audit Trail Control Evidence And Record Retention

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for audit trail control evidence and record retention within this domain.

ERP Accounting Market-Data And API Integration

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for ERP accounting market-data and API integration within this domain.

Treasury Master-Data Normalization And Lineage

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for treasury master-data normalization and lineage within this domain.

Case Workflow Exception And Task Management

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for case workflow exception and task management within this domain.

Authority context

DORA

DORA establishes requirements for ICT risk management, incident reporting, resilience testing, third-party risk, and oversight in the financial sector.

FCA operational resilience

The FCA requires in-scope firms to identify important business services, set impact tolerances, map dependencies, test, and remediate vulnerabilities.

ISO 22301:2019

ISO 22301 specifies requirements for a business-continuity management system.

ISO/IEC 27001

ISO/IEC 27001 specifies requirements for an information-security management system.

Relevant operating models

Evidence boundary

Treasury Operations Review is not a bank, broker, dealer, payment processor, investment adviser, accounting firm, law firm, tax adviser, sanctions authority, regulator, auditor, cybersecurity assessor, or software provider. Its records support research and operational review; they do not establish legal or regulatory compliance, accounting treatment, tax outcome, sanctions permissibility, payment authorization, fair value, investment suitability, hedge effectiveness, audit sufficiency, security, liquidity, or fitness of any system for a particular organization. A provider's documented capability can identify a research candidate but cannot establish buyer-specific adequacy for this domain.