TREASURY OPERATIONSREVIEW

The operating record for cash, risk, and control.

Coverage desk

Financial risk

Source-backed reporting and analysis connected to the companies, capabilities, authorities, and operating domains it affects.

A Hedgebook exposure report is not a hedge instruction

Hedgebook documents tools for FX exposure, interest-rate and commodity risk, reporting, analytics, and financial-instrument valuations. An exposure report can inform treasury judgment, but it does not authorize a trade, establish risk appetite, select an instrument, or prove the underlying exposure is complete.

A 360T FX execution does not set treasury risk appetite

360T presents electronic foreign-exchange trading, workflow, market data, automation, and integration services. An execution can evidence the terms agreed with a counterparty, but it does not define why the organization assumed or hedged the exposure, how much risk it accepts, or whether the trade fits policy.

ISO 31000 frames risk governance—not hedge effectiveness

ISO 31000:2018 remains the current published edition while a revision is under development. Its general principles, framework, and process can organize treasury risk decisions, but they do not decide an accounting designation or market outcome.

PCAOB AS 2201 starts from reporting risk—not a control inventory

The auditing standard directs a top-down, risk-based selection of controls in an integrated audit of internal control over financial reporting. Treasury automation matters when it connects to significant accounts, disclosures, assertions, and material-misstatement risk.

BCBS 239 makes treasury risk reporting an adaptable data-lineage test

BCBS 239 links bank risk reports to the governance, architecture, aggregation, and controls that produce them. Accuracy, completeness, timeliness, and adaptability must work together, so a fast treasury dashboard is not persuasive when its coverage, transformations, exceptions, or stress-time behavior cannot be explained.

OFAC's framework keeps payment screening inside a risk-based compliance program

The Treasury framework places technology alongside management commitment, risk assessment, internal controls, testing, and training. A screening alert is therefore an input to governed review—not a sanctions decision or proof that the wider program is effective.

DORA makes treasury-vendor resilience an operating record

From January 2025, regulated financial entities face a stronger evidence chain around ICT risk, incidents, resilience testing, third parties, and critical services that can reach treasury and payment technology.