TREASURY OPERATIONSREVIEW

The operating record for cash, risk, and control.

Coverage desk

Risk Desk

Source-backed reporting and analysis connected to the companies, capabilities, authorities, and operating domains it affects.

ISO 31000 frames risk governance—not hedge effectiveness

ISO 31000:2018 remains the current published edition while a revision is under development. Its general principles, framework, and process can organize treasury risk decisions, but they do not decide an accounting designation or market outcome.

PCAOB AS 2201 starts from reporting risk—not a control inventory

The auditing standard directs a top-down, risk-based selection of controls in an integrated audit of internal control over financial reporting. Treasury automation matters when it connects to significant accounts, disclosures, assertions, and material-misstatement risk.

BCBS 239 makes treasury risk reporting an adaptable data-lineage test

BCBS 239 links bank risk reports to the governance, architecture, aggregation, and controls that produce them. Accuracy, completeness, timeliness, and adaptability must work together, so a fast treasury dashboard is not persuasive when its coverage, transformations, exceptions, or stress-time behavior cannot be explained.

OFAC's framework keeps payment screening inside a risk-based compliance program

The Treasury framework places technology alongside management commitment, risk assessment, internal controls, testing, and training. A screening alert is therefore an input to governed review—not a sanctions decision or proof that the wider program is effective.

DORA makes treasury-vendor resilience an operating record

From January 2025, regulated financial entities face a stronger evidence chain around ICT risk, incidents, resilience testing, third parties, and critical services that can reach treasury and payment technology.