Distribution control register
6 min
register key controls operating in distribution processes frequencies and owners are reviewed quarterly at the distribution committee control lifecycle flowchart td a\[control identified] > b\[control designed] b > c\[assigned owner and evidence] c > d\[monthly operation and testing] d > e\[self assessment completed] e > f{any failures?} f yes > g\[remediation tracking] f no > h\[committee reporting] g > h control categories controls designed to stop issues before they occur examples include approval segregation, validation checks and system restrictions controls designed to identify issues after activity has occurred examples include reconciliations, exception monitoring and queue reviews controls or actions implemented to remediate identified failures and reduce recurrence risk control register id control process type frequency owner evidence ctrl d 03 four eyes review of fit and proper assessment intermediary onboarding preventive per application distribution ops manager second reviewer sign off on review template ctrl d 04 fsca licence validation before activation intermediary onboarding preventive per application distribution ops manager dated register screenshot ctrl d 07 segregation reviewer cannot activate record intermediary onboarding preventive per application distribution ops manager crm audit trail of distinct users ctrl d 09 commission structure restricted to approved codes crm administration preventive continuous channel manager crm validation rule + exception log ctrl d 11 call back verification for banking detail changes agreement administration preventive per change channel manager call log reference on amendment record ctrl d 14 dormant intermediary review panel management detective semi annual channel manager dormancy report with decisions ctrl d 16 referred quote queue cleared within sla quote and bind detective daily distribution ops manager queue age report evidence standard 🧾 evidence quality standard control evidence should be reviewable by an independent party without requiring additional explanation from the owner governance expectations every control must have a named owner and defined evidence requirement changes to control ownership require approval at the operational risk forum retired controls remain visible in the register for audit traceability evidence retention periods align to regulatory and audit obligations change control additions and retirements of controls go through the operational risk forum — see the risks and controls space the register version history is the audit trail; do not delete rows, mark them retired with a date
Have a question?
Our super-smart AI, knowledgeable support team and an awesome community will get you an answer in a flash.
To ask a question or participate in discussions, you'll need to authenticate first.