● Independently run the Key Risk Indicator program for IT & Cyber Security
● Review the bank’s Risk Assessment & Risk Treatment plan/register and update same with
relevant risks
● Periodically test the design strength of the controls and track changing risk patterns across
multiple IT & Cyber areas of the bank
● Conduct thematic cyber security assessments across bank for critical applications, networks,
infrastructure and processes