Skip to content
Circles Technologies

Compliance

Findings mapped to the controls you answer to.

A finding is a technical fact. What your board, your examiner and your correspondent bank need is which control it implicates. We map every finding to the specific controls it touches across the frameworks below, and your portal shows the result as a per-framework view — in French or English.

What a mapping is, and is not

A control shown with a finding is a control that finding implicates. It is not a statement that the control was formally tested, not a statement that every other control passed, and not a declaration of compliance. Unmapped controls are not asserted to pass. We say “controls with findings” and never “compliant”, because only your assessor or regulator can say the latter.

PCI-DSS v4.0

12 control areas

The twelve principal requirements, for institutions handling card data.

  • Req 1 — Network security controls
  • Req 2 — Secure configurations
  • Req 3 — Protect stored account data
  • Req 4 — Protect data in transit
  • Req 5 — Protect against malware
  • Req 6 — Secure systems & software
  • Req 7 — Restrict access by need to know
  • Req 8 — Identify & authenticate access
  • Req 9 — Restrict physical access
  • Req 10 — Log & monitor access
  • Req 11 — Test security (incl. pentest)
  • Req 12 — Security policy & programme

SWIFT Customer Security Programme

7 control areas

The seven control-objective principles behind the annual KYC-SA attestation.

  • Principle 1 — Restrict internet access & segregate
  • Principle 2 — Reduce attack surface & vulnerabilities
  • Principle 3 — Physically secure the environment
  • Principle 4 — Prevent compromise of credentials
  • Principle 5 — Manage identities & segregate privileges
  • Principle 6 — Detect anomalous activity
  • Principle 7 — Plan for incident response & sharing

ISO/IEC 27001:2022

4 control areas

The four Annex A control themes.

  • A.5 — Organizational controls
  • A.6 — People controls
  • A.7 — Physical controls
  • A.8 — Technological controls

ANTIC — Cameroon

7 control areas

The security domains supervised under the national annual audit mandate.

  • Governance & security policy
  • Access control & identities
  • Network & infrastructure security
  • Application & web security
  • Data protection & privacy
  • Incident detection & response
  • Business continuity

COBAC — CEMAC

6 control areas

The IT and cyber-risk domains the banking commission supervises.

  • IT governance & oversight
  • Access management
  • IT operations security
  • Business continuity & resilience
  • Outsourcing & third-party risk
  • Cyber-risk management

BCEAO — UEMOA

6 control areas

The cybersecurity domains supervised across the West African union.

  • Security governance
  • Access & authentication
  • Network protection
  • Monitoring & detection
  • Incident management
  • Continuity & recovery

We map against the regulator that supervises you — not every regulator on the list. A Senegalese institution is mapped against BCEAO, a Cameroonian one against ANTIC and COBAC. Speaking your regulator’s language is the point; speaking the wrong one is worse than staying silent.

For ANTIC, COBAC and BCEAO we map against the security domains these regulators supervise rather than invented article numbers. Their catalogues are not published as neat numbered lists, and a precise-looking reference we made up would be worse than an honest domain.