Here is the honest situation. If you run a Swap Execution Facility, Designated Contract Market, Derivatives Clearing Organization or Swap Data Repository, the CFTC requires a program of risk analysis and oversight across information security, business continuity, capacity and systems operations; a disaster recovery capability with a next-business-day recovery objective and geographic diversity; annual and independent testing including vulnerability, penetration, controls, incident-response and enterprise technology risk assessments; and prompt notification of cyber incidents and BCDR activation. Building and evidencing that program is a major effort, and a registered entity that cannot show its testing or its next-day recovery is exactly where registered entities fall short.
This Kit removes that build. It is every CFTC system safeguards obligation written as an adopt-ready control you personalize in a weekend, with the evidence a CFTC examiner examines.
What you get, the moment you buy
Grounded in the CFTC system safeguards rules (17 CFR 37.1401, 38.1050 to 38.1051, 39.18 and 49.24), with the program of risk analysis and oversight, the next-business-day recovery objective, geographic diversity, the required test types and prompt incident notification to CFTC staff called out. Editable Word and Excel files.
What one control looks like
This is the program of risk analysis and oversight, the backbone of the system safeguards rules. All 35 are built to this depth.
Why this is not another template pack
- The evidence is the point. A safeguard you cannot evidence is an exam finding. This tells you what a CFTC examiner examines and where registered entities fall short, for every obligation.
- Testing and next-day recovery built in. The five required test types, the next-business-day recovery objective and geographic diversity are written into the controls, the requirements examiners focus on.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. System safeguards align with the NIST CSF, FFIEC and SEC Reg SCI, so this work feeds your wider operational resilience program.
Who buys this
SEFs, DCMs, DCOs and SDRs, and the technology risk, security and compliance leads who own system safeguards, plus consultants preparing for a CFTC exam. Whether it is a first program or an exam readiness pass, you save weeks and walk in with the program, testing and evidence structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Which entities does it cover? SEFs (Part 37), DCMs (Part 38), DCOs (Part 39) and SDRs (Part 49). The controls note the entity-specific duties.
What is the recovery objective? No later than the next business day, with geographic diversity of resources. Both are built as controls.
Does it cover the required testing? Yes. Vulnerability, penetration with independence, controls, incident-response-plan and enterprise technology risk assessment testing are each their own control.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com