A focused course, tailored for you
The Index and Analytics Provider Control Inventory Playbook
Map every control across index production, ESG data, and factor models so your SOC 1 and BMR evidence holds the second a client asks.
The control matrix you submit at attestation time and the control matrix your engineering teams actually run are not the same document, and the gap shows up in a client SOC 1 finding or a BMR oversight question.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
Business risk and control inside an index and analytics provider sits between three different worlds. Index production runs on a calculation pipeline with daily corporate action handling, methodology rules, and a close-of-day rerun process. ESG and climate data flows through a separate ingestion stack with multiple upstream vendors, each with its own SOC reports and data quality controls. Factor models and risk analytics live in a third world, with model change management, backtesting, and methodology committees. The published control inventory has to cover all three with consistent owner, evidence, and frequency fields. The reality is each function maintains its own working list, the consolidation happens in a spreadsheet once a quarter, and by the time a buy-side client asks for the SOC 1 Type 2 plus the supplementary narrative on data lineage, the mapping between control IDs in the attestation and runbooks in the engineering wiki has drifted. The same gap is what an EU Benchmark Regulation oversight function will surface for any administered benchmark. The fix is a single inventory with named owners and named evidence per control, refreshed on a known cadence, with a clear carve-out treatment for sub-service organisations and a clear pointer from each external attestation line to the internal runbook that produces the evidence.
What you walk away with
- Ship one consolidated control inventory covering index production, ESG and climate data ingestion, factor and risk model change management, and client-facing analytics, with named owners and named evidence per control.
- Map every external attestation line in the SOC 1 Type 2 report to the internal runbook, ticket queue, or change record that produces its evidence, with no orphan controls on either side.
- Apply a defensible carve-out and sub-service organisation treatment for upstream data vendors and cloud providers, so the report stands up when a client's vendor risk team challenges scope.
- Run the EU Benchmark Regulation oversight overlay on any administered benchmark in scope, with the oversight function evidence, methodology change record, and conflict of interest log in one place.
- Reduce the time spent reconciling the published control matrix with the engineering reality from a quarterly fire drill to a routine refresh, with the same working files reused for the next client questionnaire.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- Twelve written modules with control taxonomy and inventory templates
- Owner-evidence-frequency matrix template ready to populate per product line
- External attestation line to internal runbook mapping file
- Benchmark Regulation oversight overlay template for administered benchmarks
- Sub-service organisation dependency view and carve-out language samples
- Buy-side vendor risk questionnaire answer library scaffold
- The hand-built implementation playbook for rolling the inventory across business lines
- 30-day money-back terms
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours: course access provisioned in the Art of Service learning environment and the hand-built implementation playbook delivered alongside.
Week one: complete modules 1 to 4 and ship a draft control taxonomy plus the first owner-evidence-frequency matrix for one product line.
Week two to three: extend the inventory across all product lines, run the reconciliation in module 7, and apply the Benchmark Regulation overlay where in scope.
Week four: stand up the refresh routine in module 12 and use the answer library in module 11 against the next live client questionnaire.
Before and after
Each business line keeps its own working control list, the consolidated matrix is rebuilt by hand the month before each SOC 1 cycle, and the gap between what the report says and what the engineering teams run is exposed every time a serious client questionnaire lands.
One living inventory covers index production, ESG and climate data, factor and risk models, and client-facing analytics, with named owners and named evidence per control, mapped directly to each external attestation line, refreshed on a quarterly cadence, and ready to feed the next client questionnaire in days rather than weeks.
What happens if you do not address this
A client SOC 1 finding or a Benchmark Regulation oversight observation that points at orphan controls in the published report does not stay quiet inside the business risk and control function. It becomes a Board-visible item, it triggers a remediation programme that runs across multiple product lines for the next attestation cycle, and it changes how every future buy-side vendor risk questionnaire reads your report.
Who it is for
Built for the practitioner inside an index, analytics, ESG, or benchmark data provider who owns business risk and control across multiple product lines. You sit close enough to index production, data ingestion, and model change management to see what actually runs day to day, and close enough to Internal Audit, Compliance, and the client-facing teams to see what the external attestation says. You are the person who has to reconcile the two before the next SOC 1 cycle opens and before the next big buy-side vendor risk questionnaire lands.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. About four to six focused hours to complete the twelve modules, then routine return visits to the templates each attestation cycle and each large client questionnaire.
Why $199 is the right number
Big4 advisory engagements on control inventory work run six figures and leave the client with a slide deck rather than a living matrix. Generic GRC platform implementations focus on tooling rather than on the index-and-analytics control taxonomy that actually has to ship. This course delivers the taxonomy, the templates, the reconciliation routine, and the implementation playbook for the role, at a price that sits inside a single team's discretionary spend.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.