Logo
CIO Dashboard/Compliance & Risk

Compliance & Risk View

Application-level and business-unit-level compliance, Infosec, deviation, and risk treatment status

Last updated: 13 May 2026, 07:45 IST

Core Compliance & Risk Fields — Current Month

Infosec Related Points

18

Security issues from audits/reviews

12% vs last month

IT Compliance Points Raised

24

IT compliance issues raised

8% vs last month

Deviations Taken

7

Approved exceptions to standard protocol

3% vs last month

RART Prepared

11

Risk Assessment & Treatment docs prepared

22% vs last month

Open & Unresolved Items

Requires attention

Open Infosec Points

9

Security observations not yet closed

18% vs last month

Open IT Compliance Points

13

IT compliance items not yet closed

10% vs last month

Deviation Count

7

Number of approved deviations

3% vs last month
Critical priority

High-Risk Compliance Items

4

High-risk unresolved compliance items

33% vs last month

Calculated KPIs

Compliance Closure Rate

54.8%

Closed points / total compliance points

8% vs last month

RART Coverage

73.3%

RART prepared / total applicable risks

15% vs last month

Deviation Aging (Avg)

42 days

Avg days since deviation approval

7% vs last month

High-Risk Open Items

4

Count of high-risk unresolved items

33% vs last month

Open Infosec Points

9

Security observations not yet closed

18% vs last month

Open IT Compliance Points

13

IT compliance items not yet closed

10% vs last month

Deviation Count

7

Number of approved deviations

3% vs last month

Disaster Recovery (DR) Details — RTO & RPO

Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets per application, with DR tier, last test result, and recovery strategy

1 Failed1 Partial4 Passed

Tier 1 Apps

2

Avg RTO: 3 hrs

Tier 2 Apps

2

Avg RTO: 10 hrs

Tier 3 Apps

2

Avg RTO: 36 hrs

DR Tests Due (90d)

3

Review schedule

ApplicationDR TierRTO TargetRPO TargetRecovery StrategyLast DR TestTest StatusNext DR Test
Core Banking SystemTier 14 hrs1 hrActive-Active12 Apr 2026Passed12 Oct 2026
Payment GatewayTier 12 hrs30 minActive-Passive05 Mar 2026Passed05 Sep 2026
Customer PortalTier 28 hrs4 hrsWarm Standby20 Feb 2026Partial20 Aug 2026
Reporting & AnalyticsTier 324 hrs12 hrsCold Standby10 Jan 2026Passed10 Jul 2026
HR & Payroll SystemTier 212 hrs6 hrsWarm Standby15 Mar 2026Failed15 Jun 2026
Document ManagementTier 348 hrs24 hrsCold Standby28 Jan 2026Passed28 Jul 2026

Infosec Points Trend

Monthly Infosec security observations raised, closed, and remaining open — 8-month rolling view

IT Compliance Issue Trend

Monthly IT compliance issues raised, closed, and remaining open — 8-month rolling view

Open vs Closed Compliance Issues

Monthly stacked view of open and closed compliance items across Infosec and IT compliance

RART Status

Risk Assessment & Risk Treatment document preparation status across applicable risks

Coverage: 73.3%
RART Prepared
11
In Progress
4
Not Started
3
Not Applicable
2
RART Coverage73.3%

Compliance Aging

Open Infosec and IT compliance items grouped by aging bucket — days since issue was raised

2 items 90+ days5 items 31–90 days

Risk Treatment Heatmap

Risk items with likelihood, impact, treatment status, and RART preparation — colour-coded by severity

2 Open2 In Progress3 Treated
Risk ItemLikelihoodImpactTreatment StatusRART Done
Data BreachHighCriticalin-progress✓ Yes
Unauthorised AccessMediumHightreated✓ Yes
Compliance ViolationHighHighopen✗ No
Patch Non-complianceMediumMediumin-progress✓ Yes
Vendor RiskLowHightreated✓ Yes
Config DriftHighMediumopen✗ No
Audit FindingMediumLowtreated✓ Yes
Deviation OverrunLowMediumaccepted✓ Yes

Deviations Register

Approved exceptions to standard protocol — with aging, risk level, approver, and current status

IDDescriptionApproved ByApproved DateAging (Days)Risk LevelStatus
DEV-001Patch cycle extended from 30 to 60 days for legacy systemCISO01 Mar 202673dHighActive
DEV-002MFA exemption for batch processing service accountIT Head15 Mar 202659dHighActive
DEV-003Firewall rule exception for third-party integrationCISO22 Mar 202652dMediumActive
DEV-004Audit log retention reduced to 6 months for test envCompliance01 Apr 202642dLowActive
DEV-005Encryption standard downgrade for legacy API endpointCISO10 Apr 202633dHighUnder Review
DEV-006Password complexity relaxed for service desk accountsIT Head20 Apr 202623dMediumActive
DEV-007Vendor access without full background check (temp)Compliance01 May 202612dMediumActive

Calculated KPI Definitions

Formulas used to derive each compliance and risk metric

Open Infosec Points

Total Infosec raised − Total Infosec closed

Open IT Compliance Points

Total IT compliance raised − Total IT compliance closed

Deviation Count

Count of approved active deviations

Deviation Aging

Days since deviation approval date (per deviation)

RART Coverage

RART prepared ÷ Total applicable risks × 100

Compliance Closure Rate

Closed compliance points ÷ Total compliance points × 100

High-Risk Compliance Items

Count of high-risk unresolved compliance items