Q3 2026
As of 9 Oct 2026
As of 9 Oct 2026
Evidence approved
77%
▲ +27 pts vs Q2 2026
The evidence approval rate rose from 50% in Q2 2026 to 77% in Q3 2026.
Investigate →Evidence not yet approved by control
evidence items pending or rejected · Q3 2026
ACC-04 · Quarterly user access review of in-scope applications5(2)ACC-03 · Privileged access is just-in-time and reviewed4(2)CHG-02 · Emergency changes are retrospectively approved3(2)BCP-01 · Backup restore and DR are tested2(0)VEN-03 · Supplier security incidents are assessed for impact and tracked2(0)LOG-01 · Security events are centrally logged and monitored 24x71(2)CHG-03 · Developers have no standing production access; deployments via pipeline only1(2)VEN-01 · Critical third parties are risk-assessed before onboarding and annually1(2)KYC-01 · Customer accounts are activated only with complete KYC1(0)VEN-02 · Provider contracts include data protection and RBI audit clauses1(0)GOV-01 · IT Strategy Committee oversees IT and cyber risk1(0)VUL-01 · Vulnerabilities are scanned and remediated within SLA0(2)PAY-01 · Payment APIs secured with mTLS, signing and customer 2FA0(2)ACC-02 · User access provisioning is approved before grant0(1)SOD-01 · Segregation of incompatible duties in SAP0(1)P2P-01 · Purchase orders follow approval thresholds; no self-approval0(1)CHG-01 · Production code changes are peer-reviewed and approved0(1)OPS-01 · Backups are performed daily and monitored0(1)
- ACC-04 · Quarterly user access review of in-scope applications 5 23%
- ACC-03 · Privileged access is just-in-time and reviewed 4 18%
- CHG-02 · Emergency changes are retrospectively approved 3 14%
- BCP-01 · Backup restore and DR are tested 2 9%
- VEN-03 · Supplier security incidents are assessed for impact and tracked 2 9%
- Other (13) 6 27%
Domains between periods
Fastest rise: Third-Party Risk (+2)
Each line is a control domain, from Q2 2026 to Q3 2026 (recorded values only). Red = rising, green = falling. Click a domain for its records.