📋

Compliance Engineering

Section 8 of 9

Regulatory frameworks (APRA, FCA, OCC), audit logging architecture, data governance, penetration testing, disaster recovery, and change management for regulated systems

3 hoursadvanced
🎯

Key Takeaways

  • Audit logs must be tamper-evident, immutable, and retained for 5–7 years — S3 Object Lock with Compliance mode is the AWS solution
  • Change management in regulated fintech requires 4-eyes approval, documented risk assessments, and rollback plans before production deployment
  • APRA CPS 234 mandates that third-party (cloud) incidents must be reportable to the regulator within 72 hours
  • DR/BCP tests are not optional — regulators expect documented RTO/RPO measurements from actual failover exercises
  • Data lineage (knowing where every piece of customer data lives and flows) is a prerequisite for GDPR Article 17 deletion requests

📝Personal Notes

Ready to test your knowledge?

Take the quiz to reinforce what you've learned

Take Quiz →