📋
Compliance Engineering
Section 8 of 9
Regulatory frameworks (APRA, FCA, OCC), audit logging architecture, data governance, penetration testing, disaster recovery, and change management for regulated systems
3 hours•advanced
🎯
Key Takeaways
- •Audit logs must be tamper-evident, immutable, and retained for 5–7 years — S3 Object Lock with Compliance mode is the AWS solution
- •Change management in regulated fintech requires 4-eyes approval, documented risk assessments, and rollback plans before production deployment
- •APRA CPS 234 mandates that third-party (cloud) incidents must be reportable to the regulator within 72 hours
- •DR/BCP tests are not optional — regulators expect documented RTO/RPO measurements from actual failover exercises
- •Data lineage (knowing where every piece of customer data lives and flows) is a prerequisite for GDPR Article 17 deletion requests
📝Personal Notes
Ready to test your knowledge?
Take the quiz to reinforce what you've learned