Espacio Fintonic
Torre de Control CTO Fintech
Unidades de Servicio en Riesgo
8
10 unidades de servicio monitorizadas
Repositorios que Impulsan Exposición
20
65 repos en el patrimonio
Acciones Vencidas
12
Hallazgos y exenciones pasada la fecha comprometida
Sistemas IA sin Gobernanza
2
6 sistemas IA rastreados
Matriz de Exposición por Entidad
Clasificado por exposición primero. Usa esto como superficie de triaje de portfolio, no la lista de entidades.
Prioridades de esta semana
Decisiones que necesitan al CTO, no otra ronda de triaje de equipo.
Review DORA ICT risk management framework for core banking services
Conduct a full DORA gap analysis across all Core service units and remediate critical ICT risk management deficiencies within 30 days.
Complete PSD2 Strong Customer Authentication compliance audit
Execute a comprehensive SCA compliance audit covering all payment initiation and account information flows.
Submit EU AI Act conformity assessment for FinScore
Prepare and submit the mandatory conformity assessment for the FinScore credit scoring system classified as high-risk under the EU AI Act.
Conduct GDPR data minimization review for banking aggregation
Audit all PSD2 account information data flows to ensure data minimization principles are enforced and excess data retention is eliminated.
Establish NIS2 incident reporting procedures
Implement NIS2-compliant incident reporting workflows with 24-hour early warning and 72-hour full notification capabilities across all service units.
Assess partner API concentration risk for lending providers
Evaluate third-party concentration risk across lending partner integrations and establish fallback routing for critical credit data providers.
Concentración de Riesgo por Repositorio
Clasificado por puntuación de riesgo del repo para que las peores rutas de release aparezcan primero.
| Repo | Entidad | Criticidad | Pipeline | Hallazgos | Uso de IA | Remediación | Último escaneo |
|---|---|---|---|---|---|---|---|
fn-core-2/finscore-model-1 AI governance | FinScore Engine | Tier 1 | Failing | 8/2 critical | Customer-facing | Blocked | 2 days ago |
fn-core-1/credit-engine-1 Credit risk controls | Lending Platform | Tier 1 | Failing | 7/2 critical | Customer-facing | Blocked | 2 days ago |
fn-core-1/psd2-gateway-2 PSD2 compliance | Lending Platform | Tier 1 | Failing | 8/1 critical | None | Blocked | 2 days ago |
fn-core-2/loan-origination-2 Lending controls | FinScore Engine | Tier 1 | Failing | 7/1 critical | Evaluation only | Blocked | 3 days ago |
fn-core-3/fraud-rules-engine-1 Fraud prevention | Banking Aggregation | Tier 1 | Degraded | 5/1 critical | Customer-facing | Needs owner | 1 day ago |
Postura de Gobernanza IA
Los sistemas en producción sin aprobación clara deben aparecer antes de que la experimentación con modelos parezca interesante.
| Sistema | Entidad | Proveedor | Riesgo | Aprobación | Procedencia | Repo propietario | Revisión pendiente |
|---|---|---|---|---|---|---|---|
Loan Eligibility Engine Transaction history + credit bureau | Lending Platform | OpenAI | High | Missing | 96% | fn-core-1/credit-engine-1 | 3 days ago |
Income Verification Assistant Banking API feeds + internal data lake | Lending Platform | OpenAI | Medium | Missing | 91% | fn-core-1/psd2-gateway-2 | 2 days ago |
FinScore Credit Scorer Banking API feeds + internal data lake | FinScore Engine | Internal ML | High | Conditional | 95% | fn-core-2/finscore-model-1 | 2 days ago |
Insurance Risk Assessor Insurance partner feeds + claims data | Insurance Marketplace | AWS SageMaker | Medium | Conditional | 93% | fn-con-1/mobile-bff-1 | just now |
Fraud Pattern Detector Banking API feeds + internal data lake | Fraud Detection | AWS SageMaker | Medium | Approved | 87% | fn-plat-2/compliance-collector-1 | in 6 days |
Mapa de presión de evidencia
Peores clústeres de evidencia obsoleta por unidad de servicio.
Data Platform
fintonic.stale_repos_detail
Partner API
fintonic.stale_repos_detail
Mobile App
fintonic.stale_repos_detail
Payment Services
fintonic.stale_repos_detail