On 29th January 2026, we will be making some changes to the standardised control framework within Risk Ledger.
We do this periodically so that the framework stays relevant, useful and practical for all users of the Risk Ledger platform.
All changes will be handled automatically within the platform and marked clearly with a full audit history kept within your activity feed.
This page gives you a summary of the changes that are coming.
What’s changing?
Added three controls from the Data Protection domain to the Small Framework.
Added controls (E13 and E14) to assess a supplier’s ability to demonstrate the provenance of any software they develop.
Added controls (K3 and K4) to assess whether suppliers have guardrails in place to mitigate potential adverse effects stemming from the use of any automated-decision making technologies.
Added a control (F33) to assess whether a supplier receives threat intelligence from the National Cyber Security Centre (NCSC)’s Early Warning programme.
Updated PCI DSS controls to clarify the documentation needed as evidence. Updated the scoping question to better reflect the applicability of PCI DSS for suppliers.
Updated control E5 to capture a supplier’s approach to incorporating threat modelling throughout the software development lifecycle.
Updated several questions and descriptions to align with industry best practices on writing styles.
Updated several questions and descriptions to improve grammar and clarity.
Deprecated control D15 regarding Windows Autorun.
As a supplier, what do you need to do?
If you have already submitted your assessment and your profile is up to date, you do not have to make any changes until your next 6 monthly re-assessment is due or one of your clients asks you to update or confirm a modified control question or answer the new control question.
You will need to update or confirm the modified control questions and answer the new control question before you can submit your next re-assessment.
If you have not yet submitted your assessment, you will need to update or confirm the modified control questions and answer the new control question before you submit.