Skip to main content

Framework Changes - Suppliers - July 2026

Written by ish

On 30th July 2026, we will be making some changes to the standardised control framework within Risk Ledger.

We do this periodically so that the framework stays relevant, useful and practical for all users of the Risk Ledger platform.

All changes will be handled automatically within the platform and marked clearly with a full audit history kept within your activity feed.

This page gives you a summary of the changes that are coming.


What’s changing?

This is a larger update than our usual releases. Alongside changes based on client feedback, two things have driven most of the additional volume:

  • A review against external frameworks. Most of the new Domain E and F controls came from mapping our framework against the NCSC Cloud Security Principles, with further updates informed by reviews against CAF, CE, and NIST CSF.

  • A restructure of Domain K (Artificial Intelligence). The previous version of K8 blurred the line between "AI embedded in the product/service" and "client data exposed to AI elsewhere," making related controls hard to answer consistently. This update also closes a gap where suppliers with no automated decision-making had no way to opt out of related questions.

Below is a full breakdown by domain.


Domain A — Governance & Risk Management

  • A21 updated: now focuses on the methodology used to prioritise and track risk treatment through to closure, rather than simply confirming that annual risk assessments take place.

  • A22 (new): whether information security and cyber risk is formally reported to, and tracked at, board level.

Domain D — Data & Patch Management

  • D28 (new): suppliers must list every country or jurisdiction where client data is stored, processed, or transferred through — including via sub-processors.

  • D29 updated: patch management now requires suppliers to state patch timeframes by severity level, rather than just confirming a process exists.

  • D38 (new): inbound email security controls to detect, filter, or quarantine phishing, spoofing, and malicious attachments.

Domain E — Software Development

Eight new controls covering security practices for the software, products, or services a supplier develops — closing gaps that previously may only have been assessed against a supplier's internal estate.

  • E16: vulnerability disclosure process for third parties

  • E17: access control and authorisation, including via APIs and management interfaces

    • E18: service credential rotation and revocation (child control)

  • E19: role-based access control and least privilege

  • E20: password policy for product/service users

  • E21: MFA for product/service users

  • E22: SSO or federated identity

  • E23: tiered or privileged access management for administrative access

  • E10 narrowed: now covers only apps the organisation builds itself — patching of procured apps is no longer in scope here, as it's already covered by D28

Domain F — Network & Cloud Security

  • F7 updated: network/cloud segmentation now explicitly includes segregation between different clients, not just internal business units or subsidiaries.

  • F12 (new): encryption of data in transit between internal service components.

  • F13 (new): encryption of client data at rest by default.

  • F37 (new): securing management interfaces for boundary firewalls and other edge devices.

Domain H — Business Resilience

  • H6 (new): testing the Incident Response Plan through realistic exercises informed by past incidents and threat intelligence.

  • H21 (new child control): whether the most recent BC/DR test met its defined RTO/RPO.

  • H24 (new): maintaining an understanding of the data critical to essential functions, including its location, flows, and impact if lost.

  • H22 and H23 moved: cyber insurance questions have moved into the Business Resilience domain, out of the Financial Risk Add-On.

Domain K — Artificial Intelligence

Restructured to create a clearer split between AI embedded in the product/service a supplier provides, and client data otherwise exposed to AI elsewhere (e.g. internal tools, sub-processors, other products).

  • K5 (new parent control): suppliers now first confirm whether they use automated decision-making at all, before being asked related questions — closing a gap where suppliers with none had no way to answer "no."

  • K8 reworded: now covers only AI embedded within the product/service; suppliers will need to re-confirm the controls sitting underneath it.

  • K14 (new child control): segregating client data — and any model trained on it — from other clients and from AI model providers' own use.

  • K17 (new parent control): covers client data reaching AI outside the direct service.

    • K18–K20 (new child controls): erasure, sensitive data handling, and training use.

  • K22 (new): safeguards against "shadow AI" — client data entered into unauthorised personal AI tools.

  • K4 deprecated: the old training question is now redundant and has been removed.

  • Renumbering: as a result of these changes, most Domain K controls have been renumbered.

Scoping & Certifications

  • The "Do you hold any security certifications?" scoping question has been removed. Suppliers without certifications are now scored not-compliant rather than not-scored.

UK Government Data & Personnel Security (Add-On)

  • Two new controls added, covering the UK Software Code of Practice and Defence Cyber Certification.


As a supplier, what do you need to do?

If you have already submitted your assessment and your profile is up to date, you do not have to make any changes until your next 6 monthly re-assessment is due or one of your clients asks you to update or confirm a modified control question or answer the new control question.

You will need to update or confirm the modified control questions and answer the new control question before you can submit your next re-assessment.

If you have not yet submitted your assessment, you will need to update or confirm the modified control questions and answer the new control question before you submit.


Did this answer your question?