Key takeaways
Control library practices
Service
ORX Membership
Community
Risk and Resilience
Risk programme
Risk Management
Key takeaways - July 2025
Between 2021-2022, ORX developed an industry first Reference Control Library. Built using data from 50 members, this sets out the typical controls the industry uses to manage each of the risks in the ORX Reference Risk Taxonomy.
As part of this work, ORX extensively examined industry practices around this topic, culminating in the publication of our Controls Practices Paper. At the time, we found that despite strong appetite to standardise and automate the control environment, for many organisations, control library developments were in their infancy.
Against the background of an external environment characterised by increased volatility, third-party reliance, fast-paced technological developments and wide-reaching regulatory change, ORX felt that now is a good time to revisit the topic.
ORX members can log in to read the findings.
Gated content start
This report is available to all ORX members
If your firm is a member of ORX, log in or create an account to access the report.
Not a member or subscriber? Talk to us today to discuss how you could join the ORX community.
Gated content stop
Contacts:

Steve Bishop
Research and Information Director, ORX

Emilie Odin
Senior Research Manager, ORX

Stanca Oproiu
Assistant Research Manager, ORX