Harborview Financial Group — a fictional mid-size financial institution
Harborview Financial Group is a fictional mid-size financial institution invented to demonstrate the control matrix output format. The synthetic profile: retail and commercial banking, domestic wires and correspondent payments, no cash-intensive branch network, and a small digital-asset custody pilot launched in 2025. The matrix below inventories 27 controls across the six-domain reference framework — customer due diligence, transaction monitoring, sanctions screening, regulatory reporting, governance, and technology — in examination-readiness context.
In this illustrative scenario the program is structurally complete: every reference control exists in some form, and 13 of 27 rate EFFECTIVE on recent operating evidence. The weakness is concentrated, not pervasive. The transaction-monitoring domain carries both INEFFECTIVE ratings — rule tuning has not run since a 2024 system migration (TM-03) and no typology-to-rule coverage assessment exists (TM-05) — and the alert-disposition backlog (TM-02) compounds the exposure. Four controls rate NOT ASSESSED because no testing or operating evidence was available; under the matrix rules that is the honest rating, never an inferred one.
The gap register lists 8 gaps: 1 CRITICAL, 3 HIGH, 3 MEDIUM, 1 LOW. The CRITICAL gap (untuned monitoring thresholds on a live transaction population) is the remediation priority; the matrix is the inventory, the gap register is the action list.
27 controls by rating. NOT ASSESSED means no evidence — never a guess.
Stacked count of controls per domain. The transaction-monitoring bar carries both INEFFECTIVE ratings.
Type: PREV preventive · DET detective. Owners are roles, never named individuals. Testing method is one of inquiry / observation / inspection / re-performance.
| ID | Control objective | Mechanism (who / what / how often / evidence) | Type | Frequency | Owner (role) | Testing | Effectiveness |
|---|
| Domain | Controls | Effective | Partially | Ineffective | Not assessed | Coverage read |
|---|
Coverage is structural completeness; effectiveness is operating reality. In this synthetic scenario every reference control exists, so the program would pass a checklist review — the table shows why that is not the same as passing an examination. Transaction monitoring has full structural coverage and the worst operating record in the matrix.
The digital-asset custody pilot expands TM and SAN expectations (wallet screening, on-chain monitoring). Those expansions are inventoried under TM-04 and SAN-04 rather than as new control IDs, and both carry gaps in the register.
Every gap ties to a control ID, carries exactly one severity, and names a remediation owner by role and a target horizon. The CRITICAL tag is reserved for absent-or-ineffective controls with material exposed risk — here, untuned monitoring on a live transaction population. "No gaps identified" would also be a valid, stated result; this scenario simply is not that.
23 of 27 ratings rest on (synthetic) testing or operating evidence; 4 rest on none and are flagged NOT ASSESSED. The inventory itself is complete against the reference framework, so structural confidence is high — effectiveness confidence is what caps the overall rating at MODERATE.