CRA Risk Management Framework (Feb?2024)

CRAs must design and adopt a comprehensive risk framework within 120 days?covering internal controls, due diligence, vendor oversight, cyber resilience, and subscriber protection. It must be board-approved and backed by regular risk reviews to uphold CRA operational integrity.