Download the matrix
The same rows as CSV, to load into your own test plan.
Eligibility
Eligibility explains these controls.| ID | Risk | Control | Type | Owner | Evidence | How to test |
|---|---|---|---|---|---|---|
| CTL-1 | An investor is admitted on unverified KYC, or beyond the asset’s rules | Each KYC claim (residency, investor type, accreditation) is recorded under four eyes against the hash of its evidence. The venue admits an investor only when its verified claims meet the asset’s policy and holder cap. A re-issue revokes the old credential in the same transaction | Preventive, in a system | Operations (operator) | Claim records with maker, approver and evidence hash; admissions and credentials, with their issue, re-issue, expiry and revocation; refusals with their codes | For a sample of admissions, confirm each claim had a distinct maker and approver and a hash that matches the KYC file, and that the claims met the policy in effect within the cap |
| CTL-2 | An investor holds the register keeper’s credential beyond the register keeper’s own terms | Where the register keeper requires its own credential, the venue admits investors only under its admission consent, checked against the terms on the ledger in the same transaction. Each claim must come from a live credential of a KYC provider the terms trust. The credential is the register keeper’s: the venue cannot issue it outside the terms, end it or revoke it. Looser terms need the register keeper’s acceptance and its delay | Preventive, on the ledger | Operations (operator) | The admission consent, its terms and their changes, with the register keeper’s acceptances; each admission under it, with the KYC credentials it read and the credential it replaced; refusals with their codes | For a sample of admissions under the consent, confirm each claim matches a credential from a KYC provider the terms in effect trusted, live at the admission, and that the terms admitted the investor’s residency and investor type; for each loosening of the terms, confirm the register keeper’s acceptance and the delay |
Limits and settlement safety
Limits and settlement safety explains these controls.| ID | Risk | Control | Type | Owner | Evidence | How to test |
|---|---|---|---|---|---|---|
| CTL-3 | The venue takes an order the asset’s rules forbid | The engine checks every act of the venue against the asset’s policy (limits, lock-up, dealing windows, eligibility, wind-down) and refuses with the rule’s code | Preventive, in a system | Structuring (operator) | Policy versions; refusals with their codes and versions | Review orders near the limits, and confirm each refusal names its rule and the version in effect |
| CTL-4 | An asset grows past its size, or its flows exceed their limits, even where the engine errs | NodeAsset’s contracts charge every mint and burn of a fund paid on the ledger, and of a backed instrument, against the register keeper’s supply terms, and refuse any beyond them | Preventive, on the ledger | Structuring (operator) | Each supply ledger: its terms, counts and windows; refused settlements | Reconcile the units in issue against the cap at period end, and review the refusals |
| CTL-5 | Units are issued without payment, or an order settles in part | Paid on the ledger, units and payment settle in one transaction, all or nothing. Paid off the ledger, an order is booked only against the register keeper’s matching mint, made after it, once. An order that cannot settle is released | Preventive, on the ledger | Operations (operator) | Each settlement’s transaction, with both registries’ legs; each order paid off the ledger, with the mint it was booked against; releases | For a sample of orders, confirm one transaction carried every leg, or a matching mint made after the order; for orders that did not settle, confirm nothing moved and each was released |
| CTL-6 | A backed instrument loses its cover, or its reserve’s assets are released | Every act that changes a reserve checks on the ledger that its assets, after haircuts, cover what is outstanding times the minimum cover. Its holdings are locked to the venue, the issuer and the reserve’s holder together, so none can release them alone | Preventive, on the ledger | Structuring (operator) | Each reserve’s holdings, outstanding and terms; its reports on the ledger; refused acts | Recompute the cover from a sample of reserve reports, and confirm each holding is locked to all three |
Pricing
Pricing explains these controls.| ID | Risk | Control | Type | Owner | Evidence | How to test |
|---|---|---|---|---|---|---|
| CTL-7 | An order settles at a price the venue or the issuer set, or at one known when the order was placed | An order settles only at the price the asset’s price source signed after the dealing point closed, checked by the engine and on the ledger. The venue, the register keeper and the treasury cannot be the price source. A backed instrument’s price is computed on the ledger from its assets’ fresh prices | Preventive, on the ledger | Valuation (operator) | Each order’s price, with its signer and dealing point; each reserve’s prices and reports; the price source each fund’s consent names; refusals | For a sample of orders, match the settlement price to the price the asset’s price source signed for it, after the order was recorded, and confirm each fund’s consent names a price source apart from the venue, the fund’s register keeper and its treasury |
| CTL-8 | Orders keep settling on a NAV that has lapsed, been withdrawn, or disagrees with the official NAV | The engine holds the asset when the kill switch is pulled, the NAV expires, or the official NAV departs from the signed price beyond tolerance. A release needs risk’s request and two approvers | Detective, in a system | Risk (risk) | NAV statements as received; reconciliation findings; holds and their releases | For each switch pulled, NAV expired and disagreement in the period, confirm the hold from that time and how it was released |
| CTL-9 | Amounts are miscalculated, or rounded against the fund | Every amount is computed one way: payments round up and payouts down, so rounding never costs the fund. Each fund’s administrator agrees the rules before go-live | Preventive, on the ledger | Valuation (operator) | Each settlement’s and distribution’s figures; the administrator’s agreement of the rules | Recompute payments, payouts and distributions for a sample |
Interventions
Interventions explains these controls.| ID | Risk | Control | Type | Owner | Evidence | How to test |
|---|---|---|---|---|---|---|
| CTL-10 | A sanctioned or restricted investor keeps acting | One person freezes an investor, or limits it to leaving, and the engine refuses its acts at once; a screening hit freezes it too. Lifting needs two approvers, and each freeze goes to the register keeper’s block list | Preventive, in a system | Compliance (compliance) or Risk (risk) | Restrictions with their reason, cited order and time; the approvals that lifted them; screening hits | For each screening hit, confirm the freeze followed it and no act of the investor ran after; for a sample of lifts, confirm two approvers distinct from the maker |
| CTL-11 | A problem asset keeps issuing, redeeming or paying | A hold, from reconciliation or risk, stops an asset’s issues, redemptions and distributions, and a reserve short of its cover holds its backed instrument’s mints. A release takes two approvers | Corrective, in a system | Risk (risk) | Holds and the pause, with their finding or reason; releases; control events | For a sample of holds, confirm no stopped act ran before the release and two approvers released each |
| CTL-12 | Units are moved without authority | A forced transfer or a recovery moves only the units of an investor that consented at admission, under the register keeper’s agreement. Each needs two approvers besides its maker and cites its grounds by document hash | Preventive, in a system | Compliance (compliance) | The register keeper’s agreement; each holder’s consent; each move’s operation, approvals and transaction, with its grounds’ reference and hash | For each move in the period, confirm the agreement in force, the holder’s consent and two approvers, and match the cited document to its hash |
Duties and governance
Duties and governance explains these controls.| ID | Risk | Control | Type | Owner | Evidence | How to test |
|---|---|---|---|---|---|---|
| CTL-13 | One person completes a sensitive act alone | Every sensitive change needs an approver other than its maker, the riskiest two, and runs exactly as approved. The auditor never approves | Preventive, in a system | Approvers (approver) | Operations and approvals, with maker and approvers | For a sample of four-eyes operations, confirm distinct people, and two approvers where the action needs them |
| CTL-14 | A rule is loosened without notice | Each asset’s policy is versioned. A tightening applies at once with one approver; a loosening needs two and waits out a delay, 24 hours by default. On the ledger, supply terms and a reserve’s terms change only once the register keeper accepts | Preventive, in a system | Structuring (operator) or Risk (risk) | Policy versions, with their approvers and effective times; the supply ledger’s and each reserve’s proposals and acceptances | For every loosening in the period, confirm two approvers and the delay, and, for supply and reserve terms, the register keeper’s acceptance |
| CTL-15 | Someone without a role at the venue reads or changes the book | The engine listens on loopback only and checks the token from the venue’s identity provider on every request. Each route admits only its roles, and an investor reaches only its own records | Preventive, in a system | The venue’s IT | The engine’s configuration and access table; refusals | Call a sample of routes with no token, with the wrong role and with another holder’s id, and confirm each refusal |
Records and privacy
Records and privacy explains these controls.| ID | Risk | Control | Type | Owner | Evidence | How to test |
|---|---|---|---|---|---|---|
| CTL-16 | The register drifts from the venue’s plans, or from the asset’s policy | Reconciliation, scheduled and on demand, matches every mint and burn to its plan, holdings to outside statements, each reserve to its locked holdings and supply, and holders, supply and transfers to the asset’s policy. A blocking finding holds the asset until two approvers release it; others are reported | Detective, in a system | Risk (risk) | Reconciliation runs, findings and releases | Confirm runs on schedule and each blocking finding released by two approvers with a reason, and that a sample of transfers no act of the venue explains was found and graded |
| CTL-17 | A distribution pays the wrong holders, or a holder loses what it is owed | Each distribution is planned from the holders of record under four eyes and checked against the administrator’s list. A line a freeze withholds is paid once the freeze lifts | Preventive, in a system | Operations (operator) | Frozen plans; the administrator’s lists; reconciliation findings; the lines paid later | Trace a sample of lines to the holders of record and the administrator’s list, and each line left out to its later payment |
| CTL-18 | An act cannot be traced, its record is altered, or a report cannot be reproduced | Every write is an operation recording who asked, under which role, who approved and its ledger transaction, in a hash-chained audit log. Every read names its point on the ledger and can be repeated there | Detective, in a system | The venue’s IT (monitor) | Operations; approvals; the audit log and its verification; events; exports | Trace a sample of ledger transactions to their operations, verify the audit log against a head recorded earlier, and reproduce a sample of reports at the points they name |
| CTL-19 | An investor’s data reaches another investor, or personal data reaches the ledger | Each order’s contracts name only its parties, and an investor reads only its own records. The ledger holds no personal data, only parties and claim codes; the KYC evidence stays with whoever ran the KYC | Preventive, in a system | The venue’s IT | Each party’s view of the ledger; the contracts the venue’s party created; the venue’s holder records | Read a sample investor’s view and confirm it shows nothing of other investors, and inspect a sample of the venue’s contracts for personal data |
Shared responsibility
NodeAsset is one part of the arrangement. Each party below runs its own part, with its own controls and its own evidence, which this matrix does not test.| Party | Responsible for | What NodeAsset relies on it for, or offers it |
|---|---|---|
| Investor The investor and its custodian | The investor’s own acts and keys: its custodian holds the keys and runs KYC and screening on its client, and every payment, acceptance and transfer of the investor’s is signed in its own wallet. | The venue moves an investor’s units or cash only through the investor’s own allocation, or under the consent it gave at admission, and offers it its own orders, holdings and statements through the venue’s API, never another investor’s. |
| Price source The price source | The price of every order: on its own Canton node it signs each NAV point and each order’s price, corrects a point by publishing a new one, and sends its official NAV with an expiry and a kill switch. | Every order settles only at the price the asset’s own price source signed for it, a party apart from the venue and from a fund’s own register keeper and treasury, and the engine holds the asset when that NAV expires, its kill switch is pulled, or its official NAV disagrees with the ledger’s. |
| Issuer The register keeper (the issuer or its transfer agent) | Every change to the register: it mints and burns, or signs once the consent under whose checks each mint and burn runs, chooses the credential its registry requires (its own, which the ledger issues under its standing admission consent and only it revokes, or the venue’s), keeps its block list, and accepts the terms and agreements the venue proposes. | Every register change rests on its own act or consent, and the venue offers it proposals to accept, the venue’s freezes to follow on its block list, and each distribution’s lines to pay. |
| The DA Registry | Who holds what: units exist only by the registrar’s mint or burn, and every mint, burn and transfer is checked against the credential the instrument requires, the block list and any lock, wherever it starts. | Its checks hold even for acts that bypass the venue, and NodeAsset adds what the registry does not know: which order each mint was for, the asset’s policy, and reconciliation. |
| The Canton network | Each party’s own Canton node runs only the contract code its owner vetted, authorizes its party’s part of each transaction and receives only the parts it is party to, and the synchronizer commits each transaction whole or not at all. | Units and payment on two registries settle in one transaction, final once it commits, and each investor’s orders and holdings stay hidden from other investors. |
| Venue The venue’s own processes | Running NodeAsset as an institution: governance and risk assessment, screening, its identity provider, network separation and host security, backups and recovery, incident response, custody of its node’s keys, records retention and the oversight of its providers. | NodeAsset offers each of them evidence: control events and signed webhooks, the hash-chained audit log, health and system status, and a retention setting per kind of record. |
| The vendor | Building and releasing NodeAsset: an independent review before each package release, a recorded id for every contract package, and a checksum of every release asset. | The venue verifies each release against its checksums and package ids before it upgrades, and the vendor runs nothing in the deployment and holds no key. |
| Legal (each party’s adviser) | Whether the arrangement holds in law where the asset is issued and distributed: when a settlement is final, which licences each party’s acts need, what an investor is owed, and which records and data location the rules require. | NodeAsset makes no claim about any jurisdiction’s rules, and its controls and their evidence are what each party’s adviser and auditor map to them. |

