Relation to international standards
Where the twelve dimensions ask the same question as a framework an organization already applies — and where they do not.
Important: This page states a correspondence, not conformity. SKN3X.COM is not certified, assessed or accredited against any of the frameworks named, and for ISO 31000 and ISO/IEC 31010 certification would not be possible at all — they are guidelines. The regulatory frameworks bind supervised institutions, not this information site. What is set out here is a translation aid: where the same question sits in a framework an organization already applies.
The frameworks drawn on
ISO 31000:2018
MethodISO- Subject
- Principles, framework and process of risk management: identification, analysis, evaluation, treatment, monitoring, communication.
- Use here
- As an ordering scheme for the sequence of the twelve dimensions: name first, examine second, evaluate third, and carry the uncertainty through all of it.
- Not established
- ISO 31000 is a guideline; certification against it does not exist. The standard text was not read here, and no claim is made that the approach used here corresponds to it.
ISO/IEC 31010:2019
MethodISO / IEC- Subject
- Risk assessment techniques and how they map to identification, analysis and evaluation.
- Use here
- As a reference point for why qualitative guiding questions, quantitative metrics, dependency analysis and explicit statements of uncertainty can sit side by side — not as evidence that any technique described there is applied here.
- Not established
- A collection of techniques does not say which technique is appropriate for a given market. None of the analyses used here is documented as an application of a named technique.
Basel Framework, SCO60
Prudential standardBCBS- Subject
- Classification of a bank's cryptoasset exposures into groups 1a, 1b, 2a and 2b and their capital treatment, including the cap on group 2 exposures.
- Use here
- As vocabulary for the bank-side guiding questions: which risk type a dimension touches at all, and where a position becomes expensive in supervisory terms.
- Not established
- Classifying a particular asset into a group is a supervisory determination in the individual case. This platform does not make it and serves no figure from which it would follow.
FSB High-level Recommendations (2023)
RecommendationFinancial Stability Board- Subject
- Recommendations to national authorities on the regulation, supervision and oversight of crypto-asset activities, together with the February 2023 financial stability analysis of DeFi.
- Use here
- As the reason leverage, liquidity and maturity mismatch, interconnectedness and operational fragility deserve dimensions of their own: the FSB names exactly these as transmission channels.
- Not established
- A recommendation to authorities is not law in force and binds no market participant. That the topics coincide implies nothing about the quality of the measures used here.
IOSCO DeFi Policy Recommendations (2023)
RecommendationIOSCO- Subject
- Understanding DeFi arrangements and structures, equivalent regulatory outcomes, identification and management of key risks, disclosure, enforcement of applicable laws, cross-border cooperation.
- Use here
- As the closest reference point for the governance and regulation dimensions: the question “is there an identifiable responsible party” is central there and equally central here.
- Not established
- These recommendations come from IOSCO, not from the Financial Stability Board — a confusion common in secondary sources. They address supervisory authorities rather than this platform, and evidence no classification of any individual protocol.
IOSCO Crypto and Digital Asset Markets Recommendations (2023)
RecommendationIOSCO- Subject
- Conflicts of interest, market manipulation, custody, cross-border risks, operational and technological risks, retail distribution.
- Use here
- As a cross-check on the market dimension: several of the questions it covers — custody, market manipulation, distribution — are expressly not collected here and stand as open points.
- Not established
- The recommendations largely concern centralized intermediaries and do not transfer straightforwardly to an arrangement with no identifiable entity.
Verordnung (EU) 2023/1114 (MiCA)
RegulationEuropäische Union- Subject
- The EU framework for crypto-assets, their issuers and certain related services.
- Use here
- As the endpoint of the chain activity → entity → jurisdiction → framework in dimension 11. The framework is expressly under review, which is noted on the evidence record itself.
- Not established
- The regulation states what applies — not how a particular DeFi arrangement is classified. That classification remains a case-by-case legal question and is not made here.
Verordnung (EU) 2022/2554 (DORA)
RegulationEuropäische Union- Subject
- ICT risk management, digital operational resilience and the oversight of ICT third-party providers for supervised EU financial entities.
- Use here
- As the reference frame for the technology, security and dependency dimensions: a dependency chain is precisely the third-party risk question in different words.
- Not established
- DORA binds supervised financial entities, not DeFi protocols and not this platform. Whether a particular dependency counts as an ICT third-party service within its meaning does not follow from this correspondence.
Correspondence per dimension
Per dimension, the named control area of each framework — and beneath it the part no listed framework covers.
01
Market
- ISO 31000:2018 — Establishing the context (scope, context, criteria)
- IOSCO Crypto and Digital Asset Markets Recommendations (2023) — Market integrity and market manipulation
Gap: Share by TVL is a recognized measure in none of these frameworks — here it is an approximation with no normative counterpart.
02
Business Model
- Basel Framework, SCO60 — Earnings and business model risk within exposure assessment
- FSB High-level Recommendations (2023) — Understanding the function actually performed
Gap: The split into base and reward yield is an observation on market data, not a supervisory category.
03
Technology
- Verordnung (EU) 2022/2554 (DORA) — ICT risk management framework
- IOSCO Crypto and Digital Asset Markets Recommendations (2023) — Operational and technological risks
Gap: Finality, bridge architecture and off-chain components are not collected by this platform; the correspondence names the question, not an answer.
04
Smart Contracts
- Verordnung (EU) 2022/2554 (DORA) — Change and configuration management, ICT security requirements
- IOSCO DeFi Policy Recommendations (2023) — Identifying who exercises control
Gap: Upgradeability, admin rights and timelock are not a data field here. No framework replaces reading the documentation and the block explorer.
05
Tokenomics
- Verordnung (EU) 2023/1114 (MiCA) — Classification and issuer obligations per crypto-asset type
- Basel Framework, SCO60 — Group classification 1a/1b/2a/2b
Gap: Vesting and unlock calendars are not available here; this platform does not classify any particular token.
06
Liquidity
- FSB High-level Recommendations (2023) — Liquidity and maturity mismatches as a transmission channel
- Basel Framework, SCO60 — Liquidity risk of an exposure
Gap: TVL measures deposited capital, not tradable depth — this platform serves no liquidity metric in the supervisory sense.
07
Economics
- ISO/IEC 31010:2019 — Scenario and sensitivity analysis
- FSB High-level Recommendations (2023) — Leverage and procyclicality
Gap: The figures shown here are snapshots. No scenario calculation in the sense of ISO/IEC 31010 is performed.
08
Governance
- IOSCO DeFi Policy Recommendations (2023) — Responsible persons and entities, conflicts of interest
- ISO 31000:2018 — Leadership and commitment (governance of risk management)
Gap: This platform collects no governance data. Voting distribution and emergency powers must be evidenced from the protocol's forums and on-chain votes.
09
Security
- Verordnung (EU) 2022/2554 (DORA) — Detection, response and recovery for ICT incidents
- IOSCO Crypto and Digital Asset Markets Recommendations (2023) — Operational resilience and custody
Gap: The risk model's track record factor is a maintained allowlist, not an audit status — no correspondence to a framework changes that.
10
Dependencies
- Verordnung (EU) 2022/2554 (DORA) — ICT third-party risk, provider concentration risk
- FSB High-level Recommendations (2023) — Interconnectedness
Gap: The dependency chain shown is as complete as the underlying mapping; an unlisted dependency is not the same as none.
11
Regulation
- Verordnung (EU) 2023/1114 (MiCA) — Scope, issuer and service provider obligations
- Verordnung (EU) 2022/2554 (DORA) — Scope for supervised financial entities
- IOSCO DeFi Policy Recommendations (2023) — Equivalent regulatory outcomes, enforcement of applicable laws
Gap: The correspondence names frameworks that could be in scope. Which of them actually applies to a particular arrangement is a legal question and is not answered here.
12
Institutional Impact
- ISO 31000:2018 — Risk evaluation and risk treatment
- Basel Framework, SCO60 — Capital treatment and the cap on group 2 exposures
Gap: Synthesizing the preceding eleven dimensions replaces no internal decision process and makes no decision.
Deliberately not mapped
These frameworks would connect well in substance but are not mapped here, because no mapping has been worked out for them. They are named so the list above is not read as complete — a framework with an invented correspondence would be worse than none.
- FATF (AML/CFT)
- NIST CSF / ISO/IEC 27001
- IFRS / applicable GAAP
- ISAE 3000