Platform · Enterprise risk management (ERM)
Risk measured against the outside world, and priced in dollars.
Most risk tools start from your own ratings. This one starts from how often institutions like yours actually drew enforcement actions and what those actions cost, then sets that against the appetite your board approved.
The problem it removes
Risk ratings nobody can check
- Likelihood and impact are usually scored from one to five by the people who own the risk.
- A board can't compare a "four" in fraud with a "four" in sanctions.
- The annual risk assessment is out of date the week a regulator changes its priorities.
What you see
Appetite, indicators and exposure on one page
Each risk area shows the limit your board set, the indicators you track against it, and the dollar range of what a gap there has cost institutions like yours.
| Risk area | Appetite | Indicator | Status | Dollar exposure |
|---|---|---|---|---|
| Sanctions | Low | Alerts past 24h: 3 | Near limit | $0.4M to $2.1M |
| Transaction monitoring | Low | Alert backlog: 41 days | Outside | $1.2M to $6.8M |
| Consumer complaints | Moderate | Late responses: 1.2% | Inside | $0.1M to $0.9M |
| Third-party oversight | Moderate | Reviews overdue: 0 | Inside | Not enough data |
Illustrative example with invented figures. Where the enforcement data is too thin for a range, the platform says so.
How it works
Appetite, indicators, exposure, weather
- Appetite. A practitioner drafts your risk appetite statement with you, with limits per risk area, for your board to approve.
- Indicators. You enter your key risk indicator figures, and written rules compare each one with its limit.
- Exposure. Each gap gets a dollar range from penalties in real enforcement actions, simulated across thousands of outcomes.
- Weather. What regulators are publishing and acting on now, read from their own sources and matched to your profile.
- Review. A practitioner reviews the picture and signs what goes to your board.
Guardrails
What it will never do
- A dollar range ranks your risks. It doesn't forecast what a regulator will do.
Where it shows up
The work this part does for you
Plain English
What this is, and how anyone does it
Reference articles from our library, cited to the published rules and standards. No sales copy.
- ReferenceCompliance Risk Quantification: Expressing Compliance Risk in DollarsWhat quantifying compliance risk means: expected-loss framing, the published factors that size penalties, why estimates are ranges, and the limits of the data.
- Field GuideHow to Build a BSA/AML Risk Assessment MatrixA step-by-step build: set the rating scale, rate inherent risk, score controls, derive residual risk, and aggregate to an enterprise rating. With a worked example.
- ReferenceBoard Compliance Reporting: What Boards Receive and WhyWhat compliance reporting to the board is, the rules and guidance behind it, what a report contains, management information and key risk indicators, and examiner packs.
Connected parts
What it works with
Talk to a practitioner
Book a 15-minute chat with our founder.
A real conversation with a senior compliance leader, to see if there's a fit. Not a sales call, not a demo, no pressure.