Platform · Compliance risk quantification
Every gap, sized in dollars, as a range.
Compliance risk quantification gives each gap an expected-cost range in dollars, built from the penalties in real, public enforcement actions. You fix the gaps that carry the most exposure first, and when the record is too thin to size a kind of gap, you're told so instead of shown a number.
The problem it removes
High, medium and low do not tell you what to fix first
- A heat map rates twenty findings "high" and gives you no way to choose between them.
- Your board asks what a gap is worth, and the honest answer today is a guess.
- A single dollar figure looks precise and hides how uncertain it's.
What you see
A range per gap, and the actions behind it
Each gap shows a low, middle and high expected cost, how many enforcement actions of that kind sit behind the range, and the order it takes in your remediation plan. A gap without enough comparable actions shows "not enough data" rather than a figure.
| Gap | Low | Middle | High | Actions |
|---|---|---|---|---|
| SAR filed after the 30-day deadline | $180K | $640K | $2.1M | 41 |
| Beneficial ownership not collected at opening | $95K | $310K | $1.2M | 27 |
| Monitoring rule thresholds never tuned | $60K | $220K | $870K | 19 |
| Training records incomplete for new hires | Not enough data too few comparable actions to size | 3 | ||
Illustrative example with invented figures and counts. Real ranges are built from the public enforcement actions for each kind of gap.
How it works
Match, simulate, rank, review
- Match. Rules match each gap to the kind of failure behind it, and to the public enforcement actions for that kind of failure, drawn from 668 curated actions.
- Simulate. A simulation over the penalties in those actions produces a range, not a single number. If there are too few comparable actions, no number is produced and the gap says so.
- Rank. Your remediation plan is ordered by the range, so the gaps carrying the most exposure come first. AI drafts the explanation of each range; it never changes the figure.
- Review and sign. A practitioner reviews the matches and the order, and signs the result.
Guardrails
What it will never do
- It doesn't tell you whether or when a regulator will act, or what a fine would be. It sizes expected cost from past actions.
- It doesn't guarantee any outcome.
- Its ranges are only as deep as the public enforcement record for that kind of gap. Where the record is thin, it gives no number.
Where it shows up
The work this part does for you
Plain English
What this is, and how anyone does it
Reference articles from our library, cited to the published rules and standards. No sales copy.
- ReferenceCompliance Risk Quantification: Expressing Compliance Risk in DollarsWhat quantifying compliance risk means: expected-loss framing, the published factors that size penalties, why estimates are ranges, and the limits of the data.
- Field GuideHow to Build a BSA/AML Risk Assessment MatrixA step-by-step build: set the rating scale, rate inherent risk, score controls, derive residual risk, and aggregate to an enterprise rating. With a worked example.
Connected parts
What it works with
Talk to a practitioner
Book a 15-minute chat with our founder.
A real conversation with a senior compliance leader, to see if there's a fit. Not a sales call, not a demo, no pressure.