PILLAR 3 OF 3
Compliance.
Demonstrable adherence to external rules — the function that converts laws into controls, controls into evidence, and evidence into the license to keep operating. The densest pillar in U.S. financial services.
Workflow categories
SOC 2 (Trust Services)5 workflows
- Control Evidence Collection & Checklist
- Vendor Risk Assessment (SOC 2 scope)
- Security Policy Library
- Penetration Test Gap Report
- Continuous Control Testing Schedule
Includes all 5 workflows above.
Financial Regulation5 workflows
- Capital Adequacy Assessment (Basel III)
- SAR Draft & Filing Workflow
- KYC/CDD Audit
- SEC Filing Readiness (10-K/10-Q)
- AML Program Review
Includes all 5 workflows above.
International Frameworks5 workflows
- DORA ICT Risk Assessment (EU Financial)
- ISO 27001 Gap Analysis & Annex A
- GDPR Article 30 Processing Records
- NIS2 Compliance Mapping
- Cross-border Data Transfer Mechanisms
Includes all 5 workflows above.
Privacy & Data Protection4 workflows
- Data Subject Request (DSR) Tracker
- Privacy Impact Assessment (DPIA)
- Breach Notification Workflow
- Data Retention Policy Review
Includes all 4 workflows above.
Ongoing / Scheduled4 workflows
- Regulatory Change Impact Review
- Annual Control Recertification
- Quarterly Risk Assessment Update
- Compliance Calendar Management
Includes all 4 workflows above.
HR & People Risk4 workflows
- Offboarding & Access Revocation Workflow
- Background Check Program
- Insider Threat Assessment
- HR Policy Compliance Review
Includes all 4 workflows above.
SOC 2 (Trust Services)
- Control Evidence Collection & Checklist
- Vendor Risk Assessment (SOC 2 scope)
- Security Policy Library
- Penetration Test Gap Report
- Continuous Control Testing Schedule
Includes all 5 workflows above.
Financial Regulation
- Capital Adequacy Assessment (Basel III)
- SAR Draft & Filing Workflow
- KYC/CDD Audit
- SEC Filing Readiness (10-K/10-Q)
- AML Program Review
Includes all 5 workflows above.
International Frameworks
- DORA ICT Risk Assessment (EU Financial)
- ISO 27001 Gap Analysis & Annex A
- GDPR Article 30 Processing Records
- NIS2 Compliance Mapping
- Cross-border Data Transfer Mechanisms
Includes all 5 workflows above.
Privacy & Data Protection
- Data Subject Request (DSR) Tracker
- Privacy Impact Assessment (DPIA)
- Breach Notification Workflow
- Data Retention Policy Review
Includes all 4 workflows above.
Ongoing / Scheduled
- Regulatory Change Impact Review
- Annual Control Recertification
- Quarterly Risk Assessment Update
- Compliance Calendar Management
Includes all 4 workflows above.
HR & People Risk
- Offboarding & Access Revocation Workflow
- Background Check Program
- Insider Threat Assessment
- HR Policy Compliance Review
Includes all 4 workflows above.
The definition
What compliance is
Every bank exam ends at the same question: prove it. Not "did you do the right thing" — show the record that says you did. Under examination, what happened matters less than what you can demonstrate happened. The standing assumption in the room is simple: if it isn't documented, it didn't happen.
That pressure is the reason this pillar exists:
Compliance is the discipline of proving that an institution follows the rules that apply to it — laws, regulations, supervisory expectations, and contractual standards. Its defining word is demonstrable.
Compliance is a translation function. Laws are written in the language of legislatures; institutions run on procedures, systems, and people. Compliance converts one into the other — obligations into controls, controls into evidence, evidence into findings, findings into remediation, tracked to close.
Where it came from
Compliance is the institutional memory of financial failure.
Select a year
1863
The OCC.
The National Currency Act created the Office of the Comptroller of the Currency — and the first federal bank examiners, empowered to inspect national banks' books. Examination as a standing practice starts here.¹
1933–1934
The crash rebuild.
After 1929, Congress separated banking from securities speculation and created the SEC — forcing honest disclosure on public companies and policing the markets they trade on.²
1970
The Bank Secrecy Act.
Compliance acquired a second mission: not just safety and soundness, but fighting financial crime. Recordkeeping and reporting requirements made banks the front line against money laundering.³
2001
The USA PATRIOT Act.
Anti-money laundering (AML) took its modern form: Customer Identification Programs, suspicious activity reporting, sanctions screening — and FinCEN was formalized in statute as the Treasury bureau administering it.⁴
2002
Sarbanes-Oxley.
After Enron, executives became personally accountable for financial reporting controls — certification with criminal exposure attached.⁵
2010
Dodd-Frank.
The largest expansion since the 1930s: the CFPB, enhanced prudential standards, and a supervisory apparatus built around consumer protection and systemic risk.⁶
The pattern: every compliance obligation is a response to a documented abuse. The rulebook is a history of what went wrong, written so it can't go wrong the same way twice.
Sources
- 1. OCC — History of the OCC, 1863–1865
- 2. SEC — The laws that govern the securities industryCongress.gov (CRS) — The Securities Exchange Act of 1934 and the creation of the SEC
- 3. FinCEN — The Bank Secrecy Act
- 4. FinCEN — History of anti-money laundering laws
- 5. Congress.gov — Sarbanes-Oxley Act of 2002, P.L. 107-204
- 6. Congress.gov — Dodd-Frank Act, P.L. 111-203
The evaluators
Compliance is a scored activity. Here's who keeps score.
The regulators and examiners.
- OCC — supervises national banks; conducts exams and issues supervisory findings
- Federal Reserve — supervises bank holding companies and state member banks; runs the stress-test regimes
- FDIC — insures deposits and supervises state non-member banks
- CFPB — consumer financial protection
- SEC & FINRA — securities markets, broker-dealers, disclosures
- FinCEN & OFAC — financial crime, AML, and sanctions
- State regulators (e.g., NYDFS) — charters, cybersecurity rules, money transmission¹
The independent attesters. CPA firms issue SOC 2 reports under the AICPA's Trust Services Criteria and opinions on SOX controls; accredited certification bodies assess ISO 27001. Attestations carry weight precisely because the attester's name and liability stand behind them.²
The internal lines of defense. First line: the business units that own the risk. Second line: the compliance and risk functions that set policy and challenge. Third line: internal audit, which answers to the board — not to management.³
The KPIs — how integrity gets measured.
- Exam ratings — the composite grades (capital, assets, management, earnings, liquidity, sensitivity) that determine supervisory intensity
- Findings and supervisory actions — count, severity, and aging of open items
- Remediation velocity — days-to-close; overdue findings are a red flag on their own
- Filing timeliness — SARs, CTRs, call reports, 10-K/10-Q deadlines
- Control test pass rates — scheduled, documented evidence that controls operate as designed
The integrity standard. Every measure above rests on the same foundation: traceable evidence. A control without evidence is an assertion — and examiners are trained to treat assertions as findings.
The stakes
Compliance is the floor that lets trust scale.
- It's the admission ticket. A charter, access to payment rails, correspondent relationships, and deposit insurance all depend on demonstrated compliance. Lose standing, and an institution doesn't just get fined — it gets excluded.
- It's macroeconomic infrastructure. The U.S. financial system moves trillions daily between parties with no personal knowledge of each other. That velocity only exists because compliance standards create a common floor of behavior every participant can rely on.
- Enforcement moves markets. Major post-crisis penalties reshaped entire business lines — banks exited markets, products, and geographies they could no longer operate compliantly. Compliance failures don't just cost money; they redraw sector maps.
- It protects the end customer invisibly. A depositor in New Jersey trusts an institution she's never visited because a century of compliance machinery stands behind that trust. When compliance works, nobody notices. That's the point.
Why it matters
The cost of failure is asymmetric. Staying on the right side of it is a strategy.
What failure looks like:
- Enforcement actions and consent orders — public, reputational, and operationally consuming for years
- Growth restrictions — the Fed's 2018 action against Wells Fargo capped the bank's assets for over seven years, until June 2025 — a penalty no fine could match¹
- Personal accountability — under SOX, executives certify controls with criminal exposure; supervisory actions can also reach officers and directors individually²
- Exclusion — loss of correspondent relationships, processor access, or the charter itself
What success looks like:
- Speed. Institutions with clean exam records get faster product approvals, smoother M&A reviews, and easier partner diligence. Compliance done well is an accelerant, not a brake.
- Negotiating position. Enterprise customers, investors, and banking partners all run compliance diligence. A documented, evidence-backed program shortens every one of those conversations.
- Durability. The institutions that survive decades aren't the ones that avoided risk — they're the ones that could always demonstrate they were inside the rules while taking it.
Evidence, not assertions
Every obligation traces to a tracked remediation
The compliance pillar's job is traceability. Follow one obligation from the rulebook all the way to a fix.
Regulatory obligation
BSA/AML program & Customer Identification Program (FinCEN / FFIEC)
Control / workflow
AML Program Review + KYC/CDD Audit
Evidence
CIP procedures, SAR filings, transaction-monitoring records
Finding
CIP gap vs. current FFIEC/FinCEN standards — High
Remediation
Gap assessment; scope IA AML program design, tracked to close
KYC / CIP Program — Prior Enforcement + Evolving Obligations
- Evidence status
- Confirmed (public enforcement record) / Conditional (post-remediation)
- Affected obligation
- AML/BSA — Customer Identification Program (CIP)
Recommended action
Gap-assess CIP/ITPP against current FFIEC & FinCEN standards; scope IA AML program design for 2028.
A financial-services workflow, in motion
Illustrative- TriggerNew lending product crosses a BSA/AML threshold
- WorkflowAML Program Review runs in Gap mode
- OutputGap report + SAR-filing readiness, with owners
AML/BSA is one of the applicable regulatory workflows. See how scoping works →
What we cover — regulators, regulations, frameworks, and attestations
| Name | What it is | RuleboardAI workflow coverage |
|---|---|---|
| SEC | Regulator | SEC filing readiness (10-K/10-Q) workflow |
| FINRA | Regulator | Covered within financial-regulation workflows |
| FinCEN | Regulator | AML program review & SAR draft/filing workflows |
| SOX | Regulation | Financial-regulation control workflows |
| Basel III | Regulation | Capital adequacy assessment workflow |
| AML/BSA | Regulation | AML program review, KYC/CDD audit, SAR workflows |
| GDPR / CCPA-CPRA | Regulation | Privacy workflows — DSR tracker, DPIA, records |
| DORA / NIS2 | Regulation | International-framework mapping workflows |
| ISO 27001 | Framework | Gap analysis & Annex A workflow |
| SOC 2 (AICPA TSC) | Attestation | Control-evidence collection & checklist — evidence prep only, not an attestation |
- SECRegulator
SEC filing readiness (10-K/10-Q) workflow
- FINRARegulator
Covered within financial-regulation workflows
- FinCENRegulator
AML program review & SAR draft/filing workflows
- SOXRegulation
Financial-regulation control workflows
- Basel IIIRegulation
Capital adequacy assessment workflow
- AML/BSARegulation
AML program review, KYC/CDD audit, SAR workflows
- GDPR / CCPA-CPRARegulation
Privacy workflows — DSR tracker, DPIA, records
- DORA / NIS2Regulation
International-framework mapping workflows
- ISO 27001Framework
Gap analysis & Annex A workflow
- SOC 2 (AICPA TSC)Attestation
Control-evidence collection & checklist — evidence prep only, not an attestation
Coverage describes the workflows RuleboardAI runs. RuleboardAI does not issue attestations or certify compliance.
Evidence handling
How each obligation is sourced and verified
Capital adequacy ratios (CET1, Tier 1)
SoFi Bank “well capitalized” across all OCC metrics.
Capital Adequacy (Basel III)
10-K FY2025
Dated 2026-02-24
VerifiedCIP / KYC procedures
$1.1M CIP/ITPP enforcement — gap-assess vs. current FFIEC/FinCEN standards.
KYC/CDD Audit
FINRA AWC (2024)
Dated 2024-05-16
Prior findingSOC 2 Type II report
No public SOC 2 report identified — requested in a full engagement.
Vendor Risk Assessment
Public sources
Dated —
Data gapSAR filing records
Not verifiable from public sources; program exists as a bank requirement.
SAR Draft & Filing
Non-public
Dated —
Data gap
Every item carries its workflow, source, date, and verification state. Unmet requests are logged as data gaps, not omitted.
Compliance calendar
Dated obligations on the horizon
- May 2024
FINRA settlement on CIP/ITPP gaps ($1.1M) for 2018–2019 conduct.
Source: FINRA
- Jan 1, 2024
Direct CFPB supervision commenced after crossing the $10B asset threshold.
Source: SoFi 10-K
- Jul 1, 2026Current state
This preliminary profile — current-state baseline from public sources.
- Jan 1, 2028Effective date
FinCEN Investment Adviser AML rule compliance date for RIAs and ERAs.
Source: FinCEN
Each entry restates a date cited elsewhere in this profile — no invented deadlines.
1 of 4