How It Works
From four inputs to a structured regulatory risk profile
A repeatable, structured process. At each step you can see exactly what you provide, what RuleboardAI performs, and what artifact comes out.
What you give, what you get — at every step
Read each column top to bottom: your input, the engine's action, the artifact produced.
Step 01
Classify
Company name, URL, public/private, ticker
RCPS classifies the client on listing status, size, industry, geography, data intensity, ownership, and growth stage.
A classified client profile. Scope is defined before the auditor defines it for you.
Step 02
Scope
The classified profile from step 01
From the pre-built workflow library covering the relevant GRC domains, the engine marks each workflow in scope, conditional, or out of scope.
A scoped workflow set. Nothing applicable is missed; nothing irrelevant is run.
Step 03
Execute & Score
Public-source data, then your evidence on verification
Workflows run in the right mode. Each finding is labeled Confirmed, Likely, Conditional, or Escalate.
Scored findings with an evidence status on each — on your radar before the examiner's.
Step 04
Deliver & Repeat
Nothing — outputs assemble from the run
Reports generate with a complete evidence trail, and every finding carries a remediation path. You decide when to run the next one.
A report structured for internal review and evidence verification. When the exam comes, the answer is documented.
Step 01 — RCPS Classification
The classification decides the scope
Before any workflow runs, the RCPS model reads the client on each classification axis. Those answers decide which obligations apply — so scope is defined by methodology, not guesswork.
The example beside is drawn from our public Sample Profile.
- 1 · Listing status
- Publicly listed
- 2 · Company size
- Large enterprise
- 3 · Industry
- Fintech + national bank
- 4 · Geography
- US-primary
- 5 · Data intensity
- Maximum
- 6 · Ownership
- Public parent
- 7 · Growth stage
- Scale-up
Step 02 — Workflow Scoping
Applicable regulatory workflows, sorted for this client
Workflow scoping
Every client is scored against the same set of applicable regulatory workflows across the relevant GRC domains. The engine sorts each workflow into one of three buckets — nothing applicable is missed, nothing irrelevant is run.
- In scope
Applies to this client — runs this cycle.
- Conditional
Applies only if a trigger is met — flagged for review.
- Out of scope
Not applicable to this client — documented, not ignored.
Illustrative — the actual scope is determined per client during RCPS classification.
Step 03 — Run Modes
Each workflow runs in the mode that fits
The same workflow behaves differently depending on where the client already stands.
Build
Input
A control area that barely exists yet
Output
Policy, evidence structure, and workflow stood up from scratch
Gap
Input
An existing program + a target framework
Output
A ranked list of what is missing based on public sources only. No client documentation is reviewed for the preliminary profile.
Maintenance
Input
An already-built program on a schedule
Output
Refreshed evidence, re-tested controls, tracked remediation
Framework Mapping
Input
Multiple overlapping frameworks
Output
One evidence set mapped to satisfy many requirements at once
Mode summaries are plain-language descriptions of RuleboardAI's run modes.
Step 04 — The Deliverable
Every finding carries its evidence
A finding is only useful if you can defend it. Each one ships with a severity, an evidence status, the obligation it touches, a cited source, and a recommended action.
See the full Sample ProfileCFPB Direct Supervision — Commenced January 1, 2024
- Evidence status
- Confirmed (public record)
- Affected obligation
- Financial Regulation — ongoing consumer-compliance supervision readiness
Recommended action
Maintain evidence for consumer-compliance obligations, structured for internal review, under direct CFPB oversight.
…and every finding lands inside a report structured for internal review and evidence verification — an executive summary, the RCPS scorecard, and a cited source appendix.
CompanyScope — Regulatory Risk Profile
SoFi Technologies, Inc.
NASDAQ: SOFI · July 1, 2026
Executive summary
Overall control maturity is Developing–Defined, with the largest gaps in cybersecurity and risk management. Four high-severity findings concentrate around bank-charter heightened standards, KYC/CIP, and crypto exposure.
Composite maturity
2.6 / 5.0
Defined
Achievable target
3.8 / 5.0
- Governance3.1 / 5
- Risk Management2.2 / 5
- Compliance2.9 / 5
- Cybersecurity2.0 / 5
- Third-Party Risk2.7 / 5
- Privacy3.0 / 5
- Monitoring2.3 / 5
Finding excerpt · prioritized findings based on available public evidence
$50B OCC heightened-standards threshold — governance uplift required
See the lifecycle end to end
This process is stages 01–03 of the RuleboardAI lifecycle — assess, verify, report.
Scope of service
- RuleboardAI does not provide legal advice.
- RuleboardAI does not issue audit opinions, examination results, or attestations.
- Preliminary reviews use public sources only.
- Final reports require authorization, evidence intake, and verification.
Customers remain responsible for their own regulatory obligations.