How It Works

From four inputs to a structured regulatory risk profile

A repeatable, structured process. At each step you can see exactly what you provide, what RuleboardAI performs, and what artifact comes out.

What you give, what you get — at every step

Read each column top to bottom: your input, the engine's action, the artifact produced.

You provide RuleboardAI does Artifact out

Step 01

Classify

You provide

Company name, URL, public/private, ticker

RuleboardAI does

RCPS classifies the client on listing status, size, industry, geography, data intensity, ownership, and growth stage.

Artifact out

A classified client profile. Scope is defined before the auditor defines it for you.

Step 02

Scope

You provide

The classified profile from step 01

RuleboardAI does

From the pre-built workflow library covering the relevant GRC domains, the engine marks each workflow in scope, conditional, or out of scope.

Artifact out

A scoped workflow set. Nothing applicable is missed; nothing irrelevant is run.

Step 03

Execute & Score

You provide

Public-source data, then your evidence on verification

RuleboardAI does

Workflows run in the right mode. Each finding is labeled Confirmed, Likely, Conditional, or Escalate.

Artifact out

Scored findings with an evidence status on each — on your radar before the examiner's.

Step 04

Deliver & Repeat

You provide

Nothing — outputs assemble from the run

RuleboardAI does

Reports generate with a complete evidence trail, and every finding carries a remediation path. You decide when to run the next one.

Artifact out

A report structured for internal review and evidence verification. When the exam comes, the answer is documented.

Structured for internal review in every run

Step 01 — RCPS Classification

The classification decides the scope

Before any workflow runs, the RCPS model reads the client on each classification axis. Those answers decide which obligations apply — so scope is defined by methodology, not guesswork.

The example beside is drawn from our public Sample Profile.

RCPS profileIllustrative — sample institution
1 · Listing status
Publicly listed
2 · Company size
Large enterprise
3 · Industry
Fintech + national bank
4 · Geography
US-primary
5 · Data intensity
Maximum
6 · Ownership
Public parent
7 · Growth stage
Scale-up

Step 02 — Workflow Scoping

Applicable regulatory workflows, sorted for this client

Workflow scoping

Every client is scored against the same set of applicable regulatory workflows across the relevant GRC domains. The engine sorts each workflow into one of three buckets — nothing applicable is missed, nothing irrelevant is run.

  • In scope

    Applies to this client — runs this cycle.

  • Conditional

    Applies only if a trigger is met — flagged for review.

  • Out of scope

    Not applicable to this client — documented, not ignored.

Illustrative — the actual scope is determined per client during RCPS classification.

Step 03 — Run Modes

Each workflow runs in the mode that fits

The same workflow behaves differently depending on where the client already stands.

Build

Input

A control area that barely exists yet

Output

Policy, evidence structure, and workflow stood up from scratch

Gap

Input

An existing program + a target framework

Output

A ranked list of what is missing based on public sources only. No client documentation is reviewed for the preliminary profile.

Maintenance

Input

An already-built program on a schedule

Output

Refreshed evidence, re-tested controls, tracked remediation

Framework Mapping

Input

Multiple overlapping frameworks

Output

One evidence set mapped to satisfy many requirements at once

Mode summaries are plain-language descriptions of RuleboardAI's run modes.

Step 04 — The Deliverable

Every finding carries its evidence

A finding is only useful if you can defend it. Each one ships with a severity, an evidence status, the obligation it touches, a cited source, and a recommended action.

See the full Sample Profile
High severityIllustrative

CFPB Direct Supervision — Commenced January 1, 2024

Evidence status
Confirmed (public record)
Affected obligation
Financial Regulation — ongoing consumer-compliance supervision readiness

Recommended action

Maintain evidence for consumer-compliance obligations, structured for internal review, under direct CFPB oversight.

…and every finding lands inside a report structured for internal review and evidence verification — an executive summary, the RCPS scorecard, and a cited source appendix.

CompanyScope — Regulatory Risk Profile

SoFi Technologies, Inc.

NASDAQ: SOFI · July 1, 2026

Executive summary

Overall control maturity is Developing–Defined, with the largest gaps in cybersecurity and risk management. Four high-severity findings concentrate around bank-charter heightened standards, KYC/CIP, and crypto exposure.

Composite maturity

2.6 / 5.0

Defined

Achievable target

3.8 / 5.0

  • Governance3.1 / 5
  • Risk Management2.2 / 5
  • Compliance2.9 / 5
  • Cybersecurity2.0 / 5
  • Third-Party Risk2.7 / 5
  • Privacy3.0 / 5
  • Monitoring2.3 / 5

Finding excerpt · prioritized findings based on available public evidence

High

$50B OCC heightened-standards threshold — governance uplift required

Source appendix · 15 cited sourcesScope: public-source, preliminary — data gaps listed in the report.

See the lifecycle end to end

This process is stages 01–03 of the RuleboardAI lifecycle — assess, verify, report.

Scope of service

  • RuleboardAI does not provide legal advice.
  • RuleboardAI does not issue audit opinions, examination results, or attestations.
  • Preliminary reviews use public sources only.
  • Final reports require authorization, evidence intake, and verification.

Customers remain responsible for their own regulatory obligations.