Regulatory risk profile
CompanyScope
A structured regulatory risk profile of your own institution
Most institutions can answer any single regulatory question, but few can show one consolidated, current view of where they stand — which obligations apply, how mature each control area is, and what an examiner or counterparty would find first.
One category, one flat fee. Nothing recurs and nothing auto-renews.
Public-source scan
Filings, registers, and enforcement records only. No system access, no document requests.
RCPS classification
The classification axes scope the workflow universe to your entity.
Scored profile delivered
Maturity scored 1–5 per axis, findings ranked by severity, gaps logged. Ten business days.
Representative output
IllustrativeComposite maturity
2.6 / 5.0
Defined
Achievable target
3.8 / 5.0
- Governance3.1 / 5
- Risk Management2.2 / 5
- Compliance2.9 / 5
- Cybersecurity2.0 / 5
- Third-Party Risk2.7 / 5
- Privacy3.0 / 5
- Monitoring2.3 / 5
Select an axis to see the maturity band its score falls in, and what the next band requires.
Restated from the public sample profile (SoFi Technologies — a public company, not a client). Your report reflects your own entity.
Who this is for
- Chief Risk Officers, CISOs, and Heads of Compliance at U.S. financial institutions
- Founders and operating executives preparing for an exam, diligence, or a board review
- Teams that want one category (e.g. cybersecurity or privacy) assessed on its own
When it lands on your desk
- An examination, audit, or counterparty diligence request is on the calendar
- New obligations arrived — a new license, product line, or regulator
- The board or an investor asked “where do we actually stand?”
The work
What CompanyScope does
- Classifies your institution with the RCPS model — the classification axes that determine which regulatory workflows apply
- Scores control maturity 1–5 on each maturity axis and rolls them into a composite with an achievable target
- Surfaces preliminary findings by severity, each tied to a source and an affected obligation
- Produces a data-gap register — what public sources could not resolve and what evidence would resolve it
- Ends in a verification roadmap: the ordered list of what to confirm next
What you provide
- Company name
- Company website
- Public or private status
- Ticker (public companies only)
- For verified conclusions: internal evidence, under a signed Letter of Authorization
How the work is done
- Public-source first: the preliminary profile is built entirely from public records — no system access, no document requests.
- The RCPS classification scopes the workflow universe to your entity: in scope, conditional, or out of scope.
- Findings are labeled Confirmed, Likely, Conditional, or Escalate, and every conclusion carries its evidence state.
- Deeper, evidence-verified review happens only after a signed Letter of Authorization.
Scoped against
- RCPS
- SOX / SEC
- BSA / AML
- FFIEC
- Basel III
- SOC 2
- GDPR / CCPA
Named standards and registers this product works from. Not a certification, attestation, or endorsement of any institution.
Deliverables
What you receive
- Regulatory risk profile document with the RCPS maturity scorecard
- Preliminary findings by severity, with sources and recommended actions
- Workflow scope determination across the applicable regulatory workflows
- Data-gap register and verification roadmap
- A structured evidence request and a 60-minute findings call
Typical timing
Ten business days from confirmed scope and cleared payment.
Questions
CompanyScope FAQ
What do you need from us to start?
Four inputs: company name, website, public/private status, and ticker if public. The preliminary profile requires nothing else — no system access, no document uploads.
What does the preliminary profile cost?
The Preliminary Regulatory Risk Profile is $500, one-time, delivered in ten business days from public sources. It requires no documents and no system access, and a named person reviews it before it reaches you.
What is a single-category profile?
A CompanyScope covering any one of the GRC categories — governance, cybersecurity, privacy, and so on — at $500, one-time. You pick the category under the most pressure.
Can the findings be treated as an audit?
No. CompanyScope is a structured intelligence product, not an audit or attestation. Preliminary findings are public-source and labeled as such; verified conclusions require your evidence under a Letter of Authorization.
How does cancellation work?
There is nothing to cancel. CompanyScope is a one-time fee for a defined deliverable — there is no subscription, nothing auto-renews, and no notice period applies. If you have a question about an engagement in progress, email support@ruleboardai.com.
What CompanyScope is not
- The preliminary profile never accesses client systems or internal documents.
- Not legal, regulatory, audit, or compliance advice — your institution remains responsible for its own regulatory obligations.
- Not an audit, audit opinion, control attestation, or certification of any kind.