All products

Regulatory risk profile

CompanyScope

A structured regulatory risk profile of your own institution

Most institutions can answer any single regulatory question, but few can show one consolidated, current view of where they stand — which obligations apply, how mature each control area is, and what an examiner or counterparty would find first.

$500one-time

One category, one flat fee. Nothing recurs and nothing auto-renews.

  1. Public-source scan

    Filings, registers, and enforcement records only. No system access, no document requests.

  2. RCPS classification

    The classification axes scope the workflow universe to your entity.

  3. Scored profile delivered

    Maturity scored 1–5 per axis, findings ranked by severity, gaps logged. Ten business days.

Representative output

Illustrative

Composite maturity

2.6 / 5.0

Defined

Achievable target

3.8 / 5.0

  • Governance3.1 / 5
  • Risk Management2.2 / 5
  • Compliance2.9 / 5
  • Cybersecurity2.0 / 5
  • Third-Party Risk2.7 / 5
  • Privacy3.0 / 5
  • Monitoring2.3 / 5
RCPS maturity by axis, against the achievable targetRCPS maturity radar, scored out of 5. Governance 3.1, Risk Management 2.2, Compliance 2.9, Cybersecurity 2.0, Third-Party Risk 2.7, Privacy 3.0, Monitoring 2.3. Achievable target 3.8 on every axis, shown as a dashed ring.Governance3.1 / 5Risk Mgmt2.2 / 5Compliance2.9 / 5Cyber2.0 / 5Third-Party2.7 / 5Privacy3.0 / 5Monitoring2.3 / 5MeasuredTarget 3.8

Select an axis to see the maturity band its score falls in, and what the next band requires.

Restated from the public sample profile (SoFi Technologies — a public company, not a client). Your report reflects your own entity.

Who this is for

  • Chief Risk Officers, CISOs, and Heads of Compliance at U.S. financial institutions
  • Founders and operating executives preparing for an exam, diligence, or a board review
  • Teams that want one category (e.g. cybersecurity or privacy) assessed on its own

When it lands on your desk

  • An examination, audit, or counterparty diligence request is on the calendar
  • New obligations arrived — a new license, product line, or regulator
  • The board or an investor asked “where do we actually stand?”

The work

What CompanyScope does

  • Classifies your institution with the RCPS model — the classification axes that determine which regulatory workflows apply
  • Scores control maturity 1–5 on each maturity axis and rolls them into a composite with an achievable target
  • Surfaces preliminary findings by severity, each tied to a source and an affected obligation
  • Produces a data-gap register — what public sources could not resolve and what evidence would resolve it
  • Ends in a verification roadmap: the ordered list of what to confirm next

What you provide

  • Company name
  • Company website
  • Public or private status
  • Ticker (public companies only)
  • For verified conclusions: internal evidence, under a signed Letter of Authorization

How the work is done

  • Public-source first: the preliminary profile is built entirely from public records — no system access, no document requests.
  • The RCPS classification scopes the workflow universe to your entity: in scope, conditional, or out of scope.
  • Findings are labeled Confirmed, Likely, Conditional, or Escalate, and every conclusion carries its evidence state.
  • Deeper, evidence-verified review happens only after a signed Letter of Authorization.

Scoped against

  • RCPS
  • SOX / SEC
  • BSA / AML
  • FFIEC
  • Basel III
  • SOC 2
  • GDPR / CCPA

Named standards and registers this product works from. Not a certification, attestation, or endorsement of any institution.

Deliverables

What you receive

  • Regulatory risk profile document with the RCPS maturity scorecard
  • Preliminary findings by severity, with sources and recommended actions
  • Workflow scope determination across the applicable regulatory workflows
  • Data-gap register and verification roadmap
  • A structured evidence request and a 60-minute findings call

Typical timing

Ten business days from confirmed scope and cleared payment.

Request CompanyScope

Tell us about your institution and objective — we respond within one business day.

Company status

By submitting you consent to us contacting you about this request. Handled per our Privacy Policy and Trust Center.

Questions

CompanyScope FAQ

What do you need from us to start?

Four inputs: company name, website, public/private status, and ticker if public. The preliminary profile requires nothing else — no system access, no document uploads.

What does the preliminary profile cost?

The Preliminary Regulatory Risk Profile is $500, one-time, delivered in ten business days from public sources. It requires no documents and no system access, and a named person reviews it before it reaches you.

What is a single-category profile?

A CompanyScope covering any one of the GRC categories — governance, cybersecurity, privacy, and so on — at $500, one-time. You pick the category under the most pressure.

Can the findings be treated as an audit?

No. CompanyScope is a structured intelligence product, not an audit or attestation. Preliminary findings are public-source and labeled as such; verified conclusions require your evidence under a Letter of Authorization.

How does cancellation work?

There is nothing to cancel. CompanyScope is a one-time fee for a defined deliverable — there is no subscription, nothing auto-renews, and no notice period applies. If you have a question about an engagement in progress, email support@ruleboardai.com.

What CompanyScope is not

  • The preliminary profile never accesses client systems or internal documents.
  • Not legal, regulatory, audit, or compliance advice — your institution remains responsible for its own regulatory obligations.
  • Not an audit, audit opinion, control attestation, or certification of any kind.