The CRA isn't a spreadsheet.
It's the routing engine.
Compliance Risk Assessment scores aren't a board artefact you redo annually. In RegAlign the residual rating on every domain drives the cadence of monitoring, the size of samples, the triage of findings and the depth of the board read-out. Change a rating → every downstream surface rebalances. Freeze a snapshot → the board gets a stable record. Both, every cycle.
Residual ratings drive cadence
Why this matters: The monitoring calendar isn't set in a separate tool. Move AML to medium and next month's plan automatically retunes the sample size and the cadence.
Triage by residual + finding severity
The same finding severity routes differently depending on the domain's residual rating. A "medium" finding in AML lands in P1; the same finding in outsourcing lands in P3. The matrix is visible and overridable with a recorded rationale.
Why this matters: The CCO stops sorting Excel rows. The board stops asking "why is this urgent?" — the answer is structural, not editorial.
Annual board assessment — frozen snapshot
Why this matters: The annual CRA the supervisor expects is the same record set the operator works from all year. No two versions, no copy-paste, no PDF drift.
Per-firm tailoring with full version history. Override at the domain level, document the rationale.
Monitoring plan, sample size and triage tier all derive from the residual rating. No double-entry.
Annual snapshot is hash-receipted and approved on-record. Working CRA continues to move; board record stays stable.
Findings and breach data feed back into next cycle's inherent / mitigation deltas. Closed-loop.
See the cycle on Saltire
Twelve seeded domains, three RCSA cycles, four CRA board assessments. Trend series populated end-to-end.