Roadmap

AR
AreaItemStatusNote
Compliance Risk AssessmentCRA with domain framework, board sign-offShippedAML, CFT and CPF scored as three distinct compliance domains under Financial Crime.
ObligationsLayered obligation model (source / normalised / applicability / implementation / evidence / monitoring / governance)Shipped
Regulatory correspondenceRegister, derivations, plain-English categoriesShipped
BRACycles, taxonomy, inherent/residual, approvalShipped
Risk AppetiteBoard-approved thresholds, breach → finding wiringShippedPromoted from Preview — JFSC expects measurable thresholds, not narrative.
Risk ActivityResidual heat by business line / activityShippedPromoted from Preview — drives risk-based focus for the next quarter.
AdvisoryAI advisory recommendations with certainty rating, decision and override trailShippedPromoted from Preview — JFSC-defensible AI use.
JFSC Mapping PackPrintable regulator pack: every JFSC obligation → controls, policies, ownersShippedLive at /governance/jfsc-mapping.
Tour narrationBritish male narrator (George) across all tour journeysShippedElevenLabs-backed, cached per step.
Route redirect regression guardAudit script catches layout-route infinite-redirect loopsShippedscripts/audit-route-redirects.ts.
CompassPer-scenario mode guidance, in-product mode pillBuilding now
MethodologyShared 5×5 risk library across CRA / BRA / RCSA visualsBuilding now
MetricsFirst-line and second-line oversight metricsNext
Task deliveryEmail-delivered tasks with secure single-task linksNext
BRA schemaClient segment, delivery channel, outsourcing dependency, evidence confidence, reassessment trigger fieldsNext
Findings ↔ CRAAuto-trigger CRA reassessment from material findingsNext
Attestation campaignsCampaign entity grouping attestations under one windowLater
Policy → procedure linkageFirst-class procedure child of policyLater
Per-folder evidence ACLHR-sensitive evidence scoped tighter than tenant-wideLater
Notification digestDaily / weekly notification summary in place of one-event-per-emailLater
CPD / Training registerTraining records and CPD loggingLater
SAR / MLRO restricted workspaceRLS-isolated restricted workspace with separate auditLater
Microsoft Teams integrationReal Teams task delivery (partner-registered)Later
EWRAEnterprise-wide risk module inside RegAlignLaterAcknowledged-and-deferred. Different buyer (CRO/COO), different cadence, different methodology. RegAlign stays focused on compliance risk; EWRA work belongs in your existing enterprise risk tooling until a separate module ships. See /risk/ewra for the scope statement.
RiskAlignAdjacent enterprise risk productLaterRevisit after three paid RegAlign pilots.
Enforcement-data feedLive ingestion of regulator enforcement and thematic reviewsWon't doLicensing-heavy and adjacent to product purpose.
Broader GRC driftGeneric GRC platform positioningWon't doLoses the compliance-first positioning.

Dated honestly. Roadmap items are not commitments to any specific tenant.

RegAlign® supports compliance governance. It does not provide legal or regulatory advice. Decisions, approvals and overrides remain the responsibility of identified humans in the audit trail.