Roadmap

AR
AreaItemStatusNote
Compliance Risk AssessmentCRA with domain framework, board sign-offShippedAML, CFT and CPF scored as three distinct compliance domains under Financial Crime.
ObligationsLayered obligation model (source / normalised / applicability / implementation / evidence / monitoring / governance)Shipped
Regulatory correspondenceRegister, derivations, plain-English categoriesShipped
BRACycles, taxonomy, inherent/residual, approvalShipped
Risk AppetiteBoard-approved thresholds, breach → finding wiringShippedPromoted from Preview — JFSC expects measurable thresholds, not narrative.
Risk ActivityResidual heat by business line / activityShippedPromoted from Preview — drives risk-based focus for the next quarter.
AdvisoryAI advisory recommendations with certainty rating, decision and override trailShippedPromoted from Preview — JFSC-defensible AI use.
JFSC Mapping PackPrintable regulator pack: every JFSC obligation → controls, policies, ownersShippedLive at /governance/jfsc-mapping.
Guernsey (GFSC) packGuernsey Fiduciary / Handbook mapping pack (equivalent to JFSC pack)LaterTrigger: first Guernsey pilot signature. Scoping doc exists internally; not built until a pilot funds the source-text licensing and reviewer time.
Isle of Man (IOMFSA) packIOMFSA rulebook mapping packLaterTrigger: first Isle of Man pilot signature. Same model as Guernsey — pilot-funded to avoid speculative build against paywalled source text.
UK (FCA/PRA) packUK Handbook mapping pack for AML/CTF scopeLaterTrigger: first UK pilot signature. Sourcebook coverage staged: SYSC + FCG first, wider Handbook by request.
Tour narrationBritish male narrator (George) across all tour journeysShippedElevenLabs-backed, cached per step.
Route redirect regression guardAudit script catches layout-route infinite-redirect loopsShippedscripts/audit-route-redirects.ts.
CompassPer-scenario mode guidance, in-product mode pillBuilding now
MethodologyShared 5×5 risk library across CRA / BRA / RCSA visualsBuilding now
MetricsFirst-line and second-line oversight metricsNext
Task deliveryEmail-delivered tasks with secure single-task linksNext
BRA schemaClient segment, delivery channel, outsourcing dependency, evidence confidence, reassessment trigger fieldsNext
Findings ↔ CRAAuto-trigger CRA reassessment from material findingsNext
Attestation campaignsCampaign entity grouping attestations under one windowLater
Policy → procedure linkageFirst-class procedure child of policyLater
Per-folder evidence ACLHR-sensitive evidence scoped tighter than tenant-wideLater
Notification digestDaily / weekly notification summary in place of one-event-per-emailLater
CPD / Training registerTraining records and CPD loggingLater
SAR / MLRO restricted workspaceRLS-isolated restricted workspace with separate auditLater
Microsoft Teams integrationReal Teams task delivery (partner-registered)Later
ERM (RiskAlign)Firm-wide multi-domain enterprise risk register — strategic, operational, financial, technology, people, reputationalLaterShips in our sister product RiskAlign (or the combined RegAlign and RiskAlign offering), not inside RegAlign. The ERM register is prepared by the CRO / Risk function (2LoD) aggregating business-owner inputs per category, and approved by the Board / Board Risk Committee — different cadence to compliance risk. COSO ERM 2017 / ISO 31000:2018-aligned. RegAlign stays focused on compliance risk: BRA (AML firm-wide, business-prepared, MLRO-challenged, board-approved), CRA (Compliance-function-prepared, board-approved), RCSA, risk appetite. Scope statement at /risk/erm. NB: 'EWRA' in AML practice is a synonym for BRA — that artefact is shipped today at /risk/bra.
RiskAlignAdjacent enterprise risk product (ERM + appetite + KRIs)LaterRevisit after ≥1 paid RegAlign pilot. Combined RegAlign and RiskAlign offering = a bounded combined offering; either product may operate independently.
Enforcement-data feedLive ingestion of regulator enforcement and thematic reviewsWon't doLicensing-heavy and adjacent to product purpose.
Broader GRC driftGeneric GRC platform positioningWon't doLoses the compliance-first positioning.

Dated honestly. Roadmap items are not commitments to any specific tenant.

RegAlign® supports compliance governance. It does not provide legal or regulatory advice. Decisions, approvals and overrides remain the responsibility of identified humans in the audit trail.