Status — Align suite roadmap. RegAlign® is in pilot. RiskAlign™ is in development (Milestone 2). The bridge contracts described below are implemented on the RegAlign side; a live end-to-end round-trip with RiskAlign™ is not yet verified. This page describes the intended pairing, not two shipping products. See /pilot for what is live today.

RegAlign® + RiskAlign™ · roadmap pairing

Two systems. One spine.

Compliance and risk have always pulled from the same well. They've just never shared a bucket. RegAlign® and RiskAlign™ are designed so that — once both are live — they will. RegAlign is pilot-stage today; RiskAlign is in active development.

RegAlign — obligations-up

For compliance.

Start with the regulator's words. End with defensible evidence.

  1. 1Regulatory change ingested
  2. 2Mapped to obligations
  3. 3Linked to controls
  4. 4Evidence captured & monitored
  5. 5Reported to the board
RiskAlign — risks-down

For risk.

Start with what could hurt the firm. End with appetite, controls and KRIs.

  1. 1Enterprise risk identified
  2. 2Inherent & residual scored
  3. 3Board appetite & limit set
  4. 4Controls & KRIs linked
  5. 5Scenarios stress-tested
They meet at the control.

One shared control reference. RegAlign records the obligations a control satisfies. RiskAlign records the risks a control mitigates. Update once, both views move.

Run them separately, or together.

CapabilityRegAlign onlyRiskAlign onlyTogether
Regulatory change tracking
Obligations register
Enterprise risk register
Risk appetite & KRIs
Shared control reference✓ (one slug, two views)
Board packCompliance packRisk packCombined pack
Audit trailPer obligationPer riskEnd-to-end

Today the bridge is a CSV obligation export from RegAlign that RiskAlign imports as read-only links. A tenant-scoped REST endpoint is on the v1.1 roadmap.

Terminology note — BRA vs ERM

RegAlign ships the BRA (Business Risk Assessment) — the AML/CFT/CPF firm-wide risk assessment required by JFSC AML/CFT/CPF Handbook §2 / UK MLR2017 reg 18. Equivalent to BWRA (UK) and "EWRA" (industry synonym in AML practice). Per the three-lines model: prepared by the business / senior management (1LoD), reviewed and challenged by the MLRO/MLCO (2LoD), and approved by the board.

RiskAlign ships ERM (Enterprise Risk Management — COSO ERM 2017 / ISO 31000:2018). A different artefact for a different buyer (the ERM register is prepared by the CRO / Risk function aggregating business-owner inputs and approved by the Board Risk Committee), covering strategic, operational, financial, technology, people, reputational risk. The two products are complementary, not duplicative.