RegAlign + RiskAlign

RegAlign and RiskAlign — two products in the Align product family.

Compliance and risk have always pulled from the same well. They've just never shared a bucket. RegAlign® and RiskAlign™ do.

RegAlign — obligations-up

For compliance.

Start with the regulator's words. End with defensible evidence.

  1. 1Regulatory change ingested
  2. 2Mapped to obligations
  3. 3Linked to controls
  4. 4Evidence captured & monitored
  5. 5Reported to the board
RiskAlign — risks-down

For risk.

Start with what could hurt the firm. End with appetite, controls and KRIs.

  1. 1Enterprise risk identified
  2. 2Inherent & residual scored
  3. 3Board appetite & limit set
  4. 4Controls & KRIs linked
  5. 5Scenarios stress-tested
They meet at the control.

Each product keeps its own control register. When both are in place, controls carry cross-references so a control that satisfies a RegAlign obligation and mitigates a RiskAlign risk appears in both views. Today that meeting point is a CSV bridge with a frozen contract; a runtime API is on the roadmap once both products have paying pilots.

Run them separately, or together.

CapabilityRegAlign onlyRiskAlign onlyTogether
Regulatory change tracking
Obligations register
Enterprise risk register
Risk appetite & KRIs
Shared control library✓ (cross-referenced)
Board packCompliance packRisk packCross-linked packs
Audit trailPer obligationPer riskCross-referenced (obligation ↔ risk lineage recorded in each product)