RegAlign + RiskAlign

RegAlign and RiskAlign — two products in the Align product family.

Compliance and risk have always pulled from the same well. They've just never shared a bucket. RegAlign® and RiskAlign™ do.

RegAlign — obligations-up

For compliance.

Start with the regulator's words. End with defensible evidence.

  1. 1Regulatory change ingested
  2. 2Mapped to obligations
  3. 3Linked to controls
  4. 4Evidence captured & monitored
  5. 5Reported to the board
RiskAlign — risks-down

For risk.

Start with what could hurt the firm. End with appetite, controls and KRIs.

  1. 1Enterprise risk identified
  2. 2Inherent & residual scored
  3. 3Board appetite & limit set
  4. 4Controls & KRIs linked
  5. 5Scenarios stress-tested
They meet at the control.

Each product keeps its own control register. Where both are in place, an obligation in RegAlign and a risk in RiskAlign can be related to the same control through governed, bounded interoperability — today a manual CSV exchange against an agreed data contract, applied per approved use case. This is not a shared or automatically synchronised record. Any future API interoperability is subject to separate architecture, evidence and approval gates.

Run them separately, or together.

CapabilityRegAlign onlyRiskAlign onlyTogether
Regulatory change tracking
Obligations register
Enterprise risk register
Risk appetite & KRIs
Control registerSeparate registers, relatable via governed exchange
Board packCompliance packRisk packSeparate packs per product
Audit trailPer obligationPer riskHeld separately in each product