Author: Admin Admin

  • Blog 6

    Strategy

    From annual RCSA to continuous risk: a roadmap for banks

    The once-a-year risk and control self-assessment was never a statement about how often risk changes. It was a statement about how much manual effort a cycle cost. Remove the manual effort, and the calendar stops making sense.

    Ask any Head of Operational Risk when their RCSA is “true,” and you will get an honest, uncomfortable answer: for about two weeks after sign-off. After that, vendors change, processes drift, a control owner leaves, a new payment rail goes live — and the register quietly diverges from reality until next year’s workshop season comes around to reconcile it.

    This is not a failure of discipline. It is the natural consequence of an assessment model built for a world where every data point had to be gathered by a human, in a meeting, into a spreadsheet. The annual cadence is the scar tissue of that effort.

    What “continuous” actually means

    Continuous risk does not mean running the same heavy workshop more often — that would just multiply the pain. It means the assessment stops being an event and becomes a state. Agents ingest control evidence, loss events, and external signals as they happen; the register re-scores itself as conditions move; and a human reviews exceptions rather than re-keying the whole inventory from scratch.

    The shift is the same one that credit risk made decades ago. No bank reassesses its loan book once a year in a room. Exposure is marked continuously, and people intervene on what moved. Operational risk has simply lacked the tooling to work the same way — until the assessment work could be carried by something other than a calendar full of analysts.

    When the cost of an assessment falls to near zero, the right frequency for it is “always.” The annual cycle survives only as long as the manual effort does.

    A four-phase roadmap

    The move from annual to continuous is not a rip-and-replace. The institutions that do this well treat it as a sequence that de-risks itself at every step, running in parallel with the existing cycle until the new model has earned trust.

    1. Connect the data you already havePoint agents at the registers, loss-event logs, control test results, and vendor data already sitting in your GRC platform and core systems. No new data mandates — just stop the manual pulls. This alone removes the staleness problem.
    2. Run agents in shadow, alongside the current cycleLet the assessment agents re-score in the background while your annual RCSA proceeds as normal. Compare. The gaps the agents surface weeks before the workshop are the proof point that wins the room.
    3. Quantify in dollars, not colorsConvert each re-scored risk into a financial exposure range with the actuarial engine, so the output speaks to the capital committee, not just the risk register. This is the moment operational risk earns a seat next to credit and market risk.
    4. Operate continuously, feeding capital and ORSARetire the calendar as the trigger. The register is now a live asset that feeds capital planning, ORSA, and board reporting on demand — with a full evidence trail behind every number.

    What changes for the board

    The most visible change is not speed; it is the nature of the conversation. A board that used to receive a point-in-time heat map now receives a trajectory: which exposures are rising, what they would cost, and how much warning there is. Board-pack preparation that consumed weeks compresses into hours, and the narrative improves because it is backed by evidence rather than assembled under deadline.

    The annual RCSA will not disappear overnight, and it does not need to. But its role changes — from the moment risk becomes visible, to a periodic attestation on top of a system that was already telling you the truth all year. That is the destination worth planning toward.

    SK
    Senthil K.
    Operational risk & GRC practitioner · Compler

    See your RCSA run continuously

    A 30-minute walkthrough on your own risk data — no migration required. We’ll show the register re-scoring itself, weeks before your next workshop would have caught it.

  • Blog 5

    Quantification

    Heat-maps lie. What capital-grade risk numbers look like

    The 5×5 red-amber-green grid is the most recognizable artifact in operational risk. It is also one of the most misleading. It looks like measurement. It is closer to a mood ring.

    Heat maps earn their place because they are easy to produce and easy to read in a meeting. But the qualities that make them convenient are exactly the ones that make them dangerous when real capital decisions ride on the output.

    Likelihood × ImpactTwo ordinal axes, twenty-five buckets, three colors. Every risk in the firm gets compressed into one of a handful of cells — and the arithmetic that produced the cell cannot survive contact with a capital model.

    Three lies the grid tells

    It pretends ordinal scores are numbers. A “4” on impact is not twice a “2.” The scale has no units, so you cannot add, average, or aggregate across risks without inventing math the scale never supported. A portfolio of “mediums” has no defined total.

    It throws away the tail. The grid’s top-right cell holds a once-a-decade catastrophe and a merely-bad quarter in the same square. Operational risk lives in that tail — and a model that cannot distinguish a P95 outcome from a P99.9 one is silent on exactly the events that determine solvency.

    It cannot speak to the CFO. A board can act on “this exposure has a 1-in-20 chance of costing more than $18 million.” No one can allocate capital against “amber.”

    A heat map answers “how worried should we be?” A capital-grade number answers “how much should we hold, and what would it cost us if we are wrong?”

    What capital-grade looks like

    The alternative is the same approach actuaries have used for insurance and that banks use for credit risk: model the frequency of loss events and the severity of each, then simulate the combined distribution thousands of times to see the full shape of what could happen — not just the average, but the tail.

    Mean / expected loss P99 P99.9
    $ loss →The decisions live in the tail, not at the mean

    Done properly, that produces a row of numbers a capital committee can actually use:

    Instead of a colorYou get
    Loss frequencyNegative Binomial — captures the overdispersion a Poisson model hides
    Loss severityLog-Normal with a calibrated heavy right tail
    Full distribution5,000 + 10,000 Monte Carlo runs, convergence-gated
    The tail itselfP99.9 via a GPD / Hill estimator above the P95 threshold
    Thin data, handledBühlmann credibility blends your history with an industry prior
    A capital figureBasel IV SMA capital, straight from the same model

    The point is not the acronyms. It is that every one of these outputs has units, can be aggregated across the portfolio, and converts a register entry into a dollar figure with a confidence level attached. The same risk that was “amber” becomes “expected loss $2.1M, P99.9 tail $18.4M, capital charge $X” — and now it belongs in the same conversation as credit and market risk.

    Keep the picture, lose the lie

    None of this means heat maps disappear. A colored grid is still a fine way to show a result to a non-technical audience. The mistake is letting it be the computation — letting the limits of a four-color scale define the limits of what your risk function can say. Compute in dollars and distributions; render in whatever picture helps the room. Just never confuse the picture for the number underneath it.

    C
    Compler Team
    AURA actuarial engine · Compler

    Put a dollar figure on every risk

    See AURA quantify your register — 35+ actuarial fields per assessment, from frequency and severity fits to a Basel IV SMA capital figure.

  • Blog 4

    Sovereignty

    Why your LLM’s passport matters under DPDP and GDPR

    For a regulated institution, the question is no longer only which model you use. It is where the model runs — and which jurisdiction’s law travels with every token your risk data passes through it.

    When a risk analyst asks an AI to assess a control or quantify an exposure, that request can carry deeply sensitive material: customer identifiers, loss-event detail, account data, internal control weaknesses. If the model answering sits in a shared cloud in another region, that data has just crossed a border — often without anyone in the second line intending it to. Under modern data-protection regimes, that crossing is a regulated act in itself.

    Residency is now a design decision, not a setting

    India’s DPDP Act 2023 draws a hard line around personal financial data and where it may be processed. The RBI IT Framework expects inference and storage to stay within India-approved boundaries. GDPR Article 25 demands data protection by design and by default — which is hard to claim when sensitive payloads leave your environment to reach a model. And under SOX, every instance of AI touching financial data needs to land in an audit trail you control.

    The common thread: where your model runs determines which regime applies, what you must prove, and how much of the burden falls on configuration after the fact versus architecture from the start. A bolt-on AI feature that calls a shared external endpoint cannot give you that control. It was not built to.

    A model’s “passport” — the jurisdiction it runs in — is becoming as material to a compliance review as the data it processes.

    Match the deployment to the mandate

    The practical answer is not a single global model. It is the ability to choose, per institution and per jurisdiction, where inference happens — and to have every mode governed identically so security never depends on which one you picked.

    RegulationRegionDeployment that fits
    DPDP Act 2023IndiaLocal LLM — personal data never exits the network
    RBI IT FrameworkIndiaLocal LLM / BYOK within approved boundaries
    GDPR (Art. 25)EU / UKBYOK · EU region, or Local for maximum control
    MAS TRMSingaporeBYOK in your own project, or Local
    PCI-DSSGlobalLocal LLM — cardholder data isolated, no external calls
    SOX (IT controls)USA / GlobalBYOK / Local — full audit trail of AI access

    Redact before you reason

    Choosing where the model runs handles residency. It does not, on its own, handle what the model sees. Even inside an approved region, a well-designed system should strip personally identifiable information — keys, email, national IDs, phone numbers — before any payload reaches inference, and sanitize the model’s output before it returns to the user. In a fully air-gapped deployment, payloads stay local-only and never traverse an external boundary at all.

    That combination — pick the jurisdiction, then minimize what crosses any boundary within it — is what lets a CISO sign off on AI in a regulated environment without a carve-out or a leap of faith. Sovereignty stops being a clause in a vendor contract and becomes a property of the architecture.

    The institutions moving fastest on AI in risk are not the ones with the loosest rules. They are the ones who made residency a first-class choice, so that adopting AI never meant renegotiating their obligations.

    C
    Compler Team
    Platform & security · Compler

    Run AI where your regulator can see it

    From cloud to fully air-gapped — every deployment mode governed identically, with PII redaction before inference and a full audit trail behind every AI action.

  • blog 3

    Heat-maps lie. What capital-grade risk numbers look like — Compler
    Quantification

    Heat-maps lie. What capital-grade risk numbers look like

    Compler Team·April 2026·6 min read

    The 5×5 red-amber-green grid is the most recognizable artifact in operational risk. It is also one of the most misleading. It looks like measurement. It is closer to a mood ring.

    Heat maps earn their place because they are easy to produce and easy to read in a meeting. But the qualities that make them convenient are exactly the ones that make them dangerous when real capital decisions ride on the output.

    Likelihood × ImpactTwo ordinal axes, twenty-five buckets, three colors. Every risk in the firm gets compressed into one of a handful of cells — and the arithmetic that produced the cell cannot survive contact with a capital model.

    Three lies the grid tells

    It pretends ordinal scores are numbers. A “4” on impact is not twice a “2.” The scale has no units, so you cannot add, average, or aggregate across risks without inventing math the scale never supported. A portfolio of “mediums” has no defined total.

    It throws away the tail. The grid’s top-right cell holds a once-a-decade catastrophe and a merely-bad quarter in the same square. Operational risk lives in that tail — and a model that cannot distinguish a P95 outcome from a P99.9 one is silent on exactly the events that determine solvency.

    It cannot speak to the CFO. A board can act on “this exposure has a 1-in-20 chance of costing more than $18 million.” No one can allocate capital against “amber.”

    A heat map answers “how worried should we be?” A capital-grade number answers “how much should we hold, and what would it cost us if we are wrong?”

    What capital-grade looks like

    The alternative is the same approach actuaries have used for insurance and that banks use for credit risk: model the frequency of loss events and the severity of each, then simulate the combined distribution thousands of times to see the full shape of what could happen — not just the average, but the tail.

    Mean / expected loss P99 P99.9
    $ loss →The decisions live in the tail, not at the mean

    Done properly, that produces a row of numbers a capital committee can actually use:

    Instead of a colorYou get
    Loss frequencyNegative Binomial — captures the overdispersion a Poisson model hides
    Loss severityLog-Normal with a calibrated heavy right tail
    Full distribution5,000 + 10,000 Monte Carlo runs, convergence-gated
    The tail itselfP99.9 via a GPD / Hill estimator above the P95 threshold
    Thin data, handledBühlmann credibility blends your history with an industry prior
    A capital figureBasel IV SMA capital, straight from the same model

    The point is not the acronyms. It is that every one of these outputs has units, can be aggregated across the portfolio, and converts a register entry into a dollar figure with a confidence level attached. The same risk that was “amber” becomes “expected loss $2.1M, P99.9 tail $18.4M, capital charge $X” — and now it belongs in the same conversation as credit and market risk.

    Keep the picture, lose the lie

    None of this means heat maps disappear. A colored grid is still a fine way to show a result to a non-technical audience. The mistake is letting it be the computation — letting the limits of a four-color scale define the limits of what your risk function can say. Compute in dollars and distributions; render in whatever picture helps the room. Just never confuse the picture for the number underneath it.

    C
    Compler Team
    AURA actuarial engine · Compler

    Put a dollar figure on every risk

    See AURA quantify your register — 35+ actuarial fields per assessment.

    Request a demo →

  • blog 2

    Why your LLM’s passport matters under DPDP and GDPR — Compler
    Sovereignty

    Why your LLM’s passport matters under DPDP and GDPR

    Compler Team·May 2026·5 min read

    For a regulated institution, the question is no longer only which model you use. It is where the model runs — and which jurisdiction’s law travels with every token your risk data passes through it.

    When a risk analyst asks an AI to assess a control or quantify an exposure, that request can carry deeply sensitive material: customer identifiers, loss-event detail, account data, internal control weaknesses. If the model answering sits in a shared cloud in another region, that data has just crossed a border — often without anyone in the second line intending it to. Under modern data-protection regimes, that crossing is a regulated act in itself.

    Residency is now a design decision, not a setting

    India’s DPDP Act 2023 draws a hard line around personal financial data and where it may be processed. The RBI IT Framework expects inference and storage to stay within India-approved boundaries. GDPR Article 25 demands data protection by design and by default — which is hard to claim when sensitive payloads leave your environment to reach a model. And under SOX, every instance of AI touching financial data needs to land in an audit trail you control.

    The common thread: where your model runs determines which regime applies, what you must prove, and how much of the burden falls on configuration after the fact versus architecture from the start. A bolt-on AI feature that calls a shared external endpoint cannot give you that control. It was not built to.

    A model’s “passport” — the jurisdiction it runs in — is becoming as material to a compliance review as the data it processes.

    Match the deployment to the mandate

    The practical answer is not a single global model. It is the ability to choose, per institution and per jurisdiction, where inference happens — and to have every mode governed identically so security never depends on which one you picked.

    RegulationRegionDeployment that fits
    DPDP Act 2023IndiaLocal LLM — personal data never exits the network
    RBI IT FrameworkIndiaLocal LLM / BYOK within approved boundaries
    GDPR (Art. 25)EU / UKBYOK · EU region, or Local for maximum control
    MAS TRMSingaporeBYOK in your own project, or Local
    PCI-DSSGlobalLocal LLM — cardholder data isolated, no external calls
    SOX (IT controls)USA / GlobalBYOK / Local — full audit trail of AI access

    Redact before you reason

    Choosing where the model runs handles residency. It does not, on its own, handle what the model sees. Even inside an approved region, a well-designed system should strip personally identifiable information — keys, email, national IDs, phone numbers — before any payload reaches inference, and sanitize the model’s output before it returns to the user. In a fully air-gapped deployment, payloads stay local-only and never traverse an external boundary at all.

    That combination — pick the jurisdiction, then minimize what crosses any boundary within it — is what lets a CISO sign off on AI in a regulated environment without a carve-out or a leap of faith. Sovereignty stops being a clause in a vendor contract and becomes a property of the architecture.

    The institutions moving fastest on AI in risk are not the ones with the loosest rules. They are the ones who made residency a first-class choice, so that adopting AI never meant renegotiating their obligations.

    C
    Compler Team
    Platform & security · Compler

    Run AI where your regulator can see it

    From cloud to fully air-gapped — every mode governed identically.

    Explore deployment modes →
  • Blog 1

    From annual RCSA to continuous risk: a roadmap for banks — Compler
    Strategy

    From annual RCSA to continuous risk: a roadmap for banks

    Senthil K.·June 2026·8 min read

    The once-a-year risk and control self-assessment was never a statement about how often risk changes. It was a statement about how much manual effort a cycle cost. Remove the manual effort, and the calendar stops making sense.

    Ask any Head of Operational Risk when their RCSA is “true,” and you will get an honest, uncomfortable answer: for about two weeks after sign-off. After that, vendors change, processes drift, a control owner leaves, a new payment rail goes live — and the register quietly diverges from reality until next year’s workshop season comes around to reconcile it.

    This is not a failure of discipline. It is the natural consequence of an assessment model built for a world where every data point had to be gathered by a human, in a meeting, into a spreadsheet. The annual cadence is the scar tissue of that effort.

    What “continuous” actually means

    Continuous risk does not mean running the same heavy workshop more often — that would just multiply the pain. It means the assessment stops being an event and becomes a state. Agents ingest control evidence, loss events, and external signals as they happen; the register re-scores itself as conditions move; and a human reviews exceptions rather than re-keying the whole inventory from scratch.

    The shift is the same one that credit risk made decades ago. No bank reassesses its loan book once a year in a room. Exposure is marked continuously, and people intervene on what moved. Operational risk has simply lacked the tooling to work the same way — until the assessment work could be carried by something other than a calendar full of analysts.

    When the cost of an assessment falls to near zero, the right frequency for it is “always.” The annual cycle survives only as long as the manual effort does.

    A four-phase roadmap

    The move from annual to continuous is not a rip-and-replace. The institutions that do this well treat it as a sequence that de-risks itself at every step, running in parallel with the existing cycle until the new model has earned trust.

    1. Connect the data you already havePoint agents at the registers, loss-event logs, control test results, and vendor data already sitting in your GRC platform and core systems. No new data mandates — just stop the manual pulls. This alone removes the staleness problem.
    2. Run agents in shadow, alongside the current cycleLet the assessment agents re-score in the background while your annual RCSA proceeds as normal. Compare. The gaps the agents surface weeks before the workshop are the proof point that wins the room.
    3. Quantify in dollars, not colorsConvert each re-scored risk into a financial exposure range with the actuarial engine, so the output speaks to the capital committee, not just the risk register. This is the moment operational risk earns a seat next to credit and market risk.
    4. Operate continuously, feeding capital and ORSARetire the calendar as the trigger. The register is now a live asset that feeds capital planning, ORSA, and board reporting on demand — with a full evidence trail behind every number.

    What changes for the board

    The most visible change is not speed; it is the nature of the conversation. A board that used to receive a point-in-time heat map now receives a trajectory: which exposures are rising, what they would cost, and how much warning there is. Board-pack preparation that consumed weeks compresses into hours, and the narrative improves because it is backed by evidence rather than assembled under deadline.

    The annual RCSA will not disappear overnight, and it does not need to. But its role changes — from the moment risk becomes visible, to a periodic attestation on top of a system that was already telling you the truth all year. That is the destination worth planning toward.

    SK
    Senthil K.
    Operational risk & GRC practitioner · Compler

    See your RCSA run continuously

    A 30-minute walkthrough on your own risk data — no migration required.

    Request a demo →