PILLAR 3 OF 3
Compliance.
Demonstrable adherence to external rules — SEC, FINRA, GLBA, state privacy, OFAC, and AICPA attestation. The densest pillar in U.S. financial services.
Evidence, not assertions
Every obligation traces to a tracked remediation
The compliance pillar's job is traceability. Follow one obligation from the rulebook all the way to a fix.
Regulatory obligation
BSA/AML program & Customer Identification Program (FinCEN / FFIEC)
Control / workflow
AML Program Review + KYC/CDD Audit
Evidence
CIP procedures, SAR filings, transaction-monitoring records
Finding
CIP gap vs. current FFIEC/FinCEN standards — High
Remediation
Gap assessment; scope IA AML program design, tracked to close
KYC / CIP Program — Prior Enforcement + Evolving Obligations
- Evidence status
- Confirmed (public enforcement record) / Conditional (post-remediation)
- Affected obligation
- AML/BSA — Customer Identification Program (CIP)
Recommended action
Gap-assess CIP/ITPP against current FFIEC & FinCEN standards; scope IA AML program design for 2028.
A financial-services workflow, in motion
Illustrative- TriggerNew lending product crosses a BSA/AML threshold
- WorkflowAML Program Review runs in Gap mode
- OutputGap report + SAR-filing readiness, with owners
AML/BSA is one of 48 workflows. See how scoping works →
What we cover — regulators, regulations, frameworks, and attestations
| Name | What it is | RuleboardAI workflow coverage |
|---|---|---|
| SEC | Regulator | SEC filing readiness (10-K/10-Q) workflow |
| FINRA | Regulator | Covered within financial-regulation workflows |
| FinCEN | Regulator | AML program review & SAR draft/filing workflows |
| SOX | Regulation | Financial-regulation control workflows |
| Basel III | Regulation | Capital adequacy assessment workflow |
| AML/BSA | Regulation | AML program review, KYC/CDD audit, SAR workflows |
| GDPR / CCPA-CPRA | Regulation | Privacy workflows — DSR tracker, DPIA, records |
| DORA / NIS2 | Regulation | International-framework mapping workflows |
| ISO 27001 | Framework | Gap analysis & Annex A workflow |
| SOC 2 (AICPA TSC) | Attestation | Control-evidence collection & checklist — evidence prep only, not an attestation |
- SECRegulator
SEC filing readiness (10-K/10-Q) workflow
- FINRARegulator
Covered within financial-regulation workflows
- FinCENRegulator
AML program review & SAR draft/filing workflows
- SOXRegulation
Financial-regulation control workflows
- Basel IIIRegulation
Capital adequacy assessment workflow
- AML/BSARegulation
AML program review, KYC/CDD audit, SAR workflows
- GDPR / CCPA-CPRARegulation
Privacy workflows — DSR tracker, DPIA, records
- DORA / NIS2Regulation
International-framework mapping workflows
- ISO 27001Framework
Gap analysis & Annex A workflow
- SOC 2 (AICPA TSC)Attestation
Control-evidence collection & checklist — evidence prep only, not an attestation
Coverage describes the workflows RuleboardAI runs. RuleboardAI does not issue attestations or certify compliance.
Evidence handling
How each obligation is sourced and verified
Capital adequacy ratios (CET1, Tier 1)
SoFi Bank “well capitalized” across all OCC metrics.
Capital Adequacy (Basel III)
10-K FY2025
Dated 2026-02-24
VerifiedCIP / KYC procedures
$1.1M CIP/ITPP enforcement — gap-assess vs. current FFIEC/FinCEN standards.
KYC/CDD Audit
FINRA AWC (2024)
Dated 2024-05-16
Prior findingSOC 2 Type II report
No public SOC 2 report identified — requested in a full engagement.
Vendor Risk Assessment
Public sources
Dated —
Data gapSAR filing records
Not verifiable from public sources; program exists as a bank requirement.
SAR Draft & Filing
Non-public
Dated —
Data gap
Every item carries its workflow, source, date, and verification state. Unmet requests are logged as data gaps, not omitted.
Compliance calendar
Dated obligations on the horizon
- May 2024
FINRA settlement on CIP/ITPP gaps ($1.1M) for 2018–2019 conduct.
Source: FINRA
- Jan 1, 2024
Direct CFPB supervision commenced after crossing the $10B asset threshold.
Source: SoFi 10-K
- Jul 1, 2026Current state
This preliminary profile — current-state baseline from public sources.
- Jan 1, 2028Effective date
FinCEN Investment Adviser AML rule compliance date for RIAs and ERAs.
Source: FinCEN
Each entry restates a date cited elsewhere in this profile — no invented deadlines.
Who this is for
Financial institutions
Basel III, SOX, AML/BSA, and SEC filings in one workflow.
SaaS & healthcare
SOC 2, HIPAA, GDPR, and DORA under a single evidence model.
Multi-jurisdiction operators
ISO 27001, GDPR, CCPA/CPRA, and NIS2 aligned to shared controls.
SOC 2 (Trust Services)
- Control Evidence Collection & Checklist
- Vendor Risk Assessment (SOC 2 scope)
- Security Policy Library
- Penetration Test Gap Report
- Continuous Control Testing Schedule
Includes all 5 workflows above.
Financial Regulation
- Capital Adequacy Assessment (Basel III)
- SAR Draft & Filing Workflow
- KYC/CDD Audit
- SEC Filing Readiness (10-K/10-Q)
- AML Program Review
Includes all 5 workflows above.
International Frameworks
- DORA ICT Risk Assessment (EU Financial)
- ISO 27001 Gap Analysis & Annex A
- GDPR Article 30 Processing Records
- NIS2 Compliance Mapping
- Cross-border Data Transfer Mechanisms
Includes all 5 workflows above.
Privacy & Data Protection
- Data Subject Request (DSR) Tracker
- Privacy Impact Assessment (DPIA)
- Breach Notification Workflow
- Data Retention Policy Review
Includes all 4 workflows above.
Ongoing / Scheduled
- Regulatory Change Monitor
- Annual Control Recertification
- Quarterly Risk Assessment Update
- Compliance Calendar Management
Includes all 4 workflows above.
HR & People Risk
- Offboarding & Access Revocation Workflow
- Background Check Program
- Insider Threat Assessment
- HR Policy Compliance Review
Includes all 4 workflows above.