PILLAR 3 OF 3

Compliance.

Demonstrable adherence to external rules — SEC, FINRA, GLBA, state privacy, OFAC, and AICPA attestation. The densest pillar in U.S. financial services.

Evidence ledgerA ledger of stacked pages with evidence tags flowing from each — demonstrable adherence, backed by evidence.

Evidence, not assertions

Every obligation traces to a tracked remediation

The compliance pillar's job is traceability. Follow one obligation from the rulebook all the way to a fix.

  1. Regulatory obligation

    BSA/AML program & Customer Identification Program (FinCEN / FFIEC)

  2. Control / workflow

    AML Program Review + KYC/CDD Audit

  3. Evidence

    CIP procedures, SAR filings, transaction-monitoring records

  4. Finding

    CIP gap vs. current FFIEC/FinCEN standards — High

  5. Remediation

    Gap assessment; scope IA AML program design, tracked to close

High severityIllustrative

KYC / CIP Program — Prior Enforcement + Evolving Obligations

Evidence status
Confirmed (public enforcement record) / Conditional (post-remediation)
Affected obligation
AML/BSA — Customer Identification Program (CIP)

Recommended action

Gap-assess CIP/ITPP against current FFIEC & FinCEN standards; scope IA AML program design for 2028.

A financial-services workflow, in motion

Illustrative
  1. TriggerNew lending product crosses a BSA/AML threshold
  2. WorkflowAML Program Review runs in Gap mode
  3. OutputGap report + SAR-filing readiness, with owners

AML/BSA is one of 48 workflows. See how scoping works →

What we cover — regulators, regulations, frameworks, and attestations

  • SECRegulator

    SEC filing readiness (10-K/10-Q) workflow

  • FINRARegulator

    Covered within financial-regulation workflows

  • FinCENRegulator

    AML program review & SAR draft/filing workflows

  • SOXRegulation

    Financial-regulation control workflows

  • Basel IIIRegulation

    Capital adequacy assessment workflow

  • AML/BSARegulation

    AML program review, KYC/CDD audit, SAR workflows

  • GDPR / CCPA-CPRARegulation

    Privacy workflows — DSR tracker, DPIA, records

  • DORA / NIS2Regulation

    International-framework mapping workflows

  • ISO 27001Framework

    Gap analysis & Annex A workflow

  • SOC 2 (AICPA TSC)Attestation

    Control-evidence collection & checklist — evidence prep only, not an attestation

Coverage describes the workflows RuleboardAI runs. RuleboardAI does not issue attestations or certify compliance.

Evidence handling

How each obligation is sourced and verified

Illustrative
  • Capital adequacy ratios (CET1, Tier 1)

    SoFi Bank “well capitalized” across all OCC metrics.

    Capital Adequacy (Basel III)

    10-K FY2025

    Dated 2026-02-24

    Verified
  • CIP / KYC procedures

    $1.1M CIP/ITPP enforcement — gap-assess vs. current FFIEC/FinCEN standards.

    KYC/CDD Audit

    FINRA AWC (2024)

    Dated 2024-05-16

    Prior finding
  • SOC 2 Type II report

    No public SOC 2 report identified — requested in a full engagement.

    Vendor Risk Assessment

    Public sources

    Dated

    Data gap
  • SAR filing records

    Not verifiable from public sources; program exists as a bank requirement.

    SAR Draft & Filing

    Non-public

    Dated

    Data gap

Every item carries its workflow, source, date, and verification state. Unmet requests are logged as data gaps, not omitted.

Compliance calendar

Dated obligations on the horizon

Illustrative
  1. May 2024

    FINRA settlement on CIP/ITPP gaps ($1.1M) for 2018–2019 conduct.

    Source: FINRA

  2. Jan 1, 2024

    Direct CFPB supervision commenced after crossing the $10B asset threshold.

    Source: SoFi 10-K

  3. Jul 1, 2026Current state

    This preliminary profile — current-state baseline from public sources.

  4. Jan 1, 2028Effective date

    FinCEN Investment Adviser AML rule compliance date for RIAs and ERAs.

    Source: FinCEN

Each entry restates a date cited elsewhere in this profile — no invented deadlines.

Who this is for

Financial institutions

Basel III, SOX, AML/BSA, and SEC filings in one workflow.

SaaS & healthcare

SOC 2, HIPAA, GDPR, and DORA under a single evidence model.

Multi-jurisdiction operators

ISO 27001, GDPR, CCPA/CPRA, and NIS2 aligned to shared controls.

SOC 2 (Trust Services)

AICPA TSCCC1–CC9Type I/II
  • Control Evidence Collection & Checklist
  • Vendor Risk Assessment (SOC 2 scope)
  • Security Policy Library
  • Penetration Test Gap Report
  • Continuous Control Testing Schedule

Includes all 5 workflows above.

Financial Regulation

Basel IIISOXSECAML/BSA
  • Capital Adequacy Assessment (Basel III)
  • SAR Draft & Filing Workflow
  • KYC/CDD Audit
  • SEC Filing Readiness (10-K/10-Q)
  • AML Program Review

Includes all 5 workflows above.

International Frameworks

DORAISO 27001GDPRNIS2
  • DORA ICT Risk Assessment (EU Financial)
  • ISO 27001 Gap Analysis & Annex A
  • GDPR Article 30 Processing Records
  • NIS2 Compliance Mapping
  • Cross-border Data Transfer Mechanisms

Includes all 5 workflows above.

Privacy & Data Protection

GDPRCCPA/CPRAHIPAADPIA
  • Data Subject Request (DSR) Tracker
  • Privacy Impact Assessment (DPIA)
  • Breach Notification Workflow
  • Data Retention Policy Review

Includes all 4 workflows above.

Ongoing / Scheduled

MonitoringChange MgmtCertification
  • Regulatory Change Monitor
  • Annual Control Recertification
  • Quarterly Risk Assessment Update
  • Compliance Calendar Management

Includes all 4 workflows above.

HR & People Risk

OffboardingAccess RevocationBackground Check
  • Offboarding & Access Revocation Workflow
  • Background Check Program
  • Insider Threat Assessment
  • HR Policy Compliance Review

Includes all 4 workflows above.