Methodology overview

Scoring standards

RCPS Methodology & Scoring Standards

What an RCPS score means, how evidence moves it, and what it cannot conclude. This is the standard every RuleboardAI report is produced under.

Version 1.0Effective July 21, 2026Contact: support@ruleboardai.com

1. Purpose and intended use

RCPS (Regulatory Classification & Profiling System) is RuleboardAI's method for turning fragmented regulatory information into a structured, comparable view of an institution's regulatory position. It answers three questions in order: which obligations apply (classification), which work matters (workflow scoping), and how mature each control area is (maturity scoring).

It is intended as decision-support intelligence for compliance, risk, and executive teams — a way to prioritize, prepare, and verify. It is not an audit standard, and its scores are not regulatory grades. The limitations in §10 are part of the methodology, not a footnote to it.

2. The two seven-axis layers

RCPS uses seven axes twice, for two different jobs — a distinction worth stating plainly because both layers appear across this site. Classification axes describe what the entity is, and determine which of the 48 workflows apply. Maturity axes describe how developed each control area is, and are what the 1–5 scores attach to.

3. Classification axes

Axis

Listing status

What it determines

Public, private, or subsidiary — drives disclosure-driven obligations.

Axis

Company size

What it determines

Asset and headcount scale — drives thresholds and examiner expectations.

Axis

Industry

What it determines

Banking, broker-dealer, advisory, fintech, insurance — drives the primary rulebooks.

Axis

Geography

What it determines

Jurisdictions of operation — drives federal, state, and cross-border regimes.

Axis

Data intensity

What it determines

Volume and sensitivity of data handled — drives privacy and security obligations.

Axis

Ownership

What it determines

Parent, sponsor, or independent — drives consolidated and affiliate obligations.

Axis

Growth stage

What it determines

Startup through mature — drives which controls are expected to exist by now.

4. Workflow-scoping logic

The classification resolves a fixed universe of 48 workflows across 11 categories into three buckets. In scope: the classification makes the obligation applicable. Conditional: applicability depends on a fact the evidence has not yet resolved — the workflow stays visible until it does. Out of scope: the classification excludes it, and it is excluded from scoring rather than scored as absent. The buckets are reported in every profile, so coverage is checkable rather than asserted.

Worked example

Scope determination — sample profile

Illustrative

Workflow scoping

48 workflows

Every client is scored against the same 48-workflow universe across 11 categories. The engine sorts each workflow into one of three buckets — nothing applicable is missed, nothing irrelevant is run.

  • 27

    In scope

    Applies to this client — runs this cycle.

  • 9

    Conditional

    Applies only if a trigger is met — flagged for review.

  • 12

    Out of scope

    Not applicable to this client — documented, not ignored.

Illustrative split — the actual scope is determined per client during RCPS classification.

How the 48-workflow universe resolves for the public sample entity: 27 in scope, 9 conditional.

See it in the sample profile →

5. Maturity axes and the 1–5 scale

Each in-scope control area is scored on seven maturity axes: Governance, Risk Management, Compliance, Cybersecurity, Third-Party Risk, Privacy, Monitoring. Scores use a five-level scale; a score is assigned only when the evidence supports it, at the level definitions below.

Level

1

Name

Initial

Definition

The control area is ad hoc. Activity depends on individuals, is largely undocumented, and produces little or no retained evidence.

Level

2

Name

Developing

Definition

Elements of the control area exist but are partial: some documentation, inconsistent application, and evidence that exists in places but cannot be produced on demand.

Level

3

Name

Defined

Definition

The control area is documented, has named owners, and is applied consistently across the organization. Evidence exists and can be located.

Level

4

Name

Managed

Definition

The control area is measured. Performance is reviewed on a schedule, exceptions are tracked to closure, and evidence is retained systematically.

Level

5

Name

Optimized

Definition

The control area is continuously improved: tested, integrated with adjacent controls, and adapted ahead of regulatory change rather than after it.

Worked example

Maturity scorecard — sample profile

Illustrative

Composite maturity

2.6 / 5.0

Defined

Achievable target

3.8 / 5.0

  • Governance3.1 / 5
  • Risk Management2.2 / 5
  • Compliance2.9 / 5
  • Cybersecurity2.0 / 5
  • Third-Party Risk2.7 / 5
  • Privacy3.0 / 5
  • Monitoring2.3 / 5

RCPS maturity is scored 1–5 across seven axes. The vertical marker on each bar is the achievable target from the sample assessment. Illustrative — scored per entity during classification.

The seven maturity axes as they appear in a delivered report, with the composite and an achievable target.

See the full sample →

6. Composite-score treatment

The composite is the average of the applicable maturity axes, reported to one decimal, alongside an achievable target— the level the entity's classification and stage make realistic, not a universal 5.0. Axes marked Not Applicable are excluded, never zero-filled. The composite is a summary for orientation: it always ships with the axis detail and findings beneath it, and it is never a substitute for reading them or for professional judgment.

7. Evidence states and finding labels

Every evidence item carries one of six states, and every finding carries one of four labels. The states describe the evidence; the labels describe the conclusion drawn from it. A conclusion can never be labeled stronger than its evidence state supports.

Evidence state

Publicly Observable

Definition

Established from public sources — filings, registers, enforcement databases, disclosures. The basis of every preliminary profile.

Evidence state

Client-Provided

Definition

Supplied by the client under a signed Letter of Authorization, but not yet corroborated.

Evidence state

Verified

Definition

Corroborated against an authoritative source (or client evidence reviewed and confirmed). Only verified evidence supports verified conclusions.

Evidence state

Partially Verified

Definition

Corroborated in part; the unresolved remainder is stated explicitly rather than assumed.

Evidence state

Unresolved

Definition

Sought but not established. Recorded in the data-gap register with the question or document that would resolve it.

Evidence state

Not Applicable

Definition

Outside the entity's classification. Excluded from scoring rather than scored as absent.

Finding label

Confirmed

Definition

Supported by verified or publicly observable evidence directly on point.

Finding label

Likely

Definition

Supported by consistent indirect evidence; stated with its inference visible.

Finding label

Conditional

Definition

Holds only under stated assumptions or pending specific evidence.

Finding label

Escalate

Definition

Requires human judgment or professional advice beyond the report's scope.

Preliminary vs. verified conclusions

A preliminary conclusion rests on Publicly Observable evidence alone — the basis of every free profile and every outside-in report, and it is labeled as such on the face of the deliverable. A verified conclusion requires Verified evidence, which in turn requires client materials supplied under a signed Letter of Authorization. Upgrading a conclusion from preliminary to verified is always explicit — never silent.

Data gaps are first-class output. Anything sought but Unresolved is reported in the data-gap register with the question or document that would resolve it — a gap is never guessed into a score.

8. Human-review points

  • Classification sign-off — the RCPS classification and resulting workflow scope are reviewed by a person before scoring begins.
  • Finding review — every finding and its label is human-reviewed before delivery; nothing ships straight from automation.
  • Escalation — any conclusion labeled Escalate is routed to human judgment rather than reported as settled.
  • Monitoring updates — each monthly update is reviewed and mapped by a person before it reaches a client tracker.

9. Version governance

The methodology is versioned. Reports cite the version they were produced under; a change in meaning — a level definition, an evidence state, the scoping logic — requires a new version, a new effective date, and a changelog entry here. Questions about any version: support@ruleboardai.com.

Version

1.0

Effective

July 21, 2026

Change

Initial published methodology: RCPS classification and maturity axes, 1–5 maturity scale, evidence states, workflow-scoping logic, and limitations.

10. Known limitations

Read before relying on any score

  • Public-source constraint: preliminary conclusions reflect what public sources reveal. Internal reality may be stronger or weaker; that residual uncertainty is why preliminary and verified conclusions are labeled differently.
  • Judgment-based scoring: maturity levels are assigned by structured human judgment against the level definitions. The scale has not been statistically validated, and no claim of statistical validation is made.
  • Point-in-time: scores describe the evidence available on the report date. They age as facts change.
  • Not a regulatory grade: RCPS scores are not issued, endorsed, or recognized by any regulator, and do not predict examination outcomes.
  • Not assurance: an RCPS score is not an audit opinion, attestation, or certification, and a composite score never replaces professional judgment.

11. Appropriate and inappropriate uses

Use RCPS to

  • Prioritizing which control areas to strengthen or verify first
  • Structuring exam, diligence, or board preparation around evidence and gaps
  • Tracking maturity movement across reporting periods
  • Framing verification questions for counterparties and vendors

Do not use RCPS to

  • Treating a score as an audit result, certification, or regulatory grade
  • Representing a score to a regulator, auditor, or counterparty as assurance
  • Substituting the composite for reading the findings and gaps beneath it
  • Making legal, investment, or transaction decisions on the score alone

RCPS Methodology v1.0 · Effective July 21, 2026 · RuleboardAI LLC