Scoring standards
RCPS Methodology & Scoring Standards
What an RCPS score means, how evidence moves it, and what it cannot conclude. This is the standard every RuleboardAI report is produced under.
1. Purpose and intended use
RCPS (Regulatory Classification & Profiling System) is RuleboardAI's method for turning fragmented regulatory information into a structured, comparable view of an institution's regulatory position. It answers three questions in order: which obligations apply (classification), which work matters (workflow scoping), and how mature each control area is (maturity scoring).
It is intended as decision-support intelligence for compliance, risk, and executive teams — a way to prioritize, prepare, and verify. It is not an audit standard, and its scores are not regulatory grades. The limitations in §10 are part of the methodology, not a footnote to it.
2. The two seven-axis layers
RCPS uses seven axes twice, for two different jobs — a distinction worth stating plainly because both layers appear across this site. Classification axes describe what the entity is, and determine which of the 48 workflows apply. Maturity axes describe how developed each control area is, and are what the 1–5 scores attach to.
3. Classification axes
| Axis | What it determines |
|---|---|
| Listing status | Public, private, or subsidiary — drives disclosure-driven obligations. |
| Company size | Asset and headcount scale — drives thresholds and examiner expectations. |
| Industry | Banking, broker-dealer, advisory, fintech, insurance — drives the primary rulebooks. |
| Geography | Jurisdictions of operation — drives federal, state, and cross-border regimes. |
| Data intensity | Volume and sensitivity of data handled — drives privacy and security obligations. |
| Ownership | Parent, sponsor, or independent — drives consolidated and affiliate obligations. |
| Growth stage | Startup through mature — drives which controls are expected to exist by now. |
Axis
Listing status
What it determines
Public, private, or subsidiary — drives disclosure-driven obligations.
Axis
Company size
What it determines
Asset and headcount scale — drives thresholds and examiner expectations.
Axis
Industry
What it determines
Banking, broker-dealer, advisory, fintech, insurance — drives the primary rulebooks.
Axis
Geography
What it determines
Jurisdictions of operation — drives federal, state, and cross-border regimes.
Axis
Data intensity
What it determines
Volume and sensitivity of data handled — drives privacy and security obligations.
Axis
Ownership
What it determines
Parent, sponsor, or independent — drives consolidated and affiliate obligations.
Axis
Growth stage
What it determines
Startup through mature — drives which controls are expected to exist by now.
4. Workflow-scoping logic
The classification resolves a fixed universe of 48 workflows across 11 categories into three buckets. In scope: the classification makes the obligation applicable. Conditional: applicability depends on a fact the evidence has not yet resolved — the workflow stays visible until it does. Out of scope: the classification excludes it, and it is excluded from scoring rather than scored as absent. The buckets are reported in every profile, so coverage is checkable rather than asserted.
Worked example
Scope determination — sample profile
Workflow scoping
48 workflowsEvery client is scored against the same 48-workflow universe across 11 categories. The engine sorts each workflow into one of three buckets — nothing applicable is missed, nothing irrelevant is run.
- 27
In scope
Applies to this client — runs this cycle.
- 9
Conditional
Applies only if a trigger is met — flagged for review.
- 12
Out of scope
Not applicable to this client — documented, not ignored.
Illustrative split — the actual scope is determined per client during RCPS classification.
How the 48-workflow universe resolves for the public sample entity: 27 in scope, 9 conditional.
5. Maturity axes and the 1–5 scale
Each in-scope control area is scored on seven maturity axes: Governance, Risk Management, Compliance, Cybersecurity, Third-Party Risk, Privacy, Monitoring. Scores use a five-level scale; a score is assigned only when the evidence supports it, at the level definitions below.
| Level | Name | Definition |
|---|---|---|
| 1 | Initial | The control area is ad hoc. Activity depends on individuals, is largely undocumented, and produces little or no retained evidence. |
| 2 | Developing | Elements of the control area exist but are partial: some documentation, inconsistent application, and evidence that exists in places but cannot be produced on demand. |
| 3 | Defined | The control area is documented, has named owners, and is applied consistently across the organization. Evidence exists and can be located. |
| 4 | Managed | The control area is measured. Performance is reviewed on a schedule, exceptions are tracked to closure, and evidence is retained systematically. |
| 5 | Optimized | The control area is continuously improved: tested, integrated with adjacent controls, and adapted ahead of regulatory change rather than after it. |
Level
1
Name
Initial
Definition
The control area is ad hoc. Activity depends on individuals, is largely undocumented, and produces little or no retained evidence.
Level
2
Name
Developing
Definition
Elements of the control area exist but are partial: some documentation, inconsistent application, and evidence that exists in places but cannot be produced on demand.
Level
3
Name
Defined
Definition
The control area is documented, has named owners, and is applied consistently across the organization. Evidence exists and can be located.
Level
4
Name
Managed
Definition
The control area is measured. Performance is reviewed on a schedule, exceptions are tracked to closure, and evidence is retained systematically.
Level
5
Name
Optimized
Definition
The control area is continuously improved: tested, integrated with adjacent controls, and adapted ahead of regulatory change rather than after it.
Worked example
Maturity scorecard — sample profile
Composite maturity
2.6 / 5.0
Defined
Achievable target
3.8 / 5.0
- Governance3.1 / 5
- Risk Management2.2 / 5
- Compliance2.9 / 5
- Cybersecurity2.0 / 5
- Third-Party Risk2.7 / 5
- Privacy3.0 / 5
- Monitoring2.3 / 5
RCPS maturity is scored 1–5 across seven axes. The vertical marker on each bar is the achievable target from the sample assessment. Illustrative — scored per entity during classification.
The seven maturity axes as they appear in a delivered report, with the composite and an achievable target.
6. Composite-score treatment
The composite is the average of the applicable maturity axes, reported to one decimal, alongside an achievable target— the level the entity's classification and stage make realistic, not a universal 5.0. Axes marked Not Applicable are excluded, never zero-filled. The composite is a summary for orientation: it always ships with the axis detail and findings beneath it, and it is never a substitute for reading them or for professional judgment.
7. Evidence states and finding labels
Every evidence item carries one of six states, and every finding carries one of four labels. The states describe the evidence; the labels describe the conclusion drawn from it. A conclusion can never be labeled stronger than its evidence state supports.
| Evidence state | Definition |
|---|---|
| Publicly Observable | Established from public sources — filings, registers, enforcement databases, disclosures. The basis of every preliminary profile. |
| Client-Provided | Supplied by the client under a signed Letter of Authorization, but not yet corroborated. |
| Verified | Corroborated against an authoritative source (or client evidence reviewed and confirmed). Only verified evidence supports verified conclusions. |
| Partially Verified | Corroborated in part; the unresolved remainder is stated explicitly rather than assumed. |
| Unresolved | Sought but not established. Recorded in the data-gap register with the question or document that would resolve it. |
| Not Applicable | Outside the entity's classification. Excluded from scoring rather than scored as absent. |
Evidence state
Publicly Observable
Definition
Established from public sources — filings, registers, enforcement databases, disclosures. The basis of every preliminary profile.
Evidence state
Client-Provided
Definition
Supplied by the client under a signed Letter of Authorization, but not yet corroborated.
Evidence state
Verified
Definition
Corroborated against an authoritative source (or client evidence reviewed and confirmed). Only verified evidence supports verified conclusions.
Evidence state
Partially Verified
Definition
Corroborated in part; the unresolved remainder is stated explicitly rather than assumed.
Evidence state
Unresolved
Definition
Sought but not established. Recorded in the data-gap register with the question or document that would resolve it.
Evidence state
Not Applicable
Definition
Outside the entity's classification. Excluded from scoring rather than scored as absent.
| Finding label | Definition |
|---|---|
| Confirmed | Supported by verified or publicly observable evidence directly on point. |
| Likely | Supported by consistent indirect evidence; stated with its inference visible. |
| Conditional | Holds only under stated assumptions or pending specific evidence. |
| Escalate | Requires human judgment or professional advice beyond the report's scope. |
Finding label
Confirmed
Definition
Supported by verified or publicly observable evidence directly on point.
Finding label
Likely
Definition
Supported by consistent indirect evidence; stated with its inference visible.
Finding label
Conditional
Definition
Holds only under stated assumptions or pending specific evidence.
Finding label
Escalate
Definition
Requires human judgment or professional advice beyond the report's scope.
Preliminary vs. verified conclusions
A preliminary conclusion rests on Publicly Observable evidence alone — the basis of every free profile and every outside-in report, and it is labeled as such on the face of the deliverable. A verified conclusion requires Verified evidence, which in turn requires client materials supplied under a signed Letter of Authorization. Upgrading a conclusion from preliminary to verified is always explicit — never silent.
Data gaps are first-class output. Anything sought but Unresolved is reported in the data-gap register with the question or document that would resolve it — a gap is never guessed into a score.
8. Human-review points
- Classification sign-off — the RCPS classification and resulting workflow scope are reviewed by a person before scoring begins.
- Finding review — every finding and its label is human-reviewed before delivery; nothing ships straight from automation.
- Escalation — any conclusion labeled Escalate is routed to human judgment rather than reported as settled.
- Monitoring updates — each monthly update is reviewed and mapped by a person before it reaches a client tracker.
9. Version governance
The methodology is versioned. Reports cite the version they were produced under; a change in meaning — a level definition, an evidence state, the scoping logic — requires a new version, a new effective date, and a changelog entry here. Questions about any version: support@ruleboardai.com.
| Version | Effective | Change |
|---|---|---|
| 1.0 | July 21, 2026 | Initial published methodology: RCPS classification and maturity axes, 1–5 maturity scale, evidence states, workflow-scoping logic, and limitations. |
Version
1.0
Effective
July 21, 2026
Change
Initial published methodology: RCPS classification and maturity axes, 1–5 maturity scale, evidence states, workflow-scoping logic, and limitations.
10. Known limitations
Read before relying on any score
- Public-source constraint: preliminary conclusions reflect what public sources reveal. Internal reality may be stronger or weaker; that residual uncertainty is why preliminary and verified conclusions are labeled differently.
- Judgment-based scoring: maturity levels are assigned by structured human judgment against the level definitions. The scale has not been statistically validated, and no claim of statistical validation is made.
- Point-in-time: scores describe the evidence available on the report date. They age as facts change.
- Not a regulatory grade: RCPS scores are not issued, endorsed, or recognized by any regulator, and do not predict examination outcomes.
- Not assurance: an RCPS score is not an audit opinion, attestation, or certification, and a composite score never replaces professional judgment.
11. Appropriate and inappropriate uses
Use RCPS to
- Prioritizing which control areas to strengthen or verify first
- Structuring exam, diligence, or board preparation around evidence and gaps
- Tracking maturity movement across reporting periods
- Framing verification questions for counterparties and vendors
Do not use RCPS to
- Treating a score as an audit result, certification, or regulatory grade
- Representing a score to a regulator, auditor, or counterparty as assurance
- Substituting the composite for reading the findings and gaps beneath it
- Making legal, investment, or transaction decisions on the score alone
12. How the products apply this methodology
CompanyScope
Applies the full methodology to your own institution: classification, workflow scoping, maturity scoring, findings, and the data-gap register.
SecureScope
Applies the evidence standards and finding labels to the technology and security axes, benchmarked to NIST CSF 2.0, ISO 27001, SOC 2, and DORA.
AcquirerScope
Applies the evidence states to a counterparty: publicly observable strengths and risks, with everything else stated as unresolved verification questions.
Full Monitoring
Keeps a scored baseline current: monthly updates are mapped to the workflows and findings the methodology produced.
RCPS Methodology v1.0 · Effective July 21, 2026 · RuleboardAI LLC