◆ For risk & compliance practitioners
Risk and compliance templates built for financial services.
Risk and compliance frameworks and Excel templates built on SR 11-7, FFIEC, NIST AI RMF, and 20+ regulatory standards. Buy once, tailor to your program, deploy in days.
◆ Sign up for our newsletter — free weekly brief →Grounded in
SR 11-7 · FFIEC IT Examination Handbook · NIST AI RMF · OCC 2021-7 · ISO 31000
Exhibit A · BCP/DR — Business Impact Analysis
★ Bestseller · KRI Library dashboard
Inside the kit
14 templates · 20+ regulatory standards · Excel-native
20+
US regulatory standards
SR 11-7 · FFIEC · NIST AI RMF · OCC · CFPB
2,400+
Pages of guidance
Across every paid and free template
500+
Downloads
Risk & compliance practitioners
685
Briefings
Enforcement, analysis, frameworks
★ Bestsellers
Most popular picks.
The four most-downloaded templates this quarter. Real screenshots, real templates, ready to deploy.
#01 bestseller
KRI Library
132 Key Risk Indicators with thresholds, data sources, and escalation triggers.
#02 bestseller
New Product Risk Assessment
Pre-launch risk evaluation across compliance, operational, financial, and reputational lenses.
#03 bestseller
BCP/DR Kit (with BIA)
Full Business Continuity & Disaster Recovery kit including Business Impact Analysis.
#04 bestseller
Risk Register — Fintech Edition
141 pre-populated fintech risks across 21 categories. ISO 31000 structure.
◆ Ready to deploy
Templates & toolkits.
Built on real regulatory guidance — not someone's old employer's templates with the logo swapped out. Tailor in an afternoon.
Template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
Template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
Template
Financial Risk Management Kit
Credit risk, liquidity, concentration, and capital adequacy templates built for fintechs.
Template
Loss Monitoring & Event Tracking Kit
Basel-aligned operational loss event tracking and root cause analysis for financial services.
Template
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
Template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
22 templates · 4 bundles · $49–$499
See all templates →★ Free · Delivered to your inbox
Start with the free frameworks.
Working introductory guides — read, evaluate, decide whether the full template is worth your money.
★ Free
AI Risk Assessment Guide
A free introductory guide to AI risk assessment for financial services teams.
Download →
★ Free
Issues Management Guide
A free introductory guide to building an effective issues management process.
Download →
★ Free
Risk Register — Fintech Edition
141 pre-populated fintech risks across 21 categories. ISO 31000 structure. Ready to use in a week.
Download →
★ Free
Threat Modeling for Agentic Payments
A 20,000-word whitepaper on threat modeling for AI-powered autonomous payment systems in financial services.
Download →
— Why this exists —
Built by a practitioner, for practitioners.
Every risk professional has done it. You join a new team, get asked to build a program from scratch, and end up calling a friend at your old company for their templates.
So I started publishing the analysis I wish I'd had — enforcement breakdowns, regulatory deep dives — and building the templates on actual regulatory guidance. The intelligence keeps you informed. The templates let you act on it.
Rebecca Leung
Editor & Founder · 8 years · Banks · Fintechs · BCG
◆ The Daily Brief
What we're tracking.
01 · AI Risk
The ESRB Upgraded AI Cyber Risk to 'Severe.' Here's the Five-Area Action Plan Europe's Biggest Banks Must File by October 31.
ESRB Warning ESRB/2026/3 and the ECB's July 7 supervisory letter require significant institutions to submit AI-enabled cybersecurity action plans by October 31, 2026. Here's what the six-area framework covers and what it means for US institutions with EU operations.
SEP 1 · Rebecca
02 · Regulatory Compliance
Lugano Diamonds SEC Fraud Case: How $1B in Alleged Fake Revenue Beat the Control Stack
The Lugano Diamonds SEC fraud case shows how alleged fake revenue, inventory, and vendor records survived acquisition and audit controls.
SEP 1 · Rebecca
03 · Regulatory Compliance
SAR Confidentiality and Customer Communications: What Banks Can Now Say
The 2026 SAR confidentiality joint statement clarifies what banks can tell customers about fraud reviews, restrictions, and account closures.
SEP 1 · Rebecca