For risk & compliance practitioners
Your next risk program starts here.
Excel frameworks grounded in SR 11-7, FFIEC, NIST AI RMF, and 20+ regulatory standards. Buy once, tailor to your program, deploy in days.
20+
Ready-to-deploy templates
$49–$79
Individual templates
20+
Regulatory standards covered
500+
Downloads
What makes these different
Grounded in regulatory guidance
Not someone's old employer's templates with the logo swapped out. Built on SR 11-7, FFIEC, OCC bulletins, and NIST AI RMF.
Deploy in days, not months
Fully editable Excel templates with pre-populated risk taxonomies, scoring models, and dashboards. Populate in an afternoon.
Price of a team lunch
Individual templates from $49. Bundles from $199. No subscriptions, no license restrictions. Buy once, use forever.
The 2025–2026 Risk & Compliance Landscape
Free Resources
Start here — frameworks and guides to get you going, no email required.
AI Risk Assessment Guide (Free)
A free introductory guide to AI risk assessment for financial services teams.
Issues Management Guide (Free)
A free introductory guide to building an effective issues management process.
Risk Register — Fintech Edition (Free)
141 pre-populated fintech risks across 21 categories. ISO 31000 structure. Ready to use in a week.
Threat Modeling for Agentic Payments (Free)
A 20,000-word whitepaper on threat modeling for AI-powered autonomous payment systems in financial services.
Need the full framework?
Templates & Toolkits
Reading about an enforcement action is step one. Having the right framework in place before the next exam is what actually matters.
Individual Templates
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
New Product Risk Assessment
Structured risk review process for new products, services, and business initiatives.
Financial Risk Management Kit
Credit risk, liquidity, concentration, and capital adequacy templates built for fintechs.
Loss Monitoring & Event Tracking Kit
Basel-aligned operational loss event tracking and root cause analysis for financial services.
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
SOC 2 Compliance Checklist
151 controls mapped to AICPA Trust Services Criteria with evidence collection guidance.
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
Bundles
GRC Starter Kit
Everything a new compliance hire needs to build their first risk program — 6 products at 46% off.
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
Operational Risk Program
Build a complete ORM program: ERM framework, RCSA, loss monitoring, financial risk, and KRIs — 37% off.
Complete GRC Library
Every template in the library — all 14 products at 58% off individual prices.
What We're Tracking
SEC enforcement, DOJ settlements, AI regulation, and the frameworks that matter — updated daily.
College Student Stole $7M from Investors. The SEC's Case Against Krish Kumar Has Lessons for Every Investment Adviser.
SEC charged Tulsa college student Krish Kumar with misappropriating nearly $7M from two investment funds. Here's what compliance officers at investment advisers need to know.
Mar 28, 2026
Regulatory ComplianceDOJ Hits Atlanta Urology Practice With $14 Million False Claims Act Settlement — What Compliance Teams Should Learn
Advanced Urology and Dr. Jitesh Patel will pay $14M to settle DOJ allegations of fraudulent billing and unnecessary procedures. Key compliance takeaways inside.
Apr 2, 2026
Regulatory ComplianceA.G. Morgan Financial Advisors Fraud: Vincent Camarda Pleads Guilty to $160M Investment Adviser Scheme
Vincent Camarda of A.G. Morgan Financial Advisors pleads guilty to defrauding 400+ clients of $160M. What compliance professionals need to know about this investment adviser fraud case.
Apr 2, 2026
Regulatory ComplianceSEC Charges Jon Fullenkamp and Scott Sand in $2.6 Million Penny Stock Fraud Scheme
The SEC filed fraud charges against Jon Fullenkamp and Scott Sand for misappropriating millions through sham agreements and fraudulent preferred share issuances at two penny stock companies.
Mar 31, 2026
Regulatory ComplianceState AI Laws Tracker 2026: Every US AI Regulation You Need to Know
45 states have introduced 1,561 AI bills in 2026 — already surpassing 2024's full-year total. Colorado, Texas, and California are the three to watch. Every enacted state AI law, organized by what your compliance team actually needs to do.
Apr 2, 2026
AI RiskAI Model Inventory Management: What Examiners Ask For First (And What Banks Can't Find)
The first question your examiner will ask isn't about bias or governance — it's 'show me your model inventory.' Most banks can't. Here's the SR 11-7 fields examiners expect, how to find shadow AI, and the vendor tracking gap that gets flagged every time.
Mar 26, 2026
AI RiskNIST AI RMF MAP Function: How to Frame AI Risk Context Before You Build or Deploy
The MAP function is where NIST AI RMF risk management actually starts. Learn what MAP 1-5 require, how financial institutions implement them, and why most teams get this wrong.
Apr 21, 2026
Regulatory ComplianceState Money Transmitter Licensing for Crypto: The Patchwork Compliance Challenge
49 states require money transmitter licenses for crypto businesses. OKX paid $505M for getting this wrong. Here's the state-by-state breakdown and how to build your licensing strategy.
Apr 21, 2026
Regulatory ComplianceVoyager Pacific Capital's $25M Ponzi: What the SEC + DOJ Double Tap Means for Investment Advisers
The SEC charged Voyager Pacific Capital Management in a $25M real estate Ponzi that ran five years. Here's what compliance teams must fix before examiners ask.
Apr 21, 2026
AI RiskAgentic AI Governance: The Compliance Gap Nobody's Talking About
SR 11-7, Reg E, and UDAAP weren't built for AI that acts autonomously. Here's where your compliance program has a blind spot—and what to build before regulators close it.
Apr 20, 2026
Regulatory ComplianceStablecoin Compliance Under the GENIUS Act: Consumer Protection Requirements Explained
The GENIUS Act is law. Here's what permitted payment stablecoin issuers owe consumers—reserve requirements, redemption policies, fee disclosures, and bankruptcy protections.
Apr 20, 2026
AI RiskContinuous Monitoring for AI Models: Drift, Degradation, and Compliance Triggers
SR 11-7 ongoing monitoring for AI models — drift detection, PSI thresholds, re-validation triggers, and what OCC examiners check in 2026.
Apr 19, 2026
Regulatory ComplianceCrypto Complaint Handling: Preparing Your Platform for CFPB Scrutiny
CFPB pulled back, but state AGs and the GENIUS Act mean crypto platforms still need robust complaint handling. Here's what the Bitcoin Depot lawsuit revealed — and what your program needs.
Apr 19, 2026
Regulatory ComplianceSEC's $16M Bitcoin Latinum Case: Why 'Insured' Crypto Claims Are a Red Flag, Not a Safety Net
SEC charges Donald Basile with $16M SAFT fraud using fake 'insured' crypto claims. What compliance teams need to know about SAFT red flags and crypto CDD.
Apr 18, 2026
Regulatory ComplianceHidden Wealth, Hidden Commissions: The SEC's $82M Radio Show Oil & Gas Fraud and What It Exposes About OBA Oversight
Three 'advisers' used radio shows and podcasts to sell $82M in unregistered oil & gas securities — pocketing $5.7M without disclosing it. Here's the OBA and RIA compliance breakdown.
Apr 18, 2026
Regulatory ComplianceUDAAP in Crypto: Why State Attorneys General Are Your New Enforcement Risk
DOJ dismantled its crypto enforcement unit. State AGs filled the vacuum — with UDAP laws that don't require proof of harm. Here's what crypto compliance teams need to know.
Apr 18, 2026
Regulatory ComplianceSEC Charges Milpitas Man with $43 Million Ponzi Scheme Targeting Indian American Investors via Telegram
SEC charges Sudheesh Nambiar with a $43M Ponzi scheme defrauding 400+ Indian American investors through fabricated statements and Telegram chatrooms.
Apr 16, 2026
AI RiskAI Model Validation Best Practices: Why Traditional Testing Breaks with Generative AI
Traditional SR 11-7 validation breaks with generative AI. Learn why deterministic testing fails for LLMs and what new validation approaches financial services firms actually need.
Apr 18, 2026
AI RiskAI Explainability Documentation: How to Show Your Work to Examiners
The model risk framework just changed. OCC 2026-13 is principles-based, GenAI is excluded, and CFPB still demands specific adverse action reasons. Here's what your explainability documentation package needs.
Apr 17, 2026
AI RiskNIST AI RMF GOVERN Function: Building AI Risk Culture, Accountability, and Inventory
The GOVERN function is the foundation of NIST AI RMF compliance. Learn what GV-1 through GV-6 actually require and how financial institutions are implementing AI accountability structures.
Apr 16, 2026
Business ContinuityOperational Resilience vs. BIA: The Regulatory Shift from RTOs to Impact Tolerances
Traditional BIA produces RTOs. Operational resilience requires impact tolerances. They're different questions with different methodology — here's how to update your BIA process.
Apr 17, 2026
Business ContinuityThird-Party Dependencies in BIA: How Deep Should You Go?
When mapping third-party dependencies in your BIA, one tier isn't enough for critical functions. Here's how to scope the analysis — and where going deeper actually matters.
Apr 15, 2026
Business ContinuityBIA for Fintech and SaaS: Mapping Cloud and API Dependencies
Most fintech BIAs skip the part that matters most: the cloud platforms and third-party APIs your entire business runs on. Here's how to map those dependencies correctly — and what your bank partners will ask about them.
Apr 14, 2026
Business ContinuityBusiness Impact Analysis for Banks: FFIEC Requirements Explained
What the FFIEC BCM booklet actually requires in your BIA — critical function identification, interdependency analysis, recovery objectives, and what Appendix A examiners test at your next IT exam.
Apr 14, 2026
Business ContinuityBIA Data Collection: Surveys vs. Interviews vs. Workshops
The method you choose for BIA data collection determines whether your RTOs reflect operational reality or wishful thinking. A practitioner's guide to surveys, interviews, and workshops — when each method works, where each fails, and how to combine them.
Apr 13, 2026
Business ContinuityHow to Present BIA Findings to the Board: Executive Summary and Business Case
A 47-page BIA full of RTOs and dependency tables won't get board buy-in for BCP investment. Here's how to translate BIA findings into an executive summary that drives decisions and satisfies FFIEC board reporting requirements.
Apr 13, 2026
Why this exists
Every risk and compliance professional has done it: you join a new team, get asked to build a program from scratch, and end up calling a friend at your old company for their templates. Or a consultant brings in frameworks recycled from another client. The result? Documents that don't quite fit and no confidence they'll hold up under regulatory scrutiny.
So I started publishing the analysis I wish I'd had — enforcement breakdowns, regulatory deep dives, practical frameworks — and building the templates on actual regulatory guidance. The intelligence keeps you informed. The templates let you act on it.
Immaterial Findings ✉️
Weekly newsletter
Sharp risk & compliance insights practitioners actually read. Enforcement actions, regulatory shifts, and practical frameworks — no fluff, no filler.
Join practitioners from banks, fintechs, and asset managers. Delivered weekly.