AI-Powered RCSA Platform

RCSA, Automated.
Defensible
by Design.

The first RCSA platform built for every stakeholder — not just the teams completing the assessment.

100%
Immutable Audit Trail
4
Deployment Tiers — Air-Gap to SaaS
Zero
Training Required for First-Line
8–123–4
Weeks — Annual RCSA Cycle
External Data Egress — Tier 1 Air-Gap
7yr
Audit Log Retention — Regulatory Standard
3
Core Modules — Compass · Engine · Living RCSA
00 — Why FirstlineIQ

From Annual Artifact
to Active Assurance

FirstlineIQ is the first RCSA platform built for every stakeholder in the risk and compliance ecosystem — not just the teams completing the assessment. First-line owners complete intake in plain English. Second-line analysts challenge, approve, and export with a full evidence trail. Internal audit accesses an immutable record without asking anyone for a spreadsheet. Compliance teams map every control to their regulatory obligations automatically. Examiners get a defensible, timestamped history of every risk decision. And senior management moves from reviewing an annual artifact to watching risk posture in real time.

One platform. Every stakeholder. RCSA as a continuous discipline — not a calendar event.

First-Line
Owners

Complete intake in plain English. No methodology training required.

Second-Line
Analysts

Challenge, approve, and export with a full evidence trail.

Internal
Audit

Immutable records. No spreadsheet requests. Full history on demand.

Compliance
Teams

Every control mapped to its regulatory obligation. Automatically.

Regulatory
Examiners

Defensible, timestamped history of every risk decision.

Senior
Management

Real-time risk posture. Not an annual report.

01 — The Platform

The RCSA process
as practiced today
produces a compliance
artifact,
not a risk tool.

Spreadsheets emailed once a year. First-line owners who don't understand inherent versus residual risk. Manual aggregation that takes weeks. Ratings that fail credible challenge. A regulatory export assembled at the last minute from a dozen inconsistent files.

FirstlineIQ replaces that entire process with a structured, AI-assisted platform spanning the full RCSA lifecycle — from first-line intake through second-line review, credible challenge, materiality determination, approval, and regulatory export.

Every decision is captured. Every rating is computed deterministically. Every version is immutable. The result is RCSA data that regulators can trust — and that your second-line team doesn't have to reconstruct from email chains.

ISO 27001:2022 AICPA TSC (SOC 2) NIST CSF Regulatory Export Ready Hash-Chained Audit Log
Module 01
Compass
AI Intake Agent

Compass interviews first-line risk owners in plain English — no methodology training required. It maps responses to risk taxonomy categories, prompts for evidence uploads, and generates a structured RCSA draft grounded in your firm's document library via retrieval-augmented generation. Every AI-generated field carries a citation or confidence flag. No field is auto-populated without user confirmation.

Module 02
Methodology Engine
Deterministic Risk Scoring

All ratings follow defined matrices exactly — no rounding, no approximation. Overrides require documented justification and second-line approval. Every computation stored with inputs, outputs, timestamp, and user identity.

Module 03
Living RCSA
Version-Controlled. Audit-Ready.

Every RCSA maintains a working draft and an immutable approved baseline, enforced at the database level. A diff engine surfaces every change at the start of each refresh cycle. Regulatory export always one click from the approved baseline.

8–12 wks → 3–4
Annual RCSA cycle time
100% Audit Trail
Every decision, hash-chained and immutable
Regulatory-Grade
Approved baselines with full version history
Zero Training
Required for first-line RCSA owners
02 — Deployment Models

Your data.
Your infrastructure.
Your call.

Data residency requirements vary. Some institutions need complete air-gap isolation. Others want the fastest path to value. FirstlineIQ meets regulated financial institutions wherever their risk posture, IT capability, and compliance requirements sit — four tiers, every scenario covered.
01
Tier 1 · Air-Gap Ready
On-Premise + Local AI
Your data never leaves.

Full on-premises deployment powered by open-weight LLM inference running entirely within your infrastructure. Zero egress. No external API calls. Air-gap friendly by design. Application, database, document store, secrets management, and AI inference all run inside your infrastructure. Requires GPU-equipped server (NVIDIA A10G or equivalent) to meet sub-5-second Compass response time.

Zero egress Open-weight LLM, local inference Air-gap compatible Customer-hosted MFA optional
02
Tier 2 · BYOLLM
On-Premise + Your AI
Your platform, your provider.

Platform lives on your infrastructure. You bring your own LLM API key — OpenAI, Anthropic, Azure OpenAI, or Google. Your data agreement with the LLM provider is yours to own and control. API keys encrypted at rest with AES-256-GCM, never logged, never returned by the API, and masked in the UI after entry. MFA mandatory when cloud model configuration is activated.

OpenAI / Anthropic / Azure Customer-hosted platform BYOLLM key MFA mandatory
03
Tier 3 · Hosted
Hosted + Your AI
Fast to deploy, provider-agnostic.

FirstlineIQ hosts and manages the platform. You bring your own LLM API key. Fastest path to a live environment without managing infrastructure — without ceding control of your LLM provider relationship. Your key, your data agreement, your choice of model. Suitable for institutions that want managed infrastructure but maintain strict AI provider requirements.

FirstlineIQ-hosted BYOLLM key Managed infrastructure MFA mandatory
04
Tier 4 · Full SaaS
Fully Hosted
Fastest path to value.

Complete SaaS deployment. FirstlineIQ provides everything — platform, infrastructure, and LLM inference. No infrastructure to provision, no API keys to manage, no operational overhead. Ideal for institutions prioritising rapid time-to-value and operational simplicity. All four deployment tiers share the same feature set — the only difference is where things run and who manages what.

Full SaaS FirstlineIQ LLM Fastest deployment MFA mandatory
03 — Who It's For

Built around the
people who own
the RCSA process.

Second Line Risk Teams

The engine of RCSA oversight. FirstlineIQ gives second-line analysts a structured, auditable surface for credible challenge, materiality determination, force actions, and regulatory export — without the manual aggregation.

  • Portfolio-level RCSA inventory with real-time status
  • Structured credible challenge threads, append-only and DB-enforced
  • Materiality queue with rule-triggered flags and decision audit trail
  • One-click regulatory export with CONFIDENTIAL classification header
  • Consolidated risk register with ISO 27001, AICPA Trust Services Criteria (SOC 2), and NIST CSF mapping
  • Immutable approved baselines with full version history

First Line RCSA Owners

Business unit operators who know their domain deeply but not risk methodology. Compass meets them in plain English, asks the right questions, and guides them through intake without requiring them to understand inherent versus residual risk.

  • Plain-English AI interview — no methodology training required
  • Compass-generated draft with citations, not black-box scores
  • Evidence upload prompts built into the intake flow
  • Diff review at refresh — Accept, Modify, or Reject with rationale
  • Structured challenge response with in-platform thread visibility
  • Status visibility at every step of the workflow

Operational Risk Teams

Operational risk teams responsible for overseeing the RCSA process, managing user access, configuring methodology, and maintaining audit chain visibility. FirstlineIQ replaces the spreadsheet distribution list and manual access review with a proper administrative surface.

  • RCSA onboarding: owner, entity, cadence, due date, Compass config
  • Role-based access via Keycloak — scoped to entity and business unit
  • Methodology matrix configuration with version history
  • Framework mapping: bulk import and export via CSV
  • Audit log chain verification — available to regulators on request
  • Admin Correction workflow with dual-approval and full audit trail
Built for the teams that manage the RCSA process at financial institutions and other regulated entities. Small to mid-size institutions carry the full regulatory obligation without the headcount of larger organisations. FirstlineIQ exists to close that gap — turning a quarterly fire drill into a continuous, defensible process.
04 — Request a Demo

See FirstlineIQ running on your scenario.

We'll walk you through a live demo configured around your deployment tier preference — from fully air-gapped on-premise to full SaaS. No generic slide deck. No marketing theatre.

The demo environment runs ACE_IQ Inc. — a fictionalised financial institution with five legal entities and sixteen active RCSAs — so you can see the full lifecycle, not just the intake flow.

No commitment required. No sales pressure.
Demo configured to your preferred deployment tier.
Bring your second-line team, your compliance team, or your CISO. All welcome.
Response within one business day.