RCSA, Automated.
Defensible
by Design.

Spreadsheets don't survive an exam. RCSA as a continuous discipline does.

The first RCSA platform built for every stakeholder — not just the teams completing the assessment.

100%
Immutable Audit Trail
4
Deployment Tiers — Air-Gap to SaaS
Zero
Training Required for First-Line
3–4 wks
vs. the traditional 8–12 week cycle
Zero data leaves your environment — for institutions where risk appetite demands it
7yr
Audit Log Retention — Regulatory Standard
3
Core Modules — Compass · Engine · Living RCSA
00 — Why FirstlineIQ

From Annual Artifact
to Active Assurance

FirstlineIQ is the first RCSA platform built for every stakeholder in the risk and compliance ecosystem — not just the teams completing the assessment. First-line owners complete intake in plain English. Second-line analysts challenge, approve, and export with a full evidence trail. Internal audit accesses an immutable record without asking anyone for a spreadsheet. Compliance teams map every control to their regulatory obligations automatically. Examiners get a defensible, timestamped history of every risk decision. And senior management moves from reviewing an annual artifact to watching risk posture in real time.

01 — The Platform

The RCSA process
as practiced today
produces a compliance
artifact,
not a risk tool.

Spreadsheets emailed once a year. First-line owners who don't understand inherent versus residual risk. Manual aggregation that takes weeks. Ratings that fail credible challenge. A regulatory export assembled at the last minute from a dozen inconsistent files.

FirstlineIQ replaces that entire process with a structured, AI-assisted platform spanning the full RCSA lifecycle — from first-line intake through second-line review, credible challenge, materiality determination, approval, and regulatory export.

Every decision is captured. Every rating is computed deterministically. Every version is immutable. The result is RCSA data that regulators can trust — and that your second-line team doesn't have to reconstruct from email chains.

The gap assessment engine surfaces control deficiencies between assessment cycles — when there's still time to remediate before the next exam. The platform recommends specific evidence artifacts so first-line teams know exactly how to demonstrate control effectiveness.

Board-ready reports in PDF or XLSX — paste directly into your institution's templates. RCSA KPI and KRI monitoring keeps risk posture visible between assessment cycles.

Standard License — Included

Automatically mapped to these frameworks.

ISO 27001:2022 NIST CSF 2.0 NIST SP 800-53 AICPA TSC (SOC 2) Basel II/III

Reg Intel (Enterprise)

DORA OCC Bulletins FFIEC InfoSec FFIEC BCP NY DFS Part 500 FINRA Rules GDPR CCPA

“Natively monitored. Automatically flagged when regulatory documents change.”

Module 01
Compass
AI Intake Agent

Compass interviews first-line risk owners in plain English — no methodology training required. It maps responses to risk taxonomy categories, prompts for evidence uploads, and generates a structured RCSA draft grounded in your firm's document library. Every AI-generated field carries a citation or confidence flag. No field is auto-populated without user confirmation.

Module 02
Methodology Engine
Deterministic Risk Scoring

All ratings follow defined matrices exactly — no rounding, no approximation. Overrides require documented justification and second-line approval. Every computation stored with inputs, outputs, timestamp, and user identity.

Module 03
Living RCSA
Version-Controlled. Audit-Ready.

Every RCSA maintains a working draft and an immutable approved baseline, enforced at the database level. A diff engine surfaces every change at the start of each refresh cycle. Regulatory export always one click from the approved baseline.

3–4 wks vs. 8–12
Annual RCSA cycle time
100% Audit Trail
Every decision, hash-chained and immutable
Defensible
Approved baselines with full version history
Zero Training
Required for first-line RCSA owners
02 — Deployment Models

Your data.
Your infrastructure.
Your call.

Data residency requirements vary. Some institutions need complete air-gap isolation. Others need to be live before the next exam cycle. Four deployment tiers because data residency requirements, IT capability, and exam risk don't look the same at every institution. The full feature set is identical regardless of which tier you run.
01
Tier 1 · Air-Gap Ready
On-Premise + Local AI
Your data never leaves.

Full on-premises deployment powered by open-weight LLM inference running entirely within your infrastructure. Zero egress. No external API calls. Application, database, document store, secrets management, and AI inference all run inside your infrastructure. Requires GPU-equipped server (NVIDIA A10G or equivalent) to meet sub-5-second Compass response time.

Zero egress Open-weight LLM, local inference Air-gap compatible Customer-hosted MFA optional
02
Tier 2 · BYOLLM
On-Premise + Your AI
Your platform, your provider.

Platform lives on your infrastructure. You bring your own LLM API key — OpenAI, Anthropic, Azure OpenAI, or Google. Your data agreement with the LLM provider is yours to own and control. API keys encrypted at rest with AES-256-GCM, never logged, never returned by the API, and masked in the UI after entry. MFA mandatory when cloud model configuration is activated.

OpenAI / Anthropic / Azure Customer-hosted platform BYOLLM key MFA mandatory
03
Tier 3 · Hosted
Hosted + Your AI
Managed infrastructure. Your LLM key, your data agreement.

FirstlineIQ hosts and manages the platform. You bring your own LLM API key. Managed infrastructure. Your data agreement, your choice of model. Suitable where speed matters and data residency permits hosted deployment.

FirstlineIQ-hosted BYOLLM key Managed infrastructure MFA mandatory
04
Tier 4 · Full SaaS
Fully Hosted
No infrastructure. No keys. Operational in days.

Complete SaaS deployment. FirstlineIQ provides everything — platform, infrastructure, and LLM inference. No infrastructure to provision, no API keys to manage, no operational overhead. All four deployment tiers share the same feature set — the only difference is where things run and who manages what.

Full SaaS FirstlineIQ LLM Fastest deployment MFA mandatory
03 — Who It's For

Built around the
people who own
the RCSA process.

Second Line Risk Teams

The engine of RCSA oversight. FirstlineIQ gives second-line analysts a structured, auditable surface for credible challenge, materiality determination, force actions, and regulatory export — without the manual aggregation.

  • Portfolio-level RCSA inventory with real-time status
  • Structured credible challenge threads, append-only and DB-enforced
  • Materiality queue with rule-triggered flags and decision audit trail
  • One-click regulatory export with CONFIDENTIAL classification header
  • Consolidated risk register with ISO 27001, AICPA Trust Services Criteria (SOC 2), and NIST CSF mapping
  • Immutable approved baselines with full version history

First Line RCSA Owners

Business unit operators who know their domain deeply but not risk methodology. Compass meets them in plain English, asks the right questions, and guides them through intake without requiring them to understand inherent versus residual risk.

  • Plain-English AI interview — no methodology training required
  • Compass-generated draft with citations, not black-box scores
  • Evidence upload prompts built into the intake flow
  • Diff review at refresh — Accept, Modify, or Reject with rationale
  • Structured challenge response with in-platform thread visibility
  • Status visibility at every step of the workflow

Operational Risk Teams

Operational risk teams responsible for overseeing the RCSA process, managing user access, configuring methodology, and maintaining audit chain visibility. FirstlineIQ replaces the spreadsheet distribution list and manual access review with a proper administrative surface.

  • RCSA onboarding: owner, entity, cadence, due date, Compass config
  • Role-based access via Keycloak — scoped to entity and business unit
  • Methodology matrix configuration with version history
  • Framework mapping: bulk import and export via XLSX or CSV
  • Audit log chain verification — available to regulators on request
  • Admin Correction workflow with dual-approval and full audit trail
Built for the teams that manage the RCSA process at financial institutions and other regulated entities. Small to mid-size institutions carry the full regulatory obligation without the headcount of larger organisations. FirstlineIQ closes that gap — structured intake, deterministic scoring, and an immutable audit trail that doesn't require a dedicated GRC team to maintain.
04 — Request a Demo

See FirstlineIQ running on your scenario.

We'll walk you through a live demo configured around your deployment tier preference — from fully air-gapped on-premise to full SaaS. No generic slide deck. The demo runs on ACE_IQ Inc. — a fictionalised community bank with sixteen active RCSAs — so you see the full lifecycle, not just the intake flow.

One hour. We run your scenario. You decide if it warrants a second conversation.
Demo configured to your preferred deployment tier.
Bring your second-line team, your compliance team, or your CISO. All welcome.
Response within one business day.