RegAlign® + RiskAlign™
Two products. One brand family. Connected controls.
RegAlign® and RiskAlign™ are two products in the Align product family, built with a shared design language and audit discipline. They run on separate databases and can each be adopted alone. This page compares them so you can start with the problem you actually need to solve.
Pick RiskAlign if…
- Your board asks "are we operating inside appetite?" and you can't answer cleanly.
- Your risk register is in a spreadsheet, residual scores are inconsistent, and KRIs aren't linked to risks.
- You need scenario analysis (stress, reverse-stress) you can defend in front of a regulator.
- Three-lines accountability isn't visible — first line owns risks, second line owns oversight, third line owns assurance, and nobody can see the seam.
Pick RegAlign if…
- Your problem starts with "the regulator just published…" and ends with "…can we prove we comply?"
- You need an obligations register with chain-of-custody, not a risk register.
- Regulatory change tracking, horizon scanning, and attestation workflows are the headline pain.
- You want a defensible link from rulebook clause → control → evidence.
Pick both if…
You're a regulated firm where both disciplines exist. Each product keeps its own control register. Today, bounded exports and imports can preserve obligation and control references between the products; automated integration remains subject to the approved architecture and release process. See how they fit together.
Side by side
| RiskAlign | RegAlign | |
|---|---|---|
| What's the starting point? | What could hurt the firm — strategic, operational, conduct, financial risks. | What the regulator requires — handbooks, rulebooks, supervisory letters. |
| Primary user | CRO, risk owners, board risk committee. | Compliance officer, regulatory change team, MLRO. |
| Core unit of work | A risk, with appetite, controls, KRIs and scenarios. | An obligation, with mapped controls and evidence. |
| Scoring model | 5×5 inherent → residual, plus velocity and persistence. | Coverage and freshness against the obligations register. |
| Board output | Risk pack: heatmap, appetite breaches, KRI trend, top issues. | Compliance pack: obligation coverage, regulatory change pipeline, attestations. |
| Regulatory change | Not handled — RiskAlign assumes the obligation set is given. | Native — ingest, triage, assign, attest. |
| Risk appetite & KRIs | Native — board appetite per category, KRI thresholds, breach alerts. | Not handled — RegAlign assumes risk appetite is set elsewhere. |
| Audit trail | Per-risk and per-decision, with chain-of-custody on residual changes. | Per-obligation, with chain-hash on every state change. |
Still unsure?
Most firms only need one of the two to start. Pick the product that solves the sharper problem first; add the other later if the operating case supports it. The products are designed to keep references linkable without requiring a shared database.