Industry Frameworks
Basel III, NIST, ISO 31000, the EU AI Act, GDPR, and others, kept current so you don't have to.
The product
Prism Layer is a single governed-assessment architecture. We tailor it to your risk domain, your frameworks, and the people who own the decision. The engine is the same. The fit is yours.
The workspace
Every assessment in one operating picture: what sits above appetite, what's ready to commit, where the control gaps are, and what's still moving.
The engine
The governed execution layer for enterprise risk: precision tools trained on your frameworks and your logic, wrapped in one control plane.
Risk intelligence outputs
Audit trail preserved from source evidence to final decision.
New assessment
Type what you need to assess, in plain language. The engine scopes it, proposes the methodology, and pulls the right records from your library.
AI-native risk assessment with human oversight and full audit provenance.
The one architecture
From scope to signed record, every step produces an artifact you can hand to a committee, an auditor, or a regulator.
Set the boundaries, objectives, jurisdictions, and assessment statement.
A scoped record: in-scope entities, jurisdictions, and success criteria.
Surface the risk areas in scope, mapped to your taxonomy.
A structured set of risk areas.
Score inherent likelihood and impact per scenario, with the reasoning behind each call.
Scored scenarios, each with a reasoning card.
Map existing and gap controls, with a mitigation percentage per scenario.
A control map with mitigation applied.
Residual risk, computed deterministically from baseline minus mitigation. No black box on the math.
A residual-risk score and band per scenario.
Set target bands from averse to opportunistic. Alignment status and the governance response surface automatically.
Alignment status with a governance response per scenario.
Assemble the full record for review, ready to export.
An exportable review pack.
Formal sign-off with expert approval on material decisions.
A signed, immutable record: ID, hash fingerprint, and reasoning trace.
The output, in full
An illustrative enterprise assessment: five risks scored, ten controls evaluated, each residual measured against the appetite you set. This is the shape of what Prism Layer hands a committee, in minutes.
Path A · Deploy
Commit targeted capital against the two risks sitting above appetite, closing the gap before the peak. Higher cash outlay, exposure retired.
Path B · Carry
Run on current controls and accept 200–400 bps of margin exposure if they slip under sustained stress. Capital preserved, the risk stays live.
The deliverable
Export the signed assessment to a paginated PDF for your committee, board, auditors, or regulators. Cover to signature, on Letter or A4, with a repeating header and footer.
Eight sections, then four appendices: the full reasoning passes, control detail, the run log and document manifest, and a signature page with the hash fingerprint.
Prism Layer · Signed Assessment
AML & Sanctions Program Risk Assessment
The assurance plane
Role-based identity, least-privilege retrieval, bounded task scope, policy guardrails, evidence-linked reasoning, expert approval, immutable capture. Every output links back to policy context, source evidence, and reviewer action.
The methodology layer
Develop, tweak, test, and refine the methodologies your assessments run on. Clone the Prism methodology, adjust the bands, weights, and steps to your program, and every new assessment inherits the version you committed.
Target risk bands
Three data layers
Basel III, NIST, ISO 31000, the EU AI Act, GDPR, and others, kept current so you don't have to.
Policies, prior assessments, audit results, and your own taxonomy. The system is trained on you.
GRC platforms, control repositories, incident systems, and data lakes, read in place.
Confidence scoring
See exactly how much of every output rests on your data versus industry defaults. Internal documents raise confidence, so you always know what's grounded in your program and what's a framework starting point.
Observable reasoning
A specialized agent runs each step and shows its work. You keep the judgment. The system keeps the record.
Scope, baseline, residual-risk, and target agents run each step and name the reasoning behind every call.
Every output shows how much rests on your data versus industry defaults. Add a foundation document to raise confidence, up to 20%.
Residual risk is computed deterministically from confirmed baselines and controls. No black box on the math.
Target bands from averse to opportunistic. Scenarios over appetite surface an alignment status and a governance response.
Reasoning, references, execution trace, and decision trace on every output. Replay any conclusion.
Formal sign-off with a hash fingerprint, and a report you can export for the committee.
Every confirmed step carries
Risk appetite bands
The document library
Three shelves feed every assessment: canonical regulatory documents vetted by Prism, industry standards surfaced for matching assessments, and your own policies scoped to your org. Foundation documents raise confidence, and every citation traces back to its shelf.
Same rigor. Shorter path to evidence.
On a use case from your world. Nothing required in advance.
See a Live Assessment