GRC platform for regulated financial institutions

MappRiskFramework

End-to-end risk management and regulatory compliance, powered by artificial intelligence.

Operational riskTechnology ContinuityAML/CFT Third partiesInternal audit
128146 RISKSOVER APPETITEWITHOUT CONTROL HEAT MAP RISK TREND
Contents

Everything this overview covers, at a glance.

The challenge

Regulatory demands keep growing. Risk management still lives in spreadsheets.

Every area keeps its own version of the truth. Controls get tested in one file, events logged in another, and the evidence for the regulator gets pulled together at the last minute — rebuilding work you'd already done. The real cost isn't the duplicated effort. It's not being able to answer, the moment you're asked, what your institution's actual risk profile is.

TODAY Matrix.xlsxEvents.xlsx ControlsBCP.docx AML/CFTVendors WITH MAPPRISK RisksControlsEvents ContinuityAML/CFTThird parties Single auditable repository REGULATOR

The difference isn't having a system instead of files. It's that the evidence is produced as you manage risk — not afterward.

Value proposition

Five reasons a regulated institution chooses MappRisk.

All-in-one platform

Operational, technology, continuity, AML/CFT, third-party and audit risk in one place, with a single methodology and a single control inventory.

Native regulatory alignment

Built on the regulations of the Superintendencia de Bancos (Superintendency of Banks) and the Superintendencia del Mercado de Valores (Superintendency of the Securities Market) — not a compliance module bolted on afterward.

Artificial intelligence in practice

Speeds up risk identification and document analysis. The AI proposes; the risk manager decides and signs off.

Configurable per institution

Matrix from 3×3 to 5×5, scales, labels, colors, catalogs, appetite and approval workflows adjust to each institution's methodology.

Data isolation and security

Strict separation of each institution's information, role-based permissions, two-factor authentication and an immutable audit log.

In one line

The rigor of a bank, backed by artificial intelligence.

Scope

Six risk domains, a single platform.

In most institutions, each risk domain is managed with a different tool, a different owner and a different assessment criterion. When the regulator asks for a consolidated view, someone has to reconcile them by hand.

MappRisk unifies all six under the same matrix, the same risk appetite and the same control inventory. A control tested once serves every domain where it applies.

The institution can start with one domain and add the others as its maturity requires, without redoing what has already been loaded.

MappRisk Framework Operational risk Technologyrisk Third-partyrisk Internal audit AML/ CFT Businesscontinuity
Modules and features

Twelve modules covering the full cycle — from risk identification to regulatory reporting.

01

Risk management core

From risk identification to the documented management decision, in a single traceable flow.

Dashboard

A snapshot of the institution's risk profile, the moment it is asked for.

  • End-to-end view of the institution's risk profile
  • Key indicators: total risks, risks over appetite, risks without controls, overdue treatments
  • Inherent and residual risk heat maps, side by side
  • Recent control tests and events
  • Risk trend view with historical comparison
  • Risk-by-risk movement table: improved, worsened, new
  • Interchangeable analytical and executive views

Risk Identification, Analysis and Assessment

The institution's methodology, configured exactly as approved in its manual.

  • Hierarchical structure of macroprocesses, processes and subprocesses with automatic coding
  • Risk matrix configurable in 3×3, 4×4 or 5×5
  • Levels, labels, ranges and colors definable by each institution
  • Definition of inherent and residual risk appetite
  • Likelihood calculation based on frequency and event history
  • Interactive analysis with heat map, risk factors and event window
  • Linkage to assets, technology threats and cybersecurity factors
  • Regulatory fields specific to banking institutions
  • Bulk upload of risks via template
  • Three-step review and approval flow

Treatment and Action Plans

The management decision is recorded, with name and date, not in an email.

  • Clickable inherent and residual heat maps
  • Guided treatment based on the risk's actual state: with or without controls, tested or not, residual versus appetite
  • Five ISO 31000 strategies: mitigate, accept, transfer, avoid, share
  • A dedicated form for each strategy
  • Action plans with tasks, owners and due dates
  • Status flow: pending, in progress, under review, completed
  • Approval or rejection by the reviewer and task reassignment
  • Closure evidence and automatic reminders
From inherent to residual risk

The heat map is not an illustration: it is the working tool. Each risk is placed according to its likelihood and impact, and the movement of the point from inherent to residual shows the measured effect of the controls that were actually tested.

I inherent risk · R residual risk. The distance between them is evidence, not a declared estimate.

Low Medium High Critical
54 321 12 345 IMPACT LIKELIHOOD I R
02

Control, events and reporting

What is tested, what happens and what is reported — with the same traceability.

Control Testing

A control does not reduce residual risk until it is proven to work.

  • Professional four-step methodology
  • Control information, design and operating-effectiveness assessments handled separately
  • Consolidated result with automatic effectiveness calculation
  • Upload of supporting evidence
  • Test history per control
  • Consolidated effect on residual risk
  • PDF reports in regulatory format

Operational Risk Events

When a risk materializes, the case file builds itself.

  • Structured logging through a guided wizard
  • Full regulatory classification aligned with the Superintendencia de Bancos manual
  • Confirmation statuses: pending, confirmed, denied
  • Configurable editing windows
  • Event coding structure configurable per institution
  • Quantification of losses and recoveries
  • Automatic notifications to the risk manager and internal control

Regulatory and Executive Reporting

The same data, in the format each superintendency requires.

  • Regulatory reports for operational risk and events
  • Automatic adaptation to the institution's regulatory regime
  • Exports specific to each regulatory regime
  • Global Risk Matrix in Excel with an analytical dashboard
  • Breakdown by macroprocess
  • Internal management reports and executive reports
Event lifecycle

Each step is dated and signed by user. When the regulator's request arrives, there is nothing to reconstruct: the event's case file has been building since the day it occurred.

DetectionGuided logging Regulatory classificationQuantification Reporting The event materializes within a process. Step-by-step wizard, no free-text fields. Category, business line, root cause. Gross loss, recoveries, net. Export to the regulator's format.
03

Technology risk and continuity

Which assets sustain operations, what threatens them and how the business recovers.

Technology Risk and Cybersecurity

From the asset inventory to the indicator presented to the committee.

  • Inventory of technology assets with criticality
  • Classification of confidentiality, integrity and availability
  • Threat and vulnerability management with likelihood and impact assessment
  • Incident management with a regulatory notification flow within defined timeframes
  • Assessment of technology vendors
  • Key risk indicators (KRIs) with traffic-light status and historical readings
  • Periodic technology risk assessments

Business Continuity (BCP/DRP)

The plan stops being a document and becomes a process with dates.

  • Business impact analysis (BIA) by location
  • Catalog of threats and disruption scenarios
  • Definition of critical personnel and technology resources
  • Recovery time and recovery point objectives (RTO and RPO)
  • Continuity and disaster recovery plans with ordered steps
  • Scheduling and tracking of drills
  • Crisis management team
  • Regulatory notifications
Key risk indicators 35% Critical patches pending 62% Incidents closed on time 85% Recovery window used

Illustrative values. Each institution defines its own indicators and traffic-light thresholds.

Recovery from disruption DISRUPTION RPO RTO Last valid backup Service restored

The objective times are defined in the BIA by process and location, and are compared against the actual result of each drill.

04

AML/CFT compliance and third-party risk

Two fronts with their own demands, managed with the same methodological discipline.

Money Laundering Risks (AML/CFT)

The matrix is calculated from the inventory — not typed in by hand.

  • Inventory of AML/CFT risks across the four FATF dimensions: customers, products, channels and geography
  • Periodic risk matrix calculated from the inventory
  • Typologies and red flags
  • AI-assisted loading from GAFILAT documents
  • AML/CFT controls and their periodic assessment
  • Key risk indicators and mitigation plans by dimension
  • Potential events with confidentiality and access traceability
  • Extended regulatory retention and notification to the Compliance Officer
  • Management of staff AML/CFT training

Third-Party Risk (TPRM)

Not every vendor requires the same level of scrutiny.

  • Materiality assessment using a weighted-factor methodology
  • Management program for material vendors
  • Due diligence by risk category
  • Multidimensional assessment of third-party risk
  • Verification of contractual compliance
  • Regulatory outsourcing register
  • Generation of PDF certificates
The four FATF dimensions CustomersProducts ChannelsGeography Profile, activity andsource of funds Nature and levelof exposure In-person, digitaland intermediated Jurisdictions andrisk zones AML/CFT
Vendor due diligence Vendor universe Materiality assessment Material vendors

Only material vendors enter the intensive management program. The rest are registered, with their assessment documented.

05

Governance, artificial intelligence and security

The layer that underpins trust in everything else.

Internal Audit

The third line works on the same data, without touching management's assessment.

  • Three lines of defense model
  • Audit plans with an approval cycle
  • Independent control tests that do not alter management's assessment
  • Finding management with severity, deadlines and follow-up through closure
  • Comparative view between management's assessment and audit's

Traceability and Audit Log

Who did what, when and on which record.

  • Auditable, immutable log of every action in the system
  • Filters by action, user, entity and date for investigation and audit

Security and Access Control

Multi-tenant, with strict separation between institutions.

  • Two-factor authentication (2FA)
  • Microsoft single sign-on (corporate SSO)
  • Permissions configurable by role and by institution
  • Strict isolation of each institution's data
Three lines of defense

Audit works on the same risks and controls as management, but its assessment is recorded separately. The comparative view shows exactly where the two differ — which is usually the committee's most useful conversation.

FIRST LINE Process owners They identify, assess and treat their own risks. SECOND LINE Risk and compliance They approve, test controls and monitor appetite. THIRD LINE Internal audit Assesses independently, without altering management.
Deliverables

What you hand the regulator.

The proof that a GRC platform works isn't the screen — it's the document it produces when the regulator's request arrives.

Operational risk report

In the format of the Superintendencia de Bancos or the Superintendencia del Mercado de Valores, depending on the institution's regime.

Event report

Materialized events with their regulatory classification, gross losses, recoveries and net.

Global Risk Matrix

In Excel, with an analytical dashboard and a breakdown by macroprocess, ready to attach to the file.

Control testing reports

In PDF, with design, operating effectiveness, calculated effectiveness and associated evidence.

Outsourcing certificates

Regulatory register of material vendors with their assessment and a PDF certificate.

Incident notifications

Technology and continuity incidents with their notification flow within the defined timeframes.

Artificial intelligence in practice

The AI proposes. The risk manager decides.

Artificial intelligence in MappRisk does not make risk decisions or sign off on assessments. It reduces transcription work and the blank-page problem, so the team can spend its time on judgment, the one thing that cannot be automated.

Every AI-generated suggestion is flagged as a proposal and requires explicit human validation before it is added to the inventory.

Assisted risk identification

Based on the institution's context — processes, products, channels and assets — it proposes candidate risks for the team to review, adjust or discard.

Cybersecurity factor suggestions

It proposes the factors applicable to each technology asset according to its nature and criticality.

Typology extraction from documents

It reads PDF documents and images — including those published by GAFILAT — and extracts typologies and red flags into the AML/CFT catalog.

Regulatory alignment

Native regulatory compliance, not an add-on.

The platform does not translate the regulations after it is built: the data structure, the catalogs and the reports are born from them. A single system for two superintendencies.

International standards

ISO 31000ISO 22301ISO/IEC 27031 ISO/IEC 27001NIST CSFNIST SP 800‑34 NIST SP 800‑161COBIT 2019

Money laundering prevention

Law 155‑17FATF · 40 Recommendations GAFILATCircular SB 005/22 Circular SB 003/18Circular SB 009/18

Superintendencia de Bancos · SIB

Manual de Requerimientos de Información (AMF 2022) Operational risk reports Circular on outsourcing

Superintendencia del Mercado de Valores · SIMV

R‑CNMV‑2018‑12‑MV amended by R‑CNMV‑2025‑04‑MV R‑CNMV‑2020‑08‑MV

Third-party risk

Basel Committee principles (BCBS)

The platform recognizes each institution's regime and adapts fields, catalogs and report formats accordingly.

Sectors served

Designed for Dominican banking, adaptable to the entire regulated financial sector.

In operation

Banking and financial intermediation entities

Commercial banks, savings and loan institutions, and credit corporations supervised by the Superintendencia de Bancos.

In operation

Securities market

Brokerage firms and investment fund managers (SAFI) under the regime of the Superintendencia del Mercado de Valores.

Service-ready

Insurers

The operational risk, continuity and third-party methodology applies to the insurance regime with no structural changes.

Service-ready

Savings and credit cooperatives

Scalable to smaller institutions, with the same methodological discipline and a proportional configuration.

The platform is multi-tenant: each institution operates with its own configuration, its own catalogs and its data completely separated from the rest.

Guided implementation

We don't just hand over a login and a manual.

Implementation is structured in phases and carried out alongside the institution's risk team, until the platform reflects the way they actually work.

PHASE 01

Kick-off

Alignment of scope, roles and owners on the institution's side.

PHASE 02

Methodology definition

Matrix size, levels, labels, appetite and assessment criteria.

PHASE 03

Provisioning

Setup of the institution, users, roles and permission scheme.

PHASE 04

Configuration

Catalogs, process structure, coding, workflows and notifications.

PHASE 05

Training

Training by role: process owners, risk, compliance and audit.

PHASE 06

Initial load

Migration of the existing risk and control inventory.

PHASE 07

Acceptance testing

Functional and reporting validation by the institution.

PHASE 08

Go-live

Production operation with support through the first cycle.

Methodology decisions are agreed with each client and documented: they are the foundation on which everything else is configured.

Frequently asked questions

What clients ask before they decide.

Why not keep managing in Excel?

Excel is great for calculating and terrible for proving. It doesn't record who changed an assessment or when, it doesn't enforce an approval flow, it doesn't link a control test to its effect on residual risk, and it doesn't produce the format the regulator requires. The point isn't the spreadsheet: it's that management evidence can't be reconstructed after the fact.

Why not an international suite?

International suites are robust and usually cover more functional ground. The difference is in the last mile: the regulatory fields of the Superintendencia de Bancos, the report formats of the Superintendencia del Mercado de Valores and local deadlines don't come preconfigured, and adapting them is a project in itself. MappRisk starts there. On top of that, the platform is in Spanish and support is local, in the same time zone.

What happens to our information if we leave the platform?

The information belongs to the institution. The terms for exporting and returning data at the end of the service are set out in the contract, and the platform includes export of the global matrix, the risk and control inventory, events and the audit log in open formats. It's a legitimate question, best settled before signing, not after.

Can we start with a single risk domain?

Yes. Many institutions start with operational risk and add continuity, AML/CFT, third parties or audit when their maturity or a regulatory requirement calls for it. The configuration grows with the organization and doesn't force you to redo what has already been loaded.

Is our data kept separate from other institutions'?

Yes. The platform is multi-tenant with strict isolation: each institution operates with its own configuration, its own catalogs and its data kept separate. Access control is by role and by institution, with two-factor authentication and an immutable audit log of every action.

Why MappRisk

Four reasons you notice after signing, not before.

01

Guided implementation

We support the methodology definition, the configuration, the initial load and the team's training, until the platform reflects the way the institution actually works.

02

In Spanish and built for Dominican regulation

Terminology, regulatory fields, report formats and local deadlines. No rough translations or adaptations of a product designed for another jurisdiction.

03

Scalable per institution

An institution can start with operational risk and add continuity, AML/CFT or third parties when its maturity requires it. The configuration grows with the organization, not the other way around.

04

Artificial intelligence that accelerates maturity

It shortens the time between identifying a risk and managing it, and frees the team from transcription work. The decision and the responsibility remain with the person managing the risk.

Next step

Request a demo.

We'll show you the platform configured with your own risk matrix, your appetite and your processes — not a generic example.

OfficeSanto Domingo, Dominican Republic