All-in-one platform
Operational, technology, continuity, AML/CFT, third-party and audit risk in one place, with a single methodology and a single control inventory.
End-to-end risk management and regulatory compliance, powered by artificial intelligence.
Every area keeps its own version of the truth. Controls get tested in one file, events logged in another, and the evidence for the regulator gets pulled together at the last minute — rebuilding work you'd already done. The real cost isn't the duplicated effort. It's not being able to answer, the moment you're asked, what your institution's actual risk profile is.
The difference isn't having a system instead of files. It's that the evidence is produced as you manage risk — not afterward.
Operational, technology, continuity, AML/CFT, third-party and audit risk in one place, with a single methodology and a single control inventory.
Built on the regulations of the Superintendencia de Bancos (Superintendency of Banks) and the Superintendencia del Mercado de Valores (Superintendency of the Securities Market) — not a compliance module bolted on afterward.
Speeds up risk identification and document analysis. The AI proposes; the risk manager decides and signs off.
Matrix from 3×3 to 5×5, scales, labels, colors, catalogs, appetite and approval workflows adjust to each institution's methodology.
Strict separation of each institution's information, role-based permissions, two-factor authentication and an immutable audit log.
In most institutions, each risk domain is managed with a different tool, a different owner and a different assessment criterion. When the regulator asks for a consolidated view, someone has to reconcile them by hand.
MappRisk unifies all six under the same matrix, the same risk appetite and the same control inventory. A control tested once serves every domain where it applies.
The institution can start with one domain and add the others as its maturity requires, without redoing what has already been loaded.
From risk identification to the documented management decision, in a single traceable flow.
A snapshot of the institution's risk profile, the moment it is asked for.
The institution's methodology, configured exactly as approved in its manual.
The management decision is recorded, with name and date, not in an email.
The heat map is not an illustration: it is the working tool. Each risk is placed according to its likelihood and impact, and the movement of the point from inherent to residual shows the measured effect of the controls that were actually tested.
I inherent risk · R residual risk. The distance between them is evidence, not a declared estimate.
What is tested, what happens and what is reported — with the same traceability.
A control does not reduce residual risk until it is proven to work.
When a risk materializes, the case file builds itself.
The same data, in the format each superintendency requires.
Each step is dated and signed by user. When the regulator's request arrives, there is nothing to reconstruct: the event's case file has been building since the day it occurred.
Which assets sustain operations, what threatens them and how the business recovers.
From the asset inventory to the indicator presented to the committee.
The plan stops being a document and becomes a process with dates.
Illustrative values. Each institution defines its own indicators and traffic-light thresholds.
The objective times are defined in the BIA by process and location, and are compared against the actual result of each drill.
Two fronts with their own demands, managed with the same methodological discipline.
The matrix is calculated from the inventory — not typed in by hand.
Not every vendor requires the same level of scrutiny.
Only material vendors enter the intensive management program. The rest are registered, with their assessment documented.
The layer that underpins trust in everything else.
The third line works on the same data, without touching management's assessment.
Who did what, when and on which record.
Multi-tenant, with strict separation between institutions.
Audit works on the same risks and controls as management, but its assessment is recorded separately. The comparative view shows exactly where the two differ — which is usually the committee's most useful conversation.
The proof that a GRC platform works isn't the screen — it's the document it produces when the regulator's request arrives.
In the format of the Superintendencia de Bancos or the Superintendencia del Mercado de Valores, depending on the institution's regime.
Materialized events with their regulatory classification, gross losses, recoveries and net.
In Excel, with an analytical dashboard and a breakdown by macroprocess, ready to attach to the file.
In PDF, with design, operating effectiveness, calculated effectiveness and associated evidence.
Regulatory register of material vendors with their assessment and a PDF certificate.
Technology and continuity incidents with their notification flow within the defined timeframes.
Artificial intelligence in MappRisk does not make risk decisions or sign off on assessments. It reduces transcription work and the blank-page problem, so the team can spend its time on judgment, the one thing that cannot be automated.
Every AI-generated suggestion is flagged as a proposal and requires explicit human validation before it is added to the inventory.
Based on the institution's context — processes, products, channels and assets — it proposes candidate risks for the team to review, adjust or discard.
It proposes the factors applicable to each technology asset according to its nature and criticality.
It reads PDF documents and images — including those published by GAFILAT — and extracts typologies and red flags into the AML/CFT catalog.
The platform does not translate the regulations after it is built: the data structure, the catalogs and the reports are born from them. A single system for two superintendencies.
The platform recognizes each institution's regime and adapts fields, catalogs and report formats accordingly.
Commercial banks, savings and loan institutions, and credit corporations supervised by the Superintendencia de Bancos.
Brokerage firms and investment fund managers (SAFI) under the regime of the Superintendencia del Mercado de Valores.
The operational risk, continuity and third-party methodology applies to the insurance regime with no structural changes.
Scalable to smaller institutions, with the same methodological discipline and a proportional configuration.
The platform is multi-tenant: each institution operates with its own configuration, its own catalogs and its data completely separated from the rest.
Implementation is structured in phases and carried out alongside the institution's risk team, until the platform reflects the way they actually work.
Alignment of scope, roles and owners on the institution's side.
Matrix size, levels, labels, appetite and assessment criteria.
Setup of the institution, users, roles and permission scheme.
Catalogs, process structure, coding, workflows and notifications.
Training by role: process owners, risk, compliance and audit.
Migration of the existing risk and control inventory.
Functional and reporting validation by the institution.
Production operation with support through the first cycle.
Methodology decisions are agreed with each client and documented: they are the foundation on which everything else is configured.
Excel is great for calculating and terrible for proving. It doesn't record who changed an assessment or when, it doesn't enforce an approval flow, it doesn't link a control test to its effect on residual risk, and it doesn't produce the format the regulator requires. The point isn't the spreadsheet: it's that management evidence can't be reconstructed after the fact.
International suites are robust and usually cover more functional ground. The difference is in the last mile: the regulatory fields of the Superintendencia de Bancos, the report formats of the Superintendencia del Mercado de Valores and local deadlines don't come preconfigured, and adapting them is a project in itself. MappRisk starts there. On top of that, the platform is in Spanish and support is local, in the same time zone.
The information belongs to the institution. The terms for exporting and returning data at the end of the service are set out in the contract, and the platform includes export of the global matrix, the risk and control inventory, events and the audit log in open formats. It's a legitimate question, best settled before signing, not after.
Yes. Many institutions start with operational risk and add continuity, AML/CFT, third parties or audit when their maturity or a regulatory requirement calls for it. The configuration grows with the organization and doesn't force you to redo what has already been loaded.
Yes. The platform is multi-tenant with strict isolation: each institution operates with its own configuration, its own catalogs and its data kept separate. Access control is by role and by institution, with two-factor authentication and an immutable audit log of every action.
We support the methodology definition, the configuration, the initial load and the team's training, until the platform reflects the way the institution actually works.
Terminology, regulatory fields, report formats and local deadlines. No rough translations or adaptations of a product designed for another jurisdiction.
An institution can start with operational risk and add continuity, AML/CFT or third parties when its maturity requires it. The configuration grows with the organization, not the other way around.
It shortens the time between identifying a risk and managing it, and frees the team from transcription work. The decision and the responsibility remain with the person managing the risk.
We'll show you the platform configured with your own risk matrix, your appetite and your processes — not a generic example.