RegAlign® + RiskAlign™
Two products. One brand family. One control.
RegAlign® and RiskAlign™ are two products in the Align product family, built with the same visual system, the same TypeScript stack, and the same audit discipline. They run on separate databases and can each be adopted alone. This page is the honest comparison so you spend on the problem you actually have first.
Pick RiskAlign if…
- Your board asks "are we operating inside appetite?" and you can't answer cleanly.
- Your risk register is in a spreadsheet, residual scores are inconsistent, and KRIs aren't linked to risks.
- You need scenario analysis (stress, reverse-stress) you can defend in front of a regulator.
- Three-lines accountability isn't visible — first line owns risks, second line owns oversight, third line owns assurance, and nobody can see the seam.
Pick RegAlign if…
- Your problem starts with "the regulator just published…" and ends with "…can we prove we comply?"
- You need an obligations register with chain-of-custody, not a risk register.
- Regulatory change tracking, horizon scanning, and attestation workflows are the headline pain.
- You want a defensible link from rulebook clause → control → evidence.
Pick both if…
You're a regulated firm where both teams exist. Each product keeps its own control register; obligations from RegAlign flow into RiskAlign as a CSV today (REST tomorrow), and controls in RiskAlign can carry the RegAlign obligation reference as metadata, so both sides know the linkage. See how they fit together.
Side by side
| RiskAlign | RegAlign | |
|---|---|---|
| What's the starting point? | What could hurt the firm — strategic, operational, conduct, financial risks. | What the regulator requires — handbooks, rulebooks, supervisory letters. |
| Primary user | CRO, risk owners, board risk committee. | Compliance officer, regulatory change team, MLRO. |
| Core unit of work | A risk, with appetite, controls, KRIs and scenarios. | An obligation, with mapped controls and evidence. |
| Scoring model | 5×5 inherent → residual, plus velocity and persistence. | Coverage and freshness against the obligations register. |
| Board output | Risk pack: heatmap, appetite breaches, KRI trend, top issues. | Compliance pack: obligation coverage, regulatory change pipeline, attestations. |
| Regulatory change | Not handled — RiskAlign assumes the obligation set is given. | Native — ingest, triage, assign, attest. |
| Risk appetite & KRIs | Native — board appetite per category, KRI thresholds, breach alerts. | Not handled — RegAlign assumes risk appetite is set elsewhere. |
| Audit trail | Per-risk and per-decision, with chain-of-custody on residual changes. | Per-obligation, with chain-hash on every state change. |
Still unsure?
Most firms only need one of the two to start. Pick the product that solves your sharper pain first; add the other later. The integration is designed so you're never locked out of running both.