Risk technology on Power Platform

Risk systems of record, built inside your Microsoft tenant instead of bought from a GRC vendor.

Model risk inventories, non-financial risk indicator systems and regulatory reporting on Power Apps, Power BI and Fabric — the workflow, the data and the reporting on one governed model. No new vendor, no data leaving the perimeter.

What we have built

Each began as a build for one institution and is now an accelerator for the next.

Model risk inventory

Model register with ownership, tiering and lifecycle; validation findings and remediation workflow; periodic attestation; reporting to the model risk committee from the same model.

Built onReplaces Archer, MetricStream, spreadsheets · Power Apps, Dataverse, Power BI
Why this way

Tenant, together, and to the standards.

Why in your tenant

Your security team already trusts Entra, Dataverse and Fabric. No new vendor to onboard, no data transfer agreement, no annual licence per seat, and your own people can maintain it.

Why workflow and reporting together

GRC tools hold the process; the reporting lives somewhere else and disagrees with it. Here the app writes to the same governed model the committee pack reads from.

Why to the standards

Designed to what examiners ask for: BCBS 239 principles for risk data, the FSB risk appetite framework and the Basel Committee’s operational risk principles. [LINKS TO ORIGINALS]

How it is delivered

Module by module, never rip-and-replace.

We start with one process the legacy tool serves badly, usually the inventory or the indicators, and rebuild it as a governed Power Apps module with Power BI on the same model. The legacy platform keeps running until each module is retired on its own evidence.

Prototypes are built on our own tenant against anonymised data before any client access; the production build is done inside the client environment. Priced as a build plus an annual support seat, not by the hour. [PRICING MODEL]

Banks usually reach this work through one of our consulting partners; funds and insurers engage us directly. Either way, the same people build it.

Case · Global bank, Americas

Model risk inventory moved off Archer onto Power Platform

Inventory, findings and validation workflow rebuilt as a governed Power Apps system in the bank’s tenant, with committee reporting in Power BI on the same model.

Read the case
[X]models in inventory
[X wks]to first module live
[X]workflows migrated
[X%]of legacy cost
Common questions

Things people ask before the first call.

Is this a product or a build?
Both. SightLine and the model risk inventory are accelerators we have built once and bring to the next institution; each deployment is then configured to your taxonomy and integrations inside your tenant. You own the result.
What happens to our Archer or MetricStream licence?
It keeps running until each module has been replaced on its own evidence. We start with one process the legacy tool serves badly, and retire modules one at a time.
Which standards do you design to?
The Basel Committee's Principles for effective risk data aggregation and risk reporting (BCBS 239), the FSB's Principles for an effective risk appetite framework, the Basel Committee's Revisions to the principles for the sound management of operational risk (2021), and for model risk SR 11-7 / OCC 2011-12. [LINKS TO ORIGINALS]
Do we need Copilot?
No, but it is the reason to govern definitions first. Once measures, indicators and commentary sit in a governed model, Copilot can answer questions over them without any further build.

Renewal coming up on a GRC licence?

Tell us which module hurts most. We will show you the same process running on Power Platform, on anonymised data, before you decide anything.