Risk systems of record, built inside your Microsoft tenant instead of bought from a GRC vendor.
Model risk inventories, non-financial risk indicator systems and regulatory reporting on Power Apps, Power BI and Fabric — the workflow, the data and the reporting on one governed model. No new vendor, no data leaving the perimeter.
Each began as a build for one institution and is now an accelerator for the next.
Model risk inventory
Model register with ownership, tiering and lifecycle; validation findings and remediation workflow; periodic attestation; reporting to the model risk committee from the same model.
SightLine — non-financial risk indicators
Indicator inventory and definitions with version history, intake and approval, appetite calculation, period close, and the line of sight from the appetite statement to the control that has to change.
Findings and issue management
Audit, regulatory and self-identified findings with owners, due dates, evidence and closure, reported on the same model as the risks they relate to.
Committee packs with commentary as data
Narrative drafted from governed measures, approved by a named person, stored as a table and exposed back into the model, so what was said can be checked against what happened.
Tenant, together, and to the standards.
Why in your tenant
Your security team already trusts Entra, Dataverse and Fabric. No new vendor to onboard, no data transfer agreement, no annual licence per seat, and your own people can maintain it.
Why workflow and reporting together
GRC tools hold the process; the reporting lives somewhere else and disagrees with it. Here the app writes to the same governed model the committee pack reads from.
Why to the standards
Designed to what examiners ask for: BCBS 239 principles for risk data, the FSB risk appetite framework and the Basel Committee’s operational risk principles. [LINKS TO ORIGINALS]
Module by module, never rip-and-replace.
We start with one process the legacy tool serves badly, usually the inventory or the indicators, and rebuild it as a governed Power Apps module with Power BI on the same model. The legacy platform keeps running until each module is retired on its own evidence.
Prototypes are built on our own tenant against anonymised data before any client access; the production build is done inside the client environment. Priced as a build plus an annual support seat, not by the hour. [PRICING MODEL]
Banks usually reach this work through one of our consulting partners; funds and insurers engage us directly. Either way, the same people build it.
Model risk inventory moved off Archer onto Power Platform
Inventory, findings and validation workflow rebuilt as a governed Power Apps system in the bank’s tenant, with committee reporting in Power BI on the same model.
Read the caseThings people ask before the first call.
Is this a product or a build?
What happens to our Archer or MetricStream licence?
Which standards do you design to?
Do we need Copilot?
Renewal coming up on a GRC licence?
Tell us which module hurts most. We will show you the same process running on Power Platform, on anonymised data, before you decide anything.