Skip to content
Live prototype

CANDOR

RCSA copilot: drafting assistance for the first line, real challenge for the second.

The problem

Risk and control self-assessment is the most widely practiced ritual in operational risk and the least challenged. Units assess themselves, the second line collects the spreadsheets, and the results converge on a suspicious sameness: every risk medium, every control effective, every rationale a paragraph of boilerplate that would survive transplantation into any other unit unchanged. The assessment program produces coverage, not information. Everyone involved knows it, and the format makes it nobody's fault.

What it does

CANDOR works both sides of the assessment. For the first line it is a drafting copilot: structured prompts that pull specifics out of the assessor, suggested risk and control language grounded in the unit's actual profile, and a visible record of what was AI-suggested versus human-authored. For the second line it is a challenge instrument: cross-unit consistency checks that flag when two units with the same process rate the same risk differently for no stated reason, staleness detection for assessments that have not moved while their environment has, and boilerplate detection that scores rationales on how interchangeable they are.

Challenge output is written as questions a reviewer would actually ask, attached to the specific cell that provoked them, and tracked to resolution.

Why it matters

The RCSA is where the first line tells the truth about itself, or does not. Basel's principles for sound operational risk management put self-assessment at the center of the identification toolkit, and supervisors increasingly read RCSA quality as a proxy for risk-culture quality. An assessment program with real challenge in it changes behavior upstream: rationales get specific because someone is reading them, ratings get honest because sameness gets flagged. That is the difference between an assessment program and a filing exercise.

Honest framing

CANDOR is a working prototype and a blueprint, not a product. It runs in the browser on a synthetic demo tenant, against fictional assessments shaped like the suite's loss and indicator data, with deterministic demo output and a seeded library sized for demonstration rather than production breadth. Open it, read the challenge queue, and decide which questions your own program would survive. That is what it is for.