CRUX
Enterprise issues management: one lifecycle, one severity scale, one taxonomy, one roll-up.
The problem
Every bank runs on issues, and almost none run them well. Issues arrive through three doors: the first and second line finding their own gaps, internal audit findings, and regulatory findings from examinations and supervisory letters. In most institutions each door keeps its own spreadsheet, its own aging clock, and its own definition of closed. The board sees three unreconciled numbers. The examiner asks how many open high-severity issues touch payments, across all sources, and the honest answer takes a week to assemble.
What it does
CRUX is a single register of record for issues across the bank: one lifecycle, one severity scale, one taxonomy, one roll-up. Issues move through an auditable workflow from identification through action plan, remediation, validation, and closure, with role-based control over who can advance each stage and an append-only audit trail underneath. Closure is evidenced, not asserted.
The roll-up is the point. Every issue is classified against the shared taxonomy spine: event type, business line, organizational unit, process, product, risk theme, root cause. Pick any node and CRUX shows every open issue rolling into it, from all three sources, aged and severity-weighted, in one view. The question that took a week now takes a click.
Why it matters
Issues management is where findings become obligations to act, and it is the discipline supervisors read most literally: aging profiles, repeat findings, validation rigor, and whether closure means anything. Basel's principles for sound operational risk management expect exactly this loop to work. A register that cannot aggregate across sources and dimensions is a filing cabinet. One that can becomes the connective tissue of the second line, linking loss events, control weaknesses, assessment findings, and regulatory commitments to the same spine.
Honest framing
CRUX is a working prototype and a blueprint, not a product. It runs in the browser on a synthetic demo tenant, with fictional issues, fictional findings, and deterministic demo data. Open it, walk an issue through its lifecycle, and interrogate the roll-up. That is what it is for.