DELPHI
Severe-but-plausible scenario narratives with quantified loss ranges, a two-pass challenger workflow, and a full governance and audit trail.
Working prototypes that blueprint what modern operational risk tooling should look like for mid-tier banks.
Every tool in this lab started as a gap I hit inside a bank: a regulatory expectation with no tooling behind it, a committee process held together by spreadsheets and goodwill, a question from an examiner that took three weeks to answer because the evidence lived in nine places.
The premise is simple. Operational risk tooling stagnated at the register stage while the discipline moved to resilience: services, tolerances, dependencies, testing, evidence. AI makes the missing instruments buildable, but only when the builder understands what a regulator will probe and what effective challenge has to capture. So I build them: as working prototypes and blueprints, not products.
Two builds are live. The rest of AEGIS, the twelve-module suite, is in research, sequenced roughly by how much pain each gap causes. Everything here is published to be examined, challenged, and cited; the full roadmap, with architecture decisions and evaluation notes, is available on request.
Severe-but-plausible scenario narratives with quantified loss ranges, a two-pass challenger workflow, and a full governance and audit trail.
An operational resilience workbench for mid-tier banks: important business services, impact tolerances, dependency mapping, scenario testing, board-ready reporting.
Nth-party dependency chains for critical services: who actually sits under your important business services, and where concentration hides.
Drafting and challenging risk and control self-assessments: consistency checks across units, stale-assessment detection, challenge prompts.
Regulatory-change tracking mapped to obligations and controls, so a new guideline lands as a delta, not a reading assignment.
Data-driven impact tolerances for important business services, in the metrics a board can actually approve.
Deduplication and gap analysis across bloated control libraries: which controls actually map to which risks, and which are theatre.
Mining public loss events and enforcement actions into structured scenario inputs and comparator benchmarks.
One register for self-identified, audit, and regulatory issues across the bank: lifecycle workflows from action plan to validated closure, and issue exposure aggregated across every taxonomy node.
Which key risk indicators actually lead losses, and which merely decorate the pack: indicator quality grading, backtested thresholds, and honest early warning.
Frequency and severity modeling for operational loss projection under stress, quantified in the shape the CCAR cycle expects.
Consistent, auditable classification of loss events at the point of capture, so the register feeds analysis instead of rework.
The full roadmap (sequencing, architecture decisions, and evaluation notes) is available on request.
Request the roadmap