Skip to content

PUBLIC PRODUCT PREVIEW

COMPASS FOR BANKING · POWERED BY ARC

ARC is the versioned AI Risk & Compliance framework for banking AI use cases.

Know what stands behind every AI risk decision.

ARC gives Compass a structured control-and-test baseline for the declared use case. DATA Compass connects the bank-validated scope to measured and attributed evidence, exposes gaps and contradictions, and preserves the bank’s accountable human decision.

The result is a versioned assessment run and a concise Assessment Decision Record the bank can review and challenge.

View the decision record

Bank-owned decision · Catalog and ruleset are version-pinned · Run evidence links are pinned and attributed

Assessment Decision Record Illustrative summary

Use case Small-Business Term Loan Risk Grade · Harborline Commercial Bank (synthetic)

Recorded decision Conditionally authorized
Decision owner
Dana Whitfield
Finding count
40 in-scope tests
Coverage
22 answered; 18 open in this completed run

Coverage basis

  1. Measured 14
  2. Attested 8
  3. Open in this run 18

Pre-authored synthetic human judgment seeded by the demo rehearsal. Not a Compass recommendation.

ARC gives the assessment banking context.

Its versioned catalog of controls, tests, rules, and citations gives the bank a disciplined starting point—not a blank checklist.

Compass makes that framework operational.

It connects the bank-validated scope to measured and attributed evidence, while gaps, contradictions, and errors remain visible.

The bank owns the decision.

An accountable reviewer validates the scope and records the judgment, rationale, owner, and provenance.

THE OPERATING GAP

The bank has the pieces. It rarely has one defensible record.

The inventory says what exists. The control library says what should apply. Evidence sits across systems, documents, and people. The decision often lands somewhere else.

  1. Use-case inventory

    Records the name, owner, and status, but not the full basis for the decision.

  2. Control scope

    Defines the expected controls and tests, but needs accountable review for this use case.

  3. Operational evidence

    Arrives from different sources, at different confidence levels, with gaps and contradictions.

  4. Assessment trail

    Must keep the decision connected to its basis and preserve prior runs when the evidence changes.

When challenge arrives, the bank should not have to reconstruct the decision from email, slides, and memory.

THE RECORD

See what the decision is built on.

This illustrative product-preview summary uses a fully synthetic bank and use case. It shows answered tests, unresolved work, and the human decision without collapsing them into one reassuring score.

Assessment Decision Record Completed synthetic run

Recorded basis

Institution
Harborline Commercial Bank (synthetic)
Use case
CSD-002 · Small-Business Term Loan Risk Grade
Nearest ARC subprocess:
Credit Scoring
Recorded decision
Conditionally authorized
Accountable owner
Dana Whitfield
Recorded rationale
CS4.2, CU1.1 and CU1.4 not satisfied, CS4.1 and CU6.7 marginal — remediate before the next quarterly run; 2 tests await a human answer and 16 await evidence
Record state
Completed synthetic assessment run · illustrative product-preview summary

Coverage state

22 of 40 in-scope tests answered

14 measured · 8 attested

18 unresolved in this completed run

2 need a person · 16 need evidence

Outcome state
OutcomeCount
Satisfied13
Marginal6
Not satisfied3
Awaiting a person2
Not assessable16
Collector errors0

Illustrative synthetic sample. “Conditionally authorized” is a pre-authored synthetic human judgment seeded by the demo rehearsal. It is not a Compass recommendation, customer result, or legal conclusion.

HOW IT WORKS

From declared use case to a record the bank owns.

  1. Declare

    Record the intended use, owner, scope, and material dependencies.

  2. Map and validate

    ARC supplies the versioned control-and-test catalog. For the current Credit Scoring preview, Compass uses deterministic rules to suggest a baseline; an accountable reviewer adjusts and validates the final scope.

  3. Connect and assess evidence

    Bring together measured data and attributed evidence while preserving gaps, contradictions, unknowns, and errors.

  4. Record the decision

    A named bank user records the judgment and rationale and names the accountable owner.

  5. Reassess

    When evidence or validated scope changes, a user starts a new run and Compass retains the prior one.

WHY IT IS DEFENSIBLE

The decision remains connected to its basis.

In the product, Compass keeps the use case, validated ARC scope, evidence, findings, reviewer actions, positions, and human decision connected across immutable runs. The one-page Assessment Decision Record is deliberately concise: judgment, rationale and owner; coverage and outcome counts; an evidence-register summary; supersession count; and pinned provenance. A fluent explanation never replaces the underlying record.

  • Versioned scope in product

    Preserve the ARC catalog, ruleset, digest, and citations used for the run.

  • Attributed evidence in product

    Keep measured, attested, missing, and failed evidence visibly distinct.

  • Named accountability in product

    Record the decision owner, rationale, concurrence or dissent, and supersession.

  • Immutable run history in product

    A user adds a new assessment run when the basis changes instead of rewriting the prior decision.

Compass supports and preserves the decision. The bank owns it.

REGULATORY CONTEXT

Model-risk guidance changed in 2026. Accountability did not.

In April 2026, the Federal Reserve, OCC, and FDIC issued revised, risk-based model-risk guidance that supersedes SR 11-7 and SR 21-8. It is expected to be most relevant to banking organizations with more than $30 billion in total assets, but may also be relevant to smaller organizations with significant model-risk exposure.

The guidance excludes generative and agentic AI models from its scope while directing banks to use their own risk-management and governance practices for systems outside it. Its principles continue to apply to traditional statistical and quantitative models and non-generative, non-agentic AI models. Separate interagency guidance says using a third party does not diminish a bank's responsibility to operate in a safe and sound manner and comply with applicable laws and regulations.

The ARC rules in this workflow are deterministic, not predictive.

SR 26-2 excludes deterministic rule-based processes from its model definition when no statistical, economic, or financial theory underpins their design or use. The bank determines the classification and controls for its deployment.

Compass does not interpret the rules or accept risk for the bank. It preserves the evidence and accountable decision behind each use case.

DEPLOYMENT

Run the assessment inside the bank's environment.

DATA Compass deploys inside the customer environment and assesses connected sources in read-only mode. AI-assisted features use an in-environment model or a customer-approved external model endpoint.

  • Customer-controlled deployment boundary
  • Read-only access to connected sources
  • Versioned evidence and assessment provenance

Bring one priority AI use case.

We will walk one declared use case through the ARC control-and-test baseline, the Compass evidence record, and the bank’s human decision using an illustrative banking dataset. No source data is required for the first conversation.

Explore all industries