Live since 1 October 2026

The whole regulatory stack, one control set.

Resilyo turns every regime a regulated institution answers to into live, trackable audit controls, reads your own documents against them, and gives the board a readiness picture it can defend.

145frameworks
2,368audit controls
7markets: EU, US, UK, Germany, Italy, Bulgaria, global standards
5languages, down to the wording of each control
One institution. Dozens of regimes.

Every one of them wants evidence. Resilyo keeps it in one place.

The catalogue is grouped by market and, inside each market, by domain: cyber and resilience, AI, privacy, prudential, payments, AML, ESG, transport and customs, health and safety, management systems. Each regime becomes a control set you can scope to your institution type and work through.

European Union

14 frameworks
DORANIS2CER DirectiveEU AI ActGDPRCRD VI / CRR IIIPSD2 → PSD3/PSRAML packageCSRD / ESRSCSDDDEBA ESG+3

United States

39 frameworks
NIST CSF 2.0NIST 800-53NIST AI RMFFedRAMPCMMC 2.0NYDFS 500SOX ICFRGLBA SafeguardsSEC CyberHIPAACCPA/CPRAUS AML (BSA)OFAC+26

United Kingdom

20 frameworks
FCASM&CRUK GDPRCAFUK NISUK MLRConsumer CreditUK Payment ServicesBribery ActOnline Safety Act+10

Germany

16 frameworks
BaFin MaRiskBAITBSIGBDSGWpHGZAGGwGLkSGHinSchG+7

Italy

14 frameworks
Banca d'Italia Circ. 285Consob Reg. IntermediariIVASS 38/2018ACN · NIS2Codice PrivacyD.Lgs. 231/2001D.Lgs. 231/2007Legge 262/2005+6

Bulgaria

19 frameworks
ЗКИЗПУПСЗМИПЗЗЛДКЗЗПФИЗКБЗЕСКодекс на труда+10

Global standards

23 frameworks
ISO 27001ISO 22301ISO 42001ISO 27701ISO 9001ISO 31000ISO 37301SOC 2PCI DSSFATF 40Wolfsberg+12

An institution-profile filter scopes the whole list to a universal bank, a payment institution, a card processor or a leasing company, and marks each regime Direct, Conditional or Out of scope with the reasoning. If the regime you answer to is not listed, say which one and why: the catalogue is data, not code, and a new control set is an editorial change rather than a release.

What it does

From regulatory text to work your team can actually finish.

Controls with depth

Every control carries its description, minimum content, suggested owner, review cadence, the articles it evidences and any proportionality relief. Underneath sit the implementation steps and the evidence artefacts an auditor expects.

DORA · Art. 17 · ICT-related incident management process
owner: Head of ICT Risk · cadence: annual · 6 steps · 4 artefacts

Per-control tracking

Status, owner, evidence location, last-reviewed date and notes on each control, with step checklists that roll up into completion. Each field is gated by its own permission, so a contributor can attach evidence without changing a status.

status · owner · evidence · reviewed · notes → five permissions, granted per workspace and per framework

AI readiness gap analysis

Upload policies, registers and plans into the workspace's document library. The AI pass compares them to the controls, grades each one Ready, Partial or Not ready, and writes down the gap and a recommendation.

2,203 controls AI-assessed from 38 documents in one pass · every grade cites the passage it relied on

Cross-framework crosswalk

Related controls are grouped into cross-cutting families, so an obligation assessed once counts everywhere it applies. Incident reporting under DORA, NIS2 and ISO 27001 is one piece of evidence, not three spreadsheets.

family: incident handling → DORA Art. 17–19 · NIS2 Art. 23 · ISO 27001 A.5.24–5.28 · NYDFS 500.17

Reports, export and audit trail

A printable readiness assessment for management or an auditor, a full JSON export of the workspace on demand, and an append-only log of who changed what and when. Your data is never locked in.

readiness-report.pdf · workspace-export.json · activity log: 14,212 entries, none editable

Financial audit BETA and OSS licences BETA

A planning-stage workbench for a bank or an ordinary company: programme checklist mapped to the ISAs, analytical-review ratios and red flags, and AI analysis of uploaded statements. Plus a bill-of-materials licence review that judges each component against your deployment context.

ISA 315 · 320 · 520 · 570 · CycloneDX, SPDX, npm license-checker, CSV · internal / hosted / distributed
Anatomy of a control

Not a checkbox. A record an auditor can read.

This is what one of the 2,368 controls looks like in the workspace. The regulatory reference, the people and dates, the steps, the evidence and the AI grade live together, so the question "can we show this?" has one answer.

  • The clause it evidences, so nobody argues about which article a policy is answering.
  • Steps and artefacts written by practitioners, in five languages, not by the model.
  • A grade that cites its source: the passage the AI relied on, and what it did not find.
  • Edits logged, never overwritten. Every change lands in the append-only trail.
DORA · Regulation (EU) 2022/2554 · Art. 17(1)–(3)

ICT-related incident management process

Partial · AI-assessed 24 Sep 2026
OwnerHead of ICT Risk
Review cadenceAnnual · next 31 Mar 2027
ApplicabilityDirect · universal bank
Also evidencesNIS2 Art. 23 · ISO 27001 A.5.24

Implementation steps 4 / 6

  • Define and document the incident management process, including roles
  • Set early-warning indicators and classification criteria (Art. 18)
  • Establish escalation to senior management and the management body
  • Record all ICT-related incidents and significant cyber threats
  • Define communication plans for clients, counterparties and the public
  • Run a post-incident review after every major ICT-related incident

Evidence artefacts

ICT Incident Management Policy v3.2 · approved 12 Feb 2026
Incident classification matrix (RTS 2024/1772 thresholds)
Incident register, FY2026 extract
Post-incident review template · not found in library
Gap: no evidence of post-incident review or external communication plans. The policy covers detection, classification and internal escalation (§4–§7) but is silent on root-cause analysis after major incidents and on client communication. Recommendation: add a review procedure referencing Art. 17(3)(h) and a communication annex; re-run the pass. Decision-support, not legal advice. Grades are preliminary and control-based.
How the AI readiness pass works

Your own documents, read against every control you carry.

The model reads what you already have. With a full library it produces a readiness picture in minutes; with an empty one it can only tell you the library is empty.

Upload your evidence

Policies, registers, plans, board minutes, test reports. PDF, Word and scans with OCR go into the workspace's document library, per tenant, with versions kept.

The pass compares and grades

Each control is checked against the library by a Claude or ChatGPT model. The result is Ready, Partial or Not ready, with the gap, the passage relied on and a recommendation. Nothing you typed is overwritten.

People decide

Owners review the grade, attach what was missing, and the dashboard, the crosswalk and the readiness report update. The checklist-derived signal stays visible next to the AI one.

Decision-support, not assurance. Resilyo supports preliminary, control-based readiness assessments. It is not a statutory audit, expresses no audit opinion and is not legal advice. Regulatory wording and translations are machine-assisted; verify anything you will rely on against the primary instrument.

Built to be audited

Isolated. Permissioned. Logged.

A compliance tool is itself evidence. Resilyo is built so that the workspace, the roles and the trail would survive the inspection they help you prepare for.

Tenant isolation · one workspace per organisation, a hard boundary Field-level RBAC · per tenant, per framework, per field Append-only audit trail · who, what, when Microsoft Entra ID sign-in · guest access by invitation Full JSON export · on demand, throughout Partner branding · your name in the chrome, not ours

For regulated organisations

Banks and credit institutions, insurers, payment and e-money firms, investment firms, ICT providers to financial entities, critical-infrastructure operators, and mid-sized companies inside a regulated supply chain.

For the firms that advise them

Multi-tenant by design: each client is its own workspace with its own data, roles and trail, one click apart. Deliver gap assessments on Resilyo and leave the client a workspace that keeps living after the engagement.

For the management body

Personal accountability for resilience wants a defensible picture, not reassurance. The readiness report shows what is evidenced, what is partial, what is missing and who owns it.

ASP.NET Core 10 · Azure Cosmos DB · Microsoft Entra ID · Claude and ChatGPT models · English, Bulgarian, German, Greek, Italian

Is Resilyo for you?

Built for organisations that answer to a supervisor.

You are the core case if…

  • You fall in scope of DORA, NIS2, the EU AI Act, MaRisk, NYDFS 500, SOX or FCA operational resilience, or you are not sure whether you do.
  • You hold or are working towards ISO 27001, 22301, 9001 or 42001, PCI DSS, SOC 2 or NIST CSF 2.0.
  • You face more than one regime and keep answering the same obligation in different spreadsheets.
  • An audit, inspection or client questionnaire is coming, the evidence exists, and nobody can produce it quickly.

You are a consultancy if…

  • You deliver compliance work for several clients and need a hard boundary between them.
  • You want the client to see your name in the product, with your own logo and colours.
  • You want the findings of an engagement to outlive the engagement.
  • You would rather sell judgement than maintain spreadsheets.

Signs it is the wrong tool

An unhappy pilot helps nobody, so be honest about these.

  • You want a certificate. Resilyo prepares you for an audit; it performs none and issues no opinion.
  • You want the tool to decide applicability for you. It shows Direct, Conditional or Out of scope with the reasoning; your people still judge.
  • You have no documents and nobody to own controls.
  • You need offline access. Resilyo is online-only, by design.
  • You want a single-user personal tracker. One person with a spreadsheet is cheaper.
Getting started

No sign-up form. A conversation, then a workspace with your name on it.

Every workspace holds a named organisation's compliance position, so workspaces are created for someone rather than handed out. There is no public price list either: the scope is agreed per engagement.

A guided demo

About 45 minutes on a demonstration workspace, run with you rather than sent to you. Bring the frameworks you actually answer to and ask to see a full control record, the AI pass on a document, the crosswalk and the report.

Ask for it at info@roussinov.eu

A pilot

A real workspace, scoped down: three to eight frameworks, your current approved documents, a few named people, a fixed period and one question worth answering, such as "can we produce a defensible readiness picture for this regime by this date".

Agreed as part of a proposal

A proposal

Some combination of the platform for your frameworks and people, onboarding and the first AI pass with your team, advisory delivery by the practice, and support. Scope, term and commercials are agreed per engagement.

A scoping call, then a written proposal