Projects
Outsourcing Register
Manage outsourcing compliance in the browser or fully offline on your own machine. Track providers, criticality and risk assessments, and contracts in alignment with CSSF 22/806 and EBA GL/2019/02, with built-in dashboards and reporting.
DORA RoI Explorer
A free interactive tool to explore the DORA Register of Information data model, understand the 15 RoI tables, and prepare your submission. Includes a readiness quiz, submission flowchart, and field-level reference — all in your browser.
DORA Incident Classifier
It's 02:00 and a system is down. Is this a major incident under DORA? Answer seven questions against the actual RTS thresholds — and see which reporting clocks are already running.
Regime Classifier: 22/806 or DORA
In April 2025 the CSSF split its outsourcing framework. This tool qualifies one arrangement in at most six questions — the governing regime (CSSF 22/806 or DORA with Circular CSSF 25/882), whether it is critical or important, and the obligations that follow — ending in a printable qualification memo. Runs entirely in your browser; nothing is stored or sent.
Contract Clause Gap Checker
Pick the regime that governs your arrangement — CSSF 22/806, DORA Article 30 or the EU AI Act — and check the contract clause by clause: every item carries its legal anchor, a severity, and the risk you run if it is missing. Mark each present, partial or missing, read the gap score, and export a gap register or a printable memo. Runs entirely in your browser; nothing is stored or sent.
Outsourcing Criticality Assessment
Determine whether an outsourced function is critical or important under CSSF Circular 22/806, points 15–20. Answer the rule-based point 18 triggers and their lettered sub-points, and get a determination reconciled point-per-point against the circular, plus register-ready values. Browser-only; nothing is stored or sent.
Outsourcing Risk Assessment
Assess an outsourcing arrangement across eleven risk dimensions under CSSF Circular 22/806, points 66–70, with the points 83–87/101 contractual-safeguards check and a reperformance note. A max-driven residual tier feeds straight into the Criticality Assessment's point 20 screen. Browser-only; nothing is stored or sent.
Outsourcing Due Diligence
Assess a prospective provider's suitability under CSSF Circular 22/806, points 65(d) and 71–75, including the points 94–96 certification-reliance conditions applied at selection stage. Overlay items turn related circular obligations into pre-contract evidence. Browser-only; nothing is stored or sent.
AI Governance Workspace
A free, browser-based workspace to govern AI across a regulated financial firm. Inventory every AI use case, classify it under the EU AI Act, run risk assessments and FRIAs, track third parties, incidents, controls, literacy and KRIs, and self-assess governance maturity — all over a single Excel workbook, with no data leaving your device.
EU AI Maturity Assessment & Risk Classification
A free interactive portal to assess your EU AI Act readiness and classify AI systems. Covers 9 governance domains (55 questions), a 5-phase risk classification engine, article explorer, timeline, glossary, and 17 curated resources — all in your browser.
Cloud vs Local AI
Where should your AI run — a frontier cloud API, or a model on your own hardware? For a regulated firm the deciding factors aren't speed and price but data location and vendor dependency. A plain-language explainer with a 60-second check that recommends a deployment tier for any given workload.
AI Act Compliance Clock
The Digital Omnibus moved some of the EU AI Act's high-risk dates — but not all of them. This page shows the revised post-Omnibus timeline, what changed versus what still lands on 2 August 2026, and a five-question check of whether the Article 50 transparency duties apply to you. Runs entirely in your browser; nothing you enter leaves the page.
Agent Governance Control Matrix
A working-paper control matrix that maps ten classic financial controls — least privilege, segregation of duties, audit trails, human sign-off, kill switches — onto AI agents across Microsoft Copilot, AWS Bedrock and AWS Quick Suite, against DORA, the EU AI Act and ISO 42001. For each control it shows what the platform gives you natively and the gap you still own. Filter, isolate the gaps, and export the full matrix to Excel.
AI Agent Portfolio (Case Study)
A sanitized case study of designing an AI agent portfolio for a second-line risk function at a regulated Luxembourg fund services firm — seven agents, five flows, one governance layer — with the part most write-ups skip: the full genericized prompt pack, the 13-risk control matrix, and the deployment probes. The prompts are copy-ready.
Article 50 Transparency Checker
Which of the four EU AI Act Article 50 transparency duties apply to each AI system you provide or deploy? Build a register of systems, answer the duty questions, and get a reperformable assessment trail, the applicable deadline, and a residual-risk rating per system — with Excel and printable-memo export. The Digital Omnibus moved the high-risk regime; it did not move Article 50.
AI Acceptable-Use Policy Builder
Generate a company AI acceptable-use policy from a guided form — scope, approved tools, data rules, human oversight, training and governance — anchored to the EU AI Act (incl. Art. 4 AI literacy), GDPR and, optionally, DORA and CSSF 22/806. Watch the document build live, then export it as a styled Word file or PDF. Runs entirely in your browser; nothing you enter leaves the page.
Vendor AI Due Diligence
A structured due-diligence questionnaire for assessing an AI vendor across EU AI Act value-chain obligations, data protection, model risk, security and DORA overlap. Weighted, re-performable scoring with a live scoreboard, critical-question floors, a gap list and a recommended contract-clause checklist. Export to CSV or print; nothing leaves your machine.
Risk & Control Self-Assessment (RCSA)
A free, browser-based Risk & Control Self-Assessment (RCSA) tool. Identify and score risks across your organisation, map controls, calculate residual exposure, and generate a visual heat map with an exportable risk register — no installation, no registration, no data stored.
Controls Testing Plan Builder
Build a control inventory, set the methodology once, and generate a risk-based annual controls testing plan: rotation, test method, sample size, timing and effort — with the scoping rationale written on every row. ISAE 3402 / SOX-style defaults, every parameter editable, exportable to Excel. Runs entirely in your browser; nothing is stored or sent.
PolicyHub
An offline, open-source desktop application for managing policy and procedure lifecycles. Track documents, review schedules, ownership, and version history with built-in dashboards and professional reporting tools.
IssueRegister
An offline, open-source desktop application for tracking organisational issues across departments. Role-based access, file attachments, audit logging, dashboards, and systematic issue lifecycle management.
Luxembourg Mortgage Calculator
A free online tool to plan your property financing in Luxembourg. Model loans across multiple tranches, stress-test different interest rate scenarios, check your debt-to-income ratio, and get a full amortization breakdown — all exportable as a clean PDF report.