Home / Industries / Financial services

MyRISK Trace · banking, insurance and superannuation

Make critical service-provider, cyber and resilience decisions explainable before anyone asks.

The systems and the committees already exist. What's hard is showing what was known at the time, who had authority, why it was reasonable, what conditions applied, and what has changed since.

Why now

“We have systems, but we could not reconstruct the decision if challenged.”

That sentence is usually said by someone who is not disorganised. The frameworks are in place, the committee met, the paper exists. The gap opens months later, when the question is no longer what was decided but what was in front of the people who decided it.

The record is spread across a board pack, an email thread, a risk system, a procurement file and someone's notes — each holding part of it. Assembling the answer takes days, and the parts that were verbal cannot be assembled at all.

The decision was probably sound. Showing that it was is a different piece of work.

What usually starts the conversation

  • A material service-provider register review under CPS 230, which commenced 1 July 2026 — or any question about a material arrangement
  • An internal audit finding on decision evidence or approval trails
  • A board or risk-committee challenge to a decision already taken
  • A control exception that has been rolled over more than once
  • An operational incident that puts an earlier trade-off under review
  • A first AI use case that needs an approval somebody will defend

Where it bites first

Five decisions worth being able to replay

01

A material service-provider decision

Why this provider, what was assessed, what was accepted, and which conditions were attached — including the ones nobody has checked since.

02

An operational resilience decision

A tolerance set, a dependency accepted, a workaround approved. The reasoning is usually sound and rarely written down where it can be found later.

03

A risk acceptance

Who accepted it, on what basis, for how long, and whether the circumstances that made it reasonable still hold.

04

A cyber or control exception

Especially one renewed more than once, where the original justification and the current one have quietly diverged.

05

An AI-use approval

What the model was approved to do, what evidence supported it, who owns it, and what would trigger a review.

Not a cyber problem

Not all of these are cyber questions. A material outsourcing decision and a resilience trade-off are the ones most often challenged, and the least likely to have a record that survives the challenge.

What you already have

The stack is not the gap.

A firm of any size in this sector already has a GRC platform, a risk register, an operational-risk function, three lines of accountability and a committee calendar. Those work. They record that a decision happened, who attended, and what the position is now.

What none of them holds is the decision as it stood at the moment it was made — the evidence relied on, the policy version in force, the alternatives weighed, the conditions attached, and what has drifted since. Trace sits alongside those systems and holds that.

What a Trace record preserves

  • The evidence that existed at the time, and the policy version that applied
  • The rationale, assumptions and alternatives considered
  • Who had authority, and what exactly was approved
  • Conditions, expiry and review dates
  • Drift — whether changed circumstances unsettle the approval

The proof

What a replay actually produces

Material service-provider decision · sanitisedExample

The comparison, gaps included

  • The decision as evidenced, dated when it was made rather than when it was written up
  • Each evidence item found, where it was held, and how long retrieval took
  • Evidence that should exist and does not — named individually rather than summarised
  • The approvals that were verbal and cannot now be confirmed
  • The conditions attached at approval, and which have been reviewed since
  • What a reviewer would ask that the current record cannot answer

The Diagnostic runs this against one decision you choose. The output includes what is missing, which is the part that makes it worth having before someone else asks.

Who this is for, and who it isn't

Two signals that send you somewhere else

Start with Consulting instead

If what brought you here is an audit finding or a workflow that keeps failing — evidence that never arrives, actions closed without proof, controls tested once — the first piece of work is diagnosis, not a decision record.

Consulting — the fixed-scope assessment

Start with Essentials instead

Smaller firms, brokers and advisers whose real burden is being asked for the same proof over and over — by insurers, licensees or clients — want a rhythm that keeps it current, not a replay of one decision.

Essentials — check what you keep rebuilding

Worth understanding one decision example first either way — it is usually what makes clear which of the three this actually is.

For your reviewers

The boundaries, in writing

What this is not

  • Whether your position satisfies an obligation is your assessment and your regulator's, never a vendor's. No product determines that for you, and one that implies otherwise is selling you a risk rather than removing one.
  • MyRISK does not sell into the compliance-platform category, which is a positioning choice rather than a limit: Core is an assurance layer and can hold controls, evidence, owners and reporting against a standard. The argument here is about the decisions taken around those controls, which is a different product and a different conversation.
  • Compliance is not guaranteed, and “regulator-ready” is not promised. Replayability is a property of the record, not a legal or supervisory conclusion.
  • No saving is quantified here. Reconstruction time varies by firm and by decision, and any figure MyRISK has not measured with you would be invented.
  • Trace complements your GRC, ITSM and collaboration systems. It replaces none of them.
  • AI can draft a narrative after the fact. It cannot prove what existed and was relied on at the time — which is the whole point of the record.

Questions readers ask

Before you take this to anyone else

Does this replace our GRC platform?

No. It holds the decision layer your GRC platform does not: what was known, relied on and authorised at a point in time. It sits alongside.

Who needs to be in the first conversation?

Usually whoever owns the decision class — operational risk, resilience, procurement risk or the CISO — plus the person who would have to answer for it. Internal audit is often the reason it is being asked at all.

What do we have to share to start?

One decision, and whatever record of it currently exists. A redacted extract or a walkthrough works; nothing sensitive is uploaded to a public form.

What does the first step actually cost us?

The check is two minutes and asks for nothing. The Diagnostic is fixed-scope against one decision you name, and its output includes the gaps.

Pick the decision you would least like to be asked about.

Not the worst one — the one where the record is thinnest and the challenge is most plausible. That is the one worth replaying while there is still time to fix what is missing.