The complete risk and compliance chain: from signal to accountability

Regulation keeps coming, faster and in greater volume. Yet in many financial institutions the link between spotting a new rule and proving you comply with it is still held together by spreadsheets and manual handovers. This is the thinking behind bringing Ruler and CERRIX together, and what a connected compliance chain looks like in practice.

The reality: a broken chain

Start with a reality check. A 2025 Wolters Kluwer study found that 42% of the financial institutions surveyed still handle regulatory compliance through manual processes.

A lot of professionals invest heavily in risk and compliance, yet relatively few feel genuinely in control. A big part of the reason is that the chain is broken.

On one side sit the regulatory signals: the new and changing rules you first have to spot, then assess and interpret. On the other sits the operational side, where you manage your risks, demonstrate that you are in control, and keep everything auditable. In most organisations those two sides live apart. Different teams, and in many cases different tools and different processes.

“The compliance team produces an assessment of what a new regulation means, they put it in a spreadsheet, and they share it with risk and internal control,” says Niels van Weereld, CEO of CERRIX & Ruler. “There is no automated link between the two, and only a limited feedback loop.”

That gap in the middle, between a rule coming in and being able to prove you have acted on it, is where many companies lose their grip.

Why the old way no longer works

The context has changed. New risks, new risk domains and new regulation are arriving at a higher pace and frequency than before. Yet plenty of organisations are still working at the tempo of an earlier era, when both the volume and the impact of change were lower.

“Not many people would drive a vintage car onto today’s motorway, with all the new technology, the higher speeds and the traffic,” says Van Weereld. “It is the same principle for risk and compliance. You have to follow today’s reality and adapt to it.”

Three shifts that decide who stays in control

Three fundamental shifts separate the organisations that will succeed at GRC from those that struggle.

  1. From manual to smart and automated. Instead of gathering evidence by hand and re-typing data into a GRC system or a spreadsheet, the goal is to ingest data automatically, whether it comes from external sources such as regulation or internal systems such as ERP, HR or CRM. All of that data is relevant to your risk profile, and once it flows in automatically it can trigger follow-ups and workflows rather than waiting on someone to chase it.
  2. From backward-looking to predictive. Today much of the work is retrospective, looking back over the past quarter or year to check whether you were in control. With the right data in place you can start to spot patterns, surface control weaknesses and flag emerging risks earlier, moving from auditing the past towards anticipating what is coming.
  3. From checklist manager to expert collaborator. Too many risk and compliance professionals spend their days as checklist managers, chasing colleagues for evidence and managing administration. With data, automated workflows and predictive insight doing the heavy lifting, that time can shift to the expert conversations that actually improve how in control a business is.

The parallel is the CRM market. A few years ago a high-performing sales organisation was one that could report growth over recent quarters. Today that is not enough; you are also expected to predict what is in the pipeline and how you will act on it.

“It is time for the GRC market to go through that same evolution,” says Van Weereld, “from a backward-looking, largely manual process towards forward-looking expert collaboration, backed by predictive intelligence.”

One platform, one chain: Ruler and CERRIX

This is the thinking behind the intelligent operating system for enterprise risk. It has two sides.

The execution side is CERRIX: the engine where you manage risks, controls, control testing, audits, incidents and third-party management, everything you need on a day-to-day basis to stay in control and demonstrate it. CERRIX was founded in 2014 and today serves more than 100 customers across a number of countries, with the ambition to be a European alternative to the large incumbents.

The intelligence side is Ruler. Ruler is the regulatory intelligence engine, the part that automatically monitors a wide range of sources for new and changing regulation and works out what it means for the organisations subject to it. Based on your profile, Ruler filters what is relevant, supports a structured assessment, and enables a gap analysis that can then flow through to the execution engine.

Put the two together and you have the basis of a single platform that closes the chain: the brain connected to the arms, with as much automation and data as possible on both sides and in the exchange between them.

“We have built one platform to fix the broken chain,” says Van Weereld, “from a regulatory change all the way to full auditability and reporting at the end.”

The regulatory bridge in practice

To make this concrete, Ruler and CERRIX have built a first working version of a regulatory bridge that connects the two platforms.

It starts with an alert in Ruler, for example a notification about the Cybersecurity Act. From there, the bridge looks at the risks and controls you actually track in CERRIX and identifies which ones relate to that alert. You confirm which are relevant, drawing on your own knowledge of the organisation, and the system then runs a gap analysis against your existing risk and control framework.

The outcome is expressed as a low, medium or high gap, together with the reasoning behind it. A low gap might mean an incoming rule is already covered by an existing framework, giving you documented assurance that you checked. A larger gap comes with concrete, specific proposals: new or updated risks and controls, with the same fields you would expect in CERRIX, ready to review and bring across.

The approach is deliberately AI-native. “We are not using AI because it is cool,” says Joachim Jonkers, CPO of CERRIX & Ruler. “We are using it because it solves the problem, and we do not know of any other technology that solves it as well right now.”

That matters most in the middle of the chain. The translation step, working out what a new rule means for your risks and controls, is the one that so often gets skipped or missed because it takes real time and effort. An AI-native approach is what makes it something you can actually keep up with.

Two principles keep it trustworthy. First, explainability: the system does not just label a gap, it tells you why it reached that conclusion. Second, human in the loop. Every AI-generated suggestion is there to be reviewed and adjusted before you act on it, and that review step is a default across the AI that Ruler and CERRIX build.

The result is a connected path from spotting a signal to demonstrating you have assessed it and acted, with an audit trail along the way.

What this means for you

The pace of regulatory and risk change is not slowing down, and the manual, disconnected way of working was built for a slower world. Closing the chain, from the first regulatory signal to full accountability, is how compliance and risk teams move from checklist fatigue to the expert work that matters.

See how Ruler and CERRIX are connecting the full risk and compliance chain, from signal to accountability.