Ok
logo_outline-1

Ruleguard FAQs

What is Ruleguard, in one sentence?

Ruleguard is an agentic AI platform for risk and compliance in regulated financial firms. Intelligent "compliance agents" read documents, apply your rules, monitor controls, flag risks, and generate audit-ready evidence continuously, rather than at quarterly snapshots. See our platform overview here for more information on what we do.

What exactly is a "compliance agent"?

A digital team member trained on regulatory knowledge and your firm's own policies. It reads regulatory texts, internal policies, risk registers and control matrices; operates within boundaries you define; works around the clock; and logs the full reasoning behind every decision. See our workflow page for more info.

Which compliance activities can it actually automate?

The platform covers a six-stage lifecycle: (1) strategic planning / horizon scanning, (2) applicability mapping by regime, (3) risk & control assessment (including RCSA), (4) policy & control refinement, (5) assurance (automated + manual), and (6) evidence & reporting for committees, boards, auditors and regulators. See our solutions page for more information

How is this different from our existing GRC platform?

Legacy GRC tools were built for periodic, point-in-time reporting and manual checklists. Ruleguard is designed for continuous monitoring: controls are checked in real time, audit evidence is generated as a by-product of daily work rather than assembled after the fact, and regulatory change is scanned continuously rather than tracked manually.

Does it replace our compliance team?

No. The model is "AI assists - humans decide." Agents remove manual monitoring, evidence-gathering and drafting effort; accountability and judgement stay with your people. Regulators are clear that accountability cannot be delegated to technology, and the platform is built around that. See more on our platform page.

Can we start small or is it all-or-nothing?

You can start with individual workflows and a single agent, with full human review, and expand from there. The platform works standalone out of the box; deeper system integration is optional and on your timeline. Have a look at a recent implementation case study.

How do we stay in control of what agents do?

Every agent operates within configurable boundaries - permitted actions, prohibited actions, escalation triggers and approval gates - all version-controlled. You set the level of autonomy per workflow and per step. See how this works on our Platform page 

What does "human in the loop" mean in practice?

Oversight is a dial, not a switch. Three modes: Full Review (every output reviewed - for initial deployment and high-risk tasks), Exception-Based (humans review only flagged items), and Autonomous (agent runs independently with periodic audits, for mature, well-understood tasks). You can dial it up or down at any time. See how this works on our Platform page 

Can the AI explain its decisions?

Yes. Every agent decision is logged with its reasoning, the sources it referenced, and the rules it applied - designed to meet supervisory expectations for transparency in AI-assisted decision-making. 

What audit trail do we get?

Immutable. Every decision, every data source consulted and every output is recorded and nothing is overwritten or lost. When a regulator or internal auditor asks why a decision was made, the full chain of reasoning is available instantly. See how this works on our Platform page

How does this map to regulatory expectations?

The platform is built around the themes supervisors emphasise: data transparency and lineage, continuous control monitoring, outcomes-based assurance, explainable AI, operational resilience (impact tolerances since March 2025), and proactive risk management. See how we help you keep pace on our Regulatory Change Management page

How do we govern the AI itself?

Ruleguard is compliant with ISO 42001, the international standard for responsible AI management — so how agents are trained, deployed and monitored sits within a formal AI management system you can point to when regulators ask how AI is controlled. Read more about our approach on the Why Ruleguard page

Which AI models does Ruleguard use? Are we locked in?

The platform uses frontier AI models within a framework purpose-built for compliance, and supports a range of models and deployment options so you can match your own AI policy, risk appetite and data-residency requirements. Read more about our approach on the Why Ruleguard page

How does the AI avoid "hallucinating" or making things up?

Agents reference your authoritative sources — your policies and procedures — not generic training data. This is structured through four context layers: organisational context, constraints (boundaries), intent (the outcome a rule serves, which cuts false positives), and modular specification. The aim is accuracy grounded in your documents, with reasoning shown. See how this works on our Platform page

What happens when our policies or the regulations change?

When your policies update, agents reflect the change immediately. On the regulatory side, agents continuously scan developments across jurisdictions, classify and prioritise them, and assess impact against your existing policies and controls. See how we help you keep pace on our Regulatory Change Management page 

Does the platform get better over time?

Yes, every task sharpens accuracy and efficiency, and agents become more attuned to your organisation. Your data is never used to train shared/base models but references your historical usage patterns and preferences securely in a single-tenant data model. See real examples on our Case Studies page

Is the platform independently certified for security?

Yes — Ruleguard holds ISO 27001 (information security) and is compliant with ISO 42001 (responsible AI). Want the full certification pack? Get in touch

Where is our data hosted, and can it stay in our jurisdiction?

The platform supports a range of frontier cloud models and on-premises deployment, so you can meet your data-residency requirements. Support for on-premises models varies by region, please enquire for details. See our Data Centers page for full hosting details

Is our data used to train AI models that other firms could benefit from?

No, this is a fundamental design principle. We use a secure single-tenant data model which isolates your data both logically and physically. Your data is never used to train models or shared with other clients and the agents on your account only access your data and usage patterns. See our Data Centers page for more on how your data is hosted and secured.

How is data segregated between clients / encrypted?

Ruleguard uses a strict single-tenant data architecture, encrypts data in transit and at rest, and has a wide range of enterprise-grade infosec and cyber security features. We use Microsoft Azure data centres with the most robust security certifications in the world. See our Data Centers page for more.

Do you support ISO 27001, penetration testing, and a security questionnaire?

Yes, Ruleguard is ISO 27001 certified, conducts regular pen testing, and is well-versed in responding to the most rigorous information security questionnaires from global banks and asset managers. Ask your account team for our latest security pack — get in touch.

How do you secure connections to our systems?

Ruleguard supports a range of integration methods including APIs, webhooks, Zaps, and CSV bulk integration. Agentic integration is via the platform's MCP server, which gives authenticated, permissioned access governed by the same audit and permission controls as the rest of the platform — and you control exactly what is shared. See our Integrations page for more 

Do we have to integrate with our core systems to get value?

No. Ruleguard works as a standalone platform out of the box. Integration is available when you're ready, at your pace. We do offer historical data import services as part of implementation, meaning that you can give your Ruleguard agents access to your relevant data stores from day one, if your use-cases demand it. See our Integrations page for more 

How does it connect to our existing infrastructure?

Through an MCP server, in two directions: your own agents/tools can be given secure access to Ruleguard's compliance data, and Ruleguard agents can reach out to external systems to pull in additional context — without re-engineering your infrastructure. See our Integrations page for more

What data sources can feed assurance?

Automated feeds via API integrations, webhooks and system logs flow in for real-time data, alongside manual inputs (attestations, checklists, approvals) for processes needing human judgement — all in one unified dashboard. See our Integrations page for more 

What's the IT lift to deploy?

Very little. Our in-house implementation team handles end-to-end deployment and implementation and typically we only need a few simple tasks from your IT team including IP whitelisting, SSO/identity (SAML/OIDC), and support for any systems integration work required for the set up. See a recent implementation case study

How long does it take to get up and running?

Very little. Our in-house implementation team handles end-to-end deployment and implementation and typically we only need a few simple tasks from your IT team including IP whitelisting, SSO/identity (SAML/OIDC), and support for any systems integration work required for the set up. See a recent implementation case study

How do you make sure teams actually use it?

The platform's maturity journey explicitly includes an Adoption stage — embedding agents into daily operations so teams work with them, not around them — followed by management, governance and measurable economic benefit stages. See how this plays out in practice in our Case Studies 

How do we build trust before letting agents run autonomously?

Start in Full Review mode so every output is checked, then move to Exception-Based and ultimately Autonomous as each agent builds a track record — entirely under your control, per workflow and per step. We recommend 10-12 weeks of agent testing and feedback to reach a steady run-rate of agent productivity and quality. See how this works on our Platform page

What support and onboarding is included?

We have an in-house implementation team covering all implementation, configuration, data import, project management, and agent training services. Our customer service team is always on-hand following full go-live and we run a 24/7 global helpdesk service. Want to talk through what onboarding looks like for your firm? Get in touch

What's the commercial / pricing model?

Ruleguard uses value-based pricing related to the number of regions, legal-entities, and compliance use-cases that our client benefits from. Pricing is tailored to your firm — speak to our team for more information.

What's the expected ROI?

Ruleguard clients experience ROI in two main ways: firstly by reducing the time and cost required to operate risk and compliance workflows given the automation provided by Ruleguard agents, and secondly by an acceleration in the time-to-market and time-to-approval resulting from the auditable compliance posture that Ruleguard delivers. Read more on the real ROI of GRC 

How financially stable / established is Ruleguard, and who else uses it?

Ruleguard has been trading since 2013, has over 50 blue-chip financial services clients globally, and is backed by one of the largest UK venture capital investors. We pass the rigorous financial checks demanded by some of the largest banks in the world. Learn more about Ruleguard or see our Case Studies