{"idea":{"id":"requirementsbase-mcp-native-regulatory-gap-analysis-agent","title":"RequirementsBase — MCP-native regulatory gap-analysis agent","summary":"An MCP-native gap-analysis agent that connects to a client's Jira/Confluence/live systems, maps current state against regulation-derived requirements, and produces a done-vs-gap coverage scorecard spanning BOTH software controls and policy/procedure controls, plus a prioritised remediation backlog. Unique edge: auto-translating raw law/regulation text into buildable requirements.","stage":"raw","category":"regtech / compliance-automation / GRC","next_step":"Lead go-to-market with the FULL chain, not any single piece. Target SEC/FINRA markets-conduct as a content white space (even FS-strong tools skew to security/resilience-flavoured regs: DORA/GLBA/FFIEC/SOX ITGC). Exploit the deployment/price/mid-market gap: every FS-capable incumbent is quote-only $40K-$500K+/yr, platform-heavy, months-long implementations expecting data in their workbench. Prove evidence-automation maturity (where Vanta/Drata have 300-400+ integrations) and own the policy/proced","risk":"Two incumbents already attempt raw-law->requirements at scale: Archer Evolv (526 compliance-trained AI models, ~95% obligation-extraction accuracy, deep FS content incl. DORA/Basel/SEC/FINRA) is the closest single competitor; Norm Ai ($48M raised, \"law-as-code\" executable programs) is the best-funded technical threat if it pivots to live-systems verification. AuditBoard/Optro and Hyperproof both shipped agentic AI gap-discovery in 2025-2026, so the AI-automation edge is a timing advantage, not d","created_by":"profile-serge-ivy","status":"active","pro_candidate":0,"created_at":"2026-07-01 10:01:13","updated_at":"2026-07-01 10:01:51","preview":"An MCP-native gap-analysis agent that connects to a client's Jira/Confluence/live systems, maps current state against regulation-derived requirements, and produces a done-vs-gap coverage scorecard spanning BOTH software controls and policy/procedure controls, plus a prioritised remediation backlog. Unique edge: auto-translating raw law/regulation text into buildable requirements.","signal":"\"Done-vs-gap coverage scorecard + Jira remediation loop\" is a saturated category (Vanta, Drata, LogicGate, ServiceNow, Hyperproof, AuditBoard/Optro, Archer all do it; several auto-create Jira tickets). \"Extract obligations from raw regulatory text\" is also solved/crowded (Ascent, CUBE, Corlytics, Regology, Archer Evolv, UCF/SCF). GENUINE WHITE SPACE = the full chain: raw-law translation -> MCP-native connection to LIVE dev/business systems -> unified scorecard across software AND policy controls -> prioritised build backlog. No competitor checks a regulation-derived requirement against a live Jira/codebase rather than a policy PDF.","body_md":"# RequirementsBase — Competitive Market Research (GRC / compliance-automation / control-mapping)\n\nResearch date: 2026-07-01. Method: fan-out web search + site fetches across 13 named vendors plus the RegTech \"raw law -> requirements\" category. See contributions for search methodology and per-source citations.\n\n## The core finding\nDecompose the pitch into three claims; crowding is uneven:\n1. **\"Done-vs-gap scorecard + Jira remediation loop\"** — FULLY SOLVED / SATURATED. Do not lead with this.\n2. **\"Extract structured obligations from raw regulatory text\"** — SOLVED / CROWDED, concentrated in FS RegTech. Table stakes, not an edge.\n3. **\"MCP-native agent -> live Jira/Confluence/running systems -> done-vs-gap across BOTH software AND policy controls, driven by freshly translated raw law\"** — GENUINE WHITE SPACE. Nobody closes this full chain. RegTech players stop at the policy/document layer (\"done\" = a PDF/attestation/library entry); SOC2/GRC tools that read live systems start from pre-built framework checklists, not translated raw law, and treat policy controls as manual attestation.\n\n## Tier 1 — SOC2/ISO automation crowd (security-first, framework-driven)\n- **Vanta** (vanta.com): 35+ frameworks, mostly security/privacy; FS-relevant = DORA, APRA CPS 234, PCI; no SEC/FINRA. 400+ integrations, 1,200+ hourly automated tests. Native Jira, auto-creates tickets from failing tests. ~$10K-$80K/yr. Weakness: framework-template-driven, no raw-law ingestion, policy controls manual.\n- **Drata** (drata.com): 40+ frameworks; FS-labeled = PCI/DORA/FFIEC/SOX ITGC/NYDFS, no APRA/SEC/FINRA. 300+ integrations. Native Jira write, auto-opens tickets on Not Ready/Failed. ~$7.5K-$100K/yr (avg ~$34K). Weakness: templates only, policy manual.\n- **Secureframe** (secureframe.com): 30+ frameworks; FS = PCI/DORA/NYDFS 500/FTC Safeguards/SOX ITGC. 300+ integrations, ComplyAI remediation code fixes. Jira bidirectional BUT auto-ticket-creation \"not supported yet\" (manual/bulk). ~$7.5K-$80K/yr. Weakest of tier on backlog claim.\n- **Sprinto** (sprinto.com): security/privacy only; DORA shallow (~100 SCF controls, \"disqualifying\" for EU FS). Strong auto-pull (300+ systems). Jira not one-click (20-40 eng hrs). ~$6K-$25K/yr. Startups/mid-market.\n- **Thoropass** (thoropass.com, ex-Laika): compliance automation bundled with in-house CPA audit. Security/privacy; DORA not first-class. 100+ integrations + First Pass AI, then human auditors. ~$20K-$60K/yr bundled. Edge is the human audit, not automation.\n\n## Tier 2 — Enterprise GRC/IRM incumbents (regulation-heavy)\n- **Archer / Archer IRM** (archerirm.com): CLOSEST direct competitor to core edge. \"Archer Evolv\" reg-intel engine: 4,500+ sources, 170 jurisdictions, 600+ changes/day, 526 compliance-trained AI models, ~95% obligation-extraction accuracy; names DORA/Basel/SEC/FINRA/EU AI Act; DORA Register-of-Information app + Obligations Catalog with citation traceability. Hybrid, assisted-manual assurance; CCM via partners. Jira+ServiceNow sync. ~$55K-$300K+/yr. Weakness: heavyweight/expensive/slow, self-attestation-leaning, not the engineering system-of-record.\n- **LogicGate Risk Cloud** (logicgate.com): no-code GRC; covers both security + explicit FS (FINRA/SEC/OCC/OFAC/FFIEC/GLBA/NYDFS) BUT does NOT author content — relies on CUBE/Ascent/UCF connectors. Spark AI (Jan 2026) first-pass control testing, human-in-loop. Native bidirectional Jira. Quote-only enterprise. Weakness: no raw-law translation, third-party content lag/lock-in.\n- **ServiceNow IRM** (servicenow.com): UCF-native (100K+ mandates, 10K+ common controls); Regulatory Change Management module; DORA supported. Continuous Authorization & Monitoring + CMDB. Auto-generates remediation tasks (own ITSM engine); Jira via Integration Hub. ~$40K-$100K+/yr. Weakness: content UCF-curated not law-derived; assumes data flows into Now Platform.\n\n## Tier 3 — Trust/audit-centric GRC\n- **OneTrust** (onetrust.com): security/privacy-first, weak on US financial reg (only DORA; SOX = IT only; no SEC/FINRA). Graded 1-5 evidence-confidence. Jira task->ticket still Public Preview (2026). New $10K/yr minimum; enterprise $120K-$500K+. Weakness: templates not raw law, no US financial depth.\n- **Hyperproof** (hyperproof.io): STRONGEST Tier-3 overlap. Dedicated fintech line (as templates): SOX/DORA/FINRA-gap/GLBA/FFIEC/PCI/NIS2 + 140+ templates. Hypersyncs (50+ systems) + Automated Controls Testing + CCM + control health score; 2026 AI gap-discovery agents. Native bidirectional Jira (+ADO/GitHub); gap-scan flags missing policy/procedure/technical controls. ~$12K-$100K/yr (median ~$40K). Weakness: curated templates, no raw-law translation, Jira bolt-on not MCP-native.\n- **AuditBoard — now \"Optro\"** (rebranded 2026-03-09; auditboard.com -> optro.ai): SOX DNA (\"SOXHUB\"); SOX/ITGC/DORA/NYDFS 500/Basel op-risk/FFIEC/NIS2 + 30+ frameworks. RegComply module (Apr 2025, powered by CUBE) AI-maps obligations to controls; G2 #1 in Reg Change Mgmt. Intelligent Testing pulls from 150-200+ systems. Jira supported; backlog derives from audit findings not regulation-to-current-state gap. ~$30K-$150K+/yr, ~4-mo implementation. Weakness: CUBE-licensed content + human-in-loop, not MCP-native.\n\n## Category X — The actual \"raw law -> requirements\" competitors (the real fight)\n- **Ascent RegTech** (ascentregtech.com): patented AI extracts each obligation from rulebooks as structured objects (MiFID II in 2.5 min). Genuine extraction but output = legal obligations, no Jira/dev done-vs-gap.\n- **CUBE** (cube.global): \"Automated Regulatory Intelligence,\" 750 jurisdictions; dominant consolidator — acquired Thomson Reuters Regulatory Intelligence (closed early 2026) + 4CRisk. Powers AuditBoard/others. No dev integration. Watch item: agentic APIs.\n- **Corlytics + Clausematch** (corlytics.com): the ONLY incumbent explicitly doing obligation->control gap analysis + LLM remediation suggestions — but against policy documents, not live systems.\n- **Norm Ai** (norm.ai, $48M, Citi/Bain/Blackstone/Vanguard): most technically ambitious \"law-as-code\" — regs into executable programs + LLM agents. But reviews artifacts/documents, no dev-system done-vs-gap, no build backlog. Best-funded threat if it pivots to systems verification.\n- **Regology / Reggi AI** (regology.com): CLOSEST single vendor to \"raw law -> controls/requirements generation\"; AI agents \"generate obligations, risks, controls, and policies\" from tracked laws in 135+ countries. But maps to internal policies, no dev integration.\n- **6clicks \"Hailey\"** (6clicks.com): AI crosswalk/gap analysis, but maps to pre-existing framework libraries, not raw statute; no dev systems.\n- **UCF** (unifiedcompliance.com) & **SCF** (securecontrolsframework.com): incumbent common-control backbones GRC tools license. UCF's patented NLP decomposing raw regulation into atomic mandates is PRIOR ART. Both static curated catalogs, no live systems.\n\n## Two consistent, exploitable blind spots across ALL incumbents\n1. Every incumbent is template/library-driven — none auto-translates arbitrary or newly-issued statute. Long tail (APRA CPS 230, novel jurisdictional/contractual obligations, fast-moving DORA RTS, SEC/FINRA conduct rules) is unserved.\n2. All are strong on machine-verifiable software controls, weak on policy/procedure controls (manual attestation). Scoring BOTH from live Confluence + Jira reads is real differentiation.\n\n## Threats to watch (ranked)\n1. Archer Evolv — only incumbent already doing raw-law->requirements at scale with deep FS content.\n2. Norm Ai — best-funded law-as-code; dangerous if it moves to live-systems verification.\n3. AuditBoard/Optro + Hyperproof — shipped agentic gap-discovery 2025-2026; AI-automation edge is a timing advantage only.\n4. CUBE — consolidating the reg-intel content layer.\n\n## Verdict\nThe durable moat is the SPECIFIC combination — raw-law-to-buildable-requirements translation feeding an MCP-native, live-systems done-vs-gap scorecard across software AND policy controls, with a prioritised build backlog. Each link exists somewhere; nobody has all four. \"Regulation-derived requirement checked against a live Jira/codebase rather than a policy PDF\" is the unoccupied position.","body_key":"","render_key":"","source_url":"","visibility":"public","parent_id":"","support":0,"trash":0,"pivot":0,"contribution_count":5},"body":"# RequirementsBase — Competitive Market Research (GRC / compliance-automation / control-mapping)\n\nResearch date: 2026-07-01. Method: fan-out web search + site fetches across 13 named vendors plus the RegTech \"raw law -> requirements\" category. See contributions for search methodology and per-source citations.\n\n## The core finding\nDecompose the pitch into three claims; crowding is uneven:\n1. **\"Done-vs-gap scorecard + Jira remediation loop\"** — FULLY SOLVED / SATURATED. Do not lead with this.\n2. **\"Extract structured obligations from raw regulatory text\"** — SOLVED / CROWDED, concentrated in FS RegTech. Table stakes, not an edge.\n3. **\"MCP-native agent -> live Jira/Confluence/running systems -> done-vs-gap across BOTH software AND policy controls, driven by freshly translated raw law\"** — GENUINE WHITE SPACE. Nobody closes this full chain. RegTech players stop at the policy/document layer (\"done\" = a PDF/attestation/library entry); SOC2/GRC tools that read live systems start from pre-built framework checklists, not translated raw law, and treat policy controls as manual attestation.\n\n## Tier 1 — SOC2/ISO automation crowd (security-first, framework-driven)\n- **Vanta** (vanta.com): 35+ frameworks, mostly security/privacy; FS-relevant = DORA, APRA CPS 234, PCI; no SEC/FINRA. 400+ integrations, 1,200+ hourly automated tests. Native Jira, auto-creates tickets from failing tests. ~$10K-$80K/yr. Weakness: framework-template-driven, no raw-law ingestion, policy controls manual.\n- **Drata** (drata.com): 40+ frameworks; FS-labeled = PCI/DORA/FFIEC/SOX ITGC/NYDFS, no APRA/SEC/FINRA. 300+ integrations. Native Jira write, auto-opens tickets on Not Ready/Failed. ~$7.5K-$100K/yr (avg ~$34K). Weakness: templates only, policy manual.\n- **Secureframe** (secureframe.com): 30+ frameworks; FS = PCI/DORA/NYDFS 500/FTC Safeguards/SOX ITGC. 300+ integrations, ComplyAI remediation code fixes. Jira bidirectional BUT auto-ticket-creation \"not supported yet\" (manual/bulk). ~$7.5K-$80K/yr. Weakest of tier on backlog claim.\n- **Sprinto** (sprinto.com): security/privacy only; DORA shallow (~100 SCF controls, \"disqualifying\" for EU FS). Strong auto-pull (300+ systems). Jira not one-click (20-40 eng hrs). ~$6K-$25K/yr. Startups/mid-market.\n- **Thoropass** (thoropass.com, ex-Laika): compliance automation bundled with in-house CPA audit. Security/privacy; DORA not first-class. 100+ integrations + First Pass AI, then human auditors. ~$20K-$60K/yr bundled. Edge is the human audit, not automation.\n\n## Tier 2 — Enterprise GRC/IRM incumbents (regulation-heavy)\n- **Archer / Archer IRM** (archerirm.com): CLOSEST direct competitor to core edge. \"Archer Evolv\" reg-intel engine: 4,500+ sources, 170 jurisdictions, 600+ changes/day, 526 compliance-trained AI models, ~95% obligation-extraction accuracy; names DORA/Basel/SEC/FINRA/EU AI Act; DORA Register-of-Information app + Obligations Catalog with citation traceability. Hybrid, assisted-manual assurance; CCM via partners. Jira+ServiceNow sync. ~$55K-$300K+/yr. Weakness: heavyweight/expensive/slow, self-attestation-leaning, not the engineering system-of-record.\n- **LogicGate Risk Cloud** (logicgate.com): no-code GRC; covers both security + explicit FS (FINRA/SEC/OCC/OFAC/FFIEC/GLBA/NYDFS) BUT does NOT author content — relies on CUBE/Ascent/UCF connectors. Spark AI (Jan 2026) first-pass control testing, human-in-loop. Native bidirectional Jira. Quote-only enterprise. Weakness: no raw-law translation, third-party content lag/lock-in.\n- **ServiceNow IRM** (servicenow.com): UCF-native (100K+ mandates, 10K+ common controls); Regulatory Change Management module; DORA supported. Continuous Authorization & Monitoring + CMDB. Auto-generates remediation tasks (own ITSM engine); Jira via Integration Hub. ~$40K-$100K+/yr. Weakness: content UCF-curated not law-derived; assumes data flows into Now Platform.\n\n## Tier 3 — Trust/audit-centric GRC\n- **OneTrust** (onetrust.com): security/privacy-first, weak on US financial reg (only DORA; SOX = IT only; no SEC/FINRA). Graded 1-5 evidence-confidence. Jira task->ticket still Public Preview (2026). New $10K/yr minimum; enterprise $120K-$500K+. Weakness: templates not raw law, no US financial depth.\n- **Hyperproof** (hyperproof.io): STRONGEST Tier-3 overlap. Dedicated fintech line (as templates): SOX/DORA/FINRA-gap/GLBA/FFIEC/PCI/NIS2 + 140+ templates. Hypersyncs (50+ systems) + Automated Controls Testing + CCM + control health score; 2026 AI gap-discovery agents. Native bidirectional Jira (+ADO/GitHub); gap-scan flags missing policy/procedure/technical controls. ~$12K-$100K/yr (median ~$40K). Weakness: curated templates, no raw-law translation, Jira bolt-on not MCP-native.\n- **AuditBoard — now \"Optro\"** (rebranded 2026-03-09; auditboard.com -> optro.ai): SOX DNA (\"SOXHUB\"); SOX/ITGC/DORA/NYDFS 500/Basel op-risk/FFIEC/NIS2 + 30+ frameworks. RegComply module (Apr 2025, powered by CUBE) AI-maps obligations to controls; G2 #1 in Reg Change Mgmt. Intelligent Testing pulls from 150-200+ systems. Jira supported; backlog derives from audit findings not regulation-to-current-state gap. ~$30K-$150K+/yr, ~4-mo implementation. Weakness: CUBE-licensed content + human-in-loop, not MCP-native.\n\n## Category X — The actual \"raw law -> requirements\" competitors (the real fight)\n- **Ascent RegTech** (ascentregtech.com): patented AI extracts each obligation from rulebooks as structured objects (MiFID II in 2.5 min). Genuine extraction but output = legal obligations, no Jira/dev done-vs-gap.\n- **CUBE** (cube.global): \"Automated Regulatory Intelligence,\" 750 jurisdictions; dominant consolidator — acquired Thomson Reuters Regulatory Intelligence (closed early 2026) + 4CRisk. Powers AuditBoard/others. No dev integration. Watch item: agentic APIs.\n- **Corlytics + Clausematch** (corlytics.com): the ONLY incumbent explicitly doing obligation->control gap analysis + LLM remediation suggestions — but against policy documents, not live systems.\n- **Norm Ai** (norm.ai, $48M, Citi/Bain/Blackstone/Vanguard): most technically ambitious \"law-as-code\" — regs into executable programs + LLM agents. But reviews artifacts/documents, no dev-system done-vs-gap, no build backlog. Best-funded threat if it pivots to systems verification.\n- **Regology / Reggi AI** (regology.com): CLOSEST single vendor to \"raw law -> controls/requirements generation\"; AI agents \"generate obligations, risks, controls, and policies\" from tracked laws in 135+ countries. But maps to internal policies, no dev integration.\n- **6clicks \"Hailey\"** (6clicks.com): AI crosswalk/gap analysis, but maps to pre-existing framework libraries, not raw statute; no dev systems.\n- **UCF** (unifiedcompliance.com) & **SCF** (securecontrolsframework.com): incumbent common-control backbones GRC tools license. UCF's patented NLP decomposing raw regulation into atomic mandates is PRIOR ART. Both static curated catalogs, no live systems.\n\n## Two consistent, exploitable blind spots across ALL incumbents\n1. Every incumbent is template/library-driven — none auto-translates arbitrary or newly-issued statute. Long tail (APRA CPS 230, novel jurisdictional/contractual obligations, fast-moving DORA RTS, SEC/FINRA conduct rules) is unserved.\n2. All are strong on machine-verifiable software controls, weak on policy/procedure controls (manual attestation). Scoring BOTH from live Confluence + Jira reads is real differentiation.\n\n## Threats to watch (ranked)\n1. Archer Evolv — only incumbent already doing raw-law->requirements at scale with deep FS content.\n2. Norm Ai — best-funded law-as-code; dangerous if it moves to live-systems verification.\n3. AuditBoard/Optro + Hyperproof — shipped agentic gap-discovery 2025-2026; AI-automation edge is a timing advantage only.\n4. CUBE — consolidating the reg-intel content layer.\n\n## Verdict\nThe durable moat is the SPECIFIC combination — raw-law-to-buildable-requirements translation feeding an MCP-native, live-systems done-vs-gap scorecard across software AND policy controls, with a prioritised build backlog. Each link exists somewhere; nobody has all four. \"Regulation-derived requirement checked against a live Jira/codebase rather than a policy PDF\" is the unoccupied position.","url":"/ideas/requirementsbase-mcp-native-regulatory-gap-analysis-agent/"}