RequirementsBase — MCP-native regulatory gap-analysis agent

RequirementsBase — MCP-native regulatory gap-analysis agent

An MCP-native gap-analysis agent that connects to a client's Jira/Confluence/live systems, maps current state against regulation-derived requirements, and produces a done-vs-gap coverage scorecard spanning BOTH software controls and policy/procedure controls, plus a prioritised remediation backlog. Unique edge: auto-translating raw law/regulation text into buildable requirements.
rawregtech / compliance-automation / GRCfree idea

RequirementsBase — Competitive Market Research (GRC / compliance-automation / control-mapping)

Research date: 2026-07-01. Method: fan-out web search + site fetches across 13 named vendors plus the RegTech "raw law -> requirements" category. See contributions for search methodology and per-source citations.

The core finding

Decompose the pitch into three claims; crowding is uneven:

  1. "Done-vs-gap scorecard + Jira remediation loop" — FULLY SOLVED / SATURATED. Do not lead with this.
  2. "Extract structured obligations from raw regulatory text" — SOLVED / CROWDED, concentrated in FS RegTech. Table stakes, not an edge.
  3. "MCP-native agent -> live Jira/Confluence/running systems -> done-vs-gap across BOTH software AND policy controls, driven by freshly translated raw law" — GENUINE WHITE SPACE. Nobody closes this full chain. RegTech players stop at the policy/document layer ("done" = a PDF/attestation/library entry); SOC2/GRC tools that read live systems start from pre-built framework checklists, not translated raw law, and treat policy controls as manual attestation.

Tier 1 — SOC2/ISO automation crowd (security-first, framework-driven)

  • Vanta (vanta.com): 35+ frameworks, mostly security/privacy; FS-relevant = DORA, APRA CPS 234, PCI; no SEC/FINRA. 400+ integrations, 1,200+ hourly automated tests. Native Jira, auto-creates tickets from failing tests. ~$10K-$80K/yr. Weakness: framework-template-driven, no raw-law ingestion, policy controls manual.
  • Drata (drata.com): 40+ frameworks; FS-labeled = PCI/DORA/FFIEC/SOX ITGC/NYDFS, no APRA/SEC/FINRA. 300+ integrations. Native Jira write, auto-opens tickets on Not Ready/Failed. ~$7.5K-$100K/yr (avg ~$34K). Weakness: templates only, policy manual.
  • Secureframe (secureframe.com): 30+ frameworks; FS = PCI/DORA/NYDFS 500/FTC Safeguards/SOX ITGC. 300+ integrations, ComplyAI remediation code fixes. Jira bidirectional BUT auto-ticket-creation "not supported yet" (manual/bulk). ~$7.5K-$80K/yr. Weakest of tier on backlog claim.
  • Sprinto (sprinto.com): security/privacy only; DORA shallow (~100 SCF controls, "disqualifying" for EU FS). Strong auto-pull (300+ systems). Jira not one-click (20-40 eng hrs). ~$6K-$25K/yr. Startups/mid-market.
  • Thoropass (thoropass.com, ex-Laika): compliance automation bundled with in-house CPA audit. Security/privacy; DORA not first-class. 100+ integrations + First Pass AI, then human auditors. ~$20K-$60K/yr bundled. Edge is the human audit, not automation.

Tier 2 — Enterprise GRC/IRM incumbents (regulation-heavy)

  • Archer / Archer IRM (archerirm.com): CLOSEST direct competitor to core edge. "Archer Evolv" reg-intel engine: 4,500+ sources, 170 jurisdictions, 600+ changes/day, 526 compliance-trained AI models, ~95% obligation-extraction accuracy; names DORA/Basel/SEC/FINRA/EU AI Act; DORA Register-of-Information app + Obligations Catalog with citation traceability. Hybrid, assisted-manual assurance; CCM via partners. Jira+ServiceNow sync. ~$55K-$300K+/yr. Weakness: heavyweight/expensive/slow, self-attestation-leaning, not the engineering system-of-record.
  • LogicGate Risk Cloud (logicgate.com): no-code GRC; covers both security + explicit FS (FINRA/SEC/OCC/OFAC/FFIEC/GLBA/NYDFS) BUT does NOT author content — relies on CUBE/Ascent/UCF connectors. Spark AI (Jan 2026) first-pass control testing, human-in-loop. Native bidirectional Jira. Quote-only enterprise. Weakness: no raw-law translation, third-party content lag/lock-in.
  • ServiceNow IRM (servicenow.com): UCF-native (100K+ mandates, 10K+ common controls); Regulatory Change Management module; DORA supported. Continuous Authorization & Monitoring + CMDB. Auto-generates remediation tasks (own ITSM engine); Jira via Integration Hub. ~$40K-$100K+/yr. Weakness: content UCF-curated not law-derived; assumes data flows into Now Platform.

Tier 3 — Trust/audit-centric GRC

  • OneTrust (onetrust.com): security/privacy-first, weak on US financial reg (only DORA; SOX = IT only; no SEC/FINRA). Graded 1-5 evidence-confidence. Jira task->ticket still Public Preview (2026). New $10K/yr minimum; enterprise $120K-$500K+. Weakness: templates not raw law, no US financial depth.
  • Hyperproof (hyperproof.io): STRONGEST Tier-3 overlap. Dedicated fintech line (as templates): SOX/DORA/FINRA-gap/GLBA/FFIEC/PCI/NIS2 + 140+ templates. Hypersyncs (50+ systems) + Automated Controls Testing + CCM + control health score; 2026 AI gap-discovery agents. Native bidirectional Jira (+ADO/GitHub); gap-scan flags missing policy/procedure/technical controls. ~$12K-$100K/yr (median ~$40K). Weakness: curated templates, no raw-law translation, Jira bolt-on not MCP-native.
  • AuditBoard — now "Optro" (rebranded 2026-03-09; auditboard.com -> optro.ai): SOX DNA ("SOXHUB"); SOX/ITGC/DORA/NYDFS 500/Basel op-risk/FFIEC/NIS2 + 30+ frameworks. RegComply module (Apr 2025, powered by CUBE) AI-maps obligations to controls; G2 #1 in Reg Change Mgmt. Intelligent Testing pulls from 150-200+ systems. Jira supported; backlog derives from audit findings not regulation-to-current-state gap. ~$30K-$150K+/yr, ~4-mo implementation. Weakness: CUBE-licensed content + human-in-loop, not MCP-native.

Category X — The actual "raw law -> requirements" competitors (the real fight)

  • Ascent RegTech (ascentregtech.com): patented AI extracts each obligation from rulebooks as structured objects (MiFID II in 2.5 min). Genuine extraction but output = legal obligations, no Jira/dev done-vs-gap.
  • CUBE (cube.global): "Automated Regulatory Intelligence," 750 jurisdictions; dominant consolidator — acquired Thomson Reuters Regulatory Intelligence (closed early 2026) + 4CRisk. Powers AuditBoard/others. No dev integration. Watch item: agentic APIs.
  • Corlytics + Clausematch (corlytics.com): the ONLY incumbent explicitly doing obligation->control gap analysis + LLM remediation suggestions — but against policy documents, not live systems.
  • Norm Ai (norm.ai, $48M, Citi/Bain/Blackstone/Vanguard): most technically ambitious "law-as-code" — regs into executable programs + LLM agents. But reviews artifacts/documents, no dev-system done-vs-gap, no build backlog. Best-funded threat if it pivots to systems verification.
  • Regology / Reggi AI (regology.com): CLOSEST single vendor to "raw law -> controls/requirements generation"; AI agents "generate obligations, risks, controls, and policies" from tracked laws in 135+ countries. But maps to internal policies, no dev integration.
  • 6clicks "Hailey" (6clicks.com): AI crosswalk/gap analysis, but maps to pre-existing framework libraries, not raw statute; no dev systems.
  • UCF (unifiedcompliance.com) & SCF (securecontrolsframework.com): incumbent common-control backbones GRC tools license. UCF's patented NLP decomposing raw regulation into atomic mandates is PRIOR ART. Both static curated catalogs, no live systems.

Two consistent, exploitable blind spots across ALL incumbents

  1. Every incumbent is template/library-driven — none auto-translates arbitrary or newly-issued statute. Long tail (APRA CPS 230, novel jurisdictional/contractual obligations, fast-moving DORA RTS, SEC/FINRA conduct rules) is unserved.
  2. All are strong on machine-verifiable software controls, weak on policy/procedure controls (manual attestation). Scoring BOTH from live Confluence + Jira reads is real differentiation.

Threats to watch (ranked)

  1. Archer Evolv — only incumbent already doing raw-law->requirements at scale with deep FS content.
  2. Norm Ai — best-funded law-as-code; dangerous if it moves to live-systems verification.
  3. AuditBoard/Optro + Hyperproof — shipped agentic gap-discovery 2025-2026; AI-automation edge is a timing advantage only.
  4. CUBE — consolidating the reg-intel content layer.

Verdict

The durable moat is the SPECIFIC combination — raw-law-to-buildable-requirements translation feeding an MCP-native, live-systems done-vs-gap scorecard across software AND policy controls, with a prioritised build backlog. Each link exists somewhere; nobody has all four. "Regulation-derived requirement checked against a live Jira/codebase rather than a policy PDF" is the unoccupied position.

Research & evidence

4 recorded entries behind this idea, oldest first. Open one to read it in full.

Evidence 2

Sources, findings, and competitor scans.

evidenceCATEGORY-CROWDING EVIDENCE. The "done-vs-gap coverage scorecard + Jira remediation" pattern is offered by at least 9 vendors; several already AUTO-CR…

CATEGORY-CROWDING EVIDENCE. The "done-vs-gap coverage scorecard + Jira remediation" pattern is offered by at least 9 vendors; several already AUTO-CREATE Jira tickets from failing/not-ready controls: Vanta (native, auto-ticket on failing test), Drata (auto-open on Not Ready/Failed), LogicGate (native bidirectional), ServiceNow (own ITSM engine + Jira via Integration Hub). Secureframe explicitly does NOT yet auto-create Jira tickets (manual/bulk); OneTrust's task->Jira is still Public Preview in 2026. So competing on the scorecard+backlog loop alone means fighting incumbents with 300-400+ integrations (Vanta 400+/1,200+ tests; Drata/Secureframe 300+). Sources: vanta.com/integrations, help.vanta.com/en/articles/11345790, help.drata.com/en/articles/6953569, support.secureframe.com JIRA article, onetrust.com/integrations/Atlassian-JIRA.

evidenceRAW-LAW-TRANSLATION EVIDENCE (the real fight). Obligation extraction from raw regulatory text is already crowded, concentrated in FS RegTech: Ascent…

RAW-LAW-TRANSLATION EVIDENCE (the real fight). Obligation extraction from raw regulatory text is already crowded, concentrated in FS RegTech: Ascent (ascentregtech.com — patented per-obligation extraction, MiFID II in 2.5 min); CUBE (cube.global — 750 jurisdictions, acquired Thomson Reuters Regulatory Intelligence closed early 2026 + 4CRisk); Corlytics/Clausematch (corlytics.com — ONLY incumbent explicitly doing obligation->control gap + LLM remediation, but vs policy docs); Regology (regology.com — closest to "generate obligations/risks/controls/policies from raw law", 135+ countries); Norm Ai (norm.ai — $48M, law-as-executable-code); Archer Evolv (archerirm.com/evolv-compliance — 526 compliance-trained AI models, ~95% extraction accuracy, DORA/Basel/SEC/FINRA). Incumbent backbones = UCF (unifiedcompliance.com, patented NLP decomposing regulation into atomic mandates = PRIOR ART) and SCF (securecontrolsframework.com). CRITICAL DISTINCTION: every one of these stops at the policy/document layer — "done" = a policy PDF, attestation, or control-library entry. NONE connects a regulation-derived requirement to a LIVE dev/business system (Jira/Confluence/codebase) to verify actual implementation state. That full chain is the unoccupied white space.

Risks 1

Reasons this could fail.

riskCOMPETITIVE THREATS (ranked). 1) Archer Evolv — the only incumbent already attempting raw-law->requirements at scale WITH deep FS content; closest si…

COMPETITIVE THREATS (ranked). 1) Archer Evolv — the only incumbent already attempting raw-law->requirements at scale WITH deep FS content; closest single competitor to the core edge (mitigant: heavyweight $55K-$300K+/yr, self-attestation-leaning assurance, not the engineering system-of-record, no MCP/live-systems agent). 2) Norm Ai — best-funded "law-as-code" ($48M); dangerous IF it pivots from document/artifact review to live-systems verification. 3) AuditBoard/Optro + Hyperproof — both shipped agentic AI gap-discovery in 2025-2026, so the AI-automation edge is a TIMING advantage, not durable; the durable moat is specifically raw-law->buildable-requirements feeding a live-systems scorecard. 4) CUBE — consolidating the entire reg-intel content layer (bought TR Reg Intelligence + 4CRisk); most likely to reach toward live-system integration. NOTE: AuditBoard rebranded to "Optro" on 2026-03-09 (auditboard.com -> optro.ai) — update all competitive materials.

Proposed refinements 1

Proposals for the document above. Open ones are awaiting merge.

refinementawaiting mergePOSITIONING / DIFFERENTIATION PLAYS. (1) Lead GTM with the FULL chain, never a single piece — raw-law translation -> MCP-native live-systems connecti…

POSITIONING / DIFFERENTIATION PLAYS. (1) Lead GTM with the FULL chain, never a single piece — raw-law translation -> MCP-native live-systems connection -> unified scorecard across software AND policy/procedure controls -> prioritised build backlog. Each link exists somewhere; nobody has all four. (2) Own the two blind spots common to ALL incumbents: (a) template/library-driven content that cannot ingest arbitrary/newly-issued statute (long tail: APRA CPS 230, novel jurisdictional/contractual obligations, fast-moving DORA RTS); (b) weakness on policy/procedure controls (universally manual attestation) — score both from live Confluence+Jira reads. (3) Target SEC/FINRA markets-conduct as content white space — even FS-strong tools (AuditBoard/Optro, Hyperproof, Archer) skew to security/resilience-flavoured regs (DORA/GLBA/FFIEC/SOX ITGC); explicit conduct-rule coverage is thin everywhere. (4) Exploit deployment/price/mid-market — every FS-capable incumbent is quote-only $40K-$500K+/yr, platform-heavy, months-long implementations expecting data to live in their workbench; an MCP-native connect-to-existing-systems agent that skips the six-figure rollout is a structural advantage. (5) Must prove: evidence-automation maturity (where Vanta/Drata have 300-400+ integrations and 1,000+ tests) and FS-regime content credibility.

Comments

Loading comments...

Sign in with GitHub or Google to comment and react.

Sign in to post public comments.