The proving ground for executable risk appetite
Steel Mountain is the pilot environment for the RiskMetrica platform. It exists for one reason: to prove that risk appetite can operate as a real control plane inside a regulated institution.
An institution engineered to behave like a supervised institution without using real customer or market data.
Full institutional structure including retail and SME customers. In the case of a Bank will have complete B/S portfolio structure.
Complete governance structures including escalation pathways, committee oversight, and senior accountability frameworks.
Everything is synthetic. Everything is auditable. Everything is designed to stand up to regulatory scrutiny.
Steel Mountain proves the foundation before anything else is added.
No. Steel Mountain runs the 11 Core Modules and a deliberately constrained agent layer. Advanced analytics, optimisation, and autonomous execution are excluded by design. Steel Mountain proves the foundation before anything else is added.
No. Steel Mountain is a pilot environment operating entirely on synthetic data. It demonstrates platform capabilities without processing real customer data or real transactions.
No. Steel Mountain is a precisely scoped, regulator-credible. It is not a playground for experimentation but a controlled proving ground with full audit trails.
No. Steel Mountain is designed to stand up to scrutiny from boards and supervisors. Every assumption, decision trail, and outcome is visible and defensible.
Four integrated components demonstrating executable risk appetite in action
Core Control Layer
Steel Mountain runs the RAC Foundation as the primary control layer. Risk appetite is not static policy. It is live, enforceable, and observable.
Machine-readable appetite statements driving real-time decisions
Structured classification enabling consistent risk identification
Precise thresholds triggering automated governance responses
Continuous monitoring with immediate escalation protocols
The machine-readable governance layer that translates board-approved risk appetite statements into executable rules, quantified thresholds, and real-time monitoring capabilities.
Bounded AI Operations
A small, tightly governed set of agents supports RAC operation. Agents are deterministic, bounded, and fully auditable. There is no autonomous decision-making.
Translating policy into operational guidance
Evaluating threshold violations and severity
Orchestrating response actions across functions
Generating regulator-grade explanations and reports
Regulatory Assessment
Steel Mountain includes a bank-grade Internal Risk and Solvency Assessment framework. IRSA is embedded, not bolted on.
Comprehensive assessment of regulatory capital adequacy
Credit, conduct, and operational risk frameworks
From raw data through to board decisions
Regulatory submissions generated from system state
Internal Risk and Solvency Assessment. The comprehensive framework demonstrating that executable risk appetite translates directly to regulatory capital adequacy and liquidity requirements.
Executive Dashboards
Steel Mountain supports a focused set of executive views. Every view is driven from the same RAC truth.
Aggregate appetite, breaches, trends, and management actions
Calibration, limit utilisation, and emerging risk indicators
Regulatory capital position and stress testing outcomes
Customer outcomes and operational resilience metrics
Before advanced AI or optimisation, RiskMetrica proves that executable risk appetite can run a bank.
Demonstrate that executable risk appetite can operate as a genuine control plane, not just a policy document gathering dust.
Steel Mountain is designed to be walked through with supervisors. Decision trails, assumptions, and outcomes are visible and defensible.
Extreme scenarios, control failures, and governance breakdowns can be tested without real-world consequences.
Steel Mountain becomes the canonical foundation on which all future RiskMetrica deployments are built.
Steel Mountain operates entirely on high-fidelity synthetic data. This is not a shortcut. It is what makes Steel Mountain safe, repeatable, and regulator-ready.
Statistically representative of real customer patterns
Correlated movements across risk, liquidity, and capital
Full audit trails enabling consistent testing and validation
No real customers, no real institutions, no privacy concerns
High-fidelity artificially generated data that preserves the statistical properties and behavioural patterns of real customer data without containing any actual customer or institutional information.
Scope: Enables safe, repeatable testing of governance frameworks while meeting data protection and regulatory requirements.
Steel Mountain starts with a banking pilot within RiskMetrica's Early Access Programme. Additional industry-specific pilots are in development.
Steel Mountain
Coming Soon
Coming Soon
Coming Soon
Coming Soon
Steel Mountain sits within the Early Access Programme as the reference implementation of RiskMetrica's core philosophy.
See it working
EAP participants first observe Steel Mountain to see executable risk appetite in action before discussing their own implementation.
Informs design
Insights from Steel Mountain inform the architecture and configuration of client-specific pilot deployments.
Risk is not a report.
Risk appetite is not a statement.
Governance is not a process document.
Steel Mountain shows how these become operational reality.
If you want to see how RiskMetrica behaves inside a bank, this is where you start.
See governance in action before commitment. Understand how risk appetite translates to daily operations and board-level oversight.
Evidence of compliance capability. Transparent, auditable governance demonstration with full decision trails and assumption visibility.
Validate the approach before transformation. Test operational risk framework efficacy and see executable risk appetite driving real decisions.
Understand day-to-day impact. See how agents augment risk decision-making and how governance becomes operational reality.
Architecture reference implementation. Understand integration patterns, data flows, and validate architectural credibility before your own build.
Request access to the Early Access Programme and see executable risk appetite in action