Quick answer
OptiTech loads the CRI Profile tier-aware: the impact assessment determines your tier, the applicable diagnostic statements load as requirements, and your existing controls cross-map onto them, with the NIST CSF function structure as the shared skeleton. Evidence collects continuously, and the Profile's maintained mappings mean the same control state renders as a Profile assessment, a 23 NYCRR 500 posture, or a DORA view, whichever the examiner or counterparty speaks.
Tiering as configuration, not negotiation
The impact questionnaire (services, interconnectedness, scale) computes your tier and documents the reasoning, so the scoping conversation with an examiner starts from a defensible record. Tier changes (growth, new critical services) arrive through the same scope-change mechanics as everything else: a reviewed delta of newly applicable diagnostic statements rather than a program rebuild.
One assessment, many audiences
The Profile's harmonization pays off operationally when each audience gets its view from the same data:
- Examiners see the Profile assessment with per-statement status and timestamped evidence, sampled through scoped read-only access.
- Counterparties running due diligence get questionnaire answers from live control state or a Trust Center view.
- The board gets the function-level trend reporting financial regulators expect of governance, generated from the same posture; see board reporting.
The financial-sector control depth
The Profile's heavier expectations run on the platform's standard machinery at financial-grade settings: access and privileged-account checks continuous against your identity provider, incident response with regulatory clocks per applicable regime, third-party risk through the supplier register with DORA-grade contract tracking, and resilience testing on a managed calendar. For technology vendors assessed in Profile terms by financial customers, the same setup answers the diligence without a bespoke project per counterparty.

Get a personalized walkthrough of automated compliance for your team. No commitment required.