
Written by Alessandro Fonseca, Director of Latin American Sales at Archer.
I’ve been in risk and compliance long enough to know when a vendor is repackaging the same dashboard with a shinier label, and I’ve also learned to spot the rarer moment when something genuinely changes the shape of the work. What Archer has shipped this year, and what is still coming, is the second kind of moment, and I want to explain why, in plain terms, without the usual buzzword soup.
Let me start with the part that almost never gets mentioned in these announcements: the data.
Twenty five years of thousands of risk programs, all in one place
Archer has spent a quarter of a century sitting inside the risk and compliance operations of some of the most regulated organizations on the planet. Banks, insurers, healthcare systems, energy companies, more than half the Fortune 500 have run their risk registers, their controls, their assessments and their audit trails through Archer at some point. That is not a marketing line, it is an operational fact, and it matters enormously right now because of what it makes possible.
Every serious AI system is only as good as what it learned from. A general purpose model can write you a fluent paragraph about operational risk, but it has never seen how a real control failure moved through a real organization, how a real regulator responded to a real gap, or how a real risk committee actually made a call under pressure. Archer has seen exactly that, at scale, across industries and geographies, for decades. That history is the raw material behind what the we now calls our AI Operators, and it is the reason this feels different from yet another chatbot wrapped around a spreadsheet.
This is pillar one of how we think about the whole story: Archer GRC as the system of record. Not a side project, not a bolt on. The workflows, the risk data, the controls, the evidence, all of it already lives there for our customers. Everything new that gets built sits on top of that foundation instead of asking anyone to rip it out and start over.
Operators that actually work inside your risk domains
Here is where it gets exciting. Archer is not shipping one generic AI feature and calling it done. It is building AI Operators structured around specific risk domains, regulatory intelligence, regulatory change, AI risk, decision support, with operational risk, IT risk, policy content and third party risk right behind them. Each operator is trained and purpose built for its domain, not a general assistant asked to guess at GRC vocabulary.
What makes this genuinely proprietary, and worth being proud of, is the intellectual property behind it. We already hold patents on this technology, with 18 more in the pipeline, protecting exactly the kind of domain specific reasoning that took decades of real program data to build. That is not something a competitor can replicate by fine tuning an open model over a weekend (or even a decade, for that matter).
And the operators do not stop at producing a summary for someone to read and forget. They open the assessment, they assign the owner, they update the register, inside Archer, the same system your team already works in. Every action carries its own trail: what the operator looked at, what it concluded, how confident it was, and who it routed the decision to when it was not sure. That last part matters more than people realize. An operator that knows when to stop and hand a judgment call to a human is far more useful, and far more trustworthy, than one that always sounds certain.
Think about what that frees up. A risk analyst spends less time chasing down which policy version applies to which control, and more time thinking about whether the organization’s actual risk appetite still makes sense given what changed this quarter. A compliance officer spends less time manually mapping a new regulation to forty existing controls, and more time deciding what to tell the board about the one gap that truly matters. That is the whole point. The operators absorb the grinding, repetitive first pass so your best people can spend their attention on judgment, and judgment is the one thing that should never be automated away, as it is precisely where the real value out of the bright minds on your risk team sits.
Regulation never stops moving, and neither does the content feeding these operators
The third piece of this story is the one I think gets underestimated the most: a constantly refreshed library of external content, organized by jurisdiction, feeding directly into the operators so a risk program stays audit ready instead of playing catch up every time a regulator publishes something new.
I say this as someone sitting in Latin America, watching the regulatory calendar fill up faster than most global risk teams have noticed. Brazil alone gives us a preview of what is coming everywhere. The Banco Central published Resolução Conjunta 18 late last year, which turns data quality, governance and full traceability of everything reported to the regulator into an auditable obligation, with a hard deadline at the end of this year and personal accountability sitting with senior leadership. Around the same time, CMN Resolução 5.274 and its mirror rule BCB 538 rewrote the minimum bar for cybersecurity, third party technology governance and incident response for financial institutions, with a compliance deadline landing in March. In parallel, BCB Resoluções 519, 520 and 521 built an entirely new licensing and governance regime for virtual asset providers, effectively asking crypto companies to meet a banking grade standard for risk management, internal controls and capital, on a clock that started earlier this year. On the insurance side, CNSP Resolução 471 introduced ORSA, the own risk and solvency assessment discipline that European insurers have lived with for years, now rolling out to Brazilian insurers in stages through next year.
When we look at the entire region, the picture is similar.
- In Mexico, the resolution the CNBV published in the Diario Oficial on July 6 this year requires every regulated fintech institution to name a dedicated information security officer, run a documented incident response process, and report any confirmed security incident to the board or its risk committee at the very next meeting rather than folding it into an annual review.
- In Colombia, Decreto 368, issued in April, made open finance mandatory for every entity the Superintendencia Financiera supervises, and the technology and security standards tied to the earlier Circular 004 carry their own deadline of August 7 this year, so proving real architecture and governance is neither optional nor theoretical anymore.
- In Peru, Resolución SBS 01029, published April 15, reclassified failures to protect client information, including data loss, theft or fraud tied to a security incident, as some of the most serious infractions a supervised institution can commit.
- And in Chile, Ley 21.663 has required board level accountability and active enforcement from the national cybersecurity agency since its key articles took effect on March 1 last year, with fines that can reach 40,000 UTM for the operators it treats as critical.
Taken one country at a time, each of these is a manageable project. For an organization running risk and compliance across five, six or seven of these markets at once, which describes most of the companies I work with in this region, the burden does not simply add up, it compounds. Every regulator wants its own evidence, on its own calendar, in its own format, and a team trying to satisfy all of that with spreadsheets and good intentions runs out of hours long before it runs out of obligations.
None of these are isolated events. They are part of a broader pattern across the region moving in the same direction, tightening operational resilience, third party oversight and data governance requirements at a pace that most risk teams were not built for. A risk program that relies on someone manually reading every new resolution and mapping it to existing controls will always be behind. An AI Operator that continuously monitors thousands of regulatory sources across jurisdictions, understands regulatory language rather than just general prompts, and turns a new obligation into a mapped control gap within hours instead of months, changes the entire cost of staying compliant. That is not a nice to have anymore, given the calendar I just walked through, it is close to survival.
Building what you cannot buy off the shelf
The fourth pillar is the one I am personally most curious to watch develop: the ability for our partners and customers to build their own custom operators through Archer’s Foundry Program. Every organization has a corner of its risk program that is genuinely unique, a homegrown methodology, an industry specific requirement, a process nobody else has. The four domain operators shipping today and the ones coming next cover an enormous amount of ground, but they will never cover everything, and they should not try to. Foundry is the answer to that gap, giving partners and customers a path to extend the same governed, traceable AI approach into the parts of their program that are theirs alone.
That is the part that turns this from a product update into a platform strategy. Archer is not trying to be the only brain in the room. It is trying to be the trustworthy foundation that every other brain, ours, our partners’, our customers’ own teams, can build on without starting from zero.
Why this matters right now, from where I sit
I run the Latin America business for a company that has spent twenty five years earning the trust of risk and compliance leaders, and I get to watch that trust turn into something genuinely new: AI that understands risk because it was built from risk, not from the general internet. The region I cover is entering one of the busiest regulatory stretches I have seen, and the organizations that get ahead of it will not be the ones that hired the most people to read PDFs faster. They will be the ones that gave their risk teams a system that reads, reasons and acts inside the same platform where the work already lives.
We shipped 43 of these operators already. 200+ more are on the way by the end of the year. And now, with Foundry, the door is open for our partners across the region to build the parts that are uniquely theirs. If you sit on a risk or compliance team anywhere in Latin America and you have not looked at what this actually does yet, I would genuinely love to show you. Not because I need to sell you something today, but because I think the shape of this work is about to change for everyone doing it, and I would rather you hear it from me now than catch up on it later.
FAQs
At Archer Accelerate, at the São Paulo (October 6) and Santiago (October 8) stops. Alessandro Fonseca opens and closes both events, and the 9:30 AM session, “Regulatory Change, Automated: From Signal to Control in Real Time” with Sarah Dalton, walks through exactly what this blog describes: catching a regulatory signal, turning it into a mapped control, and documenting the trail from source to action.
São Paulo (October 6): https://www.thearchersummit.com/event/accelerate/Saopaulo
Santiago (October 8): https://www.thearchersummit.com/event/accelerate/Santiago
A general-purpose model can write fluently about operational risk, but it’s never seen how a real control failure moved through a real organization or how a real risk committee made a call under pressure. Archer’s Operators are grounded in 25 years of program data across regulated industries, so the reasoning behind a result traces back to something real.
A way for partners and customers to build their own AI Operators for the parts of their risk program that are unique to them, a homegrown methodology, an industry-specific requirement, anything the domain operators don’t already cover, on the same governed, traceable foundation.
The regulatory calendar across the region is compounding: Brazil’s Resolução Conjunta 18, CMN 5.274/BCB 538, and the new virtual-asset licensing rules; Mexico’s CNBV incident-reporting requirement; Colombia’s open finance mandate under Decreto 368; Peru’s reclassified data-protection infractions; Chile’s board-level cybersecurity accountability. Each is manageable alone. Running risk and compliance across five or six of these markets at once is where teams run out of hours before they run out of obligations.
AI systems built for specific risk domains rather than general assistants guessing at GRC vocabulary. Four are live today — regulatory intelligence, regulatory change, AI risk, and decision support — with operational risk, IT risk, policy content, and third-party risk operators coming next. Each one works inside Archer, opening assessments, assigning owners, updating the register, and every action leaves a trail of what it looked at and who it routed the decision to when it wasn’t sure.










