← All projects
SOFTWARE + GOVERNANCE, RISK & COMPLIANCE

Community Bank CRM
& Risk Assessment

One project, two perspectives: build a banking workflow, then assess what it would take to protect real customer data. Explore client relationships, leads, meetings, and live fraud-note scoring, alongside a source-based review of ten risk scenarios and proposed controls.

JavaScriptBanking workflowsRisk assessmentControl evidenceTreatment planning

Sample-data prototype with simulated roles and browser-local notes. Add a Fraud Note to recalculate its score. The linked GRC exercise assesses a hypothetical production deployment; proposed controls are not implemented.

BUILD · ASSESS · IMPROVE
  1. 01 / EXPLORETry the banking workflows

    Client lookup · leads · meetings · fraud scoring

  2. 02 / ASSESSTrace risks to the source

    Ten scenarios linking code evidence to business impact

  3. 03 / PLANDocument the path forward

    Proposed controls, treatment updates, and assessment export

TECHNICAL DOCUMENTATION / VERSION CONTEXT

Architecture behind the prototype

My June 2026 technical documentation describes a fuller Node.js and SQLite prototype. The public portfolio runs a static adaptation so visitors can explore sample workflows without a server account. These versions have different security boundaries.

  1. DOCUMENTED FRONTEND

    Browser interface

    HTML, CSS, JavaScript, and Fetch-based calls for customer, lead, meeting, and note workflows.

  2. DOCUMENTED BACKEND

    Application API

    The document describes password hashing, expiring bearer sessions, and permission checks on API operations.

  3. DOCUMENTED DATABASE

    SQLite records

    Related customer and workflow tables, a role-permissions table, and paginated queries.

Backend controls described in the document are not running in the public static demo. They require source review and direct API tests before claiming verified access enforcement or production readiness. The document also lists edit operations and audit logging as future work, so its broad completion claims are not used here.

IMPLEMENTED IMPROVEMENT

Render bank notes as text

The public demo now builds the bank-note author, date, body, and action buttons with DOM elements. Note text no longer enters the HTML template in this rendering path.

This addresses the specific bank-note rendering gap identified as R03 in the original GRC assessment. The assessment remains pinned to its historical source snapshot; this focused improvement does not establish that the entire application is secure or close other risks.

Next verification priorities for the documented backend are denied-request tests for each role, record-level access checks, session expiry and logout tests, and evidence of security event logging.