Implementation update: the current CRM bank-note rendering path now uses text nodes. This assessment keeps its original source baseline and ratings. See the architecture and improvement notes for version context.
SIMULATED ASSESSMENT / 29 SEP 2026
Risk, with evidence.
Community Bank CRM
A practical review of risks, controls, and the path to production.
Portfolio exercise using sample data. Ratings assume a hypothetical move to real customer information. Proposed controls are not implemented; this is not an audit opinion or compliance certification.
01 / ASSESS & PRIORITIZE
Risk register
| Risk / scenario | Inherent rating | Owner / target | Exercise status |
|---|
No risks match these filters.
Ratings remain unchanged when treatment status changes. Residual risk requires separate validation.
02 / BUSINESS DECISION
Keep the prototype
on sample data.
The CRM demonstrates relationship management and fraud triage. Moving it to real customer data would require enforceable access controls and a different storage architecture.
- Enforce access on the server. Browser role switching cannot establish a trusted authorization boundary.
- Protect the underlying records. A JavaScript dataset is delivered to visitors regardless of which panels are visible.
- Render note text safely. The reviewed bank-note rendering path interpolates text into HTML.
Start with these release blockers, then verify logging, retention, recovery, and fraud-rule quality. Named roles and target dates in this exercise are illustrative, not real organizational commitments.
03 / ASSESSMENT BASIS
Trace the judgment.
Scope
Source review of the portfolio’s static CRM at commit da346f3: role switching, shipped sample data, local note storage, rendering, and fraud rules. No production bank systems, hosted backend, repository settings, vendor contracts, or exploit testing were assessed.
Data flow
- Static host serves sample data and scripts
- Browser applies simulated role views and fraud rules
- Browser saves notes, leads, and meetings in localStorage
Risk method
Likelihood × impact, each from 1–5. Likelihood runs from rare to near certain; impact runs from negligible to severe customer-data or service harm. These are qualitative judgments for the hypothetical production scenario.
Low: 1–5 · Moderate: 6–11 · High: 12–19 · Critical: 20–25
Evidence and limitations
Each finding distinguishes observed behavior from controls not evidenced in scope. A missing artifact does not prove that a control is absent elsewhere. Proposed controls need implementation and testing before residual risk can be assessed.
Updates are retained in this tab only. Reloading resets the exercise; export your assessment to keep a copy.