Package contents
9 sectionsWhat is not in it
Metadata and structure only
No customer, account or transaction record appears in the package. What SmarterFI receives is the shape of the bank’s systems: domain names, systems of record, row counts, integration methods, scores, the criteria behind each score, and constraints. The payload below is the whole of it — there is no second file.
1 discovered schema was withheld by the bank
Redacted at review and absent from the package entirely — not by name, not by table count, not by volume. The package reports 271 tables where the bank’s own audit log records 280 enumerated, and that difference is the redaction rather than an error. The reason the domain is out of scope travels with the package; how much of it there is does not.
The bank keeps the full result set, including what was withheld. The audit log on the scan page records who redacted it, when, and the statutory basis.
The checklist on the dashboard shows the share step as still open, because it is: what governs the copy SmarterFI would hold is a data agreement, and this build does not have one. Nothing on this page shares anything.
Structured payload
Generated from the same record every page on this site reads.Also at /api/v1/mapping{
"institution": {
"name": "First Community Bank",
"charter": "State nonmember",
"assets": "$1.42B",
"branches": "14",
"regulator": "FDIC / State",
"contact": "Dana Whitfield",
"email": "dwhitfield@firstcommunity.bank"
},
"core": {
"vendor": "Jack Henry",
"product": "SilverLake System",
"version": "2024.2",
"hosting": "In-house — bank-managed hardened VM",
"ancillary": [
"Banno Digital",
"Yellow Hammer BSA",
"Synergy ECM",
"PassPort EFT"
]
},
"domains": [
{
"domain": "Customer / CIF",
"system": "SilverLake CFMAST",
"documentedRecords": 31893,
"classification": "NPI",
"sensitivity": "High"
},
{
"domain": "Deposits",
"system": "SilverLake DDMAST",
"documentedRecords": 63896,
"classification": "NPI",
"sensitivity": "High"
},
{
"domain": "Loans",
"system": "SilverLake LNMAST",
"documentedRecords": 6952,
"classification": "NPI",
"sensitivity": "High"
},
{
"domain": "General Ledger",
"system": "SilverLake GLMAST",
"documentedRecords": 3090,
"classification": "None",
"sensitivity": "None"
},
{
"domain": "Accruals",
"system": "SilverLake GLMAST",
"documentedRecords": 6765,
"classification": "None",
"sensitivity": "None"
},
{
"domain": "Officer / Branch hierarchy",
"system": "SilverLake CFMAST",
"documentedRecords": 190,
"classification": "None",
"sensitivity": "None"
},
{
"domain": "Transactions",
"system": "Enterprise Data Warehouse",
"documentedRecords": 18736341,
"classification": "NPI",
"sensitivity": "High"
},
{
"domain": "Cards & Payments",
"system": "PassPort Debit",
"documentedRecords": 27999,
"classification": "NPI, PCI DSS",
"sensitivity": "High"
},
{
"domain": "Digital Banking",
"system": "Banno Online",
"documentedRecords": 21155,
"classification": "NPI",
"sensitivity": "High"
}
],
"excludedDomains": [
{
"domain": "BSA / AML",
"reason": "Excluded from scope by the bank. The existence of a report may not be disclosed to any third party. Not shareable in any form, including counts. (31 CFR 1020.320(e))",
"discoveredSchemaWithheld": true
}
],
"integrations": [
{
"name": "Core nightly extract",
"type": "SFTP file drop",
"direction": "Outbound",
"frequency": "Nightly, after EOD",
"enabled": true
},
{
"name": "jXchange",
"type": "SOAP / XML web services",
"direction": "Bidirectional",
"frequency": "Real-time inquiry",
"enabled": true
},
{
"name": "Enterprise Data Warehouse",
"type": "ODBC, read replica",
"direction": "Read-only",
"frequency": "Hourly",
"enabled": true
},
{
"name": "Salesforce FSC",
"type": "REST API",
"direction": "Bidirectional",
"frequency": "15 min",
"enabled": false
},
{
"name": "Synergy ECM documents",
"type": "SMB share",
"direction": "Read-only",
"frequency": "On demand",
"enabled": true
}
],
"scan": {
"schemas": [
{
"schema": "FCBPROD.CFMAST",
"readFrom": "Core (Db2 for i)",
"tables": 42,
"documentedRecords": 32083,
"observedRows": 32236,
"variance": 153,
"status": "reconciled",
"mappedDomains": [
"Customer / CIF",
"Officer / Branch hierarchy"
],
"classification": "NPI"
},
{
"schema": "FCBPROD.DDMAST",
"readFrom": "Core (Db2 for i)",
"tables": 68,
"documentedRecords": 63896,
"observedRows": 64655,
"variance": 759,
"status": "reconciled",
"mappedDomains": [
"Deposits"
],
"classification": "NPI"
},
{
"schema": "FCBPROD.LNMAST",
"readFrom": "Core (Db2 for i)",
"tables": 91,
"documentedRecords": 6952,
"observedRows": 6999,
"variance": 47,
"status": "reconciled",
"mappedDomains": [
"Loans"
],
"classification": "NPI"
},
{
"schema": "FCBPROD.GLMAST",
"readFrom": "Core (Db2 for i)",
"tables": 24,
"documentedRecords": 9855,
"observedRows": 9792,
"variance": -63,
"status": "reconciled",
"mappedDomains": [
"General Ledger",
"Accruals"
],
"classification": "None"
},
{
"schema": "EDW.TRANSACTIONS",
"readFrom": "Enterprise Data Warehouse",
"tables": 12,
"documentedRecords": 18736341,
"observedRows": 18687800,
"variance": -48541,
"status": "reconciled",
"mappedDomains": [
"Transactions"
],
"classification": "NPI"
},
{
"schema": "EDW.CARD_ACTIVITY",
"readFrom": "Enterprise Data Warehouse",
"tables": 19,
"documentedRecords": 27999,
"observedRows": 22959,
"variance": -5040,
"status": "variance",
"mappedDomains": [
"Cards & Payments"
],
"classification": "NPI, PCI DSS"
},
{
"schema": "EDW.DIGITAL_PROFILE",
"readFrom": "Enterprise Data Warehouse",
"tables": 15,
"documentedRecords": 21155,
"observedRows": 21245,
"variance": 90,
"status": "reconciled",
"mappedDomains": [
"Digital Banking"
],
"classification": "NPI"
}
],
"tablesEnumerated": 271,
"rowsExtracted": 0,
"schemasWithheldByTheBank": 1,
"note": "1 discovered schema is not represented in this package, by name, count or volume — withheld either by the bank at review or because the domain it holds may not be disclosed to a third party at all. The bank's own audit log records the reviewer and the statutory basis."
},
"environment": {
"deployment": "onprem",
"region": "US-East (bank data center, Springfield)",
"identity": "Microsoft Entra ID (SAML 2.0)",
"retention": "7 years",
"encryption": [
"TLS 1.3 in transit",
"AES-256 at rest",
"HSM-managed keys"
],
"classificationScheme": "GLBA / Regulation P, with PCI DSS scope marked separately"
},
"maturity": {
"overall": 65,
"referenceBand": 56,
"referenceBandProvenance": "The reference band is SmarterFI’s own maturity model, not a survey of institutions: it is the level the model expects of a community bank of this asset size, and no bank’s answers are in it.",
"dimensions": [
{
"dimension": "Core & System Landscape",
"score": 73,
"referenceBand": 63,
"criteria": [
{
"criterion": "Core banking system identified and on a vendor-supported release",
"level": "managed",
"points": 30,
"outOf": 30,
"answeredBy": "capture",
"from": "Step 2 — Core Banking Systems",
"evidence": "Jack Henry SilverLake 2024.2, in-house on a bank-managed hardened VM."
},
{
"criterion": "Ancillary system inventory complete",
"level": "managed",
"points": 20,
"outOf": 20,
"answeredBy": "capture",
"from": "Step 2 — Core Banking Systems",
"evidence": "Four ancillary systems recorded: Banno Digital, Yellow Hammer BSA, Synergy ECM, PassPort EFT."
},
{
"criterion": "Integration architecture aligned to the vendor’s roadmap",
"level": "initial",
"points": 10,
"outOf": 30,
"answeredBy": "assessor",
"from": "Interview — IT Director, 5 Aug 2026",
"evidence": "jXchange is on SOAP with no OAuth 2.0 migration planned. Jack Henry retires the current authentication between 2026 and 2028; the bank has no dated plan."
},
{
"criterion": "Environment and hosting documented",
"level": "defined",
"points": 13,
"outOf": 20,
"answeredBy": "capture",
"from": "Step 5 — Environment & Security",
"evidence": "Region, identity provider, retention and encryption recorded; disaster-recovery runbook not attached."
}
]
},
{
"dimension": "Data Quality & Accessibility",
"score": 66,
"referenceBand": 56,
"criteria": [
{
"criterion": "Core master files complete and extractable",
"level": "managed",
"points": 30,
"outOf": 30,
"answeredBy": "scan",
"from": "Read-only scan — FCBPROD, 5 Aug 2026",
"evidence": "4 core schemas enumerated across 225 tables, every one reconciling with the documented volume."
},
{
"criterion": "Warehouse lineage documented",
"level": "initial",
"points": 10,
"outOf": 30,
"answeredBy": "assessor",
"from": "Interview — IT Director, 5 Aug 2026",
"evidence": "The warehouse has no lineage catalogue. Transformations live in scheduled jobs and are not documented outside them."
},
{
"criterion": "Record volumes reconcile between source and warehouse",
"level": "defined",
"points": 13,
"outOf": 20,
"answeredBy": "scan",
"from": "Read-only scan — variance report, 5 Aug 2026",
"evidence": "6 of 8 schemas reconcile inside tolerance and 1 belongs to a domain the bank excluded. EDW.CARD_ACTIVITY does not reconcile, and the gap is not explained."
},
{
"criterion": "Data dictionary maintained for in-scope domains",
"level": "defined",
"points": 13,
"outOf": 20,
"answeredBy": "capture",
"from": "Step 3 — Data Domains",
"evidence": "Every in-scope domain has a system of record and a documented volume; field-level definitions exist for the core, not the warehouse."
}
]
},
{
"dimension": "Integration & Architecture Maturity",
"score": 64,
"referenceBand": 54,
"criteria": [
{
"criterion": "Real-time inquiry capability available",
"level": "managed",
"points": 28,
"outOf": 28,
"answeredBy": "capture",
"from": "Step 4 — Integration Points",
"evidence": "jXchange is enabled and serving real-time inquiry."
},
{
"criterion": "Batch extract scheduled and monitored",
"level": "managed",
"points": 18,
"outOf": 18,
"answeredBy": "capture",
"from": "Step 4 — Integration Points",
"evidence": "Core nightly extract runs after end-of-day over SFTP, with alerting on failure."
},
{
"criterion": "Event-driven or streaming capability",
"level": "none",
"points": 0,
"outOf": 18,
"answeredBy": "assessor",
"from": "Interview — IT Director, 5 Aug 2026",
"evidence": "No message bus, no change-data-capture, no event stream. Everything is batch or synchronous request."
},
{
"criterion": "API authentication modernised to OAuth 2.0",
"level": "initial",
"points": 6,
"outOf": 18,
"answeredBy": "assessor",
"from": "Interview — IT Director, 5 Aug 2026",
"evidence": "Salesforce FSC would use OAuth 2.0 when enabled. Everything currently in production authenticates on shared secrets."
},
{
"criterion": "Integration register complete with direction and frequency",
"level": "defined",
"points": 12,
"outOf": 18,
"answeredBy": "capture",
"from": "Step 4 — Integration Points",
"evidence": "Five integration points documented with type, direction and frequency; one of the five is not enabled."
}
]
},
{
"dimension": "Security & Controls",
"score": 77,
"referenceBand": 64,
"criteria": [
{
"criterion": "Encryption in transit and at rest with managed keys",
"level": "managed",
"points": 24,
"outOf": 24,
"answeredBy": "capture",
"from": "Step 5 — Environment & Security",
"evidence": "TLS 1.3 in transit, AES-256 at rest, keys held in an HSM."
},
{
"criterion": "Identity federation with multi-factor authentication enforced",
"level": "managed",
"points": 25,
"outOf": 25,
"answeredBy": "capture",
"from": "Step 5 — Environment & Security",
"evidence": "Microsoft Entra ID over SAML 2.0, MFA enforced organisation-wide."
},
{
"criterion": "Access reviews current",
"level": "defined",
"points": 11,
"outOf": 17,
"answeredBy": "assessor",
"from": "Interview — Risk & Compliance, 5 Aug 2026",
"evidence": "Quarterly reviews are performed and evidenced. Privileged access is reviewed on the same cycle rather than more often."
},
{
"criterion": "Least-privilege service accounts for vendor access",
"level": "defined",
"points": 11,
"outOf": 17,
"answeredBy": "scan",
"from": "Read-only scan — audit log, 5 Aug 2026",
"evidence": "SVCACCT_SMARTERFI_RO holds *USE and no *CHANGE. The write-permission check was attempted and denied, and the denial is in the log."
},
{
"criterion": "Data classification applied per domain",
"level": "initial",
"points": 6,
"outOf": 17,
"answeredBy": "capture",
"from": "Step 3 — Data Domains",
"evidence": "Domains carry NPI, PCI and SAR-confidential markings. The markings are not yet mapped to what each one permits a vendor to do, outside this record."
}
]
},
{
"dimension": "Existing AI & Automation Footprint",
"score": 66,
"referenceBand": 50,
"criteria": [
{
"criterion": "Rules-based automation in production",
"level": "managed",
"points": 30,
"outOf": 30,
"answeredBy": "assessor",
"from": "Interview — SVP Operations, 5 Aug 2026",
"evidence": "Yellow Hammer BSA runs rules-based fraud and AML alerting in production, tuned quarterly."
},
{
"criterion": "Automation coverage across business lines",
"level": "defined",
"points": 13,
"outOf": 20,
"answeredBy": "assessor",
"from": "Interview — SVP Operations, 5 Aug 2026",
"evidence": "Deposit operations and BSA are automated. Lending and finance are manual end to end."
},
{
"criterion": "Staff familiarity with AI-assisted workflows",
"level": "defined",
"points": 13,
"outOf": 20,
"answeredBy": "assessor",
"from": "Interview — SVP Operations, 5 Aug 2026",
"evidence": "The executive team uses general-purpose assistants daily. Branch staff have had no exposure."
},
{
"criterion": "Machine-learning models in production",
"level": "none",
"points": 0,
"outOf": 20,
"answeredBy": "assessor",
"from": "Interview — SVP Operations, 5 Aug 2026",
"evidence": "None. Every production decision rule is hand-written and reviewable."
},
{
"criterion": "A named owner for automation initiatives",
"level": "managed",
"points": 10,
"outOf": 10,
"answeredBy": "assessor",
"from": "Interview — SVP Operations, 5 Aug 2026",
"evidence": "Dana Whitfield, SVP Operations, with time formally allocated."
}
]
},
{
"dimension": "Model Risk & Governance Readiness",
"score": 45,
"referenceBand": 48,
"criteria": [
{
"criterion": "Model inventory maintained",
"level": "none",
"points": 0,
"outOf": 25,
"answeredBy": "assessor",
"from": "Interview — Risk & Compliance, 5 Aug 2026",
"evidence": "There is no inventory of models or decision rules. The BSA rule set is documented inside the vendor product and nowhere else."
},
{
"criterion": "Independent validation policy",
"level": "none",
"points": 0,
"outOf": 15,
"answeredBy": "assessor",
"from": "Interview — Risk & Compliance, 5 Aug 2026",
"evidence": "No validation policy exists, and no function is designated independent of model development."
},
{
"criterion": "Model risk guidance alignment programme (FDIC FIL-22-2017)",
"level": "initial",
"points": 5,
"outOf": 15,
"answeredBy": "assessor",
"from": "Interview — Risk & Compliance, 5 Aug 2026",
"evidence": "FIL-22-2017, which adopts the SR 11-7 principles for FDIC-supervised institutions, has been read and circulated. No gap assessment has been performed and no programme is dated."
},
{
"criterion": "Vendor model risk inside third-party due diligence",
"level": "managed",
"points": 15,
"outOf": 15,
"answeredBy": "assessor",
"from": "Interview — Risk & Compliance, 5 Aug 2026",
"evidence": "The third-party risk programme is mature and covers vendor-supplied analytics, with annual reassessment."
},
{
"criterion": "Board and committee oversight of AI use",
"level": "managed",
"points": 15,
"outOf": 15,
"answeredBy": "assessor",
"from": "Interview — Risk & Compliance, 5 Aug 2026",
"evidence": "The technology committee has a standing AI agenda item and minutes it to the board quarterly."
},
{
"criterion": "Change control over production analytics",
"level": "defined",
"points": 10,
"outOf": 15,
"answeredBy": "assessor",
"from": "Interview — Risk & Compliance, 5 Aug 2026",
"evidence": "Changes go through the standard IT change board. There is no separate gate for a change that alters a decision rule."
}
]
},
{
"dimension": "Organizational & Change Readiness",
"score": 67,
"referenceBand": 54,
"criteria": [
{
"criterion": "Executive sponsorship secured",
"level": "managed",
"points": 28,
"outOf": 28,
"answeredBy": "assessor",
"from": "Interview — SVP Operations, 5 Aug 2026",
"evidence": "The CEO sponsors the programme and it is minuted. Budget is allocated for the current year."
},
{
"criterion": "Project owner named with time allocated",
"level": "managed",
"points": 18,
"outOf": 18,
"answeredBy": "assessor",
"from": "Interview — SVP Operations, 5 Aug 2026",
"evidence": "Dana Whitfield owns the programme with a formal time allocation; Marcus Reyes owns delivery."
},
{
"criterion": "Frontline enablement planned",
"level": "none",
"points": 0,
"outOf": 27,
"answeredBy": "assessor",
"from": "Interview — SVP Operations, 5 Aug 2026",
"evidence": "No training plan, no enablement owner and no dates. The programme currently stops at the executive team."
},
{
"criterion": "Change communication plan",
"level": "initial",
"points": 3,
"outOf": 9,
"answeredBy": "assessor",
"from": "Interview — SVP Operations, 5 Aug 2026",
"evidence": "Announcements are drafted per project. Nothing is standing or scheduled."
},
{
"criterion": "Prior technology change delivered successfully",
"level": "managed",
"points": 18,
"outOf": 18,
"answeredBy": "assessor",
"from": "Interview — SVP Operations, 5 Aug 2026",
"evidence": "The Banno Digital rollout landed on schedule in 2025 with the same sponsor and delivery owner."
}
]
}
]
},
"blueprint": [
{
"application": "CEO Co-Pilot",
"requirementsMet": 9,
"requirementsTotal": 10,
"deployable": false,
"openItems": [
"Model Risk & Governance Readiness"
]
},
{
"application": "Month-End Close",
"requirementsMet": 7,
"requirementsTotal": 8,
"deployable": false,
"openItems": [
"Model Risk & Governance Readiness"
]
},
{
"application": "Money Management",
"requirementsMet": 6,
"requirementsTotal": 9,
"deployable": false,
"openItems": [
"Cards & Payments",
"Salesforce FSC",
"Model Risk & Governance Readiness"
]
}
],
"openItems": [
{
"item": "volume-variance",
"owner": "Marcus Reyes",
"ownerRole": "Editor · IT Director",
"nextActions": [
"Explain or correct the gap between EDW.CARD_ACTIVITY and the documented volume for Cards & Payments"
]
},
{
"item": "dimension-below-threshold",
"owner": "Priya Nandakumar",
"ownerRole": "Approver · Risk & Compliance",
"nextActions": [
"Model inventory maintained",
"Independent validation policy",
"Model risk guidance alignment programme (FDIC FIL-22-2017)",
"Change control over production analytics"
]
},
{
"item": "integration-disabled",
"owner": "Marcus Reyes",
"ownerRole": "Editor · IT Director",
"nextActions": [
"Enable Salesforce FSC (REST API, 15 min) or drop Money Management from this phase"
]
}
],
"implementationPlan": [
{
"phase": "Phase 1 — Deploy what the mapping already supports",
"summary": "No application meets every documented requirement yet. One item — Model Risk & Governance Readiness — accounts for 3 of 3, so it is the first thing to close.",
"prerequisites": [
"Container image reviewed by information security and placed on a bank-managed host.",
"Read-only service account provisioned against the replica, not the production system."
],
"delivers": [
"Nothing deploys in this phase — see Phase 2."
]
},
{
"phase": "Phase 2 — Close the open items",
"summary": "3 of 3 applications are waiting, and Model Risk & Governance Readiness is what 3 of them are waiting on.",
"prerequisites": [
"Model Risk & Governance Readiness — required by CEO Co-Pilot and Month-End Close and Money Management.",
"Cards & Payments — required by Money Management.",
"Salesforce FSC — required by Money Management."
],
"delivers": [
"CEO Co-Pilot unblocked and deployed.",
"Month-End Close unblocked and deployed.",
"Money Management unblocked and deployed."
]
},
{
"phase": "Phase 3 — Extend the scope deliberately",
"summary": "BSA / AML sits outside the mapping, by the bank’s decision.",
"prerequisites": [
"A written decision from the bank on whether any excluded domain should come into scope.",
"For BSA / AML specifically: the existence of a suspicious activity report may not be disclosed to a third party under 31 CFR 1020.320(e), so the exclusion is a control rather than a gap to close — which is why the discovered schema is withheld from the export rather than merely marked."
],
"delivers": [
"Specialised agents (Deposit Defense, Margin Optimization) mapped the same way when the bank selects them.",
"The landscape map re-run and the blueprint regenerated from the updated record."
]
}
],
"attestation": {
"sections": [
{
"section": "Institution profile",
"asOf": "5 Aug 2026",
"attestedBy": "dwhitfield@firstcommunity.bank",
"reviewBy": "5 Aug 2027",
"cycle": "Annual"
},
{
"section": "Core & ancillary systems",
"asOf": "5 Aug 2026",
"attestedBy": "mreyes@firstcommunity.bank",
"reviewBy": "5 Feb 2027",
"cycle": "On every core release"
},
{
"section": "Data domains",
"asOf": "5 Aug 2026",
"attestedBy": "mreyes@firstcommunity.bank",
"reviewBy": "5 Aug 2027",
"cycle": "Annual"
},
{
"section": "Integration register",
"asOf": "5 Aug 2026",
"attestedBy": "mreyes@firstcommunity.bank",
"reviewBy": "5 Feb 2027",
"cycle": "Semi-annual"
},
{
"section": "Environment & security",
"asOf": "5 Aug 2026",
"attestedBy": "pnandakumar@firstcommunity.bank",
"reviewBy": "5 Aug 2027",
"cycle": "Annual"
},
{
"section": "Scan results",
"asOf": "5 Aug 2026",
"attestedBy": "mreyes@firstcommunity.bank",
"reviewBy": "5 Nov 2026",
"cycle": "Quarterly, or on a schema change"
},
{
"section": "Maturity scorecard",
"asOf": "5 Aug 2026",
"attestedBy": "pnandakumar@firstcommunity.bank",
"reviewBy": "5 Feb 2027",
"cycle": "Semi-annual"
}
],
"recordReviewDue": "2027-08-05"
},
"generatedAt": "2026-08-05T14:20:00Z"
}