Reyl logo

How REYL Intesa Sanpaolo Brought Risk Management Workflows In-House with Posit Connect

view of geneva from a plane with mountains in distance

Summary

When REYL Intesa Sanpaolo's Risk Management team set out to modernize how the Bank tracks and resolves operational incidents, they didn't open a procurement process. They built the solution themselves, using R, Shiny, and Posit Connect, and deployed it across the entire organization in a matter of months. What started as a question about workflow has become a quiet demonstration of what's possible when domain experts are also given the tools to be builders.

Photo by Frank Oosterbaan on Unsplash

About:

REYL Intesa Sanpaolo is a Geneva-based private and investment bank founded in 1973, operating across wealth management and asset services. A subsidiary of Intesa Sanpaolo, one of Europe's largest banking groups, REYL Intesa Sanpaolo combines the agility of a boutique institution with the resources of a global network.

Industry:

Banking

Technology used:

Posit Connect

The challenge

A Workflow Ready for an Upgrade

For a bank, operational risk incidents are a fact of life. For example, a front-office trader fills a stock order incorrectly resulting in a financial discrepancy that needs to move through accounting, back office, and Risk Management before it can be resolved. Every one of these events needs to be documented, routed for review, and ideally logged with the full chain of communication intact.

REYL Intesa Sanpaolo had a structured process for managing these incidents. Reports went out, managers reviewed them, Risk Management weighed in. However, like many well-designed processes that grew up around email and document-based workflows, the practical reality was more cumbersome than the policy. Incident reports arrived as Word documents with free-text fields and supporting communications were scattered across email chains, phone calls, and Teams messages. By the time a report reached Risk Management, reassembling the full picture often meant days of follow-up across departments.

For Laetitia Deladoëy, the issue was less about any single incident and more about what the accumulated friction meant for the quality of the data they could actually work with and the time spent chasing. Building coherent reporting on top of unstructured input is slow and error-prone. Understanding the Bank's true risk profile requires seeing patterns across incidents and that requires clean, consistent, structured data. The team saw an opportunity to do better.

The solution

Not a Dashboard, But a Workflow Engine Deployed to Posit Connect

When the Risk Management team identified the need for a structured, web-based incident reporting tool, Shiny was the natural next step. The team had been working in R, and Shiny meant they could build an interactive interface entirely within that environment, without depending on IT for every change.  As Giuseppe Gerardi emphasized, this approach allowed the Risk team to develop the solution independently, while IT focused primarily on governance and infrastructure integration.

What made Shiny the right fit wasn't just familiarity. It gave the team a single framework where data manipulation, business logic, and front-end visualization could all live together, reducing the context switching that comes with stitching together tools from different worlds. And because R's syntax is approachable for professionals with programming skills, the team could manage and evolve the entire stack themselves, without handing off to engineering every time something needed to change.

The missing piece was deployment. Open-source Shiny Server could get an app running, but it couldn't satisfy the security and governance requirements of a regulated banking environment. Posit Connect filled that gap. It gave IT the controls they needed, auditable deployments, role-based access, and Active Directory integration, without creating a bottleneck for the Risk team. Gary Gosse, System/DevOps Engineer, led the integration of Posit Connect into the bank's infrastructure, building a CI/CD pipeline on Azure DevOps so that changes move cleanly through development, UAT, and production environments. Any commit to the source control system triggers a new deployment in the dev environment automatically. The Risk team could move at their own pace. IT could maintain oversight. Neither had to compromise.

The Incident Management Tool (IMT) they built isn't a dashboard. It's a workflow engine. Laetitia Deladoëy, Project Manager, worked closely with the development team, including Valentin Piquerez, translating functional requirements into a tool that enforces every step of the incident process: manager review, Risk Management analysis, CEO sign-off where required, and routing to accounting for any financial impacts. Automated emails go out at each stage. No one has to chase anyone down.

The role-based access is worth noting on its own. Depending on who logs in, an incident issuer, a direct manager, the CEO, an accounting officer, or a risk manager, the interface adapts to show them exactly what they need to do next. The tool knows the organizational structure and reflects it. As Vivien de Beaucé, Head of the Regulatory Risk team, put it: "Users don't have to think about where they are in the process — the interface shows them their next action and won't let them skip ahead. Automated emails go out at each stage so no one has to chase anyone down. Furthermore, it means less reliance on third-party tools, no black box."

The results

Cleaner Data, Clearer Picture

The IMT went live in January 2026, and the benefits have been felt across the organization. Incident reports now arrive with structured, consistent information because the tool requires it. This has reduced the back-and-forth between incident reporters and risk management. For the first time, everyone involved in an incident, from the person who filed it to their manager to accounting, can see exactly where it sits in the process. And underneath all of that, a well-ordered database is quietly accumulating the kind of clean, consistent incident data that can eventually support pattern analysis and predictive risk modeling across the organization.

What Vivien emphasizes most, though, isn't any single efficiency gain. It's what the project represents for how risk management at REYL Intesa Sanpaolo thinks about its own capabilities.

4 people in meeting room posing
REYL Intesa Sanpaolo Team: Giuseppe, Laetitia, Gary and Vivien

48X

Faster

From days of follow-up to 30 minutes for a straightforward incident.

300

Employees

Number of REYL Intesa Sanpaolo employees with access to the Incident Management Tool

30

Minutes

New follow-up time on a simple incident, down from a process that could previously stretch across days.

Real world example

From Trade Error to Closed Incident

Consider a scenario anyone in front-office operations would recognize: a trader needs to buy 50 shares of Apple for a client and instead buys 50 shares of Amazon. The position has to be corrected, the client may need to be made whole, and the incident needs to be formally documented, reviewed, and closed.

Before the IMT, that meant coordinating across multiple channels, documents, email threads, phone calls, Teams messages to assemble a complete picture. Supporting documents might arrive separately or not at all. Risk management would often receive the final report without full visibility into what had happened before it reached them.

Now the incident goes into the IMT at the moment it's identified. The form requires structured information (the type of incident, when it was detected, when it occurred, the financial impact if applicable) and supporting documents are attached directly to the record. As the incident moves through review stages, comments stay inside the tool deployed to Posit Connect. Everyone involved can see where the incident sits in the workflow at any time.

For Risk Management, the downstream benefit is equally significant. Every incident now lands in a well-structured database with unique identifiers, event journals, and consistent categorization. That data is the foundation for the automated reporting the team is now building out on Posit Connect, and eventually for more sophisticated analysis of the bank's risk profile over time.

Looking ahead

A Decision Intelligence Layer

The IMT is the first application to come out of a broader internal initiative the team calls RADAR, a framework for building R-based data products on Posit Connect across REYL Intesa Sanpaolo's risk management function. Incident management was chosen deliberately as a starting point: high visibility, bank-wide reach, and a use case where the benefits of replacing a manual process with a structured workflow would be immediate and measurable.

What comes next is already taking shape. The team is planning to bring mitigation monitoring into the tool, tracking progress on how incidents are resolved and what they reveal about gaps in the bank's control environment. Beyond that, they're exploring applications for liquidity monitoring, credit risk appetite, risk exposure forecasting and stress testing, and interbank relationship management, all following the same pattern: R-based, deployed through Posit Connect, built and owned by the domain experts who understand the data.

For Vivien, Laetitia, and Giuseppe, the longer-term vision is a Decision Intelligence layer for the bank, a foundation of reliable, well-governed data that supports everything from routine reporting to predictive risk modeling, built and maintained by the risk team themselves, without needing to hand off to a vendor or wait in IT's queue.

As Vivien puts it: "It's quite a novel approach for financial institutions in Switzerland to do this." The team is proud of it. And they're just getting started.

Helpful resources

person tracking finances on laptop

AI-ready analytics for financial services