Everything you need to manage risk properly
Registers, controls, actions, events, obligations, reporting — connected in one platform with a full audit log.
Start free trialRisk registers with structure
Create registers for different parts of your organisation. Build hierarchies — nested registers and categories — so risks live where they belong. Every risk has a lifecycle: draft, identify, assess, manage, close. Scoring uses your own likelihood and impact scales, visualised on a heatmap with risk appetite overlays.
Controls that stay current
Track controls with effectiveness assessments, evidence, and KPIs. Link controls to the risks they mitigate. Set assessment schedules and get notified when assessments are overdue. Control owners see what needs their attention — not a dashboard designed for someone else.
Actions that get done
Raise actions from risks, controls, or events. Assign owners, set due dates, track status. Actions link back to whatever triggered them, so nothing gets lost.
Capture what happened
Record events — incidents, near misses and other occurrences — with custom event types and categories, each carrying its own loss rows. Link events to the risks they relate to. Attach evidence. Build the picture of what actually happens, not just what might.
Obligations, connected
Import a compliance framework as an obligation — SOC 2, ISO 27001, NIST, or any standard your organisation follows. Map each of its requirements to your controls with coverage metadata: full, partial, or planned. Generate a Statement of Applicability report. See where your gaps are.
Reports that answer the question
Risk heatmaps with appetite overlays. Statement of Applicability. Reports are built for the board conversation — clear, visual, defensible.
Built right, from the ground up
Your scales, your taxonomy, your appetite
Configure likelihood scales, impact tables, and risk taxonomy to match how your organisation thinks about risk. Define risk appetite at the level that makes sense — organisation-wide, per domain, or per category. Draft, review, and activate new versions without disrupting live data.
The right access for the right people
Create permission roles with granular permissions across registers and categories. Permissions inherit down hierarchies, so a grant on a parent category applies to everything beneath it. Role membership is managed by your organisation's administrator — no platform support tickets needed.
Every change, every time
An append-only audit log for every risk, control, and event. Every change is captured with who made it and when. Built for the audit conversation, not bolted on afterwards.
Bring your existing data
Bulk-import your risks and controls, and import obligations from CSV. Validation and dry-run mode catch errors before anything is committed. Combined with AI Integration, you can restructure messy spreadsheet data before import.