Everything you need to manage risk properly
Registers, controls, actions, events, obligations, reporting — connected in one platform with a full audit trail.
Start free trialRisk registers with structure
Create registers for different parts of your organisation. Build hierarchies — nested registers and categories — so risks live where they belong. Every risk has a lifecycle: draft, identify, assess, manage, close. Scoring uses your own likelihood and impact scales, visualised on a heatmap with risk appetite overlays.
Controls that stay current
Track controls with effectiveness assessments, evidence attachments, and KPIs. Link controls to the risks they mitigate. Set assessment schedules and get notified when assessments are overdue. Control owners see what needs their attention — not a dashboard designed for someone else.
Actions that get done
Raise actions from risks, controls, or events. Assign owners, set due dates, track status. Actions link back to whatever triggered them, so nothing gets lost.
Capture what happened
Record risk events — incidents, near-misses, losses — with custom event types and categories. Link events to the risks they relate to. Attach evidence. Build the picture of what actually happens, not just what might.
Compliance frameworks, connected
Import compliance frameworks from CSV — SOC 2, ISO 27001, NIST, or any framework your organisation follows. Map obligations to your controls with coverage metadata: full, partial, or planned. Generate a Statement of Applicability report. See where your gaps are.
Reports that answer the question
Risk heatmaps with appetite overlays. Statement of Applicability. Reports are built for the board conversation — clear, visual, defensible.
Built right, from the ground up
Your scales, your taxonomy, your appetite
Configure likelihood scales, impact tables, and risk taxonomy to match how your organisation thinks about risk. Define risk appetite at the level that makes sense — organisation-wide, per domain, or per category. Draft, review, and activate new versions without disrupting live data.
The right access for the right people
Create custom roles with granular permissions across registers and categories. Permissions inherit down hierarchies, so a grant on a parent category applies to everything beneath it. Role membership is managed by your tenant admin — no platform support tickets needed.
Every change, every time
Append-only history for every risk, control, and event. Every change is captured with who made it and when. Built for the audit conversation, not bolted on afterwards.
Bring your existing data
Import risks, controls, and compliance frameworks from CSV. Validation and dry-run mode catch errors before anything is committed. Combined with the GenAI API, you can restructure messy spreadsheet data before import.