Enterprise Risk (ERM)
A risk register that reflects how you actually score risk
Matrices, formulas, and taxonomy are configuration rather than assumptions baked into the code, so the register matches your methodology instead of the other way round.
- Versioned taxonomy: type, category, and subcategory, with diff before activation
- Configurable matrix axes, levels, severity bands, and scoring formulas
- Appetite definitions and tolerance bands with defined breach actions
- Quantitative analysis with frequency and magnitude distributions
Privileged accounts without review
KRI · monthly · owner: Security Operations
Methodology
Your scoring model, not ours
Matrix definitions carry versions, axes, axis levels, severity bands, and per-cell mappings. Formulas are versioned too, with overrides where a programme needs to diverge.
- Matrix and formula versions kept side by side so history stays interpretable
- Normalisation profiles when programmes score on different scales
- Taxonomy imported as a draft, diffed against the active version, then activated
- Deletion guarded: a node in use returns a conflict rather than orphaning records
Treatment
Mitigate, transfer, avoid, or formally accept
Acceptance is a first-class path with a named acceptance authority and an expiry, so accepted risk returns for re-decision instead of quietly persisting.
- Treatment plans with actions, owners, priorities, and status
- Reviews and reassessments that recalculate residual exposure
- Score snapshots and full history retained per risk
- Board rollup snapshots and hierarchy aggregates for reporting
Treatment decision
- 1Treatment planActions with owners, priority, and due dates
- 2Action trackingStatus per action, SLA where defined
- 3ReassessmentResidual score recalculated after closure
Assurance
RCSA cycles and an attested risk universe
Departmental self-assessment runs as a cycle with its own entries and evidence, and the risk universe is versioned with attestation rather than being an untracked list.
- RCSA cycles with department assessments, entries, and evidence
- Risk universe versions, items, and attestation records
- Loss events with categories and root causes
- Scenarios with explicit stated assumptions
Stage 1 of 5
Open cycle
Scope and period set by the risk function
Loss events feed the same register, with category and root cause recorded.
Framework alignment
Works with your control frameworks
This module shares the platform control library. Map national frameworks and global standards alongside jurisdiction-specific authorities.
Solutions by role
Built for your team
See enterprise risk in your environment
A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.