Risk Management
Identify, score, treat and review your risks in one place - with AI to help anyone run a proper assessment, and a defensible trail behind every decision.
Keep a living risk register your whole team can maintain - score risks on a consistent, calibrated scale, treat and review them on a cadence the system tracks, and run audit-ready assessments, with an AI companion that helps non-specialists do it properly.
A risk register that stays alive
Most risk registers are a spreadsheet written once for an audit and never reopened. Risk Management makes risk a running practice: every risk is owned, scored on a scale everyone reads the same way, given treatment with owners and dates, and reviewed on a cadence the system keeps for you. What you get back is not a document - it is the evidence of how you arrived at it.
- One register, consistently scored, so prioritising is a comparison rather than a guess
- Treatment actions and plans with owners, due dates and sign-off
- Reviews scheduled by risk level, so the register reflects today’s risks - not last year’s
- A full history of how each risk and its treatment changed over time
AI helps anyone run a proper assessment - and you stay in control
Risk work is usually gatekept by specialists: most people asked to complete a data-protection impact assessment do not know what half the questions mean. A built-in AI companion changes that - it explains each term in plain English with the standard it comes from, drafts a suggested answer from what you already know, and checks the assessment for gaps before you submit. When the assessment is approved, it proposes the risks the answers imply, each with its reasoning and the clause behind it, for your reviewer to accept, edit or reject.
And the maths stays yours. Every score in your register is calculated from values a person entered - AI can suggest a score and explain its thinking, but it never writes one, and no risk becomes active without someone confirming it. You get the speed of AI with the accountability a regulated decision needs.
Scoring you can defend
Risk Management ships with a fully calibrated 5×5 Likelihood × Impact model, grounded in NIST SP 800-30, so “why is this a four?” finally has a written answer. As you set likelihood and impact, the score, its band and colour, and the treatment expected all appear at once - the assessor sees the consequence before committing to it. Treatment is required above Medium and enforced when you save, and if a residual risk stays Medium or higher the product asks for the documented sign-off that accepting it requires - closing the gap that is the most common audit finding in risk management.
Need a different model? A methodology engine lets your administrator author your own scoring - multi-factor, weighted or highest-severity - version it and publish it out, so customising your scale and staying current are no longer a trade-off.
Never stale, always ready for the audit
Each risk carries a next-review date set by its band - Critical and High monthly, Medium quarterly, Low annually - and the owner is chased when it falls due. Even a “nothing changed” review counts: it resets the clock and leaves documented evidence that you looked. Assessments become a repeatable, dated, signed-off exercise - the person who fills one in cannot approve it, and once approved it is sealed and kept for good. When an auditor asks how you identified your risks and who signed them off, the Acceptance Log and the assessment record already hold the answer.
What it looks like

Placeholder - the risk register. Upload the real screenshot in the admin.
Use cases
Anyone can run a proper assessment
A built-in AI companion explains the jargon with the standard behind it, drafts answers from what you already know and flags gaps before you submit - so a DPIA or an ISMS risk assessment gets done properly, not left to the one specialist who understands the questions.
Prove how you identified your risks
An assessment turns risk identification into a dated, signed-off exercise: the person who completes it cannot approve it, approval seals the record, and AI’s proposed risks - each with its reasoning and the clause behind it - sit on file next to who confirmed them.
Re-assess without starting over
When an assessment comes due, the next round is pre-filled with the last approved answers, so you only touch what changed - and on approval AI works out the difference risk by risk and proposes it for your reviewer to confirm.
Evidence of active management
Reviews are scheduled by risk level and chased when overdue, every treatment and acceptance is on the record, and the Acceptance Log hands an auditor the governed decisions - the rationale, who accepted, and when - without a scramble.
Risk management that holds up at audit
AI that assists, never decides
A companion helps non-specialists assess properly and proposes the risks an assessment implies - but every score is a number a person entered, and every proposal needs a human’s acceptance.
Scoring you can defend
A calibrated 5×5 Likelihood × Impact model grounded in NIST SP 800-30, with band, colour and expected treatment shown as you score - and an engine to author your own model when you need one.
Reviewed on cadence, ready for audit
Reviews scheduled by risk level and chased when due, residual acceptance captured with sign-off, and approved assessments sealed for good - the trail an auditor asks for, already there.
