Start a free trial
Menu

Risk Management

Identify, score, treat and review your risks in one place - with AI to help anyone run a proper assessment, and a defensible trail behind every decision.

Keep a living risk register your whole team can maintain: consistent scoring, treatment and review on a cadence the system tracks, and audit-ready assessments.

Turn risk assessments into decisions you can follow through

Most risk registers are a spreadsheet written once for an audit and never reopened. Risk Management makes risk a running practice: every risk is owned, scored on a scale everyone reads the same way, given treatment with owners and dates, and reviewed on a cadence the system keeps for you. What you get back is not a document, it is the evidence of how you arrived at it.

Risks arrive from more than one place. Assessments, stakeholder reviews and quality work can all raise one, and a risk created from a source arrives for review rather than arriving endorsed. Business domains, categories and saved views keep a register that spans the organisation readable.

What it looks like

  • Risk register with three synthetic engineering risks, inherent scores and review dates.
    Keep risks, scores and review dates in one register. These are saved draft risks with calculated inherent scores; their residual assessment has not been made yet, and the register says so.

Use cases

  • Anyone can run a proper assessment

    A built-in AI companion explains the jargon with the standard behind it, drafts answers from what you already know and flags gaps before you submit - so a DPIA or an ISMS risk assessment gets done properly, not left to the one specialist who understands the questions.

  • Prove how you identified your risks

    An assessment turns risk identification into a dated, signed-off exercise: the person who completes it cannot approve it, approval seals the record, and AI’s proposed risks - each with its reasoning and the clause behind it - sit on file next to who confirmed them.

  • Re-assess without starting over

    When an assessment comes due, the next round is pre-filled with the last approved answers, so you only touch what changed - and on approval AI works out the difference risk by risk and proposes it for your reviewer to confirm.

  • Evidence of active management

    Reviews are scheduled by risk level and chased when overdue, every treatment and acceptance is on the record, and the Acceptance Log hands an auditor the governed decisions - the rationale, who accepted, and when - without a scramble.

Risk management that holds up at audit

  • AI that assists, never decides

    A companion helps non-specialists assess properly and proposes the risks an assessment implies - but every score is a number a person entered, and every proposal needs a human's acceptance.

  • Scoring you can defend

    A calibrated 5x5 Likelihood x Impact model grounded in NIST SP 800-30, with band, colour and expected treatment shown as you score - and an engine to author your own model when you need one.

  • Reviewed on cadence, ready for audit

    Reviews scheduled by risk level and chased when due, residual acceptance captured with sign-off, and approved assessments sealed for good - the trail an auditor asks for, already there.

Likelihood times impact methodology with scoring factors and risk thresholds.

Methodologies

Use the methodology your decision needs

The product ships with a fully calibrated 5x5 Likelihood x Impact model grounded in NIST SP 800-30, so "why is this a four?" has a written answer. That model is one option rather than the only one: a methodology engine lets your administrator author scoring of their own - multi-factor, weighted or highest-severity - set the thresholds, version it and publish it out.

Making the method explicit is the point. Factors, scales and band thresholds are configuration you can show an auditor, and the treatment and review rules that follow from a band are attached to the methodology rather than left to habit. The values above are this workspace's configuration, not a fixed scale everyone receives.

  • Factor-based scoring with scales and thresholds you can read and change
  • Band-dependent treatment and review rules, defined with the methodology
  • Versioned methodologies, so changing your scale does not rewrite history
Risk detail showing likelihood 3, impact 4, inherent score 12 and residual assessment pending.

Assessment and treatment

Separate the original exposure from what is controlled

A risk record keeps its inherent scoring, the assessment behind it, the controls it relies on and the treatment planned, and it keeps them apart. Inherent and residual are different numbers, and a control that is proposed is not a control that is operating - linking one does not lower the other on its own.

The risk above is a saved draft: described, scored for inherent exposure, with its review and treatment context in place and its residual assessment still to be made. Treatment is required above Medium and enforced when you save, and a residual risk that stays Medium or higher asks for the documented sign-off that accepting it requires.

  • Inherent and residual scoring held separately, with linked control implementations
  • Treatment plans with owners, due dates and sign-off
  • Reviews scheduled by band - Critical and High monthly, Medium quarterly, Low annually
  • An Acceptance Log holding the rationale, who accepted and when

See it on your own processes

A 30-minute demo, walked through with your quality or compliance lead. No slides - the product, on the workflows you actually run. Or start a trial and we will set up a workspace to match what you are working on.