
Nine connected pages, from the register through to the board pack. Every risk carries its controls, treatments, threats and assurance in one place — so "how do we know?" always has an answer.

Most registers reduce a complex position to one subjective colour, chosen by whoever owns the row. The composite assurance score replaces that with measurable inputs — control coverage, evidence currency, treatment progress, review recency — so the number moves when reality moves.
47 risks · 12 columns · 9 filters
| Ref | Risk | Inherent | Residual |
|---|---|---|---|
| R-018 | Third-party data breach | 20 | 12 |
| R-004 | Ransomware — core systems | 25 | 10 |
| R-022 | Key person dependency | 15 | 6 |
| R-009 | DORA ICT non-compliance | 20 | 9 |
| R-031 | Model drift — credit scoring | 16 | 8 |
Each one is a working part of the product, not a tab on a single screen.

The enterprise register — create, score, treat, link and sign off, with a 5×5 heat map and per-risk deep dive.

178 shared templates across 16 categories, with a guided wizard and AI-assisted risk extraction.

Four treatment types with progress and budget tracking, linked back to the risks they mitigate.

Dynamic ranking with key-risk flagging and historical trend tracking.

The board-level register with oversight tracking — the backbone of a Provision 29 declaration.

A threat library linked to risks, vulnerabilities and mitigating controls.

Technical vulnerability register tied to critical assets and risk exposure.

Executive, operational and financial views with interactive heat maps.

Six AI-generated report types, from landscape analysis to control-gap review.
Every module shares one system of record, so evidence gathered in one place counts everywhere it is needed.



Bring a risk you find hard to evidence today.