Connected risk intelligence

Risk management you can prove

One platform for the whole risk cycle: register, controls, indicators, breaches, remediation and board reporting. One record, one audit trail, nothing re-keyed.

The decisions that need two people are enforced by the platform rather than left to policy.

or write to sales@puretrace.co.uk

There is no form here and no marketing sequence. You email us and a person replies.

PureTrace is for organisations that have to prove they manage risk, not only manage it. If a board, a regulator, an accreditor, an auditor, an insurer or a customer's assurance team can ask you to show your working, this is built for you.

Healthcare and care groups·Energy and utilities·Legal and professional services·Technology and managed services·Manufacturing and logistics·Education·Housing·Financial services


One record. Six stages. Nothing re-keyed between them.

Most risk functions run on a chain of workbooks. A number is chased, pasted, re-scored and consolidated, and by the time it reaches the board nobody can say what it was measured against. PureTrace is one dataset instead. A risk carries its controls. Those controls carry the indicators that test them. An indicator that crosses red raises a formal breach. The breach carries its response and its remediation. The committee pack assembles from that live data rather than a copy of it.

The PureTrace risk cycle Six stages arranged clockwise on a ring: risk, control, indicator, breach, action and committee pack, with the cycle closing back round to risk. Every stage writes to a single audit trail, shown at the centre of the ring. 01 02 03 04 05 06 Risk Control Indicator Breach Action Committee pack One audit trail
One record, six stages and one audit trail underneath all of them. Nothing is re-keyed on the way round.
01

Risk

Categories and the risks beneath them, inherent and residual positions, an appetite position with its reasoning and a named owner on every line.

02

Control

Controls sit in a library and link to the risks they mitigate. Downgrade one and you see every risk it touches move with it, on the same screen.

03

Indicator

A value scores the moment somebody enters it, against the thresholds that applied to that unit at that moment. A breach is visible the day it happens.

04

Threshold breach

Crossing red raises a formal record with its own lifecycle and its own response, written by somebody who did not produce the number.

05

Remediate

Actions arrive from breaches, risk events, control failures and quality findings, each linked back to its cause. Closing one takes two people.

06

Report

Committee packs assemble from live data into sections you choose, order and filter. PDF export, watermarked DRAFT until approved.


Some things the platform will not let you do

Most systems record who did what and leave the control to a policy nobody reads at the moment it matters. PureTrace refuses the action.

  • The person who submitted a breaching value cannot write the response to it, and neither can the author of the original submission.
  • The person who compiled a committee pack cannot approve any step of it, and no one person can clear two steps of the same pack.
  • The person who asks to close a remediation action cannot approve that closure. Closure always takes two.

Nobody grants themselves a role, deactivates their own account or resets their own second factor. Nobody, at any level, edits or deletes an audit entry. There is no administrator override, because no code path performs one.


One group. Several entities. One record.

Each entity has its own leadership, its own operating reality and often its own external scrutiny, and the centre still needs one consolidated view. PureTrace holds one record with the local position held against each entity. The risk is written once. Each entity it applies to carries its own residual and its own named owner, and anything not set locally inherits the group view.

One risk record resolved across four entities One risk, client data lost or disclosed without authorisation, is maintained once at group level with a residual of 9 and a group risk owner. Four entities sit beneath it. The platform business resolves to 16 and is outside appetite, the discretionary business to 12, the advice business to 9 because it inherits the group view, and the nominee company to 6. Each entity except the advice business has its own named owner. ONE RISK RECORD Client data lost or disclosed Group view 9, group risk owner resolves per entity Platform 16 Set locally Outside appetite Discretionary 12 Set locally Advice 9 Inherits group Nominee 6 Set locally
One risk, maintained once, resolving to four different positions. A risk that does not apply to an entity has no line for it at all, so it drops out of that entity's register rather than sitting there scored as not applicable. Nobody maintains four risks.

Every change, on a record you cannot edit

Every change writes an entry: who made it, what it was before, what it became, when, the role they held at that moment and the line of defence they acted in. Names and roles are captured at the time, so the trail still reads correctly after somebody changes role or leaves.

Nothing edits it and nothing deletes it. Not a user, not an administrator, not us. Entries are chained together, so an entry altered after the fact no longer fits and a check reports where. That is the difference between a log you keep and evidence you can hand over.

How the record is protected


Built by people who have had to answer for it

PureTrace is built by risk and compliance professionals who have spent their careers inside heavily regulated businesses, at every level from running the process to answering for it in front of a board. Between us we have held executive and board positions, including chief executive, chief operating officer and chief risk officer.

We have chased the indicator returns, rebuilt the committee pack the weekend before the meeting and taken the challenge when the group number did not stand up. That is why this works the way a risk function works, rather than the way a database prefers to store things.

More about 10th Bridge