Platform
One chain, and what each link carries
The governance core is a single continuous chain. A risk carries its controls. Those controls carry the indicators that test them. An indicator that crosses red raises a threshold breach. The breach carries its response and its remediation. The pack that goes to committee assembles from all of it.
What follows is what each link holds and what it hands on. None of it depends on sector: a risk, a control, an indicator and a committee paper behave the same way whether the scrutiny comes from a regulator, an accreditor, an insurer or a customer's assurance team.
The register
Two levels: categories and the risks beneath them. Every risk carries an inherent and a residual position across likelihood and impact, and the platform works out the score rather than asking somebody to type it. Eight impact dimensions are available and all are optional, so a framework that scores on three does not carry five empty columns.
Each risk records a named owner, an appetite position with its reasoning and a cause and consequence structure through bow-tie analysis. Causes draw on a shared library you control, with rename, merge and archive, so a cause becomes countable across the register instead of being typed five different ways.
Risk events record incidents and near misses against the risk they belong to, with a materiality assessment and a reportable flag.
What flexes and what does not. Impact dimensions, appetite vocabulary, risk categories, ownership, per-unit variance and pack composition all adapt to your framework. The scoring grid is a five-by-five likelihood and impact matrix. If your methodology runs a different grid, tell us early and we will tell you straight whether it fits.
Controls
Controls sit in a library and link to the risks they mitigate, so you maintain one control that covers four risks once.
Design and operating effectiveness are assessed separately, and every assessment stays on the record. "The control works" therefore carries a date and an assessor, and last year's judgement is still on the record when somebody asks what changed.
An assessment that finds a control ineffective can raise a remediation action, which then appears alongside every other open action.
Indicators
Indicators carry green, amber and red thresholds and three directions: higher is better, lower is better and within a range. Collection runs in cycles with a defined open and close, one line per indicator per unit, monthly, quarterly, half-yearly or annual. A value needed outside a cycle can be captured immediately.
A submission scores the moment somebody enters it. Nobody waits for a workbook to be consolidated to find out that a number went red.
Thresholds, targets and owners can differ from one unit to the next, and a submission is scored against that unit's own set. Direction and reporting cycle stay the same everywhere, because a metric only has one of each.
Every submission stores the thresholds it was scored against, so an assessor can reconstruct a rating from the submission alone two years later.
Corrections without rewriting history
Nothing overwrites a submission. A correction is a new version, and the earlier one stays on the record with the reason it changed.
The number the board saw last quarter is still recoverable, alongside the one that replaced it.
Threshold breaches
A value that crosses a red threshold raises a formal breach record automatically. Amber is a watch state, and a breach can be raised there by hand where somebody judges it warranted.
A breach is a record in its own right, with its own lifecycle and versioned response, independent of the indicator stream that produced it. A new breaching value never quietly reopens or closes a previous one.
Two people are frozen onto the record: the author of the original submission and the author of the value that crossed red. Neither can write the response. That closes the loophole where a benign figure is submitted by one person and amended into a breach by another.
Remediation, and what "closed" means
Actions arrive from four sources: indicator breaches, risk events, control failures and quality findings. Every one links back to what caused it, so an open action always carries its reason.
One view shows every open remediation across the organisation, whatever raised it.
Closing an action takes two people. The owner or a risk manager requests closure, and somebody in an oversight role who is not the requester decides. There is no one-click close and no one-click cancel. "Closed" means two people agreed it was.
Committee reporting
Packs assemble from live data rather than being written by hand. Eight sections, each one switchable, reorderable, filterable to a band, cappable to a top few and able to carry its own commentary.
A configuration saves as a named, reusable template. Editing a template never changes a pack already produced, because generation copies the configuration onto the pack.
Packs move through a recorded approval chain with segregation of duties enforced at every gate. Each step records who approved, when and in what role, and no one person takes a pack through two steps of it.
Export is PDF, watermarked DRAFT until approved. Every page carries the data-as-at and export instants, and the cover carries who produced it. Generation runs in the background.
A group pack and a single unit's pack come from the same engine. The unit's pack ranks, bands and counts on that unit's own figures.
Quality checks on the register itself
Nine fixed rules check the register overnight, and a change to a risk, a control or a breach recomputes the affected findings straight away rather than waiting for the sweep.
Risks with no controls. Controls assessed ineffective. Open breaches. Repeat breaches. Red indicators. Residual positions outside appetite. Appetite positions with no rationale. Reviews that have gone stale. Actions past their date.
Each finding names its rule and the evidence that raised it. You decide which rules apply, how serious each is and how long one can be set aside. Setting a finding aside needs a written note, snoozes it rather than closing it and can raise a remediation action in the same step. It clears when the evidence goes away, not when somebody says so.
Where a rule tests appetite, it tests every unit's effective figure and names the units that breach, rather than reporting that one of them did.
No model makes a judgement about a risk. The rules are code, they are written down and they produce the same answer twice.
The record behind the record
Every change writes an entry: who, what changed, from what to what, when, the role held at that moment and the line of defence. Names and roles are captured at the time, so the trail still reads correctly after somebody moves role or leaves.
Nothing edits it and nothing deletes it. Where a record is removed for data protection reasons, the trail describing it survives.
Entities, sites or business units
One record, with the local variance held against each unit. The risk exists once. Each unit it applies to gets its own line, carrying its own residual position and owner. For indicators it carries its own thresholds and target. Anything not set locally inherits the group value.
A worked example. An investment platform group owns one risk for client data being lost or disclosed without authorisation. Every entity holds client data, so the risk sits on all of them. The entity holding most of the records carries a higher residual and its own named owner.
| Scope | Residual | Owner |
|---|---|---|
| Group view | 9 (likelihood 3, impact 3) | Group risk owner |
| Advice business | Inherits the group view | Inherits the group owner |
| Platform business | 16 (likelihood 4, impact 4), outside appetite | Its own named owner |
Who sees what
Five roles are assignable: risk manager, indicator owner, compliance officer, read-only auditor and the board and executive view. Each has a genuinely different surface, not the same screen with buttons removed.
A role applies to one unit or across all of them. An indicator owner responsible for one site sees that site and nothing else.
Nobody grants themselves a role, deactivates their own account or resets their own second factor. Asking for something you are not entitled to gets a refusal, not a hint that it exists.
Our own staff sign in separately, configure your environment and handle the support tickets you raise. They cannot read your risk register, controls, indicators or committee packs.
Getting your existing register across
Migration is a controlled process, not a data entry marathon. We work from your own workbooks, tell you what needs fixing before anything is loaded and prove the load on a run that writes nothing.
Every imported record lands with its audit entry, so the trail starts complete rather than at day two. We will walk you through the whole process before you commit to it.
How it is packaged
You license the governance core, which is complete on its own: the risk register, controls, indicators and collection cycles, risk events, threshold breaches, remediation, committee packs, the dashboard and the audit trail.
Optional modules switch on per organisation, so you carry the ones you use and none of the ones you do not.
Pricing depends on how many people use it and how you are structured, so we quote against your shape rather than a table.
On the roadmap
What comes next
These are named in the module catalogue and are not available today. We list them so you can see where the platform is going, and so you can tell us which of them matter to you.
- Supplier Due Diligence. Assessing and monitoring the third parties you depend on, with the same evidence trail as the rest of the register.
- Regulatory Monitoring and Traceability. Tracing external obligations through to the risks and controls that address them.
- Policy Management. Holding policies, their owners and their review dates against the risks they control.
- Trust Centre. A published view of your control posture that customers and their assurance teams can read for themselves.
The list is a direction of travel and not a commitment to a date. Ask us where something sits before you plan around it.
Where the depth came from
The deepest domain work behind PureTrace is in United Kingdom financial services, one of the most heavily evidenced regulatory environments there is. Building to that bar produced a platform any board, auditor or assurance team recognises.
You set the risk categories, the causes and consequences, the appetite wording and the impact dimensions you score on. The discipline travels.