Platform
One chain, and what each link carries
The governance core is a single continuous chain. A risk carries its controls. Those controls carry the indicators that test them. An indicator that crosses red raises a threshold breach. The breach carries its response and its remediation. The pack that goes to committee assembles from all of it.
None of it depends on sector. A risk, a control, an indicator and a committee paper behave the same way whether the scrutiny comes from a regulator, an accreditor, an insurer or a customer's assurance team.
The register
Two levels: categories and the risks beneath them. Every risk carries an inherent and a residual position across likelihood and impact, and the platform works out the score rather than asking somebody to type it. Eight impact dimensions are available and all are optional, so a framework that scores on three does not carry five empty columns.
Each risk records a named owner, an appetite position with its reasoning and a cause and consequence structure through bow-tie analysis. Causes draw on a shared library you control, so a cause becomes countable across the register instead of being typed five different ways. Risk events record incidents and near misses against the risk they belong to.
Controls
Controls sit in a library and link to the risks they mitigate, so you maintain one control that covers four risks once.
Design and operating effectiveness are assessed separately, and every assessment stays on the record. "The control works" therefore carries a date and an assessor, and last year's judgement is still there when somebody asks what changed. An assessment that finds a control ineffective can raise a remediation action.
Indicators
Indicators carry green, amber and red thresholds and three directions: higher is better, lower is better and within a range. Collection runs in cycles with a defined open and close, one line per indicator per unit, monthly, quarterly, half-yearly or annual. A value needed outside a cycle can be captured immediately.
A submission scores the moment somebody enters it. Nobody waits for a workbook to be consolidated to find out that a number went red. Thresholds, targets and owners can differ from one unit to the next, and a submission is scored against that unit's own set.
Nothing overwrites a submission. A correction is a new version, and the earlier one stays on the record with the reason it changed. The number the board saw last quarter is still recoverable, alongside the one that replaced it.
Breaches and remediation
A value that crosses a red threshold raises a formal breach record automatically, with its own lifecycle and its own versioned response. Two people are frozen onto it: the author of the original submission and the author of the value that crossed red. Neither can write the response, which closes the loophole where a benign figure is submitted by one person and amended into a breach by another.
Actions arrive from four sources: indicator breaches, risk events, control failures and quality findings. Every one links back to what caused it, and one view shows every open remediation across the organisation.
Closing an action takes two people. The owner or a risk manager requests closure, and somebody in an oversight role who is not the requester decides. There is no one-click close and no one-click cancel. "Closed" means two people agreed it was.
Committee reporting
Packs assemble from live data rather than being written by hand. Eight sections, each one switchable, reorderable, filterable to a band, cappable to a top few and able to carry its own commentary. A configuration saves as a named, reusable template, and editing a template never changes a pack already produced.
Packs move through a recorded approval chain with segregation of duties enforced at every gate. Each step records who approved, when and in what role, and no one person takes a pack through two steps of it.
Export is PDF, watermarked DRAFT until approved. Every page carries the data-as-at and export instants. A group pack and a single unit's pack come from the same engine, and the unit's pack ranks, bands and counts on that unit's own figures.
The record, and the checks that run over it
Every change writes an entry: who, what changed, from what to what, when, the role held at that moment and the line of defence. Names and roles are captured at the time, so the trail still reads correctly after somebody moves role or leaves. Nothing edits it and nothing deletes it.
A fixed set of rules checks the register overnight, and a change to a risk, a control or a breach recomputes the affected findings straight away. Risks with no controls. Controls assessed ineffective. Open and repeat breaches. Residual positions outside appetite. Reviews that have gone stale. Actions past their date.
Each finding names its rule and the evidence that raised it. You decide which rules apply and how serious each is. Setting a finding aside needs a written note, and it comes back if the evidence does not go away. No model makes a judgement about a risk anywhere in this platform.
A finding you cannot explain is a finding you cannot defend.
Entities, sites or business units
One record, with the local variance held against each unit. The risk exists once. Each unit it applies to gets its own line, carrying its own residual position and owner. For indicators it carries its own thresholds and target. Anything not set locally inherits the group value.
A risk that does not apply to a unit has no line for it at all, so it drops out of that unit's register and its committee pack rather than sitting there scored as not applicable. Where a rule tests appetite, it tests every unit's effective figure and names the units that breach.
Who sees what
Five roles are assignable: risk manager, indicator owner, compliance officer, read-only auditor and the board and executive view. Each has a genuinely different surface, not the same screen with buttons removed. A role applies to one unit or across all of them, so an indicator owner responsible for one site sees that site and nothing else.
Nobody grants themselves a role, deactivates their own account or resets their own second factor. Asking for something you are not entitled to gets a refusal, not a hint that it exists.
Our own staff sign in separately, configure your environment and handle the support tickets you raise. They cannot read your risk register, controls, indicators or committee packs.
How it is packaged
You license the governance core, which is complete on its own: the risk register, controls, indicators and collection cycles, risk events, threshold breaches, remediation, committee packs, the dashboard and the audit trail.
Optional modules switch on per organisation, so you carry the ones you use and none of the ones you do not. Ask us which are available and where the rest sit before you plan around them.
Pricing depends on how many people use it and how you are structured, so we quote against your shape rather than a table.