
Risk Management
Score, treat and evidence risk across nine connected pages — register, assessments, treatments, principal risks and board reporting.
Learn more
Risk, compliance, audit, third-party risk, continuity, AI governance and ESG —
in one system, with unlimited users.
29 standards active across 9 module groups
The organisation currently holds 39 active risks, with a heavy concentration at the top end of severity: 11 critical and 25 high risks account for 92% of the total register, and there are no low-rated risks providing balance. While all risk reviews are technically up to date, the underlying treatment and control data tell a more concerning story — treatment completion stands at just 5.4% and average control effectiveness is 3.2%. This is a risk register that is well-catalogued but poorly mitigated.
RISK-2026-0042 shows no risk reduction at all — inherent and residual scores are identical (16/16) — and it also appears in the coverage gap list with no linked treatment.
RISK-2026-0041 (Ransomware), rated critical, has no linked treatment. Given the severity classification and the threat landscape, this is one of the most exposed items on the register.
11 of 56 treatments (nearly 20%) are overdue, indicating the mitigation pipeline is stalling rather than progressing.
Alex Cooper owns four of the top ten residual risks (RISK-2026-0006, 0010, 0014, 0035) — a significant concentration of high-severity ownership in one individual.
Eight risks currently have no linked treatment, including two critical risks (RISK-2026-0041 Ransomware, RISK-2026-0014 Working Capital) and six high risks. This means roughly a fifth of the active register has no documented mitigation pathway at all.
Control effectiveness data reveals six named weak controls (<50% effectiveness), spanning AI/technical security, DLP and monitoring, working capital financing and vendor concentration — a spread across cyber, financial and strategic domains rather than one isolated area.
Risk reviews are fully current with zero overdue — the review discipline and governance cadence is being maintained, which is the foundation everything else can be built on.
Three treatments have been completed, and several critical risks (RISK-2026-0020, 0021, 0035) show substantial inherent-to-residual score reduction (20 → 6), indicating that where treatments have been applied, they are demonstrably effective.
No critical or high audit findings are currently open. Combined with the weak control and low-treatment-completion picture, however, this raises the question of whether audit coverage has been comprehensive enough to surface these issues.
Link treatments to the eight uncovered risks — starting with the two critical items, which represent the clearest single gap between the register as documented and the risk actually being managed.
Investigate the 3.2% control effectiveness figure before acting on it. A number this low across the whole estate usually indicates a measurement or evidence-capture problem rather than genuine near-total control failure; either interpretation warrants immediate clarification from the control owners.
Redistribute concentrated ownership. Four of the top ten residual risks sitting with one owner is a key-person dependency in its own right, and it slows the treatment pipeline that is already stalling.
Clear the overdue treatment backlog — 11 of 56 overdue is the leading indicator that mitigation is falling behind identification, and it will compound quarter on quarter if left.
Risks link to controls. Controls carry evidence. Incidents raise non-conformances. Change one thing and it updates everywhere it matters — because it is one platform, not seven integrations.

Score, treat and evidence risk across nine connected pages — register, assessments, treatments, principal risks and board reporting.
Learn more
1,109 mapped controls, guided audits, findings and non-conformances tracked to the clause. Evidence once, satisfy every framework that needs it.
Learn more
Continuous, evidence-based due diligence across 13 pages. No annual questionnaires — findings arrive graded, timestamped and audit-ready.
Learn more
AI portfolio, use cases, model registry, maturity scoring, the EU AI Act wizard and Article 27 fundamental-rights assessments.
Learn more
Scope 1, 2 and 3 carbon accounting, double materiality, seven disclosure frameworks and AI-written sustainability reports.
Learn more
ISO 22301 impact analysis with RTO, RPO and MTPD, recovery strategies, exercises, live activations and a critical-asset register.
Learn more
A per-company security intelligence service across fourteen surfaces — your estate matched to live CVE/KEV and campaigns, threat forecasts with detection rules written, and a tenant-fenced analyst.
Learn more
29 courses across 337 modules with certificates and verification codes, plus AI-generated ISO documentation from 723 templates.
Learn moreAsk for a statement of applicability, a DPIA or a quarterly board pack. It assembles from your live register — real scores, real control status, real findings — and streams to the screen as it writes.
723 templates · 29 frameworks
The organisation has determined the controls from Annex A necessary to address the risks identified in its risk assessment. Of the 93 Annex A controls, 87 are applicable and 6 are excluded with documented justification…
| Document | Framework | Status |
|---|---|---|
| Statement of Applicability | ISO 27001 | Streaming |
| DPIA — new CRM processor | UK GDPR | Approved |
| ICT Risk Assessment | DORA | In review |
| AI Impact Assessment | ISO 42001 | Approved |
Every framework, control library, template and course is pre-populated. There is no content-loading phase before you see value.
No per-module pricing, no per-framework upsell, no seat count to negotiate. Add your whole organisation and the invoice does not move.
Per company entity. All 29 standards, every core module, unlimited users and all future updates.
See what's includedTPRM & vCISO — continuous vendor intelligence plus your own estate watched, unlimited monitored third parties. Also available standalone.
Explore TPRM & vCISOThree days of professional onboarding with a qualified auditor, from discovery through to full handover.
Onboarding detailA live walkthrough of the actual platform — not a slide deck.