AI-Powered GRC Platform

Every framework. One platform. One price.

Risk, compliance, audit, third-party risk, continuity, AI governance and ESG —
in one system, with unlimited users.

+GR
GGRCxAI

GRC Overview

29 standards active across 9 module groups

AllISOReg
Total Risks
39
11 critical · 25 high
Overdue Items
12
11 treatments · 1 review
Assurance Score
78%
+5% this quarter
Frameworks
29
1,109 controls mapped
Third Parties
214
3 urgent findings
Executive BriefingUpcoming & ScheduleRisk OverviewRisk Trends
AI Executive Briefing 18d agoStaleRegenerate
Risk Posture Summary

The organisation currently holds 39 active risks, with a heavy concentration at the top end of severity: 11 critical and 25 high risks account for 92% of the total register, and there are no low-rated risks providing balance. While all risk reviews are technically up to date, the underlying treatment and control data tell a more concerning story — treatment completion stands at just 5.4% and average control effectiveness is 3.2%. This is a risk register that is well-catalogued but poorly mitigated.

Key Concerns

RISK-2026-0042 shows no risk reduction at all — inherent and residual scores are identical (16/16) — and it also appears in the coverage gap list with no linked treatment.

RISK-2026-0041 (Ransomware), rated critical, has no linked treatment. Given the severity classification and the threat landscape, this is one of the most exposed items on the register.

11 of 56 treatments (nearly 20%) are overdue, indicating the mitigation pipeline is stalling rather than progressing.

Alex Cooper owns four of the top ten residual risks (RISK-2026-0006, 0010, 0014, 0035) — a significant concentration of high-severity ownership in one individual.

Coverage Gaps

Eight risks currently have no linked treatment, including two critical risks (RISK-2026-0041 Ransomware, RISK-2026-0014 Working Capital) and six high risks. This means roughly a fifth of the active register has no documented mitigation pathway at all.

Control effectiveness data reveals six named weak controls (<50% effectiveness), spanning AI/technical security, DLP and monitoring, working capital financing and vendor concentration — a spread across cyber, financial and strategic domains rather than one isolated area.

Positive Developments

Risk reviews are fully current with zero overdue — the review discipline and governance cadence is being maintained, which is the foundation everything else can be built on.

Three treatments have been completed, and several critical risks (RISK-2026-0020, 0021, 0035) show substantial inherent-to-residual score reduction (20 → 6), indicating that where treatments have been applied, they are demonstrably effective.

No critical or high audit findings are currently open. Combined with the weak control and low-treatment-completion picture, however, this raises the question of whether audit coverage has been comprehensive enough to surface these issues.

Recommended Actions

Link treatments to the eight uncovered risks — starting with the two critical items, which represent the clearest single gap between the register as documented and the risk actually being managed.

Investigate the 3.2% control effectiveness figure before acting on it. A number this low across the whole estate usually indicates a measurement or evidence-capture problem rather than genuine near-total control failure; either interpretation warrants immediate clarification from the control owners.

Redistribute concentrated ownership. Four of the top ten residual risks sitting with one owner is a key-person dependency in its own right, and it slows the treatment pipeline that is already stalling.

Clear the overdue treatment backlog — 11 of 56 overdue is the leading indicator that mitigation is falling behind identification, and it will compound quarter on quarter if left.

Risk Heat Map39 plotted
621 4213 21 1
Impact ↑Likelihood →
Attention Required12
TREAT-012Inflation-Responsive Pricing Model31 Jul
TREAT-013Cost Base Reduction & Sourcing30 Jun
TREAT-014Working Capital Framework30 Jun
TREAT-015Receivables Collection31 Jul
TREAT-003AI Ethics Review Board Protocol31 Jul
Recent Activity
ISO 27001 A.8.1 — evidence expired1h ago
DORA ICT assessment — due in 14 days3h ago
AI: Board report (Q3 2026) generated6h ago
TREAT-021 closed by A. Okafor1d ago
The platform

Nine modules. One system of record.

Risks link to controls. Controls carry evidence. Incidents raise non-conformances. Change one thing and it updates everywhere it matters — because it is one platform, not seven integrations.

Risk register with a 5×5 heat map

Risk Management

Score, treat and evidence risk across nine connected pages — register, assessments, treatments, principal risks and board reporting.

Learn more
Control library with evidence status

Compliance & Audit

1,109 mapped controls, guided audits, findings and non-conformances tracked to the clause. Evidence once, satisfy every framework that needs it.

Learn more
Vendor dossier with risk, confidence and coverage scores

Third-Party Risk

Continuous, evidence-based due diligence across 13 pages. No annual questionnaires — findings arrive graded, timestamped and audit-ready.

Learn more
AI portfolio and model registry

AI Governance

AI portfolio, use cases, model registry, maturity scoring, the EU AI Act wizard and Article 27 fundamental-rights assessments.

Learn more
ESG dashboard with pillar scores and emissions

ESG & Sustainability

Scope 1, 2 and 3 carbon accounting, double materiality, seven disclosure frameworks and AI-written sustainability reports.

Learn more
Business continuity plans and recovery objectives

Business Continuity

ISO 22301 impact analysis with RTO, RPO and MTPD, recovery strategies, exercises, live activations and a critical-asset register.

Learn more
vCISO dashboard and threat radar

vCISO & Threat Radar

A per-company security intelligence service across fourteen surfaces — your estate matched to live CVE/KEV and campaigns, threat forecasts with detection rules written, and a tenant-fenced analyst.

Learn more
ISO training courses and certificates

ISO & Training

29 courses across 337 modules with certificates and verification codes, plus AI-generated ISO documentation from 723 templates.

Learn more

See every module and capability

Built-in AI

Board reports in minutes, not consultant-weeks.

Ask for a statement of applicability, a DPIA or a quarterly board pack. It assembles from your live register — real scores, real control status, real findings — and streams to the screen as it writes.

  • Grounded in your data. Documents cite your own records, so review is verification rather than rewriting.
  • 723 templates across 29 standards, with branded DOCX export and full version history.
  • An always-on compliance assistant that answers clause-level questions and cross-references frameworks.
  • A person always approves. Nothing is filed or signed off automatically.
Explore AI documents
+GR
GGRCxAI

AI ISO Documents

723 templates · 29 frameworks

GeneratingLibrary
Templates
723
across 29 frameworks
Generated
2,340
this organisation
Awaiting review
6
human approval
Statement of Applicability — ISO 27001Streaming

The organisation has determined the controls from Annex A necessary to address the risks identified in its risk assessment. Of the 93 Annex A controls, 87 are applicable and 6 are excluded with documented justification…

Recent generations
DocumentFrameworkStatus
Statement of ApplicabilityISO 27001Streaming
DPIA — new CRM processorUK GDPRApproved
ICT Risk AssessmentDORAIn review
AI Impact AssessmentISO 42001Approved

What ships on day one

Every framework, control library, template and course is pre-populated. There is no content-loading phase before you see value.

29
Standards & frameworks
1,109
Mapped controls
723
Document templates
337
Training modules
Pricing

One price. Unlimited users.

No per-module pricing, no per-framework upsell, no seat count to negotiate. Add your whole organisation and the invoice does not move.

Complete platform

£2,000/month

Per company entity. All 29 standards, every core module, unlimited users and all future updates.

See what's included
Premium add-on

+£2,000/month

TPRM & vCISO — continuous vendor intelligence plus your own estate watched, unlimited monitored third parties. Also available standalone.

Explore TPRM & vCISO
Optional

£3,000 one-off

Three days of professional onboarding with a qualified auditor, from discovery through to full handover.

Onboarding detail

See it on your own requirements.

A live walkthrough of the actual platform — not a slide deck.