Your own risk and your vendors' risk, in the same number
A risk register under ISO 31000, consolidated financial exposure for the board, and a composite score that weighs your self-assessment against the aggregate risk of your vendor portfolio, across all 11 risk categories.
Get startedTwo risks that never add up
Vendor risk lives in one tool and your own risk in a spreadsheet. The committee gets two numbers that do not talk to each other and decides on the larger one.
A colour matrix does not carry a decision
Red, amber and green say a problem exists, not what it costs. With no figure attached, prioritizing becomes a contest of opinions.
Risk accepted with no owner and no deadline
Someone accepted the risk at some point, verbally. When the incident arrives there is no record of who, when, or for how long.
A risk register under ISO 31000
Organizational context, interested parties, areas, business processes and products. Every risk with an inherent and a residual assessment, an owner, and the controls tied to it.
A composite score across 11 risk categories
Your organization's self-assessment and the aggregate vendor risk land on the same axis, with each side's weight configurable — and the radar shows where the two disagree.
Financial exposure by domain
The organizational matrix consolidates exposure in currency by risk domain and names the critical one. It is the view a board can actually act on.
Action plan and acceptance letter
What is not treated becomes a plan with an owner and a date. What is accepted becomes a signed letter, with history and a review trigger.
See the risk of your whole organization
Register your organizational context and get the first composite by category.
Get started