Organizational Risk

Your own risk and your vendors' risk, in the same number

A risk register under ISO 31000, consolidated financial exposure for the board, and a composite score that weighs your self-assessment against the aggregate risk of your vendor portfolio, across all 11 risk categories.

Get started

Two risks that never add up

Vendor risk lives in one tool and your own risk in a spreadsheet. The committee gets two numbers that do not talk to each other and decides on the larger one.

A colour matrix does not carry a decision

Red, amber and green say a problem exists, not what it costs. With no figure attached, prioritizing becomes a contest of opinions.

Risk accepted with no owner and no deadline

Someone accepted the risk at some point, verbally. When the incident arrives there is no record of who, when, or for how long.

A risk register under ISO 31000

Organizational context, interested parties, areas, business processes and products. Every risk with an inherent and a residual assessment, an owner, and the controls tied to it.

A composite score across 11 risk categories

Your organization's self-assessment and the aggregate vendor risk land on the same axis, with each side's weight configurable — and the radar shows where the two disagree.

Financial exposure by domain

The organizational matrix consolidates exposure in currency by risk domain and names the critical one. It is the view a board can actually act on.

Action plan and acceptance letter

What is not treated becomes a plan with an owner and a date. What is accepted becomes a signed letter, with history and a review trigger.

See the risk of your whole organization

Register your organizational context and get the first composite by category.

Get started