GRC SaaS

Platform capability

Risk Management

Maintain a risk register with inherent and residual scoring, treatments, and appetite thresholds, tied directly to the requests and controls they affect.

The business problem

  • Risk registers live in spreadsheets, disconnected from day-to-day approvals.
  • There is no automatic link between a flagged risk and the requests it should affect.

Key capabilities

  • Configurable risk categories, likelihood/impact scoring, and appetite bands
  • Risk-aware routing — requests above a risk threshold escalate automatically
  • Risk heat-map and trend projections

Example workflow

  1. 1A trade breaches a configured exposure limit.
  2. 2The system flags the risk and routes the request to Investment Committee-level approval.

Who uses this

Risk/Control OwnerLevel 2/3 ApproverExecutive/Board Viewer

Security and audit considerations

Every action within this capability writes to the platform's append-only audit log — actor, action type, timestamp, and before/after state — independent of the business record. See Security & Trust for the full model.

See Risk Management in a live walkthrough.