PLATFORM
Nine modules over one register.
Each module is described below by what you control, not by what the system contains. They share one record: a failed control test changes a residual score, raises an issue and writes to the audit trail in a single action.
RISK
Risk register
You keep one register, and it is always the current one.
Every risk carries an owner, an inherent score, the controls that reduce it, a residual score, and a treatment plan with a date. When someone changes a rating, the register records who changed it and why. There is no second version circulating by email.
- Score likelihood and impact on a scale you configure, and see the inherent and residual position of every risk
- Set risk appetite thresholds and get told when a residual score sits outside them
- Give every risk a named owner, not a department
- Attach treatment plans with owners, due dates and progress, and see what is overdue
- Version the register, so the position you reported to the committee in March is still retrievable in November
- Group risks by category, business unit, strategic objective or whatever taxonomy your board already uses
CTRL
Control library
You can show which control reduces which risk, and whether it worked.
Controls are mapped to the risks they mitigate, tested on a schedule, and evidenced. The gap between a control that exists on paper and a control that operated is the gap most registers cannot close. This one can.
- Map each control to the risks it mitigates, so a change to one is visible against the other
- Test design effectiveness and operating effectiveness separately, and record both results
- Attach the evidence to the test, not to an email thread
- Ask control owners to attest on a cycle, and see who has not responded
- Raise an issue straight from a failed test, so nothing falls out of the loop
- Report control coverage by risk, so you can see which risks are carried by nothing but a policy
-
01
Control
Mapped to the risks it mitigates, so a change to one is visible against the other.
-
02
Test
Design effectiveness and operating effectiveness tested separately, both results recorded.
-
03
Evidence
Attached to the test itself, not to an email thread near it.
-
04
Result
Pass or fail, with the tester and the date. A residual score moves on the register.
-
05
Issue
Raised straight from a failed test, with an owner and a due date, tracked to closure.
-
06
Pack
The committee reads the result and the movement, generated from the same record.
Every transition above writes to the audit trail with the user, the timestamp and the previous value. That is the difference between a control you believe in and a control you can evidence.
OBLG
Compliance obligations
You hold one list of what you owe your regulator, and who owes it.
Every statutory and licence obligation you carry, with the person accountable for it, the control that satisfies it, the evidence behind it, and the date it is next due. Returns and renewals stop being remembered and start being scheduled.
- Build an obligations register from your licences, statutes and supervisory guidance
- Assign each obligation to a named owner and map it to the control that satisfies it
- Track filing and renewal dates on a calendar, with reminders before they bite
- Attach the evidence of compliance to the obligation itself
- Record a breach or late filing against the obligation, so the pattern is visible
- Report obligation status by regulator, so a supervisory visit starts from a list rather than a search
POLY
Policy management
You know which policy is current, when it was approved, and who has read it.
Policies move through drafting, review, approval and publication on a cycle you set. Staff attest that they have read what applies to them. When an auditor asks who signed off the current credit policy and when, the answer takes a moment.
- Run a policy through drafting, review and approval with the sign-offs recorded
- Set a review cycle per policy and get told before it lapses
- Publish the approved version, and keep every superseded version retrievable
- Run attestation campaigns against a staff group and chase the people who have not responded
- Link a policy to the risks and controls it governs
- Export an attestation report for a specific policy and period
INCD
Incidents and loss events
You capture what went wrong while people still remember it.
Incidents, losses and near-misses are logged against the risk they belong to, categorised, investigated for root cause, and closed with a corrective action. Over a year, that log tells you which risks are real and which are theoretical.
- Log an incident in a short form anyone in the organisation can complete
- Categorise by event type and business line, and record gross loss, recovery and net loss
- Link the incident to the risk and the control that should have caught it
- Record root cause and assign corrective actions with owners and dates
- Track near-misses separately, so the count is not lost in the loss data
- Report loss trends by category and business line for the committee pack
ISSU
Issues and actions
You track every finding to closure in one place, whoever raised it.
Internal audit findings, external audit management letters, regulator inspection findings and your own self-assessments all land in the same register, with the same owners, dates and evidence of closure. No more three separate trackers that disagree.
- Raise issues from internal audit, external audit, regulator inspection, control testing or self-assessment
- Rate each issue, assign an owner and agree a due date
- Break an issue into actions, each with its own owner and date
- Require evidence before an issue can be marked closed
- See what is overdue, by owner and by source, before the committee does
- Report the open-issue position by source and age for the audit committee
ASSR
Assurance reporting
You build the committee pack from the register, not from memory.
Heat maps, movement since the last meeting, overdue treatments, open issues by source, loss trends — generated from the live register and exported in a form the board can read. The pack takes an afternoon instead of a fortnight.
- Generate the heat map at inherent or residual, filtered to the committee's scope
- Show what moved since the last meeting, and why
- Report overdue treatments, open issues and control test failures in one pack
- Export to Word, Excel or PDF for the board pack, or send the register straight into an eBoard meeting
- Save a reporting view per committee, so the same cut is produced the same way each quarter
- Trend a risk, a category or a loss type over any period you have data for
TRAIL
Audit trail
You can prove what the register said on any date, and who changed it.
Every create, edit, approval, score change and closure is recorded with the user, the timestamp and the previous value. The record cannot be edited or deleted from the application. This is the part a spreadsheet cannot do at all, and it is usually the reason the spreadsheet has to go.
- See the full change history of any risk, control, obligation, policy or issue
- Read the previous and new value on every change, with the user and timestamp
- Reconstruct the register as at a given date for a regulator or an auditor
- Export a trail for a named record, period or user
- Record approvals and attestations as events in the same trail
- Restrict who can see what through role-based access, and log that too
AI
AI assistance
You get a first draft, and you keep the decision.
AI reads the documents you already have and proposes register entries, control gaps and affected obligations. Nothing it proposes enters the register until a person accepts it, and the acceptance is recorded in the audit trail like any other change.
- Draft register entries from a policy, procedure or audit report you upload
- Flag risks in the register that are carried by no control, or by only an untested one
- Surface the obligations and controls a regulatory change is likely to affect
- Suggest a treatment plan from how similar risks in your own register were treated
- Summarise movement since the last committee meeting into draft narrative
- Keep every suggestion reviewable — a person accepts or rejects it, and the trail records which
SETUP
How it gets stood up.
This is the one genuinely sequential thing on this site, so it is the only thing numbered. Duration depends on how many registers you are consolidating and how much of your obligations list already exists in writing.
-
Discovery
We read what you already have — the current register, the last two committee packs, your obligations list if one exists, and the most recent audit findings. The point is to configure around how you already report, not to ask you to change it.
- Agreed scoring scales, matrix dimensions and appetite thresholds
- The list of registers being consolidated
- A configuration document you sign off before anything is built
-
Configuration
Your taxonomy, scales, roles and reporting views are set up in your environment. Entra ID sign-on is connected and access is mapped to the groups you already maintain.
- Your environment, configured and connected to Entra ID
- Role mapping for risk owners, control owners, audit and committee members
- Committee reporting views matching your existing pack
-
Migration
Your existing register, controls, obligations and open audit findings are loaded. Everything that comes across keeps its history where you have it, and anything ambiguous is queried rather than guessed.
- Register, controls and obligations loaded and reconciled against the source
- Open issues from internal and external audit loaded with their original dates
- A reconciliation you can check line by line
-
Training
Separate sessions for administrators, risk and control owners, and committee members — because they need different things and a single combined session serves none of them well.
- Administrator training and a written runbook
- Owner training, delivered close to the first live update cycle
- A short read-only walkthrough for committee members
-
First reporting cycle
We stay close through the first quarter's update and committee pack. This is where a GRC implementation succeeds or quietly reverts to the spreadsheet, and it is the phase most vendors leave you to do alone.
- First committee pack produced from the system
- Adjustments made from what the cycle actually revealed
- Handover to normal support
ASKED
Questions about how it works.
Can we keep our own scoring scale and matrix?
Yes. Scales, matrix dimensions, appetite thresholds and taxonomy are configured to what your board has already approved. Changing your risk methodology to suit a piece of software is the wrong way round, and it makes the first committee meeting harder than it needs to be.
What does the AI actually do, and what does it decide?
It drafts. It can propose register entries from a policy or audit report you upload, flag risks carried by no control or only an untested one, and surface obligations a regulatory change is likely to affect. Nothing it proposes enters the register until a person accepts it, and that acceptance is recorded in the audit trail like any other change.
How does it connect to eBoard?
The reporting views you approve in eGRC — the heat map, the movement summary, overdue treatments and open issues — export into the board pack in eBoard rather than being retyped into it. eBoard is a separate product in the same suite and can be bought independently.
Bring the register you have.
The fastest way to judge this is to see your own risks in it. We can load a slice of your existing register into a demo environment and show you the same view your committee would see.