The Risk Register

Features

A risk register, business impact analysis, and key risk indicators, linked together instead of scattered across spreadsheets and one-off documents.

Log and score

Structured risk records

Log a risk with a category, an owner, a description of existing controls, and a likelihood/impact score, not a row in a spreadsheet nobody owns.

Residual scoring

Track both the inherent score and the residual score after controls, so you can see the actual effect of mitigation over time.

Mitigate and monitor

Mitigation actions

Attach actions to a risk with an owner, a status, and dates raised and closed. Every update to a risk is timestamped.

Key risk indicators

Set a KRI with a target value, a unit, and a measurement frequency, and keep a running history of readings against it, so early warning signs are visible before a risk materialises.

See the whole picture

Heat map

Every risk plotted on a 5x5 likelihood/impact grid, colour-coded by severity, with each cell linking straight through to the underlying risks.

Business impact analysis

Departments and business functions carry recovery targets (RTO/RPO), the systems, suppliers, sites and critical roles they depend on, and the risks linked to them, so a single view shows what's exposed and why.

Respond and learn

Incident logging

Record an incident with a severity, a timeline, and the actions taken, and link it back to the risks it relates to, so a materialised risk feeds straight into your record instead of living in a separate email thread.

Audit trail

Every create, update, and delete across risks, actions, and incidents is logged with who did it and when, giving you a full history to point to at audit time.

Run it safely

Security by default

EU hosting, encryption in transit and at rest, tenant isolation enforced at the data layer, and MFA-capable sign-in.

Built for teams

Your organisation is the account: members share one workspace, with access scoped to your organisation.