Skip to main content
Enterprise risk management software

Identify, assess and monitor risk in one system

Risk anchored to business objectives — a register with screening and review, a heat map before and after controls, indicators against approved thresholds.

ISO 310005×5 matrixThree lines of defence
Illustration of the product interface
What to know before you choose

Is this module right for your organisation?

What is RiskTech risk management?

It is the module that manages risk across the enterprise following ISO 31000. Risks are always anchored to a unit's business objectives, screened and reviewed before entering the register, positioned on a 5×5 heat map before and after controls, then monitored with indicators against approved thresholds.

Who is it for?

The risk function operates the register and the monitoring indicators. Risk owners in business units update assessments and treatment actions. Leadership and the board track risk levels against the approved appetite.

What problems does it solve?

Three problems: the risk register is a spreadsheet updated once a year and therefore always out of date; there is no distinction between risk before and after controls; and without alert thresholds, problems only surface once a loss has occurred.

How is it different from a risk spreadsheet?

New risks must pass screening and review before they are recorded, so the register does not bloat with duplicates. Monitoring indicators have explicit thresholds and update schedules. Actual loss data feeds back into the assessed level.

How is it rolled out?

The module runs on its own and is often the starting point, because reporting reaches leadership from the earliest stage. Initial data covers business objectives per unit, the identified risk catalogue and the approved risk appetite.

The business problem

When data is scattered, material risk slips through

01

The register is updated once a year

The spreadsheet is drawn up in January and reviewed in December. By then the business context has shifted several times.

02

No distinction before and after controls

There is only one assessed level, so nobody can see how much the controls are actually reducing risk.

03

No alert thresholds

Indicators are tracked in isolation, with no threshold and no link to any specific risk.

04

Losses never feed back into assessments

An incident happens and still nobody adjusts the corresponding risk level in the register.

Photo of a leadership meeting on risk — landscape
Risk management
Risk anchored to objectives, monitored against approved thresholds.
End-to-end process

Manage risk from identification through to monitoring

Input
Business objectives, context, approved risk appetite
Activity
Identify · screen · assess · position on the heat map
Control and approval
Review before entry; approve the treatment plan
Output
Heat map, breached indicators, board reporting
Risk management lifecyclesix steps, following ISO 310006 steps
  1. 1Objectives and context
    Establish the context and business objectives the risk attaches to.
  2. 2Risk identification
    Record new risks, screen and review them before entry.
  3. 3Risk assessment
    Likelihood and impact, positioned on the 5×5 heat map.
  4. 4Response and treatment
    Treatment plan, progress, cost and completion deadline.
  5. 5Indicator monitoring
    Key risk indicators against thresholds, checked against appetite.
  6. 6Periodic review
    Update the register each period and against actual loss data.
Product screens

See risk management working in practice

Two representative screens illustrating the product interface. The figures shown are sample data.

5×5 heat map

Screen 1

Position risks by likelihood and impact, comparing before and after controls. Click a cell to open the risks inside it.

Key risk indicator monitoring

Screen 2

Each indicator is tied to a specific risk, with a threshold, an update schedule and an owner; three states: within threshold, warning, breached.

Feature groups

Every role sees exactly what they are responsible for

Objectives and context

Leadership, risk function
  • Business objectives per unit
  • Every risk tied to at least one objective
  • Internal and external context

Risk register

Risk function, risk owners
  • New risks pass screening and review before recording
  • Assessment before and after controls
  • Clear owner, unit and point of contact

5×5 heat map

All roles
  • Positioned by likelihood and impact
  • Compare risk levels before and after controls
  • Click a cell to open the matching risk list

Risk appetite

Leadership, board
  • Approved limits per risk category
  • Alerts for risks above their limit
  • Total risk level checked against appetite

Indicator monitoring

Risk function
  • Key risk indicators with thresholds and update schedules
  • Each indicator tied to a specific risk
  • Three states: within threshold, warning, breached

Treatment and loss data

Risk owners
  • Treatment plan, progress, cost, completion deadline
  • Actual loss events recorded
  • Losses feed back into the assessed level
Who it fits

Who is it for and what do you need to prepare?

Portrait photo of a risk management specialist
Who it fitsWhen to use itData to prepare
Organisations starting to build a risk frameworkWhen leadership asks for periodic risk reportingBusiness objectives per unit
Organisations with a risk register that lives in a spreadsheetWhen the number of risks outgrows manual trackingThe identified risk catalogue
Organisations that need a risk-based audit planWhen you want to link with the internal audit moduleThe approved risk appetite
Reference standards

Which standards is it built around?

RiskTech supports organisations operating to the standards below. This is not a certification claim for the software or for the organisations using it.

ISO 31000
Risk management — guidelines
5×5 matrix
Likelihood and impact
Three lines of defence
Responsibility model
Application scenario

Illustrative application scenario

This scenario explains how the product is used; it is not the result of a rollout at a specific client. Once we have a real client scenario with written consent to publish, this section will be updated.

Frequently asked questions

Risk management

See how RiskTech supports enterprise risk management

A 30-minute demo following the role you hold. No data preparation needed beforehand. We respond within one business day.

ceo-office@risktech.asia