GRC Ctrl
Sign in

Governance · Risk · Compliance Control

IT risk assessments made easy, while still complying with EU DORA and NIS2 requirements

GRC Ctrl covers the minimum risk management requirements EU organisations face under NIS2 and DORA — guided identification, 5×5 analysis, treatment and acceptance, third-party oversight and an auditable trail — for teams from ten people to ten thousand.

Risk scale

Very lowLowModerateHighVery high
Illustration of a risk matrix resolving into a governance and compliance dashboard
ISO/IEC 27005NIS2 Article 21DORANIST AI RMFSAML 2.0 SSO

Analysis

A 5×5 matrix your board can read

Likelihood × impact on a five-band scale from very low to very high, in the same colours everywhere — heatmap, register, score badges and exported reports. Inherent and residual views sit side by side so treatment effect is visible, not asserted.

Illustration of a five-by-five risk heatmap with plotted risks trending from high to low

Third-party risk

ICT suppliers, mapped and monitored

Criticality, subcontracting chains, hosting location, substitutability and exit strategy for every supplier — the structure DORA's register of information expects, ready before the regulator asks.

Illustration of an ICT supplier dependency network with criticality rings

AI governance

AI risk aligned to the NIST AI RMF

Model type, lifecycle stage, autonomy, data provenance, trustworthiness characteristics and human oversight — assessed across GOVERN, MAP, MEASURE and MANAGE, with weak answers turned into registered risks.

Illustration of the four NIST AI Risk Management Framework functions in a loop

From a hunch to documented evidence, in four steps

01

Identify

Guided intake captures asset, threat and vulnerability.

02

Analyse

Score likelihood and impact on the shared 5×5 scale.

03

Treat

Choose a treatment, assign owners and set due dates.

04

Evidence

Map to NIS2, DORA and AI RMF, then export the report.

Illustration of a risk appetite gauge with a tolerance threshold crossed by rising exposure

Appetite & tolerance

Know the moment exposure passes what you accept

Set the organisation's appetite once. The dashboard flags every breach, ranks the ten highest residual risks and points at the mitigations that are late — so review meetings start from decisions rather than data gathering.

AI-guided risk intake

Describe a risk in plain language. The assistant determines the category and asks only the follow-up questions that category needs.

ISO 27005 method

Asset, threat, vulnerability, existing controls, 5×5 analysis, treatment option and documented acceptance — the full chain.

ICT third-party register

Supplier criticality, subcontracting, hosting and exit strategy, structured for the DORA register of information.

NIS2 & DORA coverage

A live view of which Article 21 measures and DORA requirements have evidence, and which are still uncovered.

Per-customer isolation

Every organisation is its own tenant. Row-level policies mean no customer can read another customer's data.

Local login or SSO

Email and password out of the box, or SAML 2.0 single sign-on with Microsoft Entra ID and AD FS.

Auditable trail

Who created, edited, completed or deleted what — append-only and scoped per organisation.

Mitigation reminders

Overdue and due-soon treatment actions surfaced to owners and risk managers before review dates slip.

Five risk categories

IT asset, supplier, policy exception, business and AI risk — each with its own fields and questionnaire.

Evidence

Coverage you can show an auditor

Every risk, supplier and completed assessment can be tagged against the requirement it evidences. The compliance view then shows what is covered and what is still open — per regime, at a glance.

  • NIS2 Article 21 measures
  • DORA ICT risk requirements
  • ISO/IEC 27005 process
  • NIST AI RMF functions
Illustration of layered compliance shields representing NIS2, DORA and ISO coverage

Start your risk register today

Create your organisation, invite the team and document your first risk in minutes.

Get started