Governance · Risk · Compliance Control
GRC Ctrl covers the minimum risk management requirements EU organisations face under NIS2 and DORA — guided identification, 5×5 analysis, treatment and acceptance, third-party oversight and an auditable trail — for teams from ten people to ten thousand.
Risk scale

Analysis
Likelihood × impact on a five-band scale from very low to very high, in the same colours everywhere — heatmap, register, score badges and exported reports. Inherent and residual views sit side by side so treatment effect is visible, not asserted.

Third-party risk
Criticality, subcontracting chains, hosting location, substitutability and exit strategy for every supplier — the structure DORA's register of information expects, ready before the regulator asks.

AI governance
Model type, lifecycle stage, autonomy, data provenance, trustworthiness characteristics and human oversight — assessed across GOVERN, MAP, MEASURE and MANAGE, with weak answers turned into registered risks.

Guided intake captures asset, threat and vulnerability.
Score likelihood and impact on the shared 5×5 scale.
Choose a treatment, assign owners and set due dates.
Map to NIS2, DORA and AI RMF, then export the report.

Appetite & tolerance
Set the organisation's appetite once. The dashboard flags every breach, ranks the ten highest residual risks and points at the mitigations that are late — so review meetings start from decisions rather than data gathering.
Describe a risk in plain language. The assistant determines the category and asks only the follow-up questions that category needs.
Asset, threat, vulnerability, existing controls, 5×5 analysis, treatment option and documented acceptance — the full chain.
Supplier criticality, subcontracting, hosting and exit strategy, structured for the DORA register of information.
A live view of which Article 21 measures and DORA requirements have evidence, and which are still uncovered.
Every organisation is its own tenant. Row-level policies mean no customer can read another customer's data.
Email and password out of the box, or SAML 2.0 single sign-on with Microsoft Entra ID and AD FS.
Who created, edited, completed or deleted what — append-only and scoped per organisation.
Overdue and due-soon treatment actions surfaced to owners and risk managers before review dates slip.
IT asset, supplier, policy exception, business and AI risk — each with its own fields and questionnaire.
Evidence
Every risk, supplier and completed assessment can be tagged against the requirement it evidences. The compliance view then shows what is covered and what is still open — per regime, at a glance.

Create your organisation, invite the team and document your first risk in minutes.