ISO 31000-aligned risk management software

Risk management software without the GRC tax.

A live risk register, assessment workflow and treatment tracker built for UK SMEs, consultants and multi-tenant teams. Replace fragile spreadsheets with audit-ready risk management software that actually gets used.

ISO 31000
aligned methodology built in
5×5
likelihood × impact scoring
Multi-tenant
workspaces for consultants
Audit-ready
evidence and reports on demand

Risk management software should do more than store a list of risks. It should give you a repeatable assessment process, a treatment workflow with owners and deadlines, control mappings to the standards you are assessed against, and reports that leadership and auditors can read without a manual. ISO-STANDARD.app is a risk management platform designed for organisations that want ERM discipline without enterprise software complexity.

Whether you are looking for risk assessment software, an enterprise risk management system, or a risk and compliance software platform that covers ISO 27001, SOC 2 and ISO 42001, the same workspace handles the full risk lifecycle.

Features

Everything a modern risk management system needs

Live risk register

Every risk links to an asset, owner, controls and treatment plan. Changes are timestamped and attributable — no more wondering which spreadsheet is current.

Built-in risk assessment

5×5 likelihood × impact matrix, configurable appetite and tolerance, and residual risk tracking. The methodology is ISO 31000 aligned from the start.

Control library mapped to standards

Annex A, SOC 2 TSC, ISO 42001, PCI DSS, GDPR and Cyber Essentials controls ready to apply. One control can satisfy multiple frameworks.

Treatment workflow with evidence

Treat, transfer, tolerate or terminate — each with an owner, due date and attached evidence. This is what auditors test first.

Reports leadership will read

Heatmap, top risks, trend over time and treatment progress — generated from live data, not rebuilt by hand each quarter.

Multi-tenant by design

Consultants and groups can run isolated workspaces for each client or entity. Proper data separation, one login, one bill.

Use cases

Built for the teams who actually run risk

SMEs preparing for ISO 27001 or SOC 2

Pain: Risk registers live in spreadsheets that drift out of date before audit week.

With ISO-STANDARD.app: A single risk register with Annex A / SOC 2 control mappings and evidence links, ready for the auditor.

Consultants managing risk for clients

Pain: Juggling separate files for each client and rebuilding the same framework every engagement.

With ISO-STANDARD.app: Isolated workspaces per client, reusable templates and rollup reporting across the portfolio.

Teams adopting AI governance (ISO 42001)

Pain: AI risk assessments are new, and generic risk tools do not cover AI system lifecycle risks.

With ISO-STANDARD.app: ISO 42001 control mappings, AI impact assessments and model lifecycle risk tracking in the same workspace.

Comparison

Spreadsheets vs legacy GRC vs ISO-STANDARD.app

CapabilityISO-STANDARD.appSpreadsheetsLegacy GRC
Live risk register
ISO 31000 methodology Sometimes
Control mapping to ISO 27001 / SOC 2 / ISO 42001
Treatment workflow with owners & evidence
Audit-ready heatmaps and reports
Multi-tenant client workspaces Expensive
Setup measured in hours, not months
Predictable SME pricing
Implementation

From first risk to audit-ready in days

01

Import or create your register

Start from a template, import a CSV, or build your first risks in minutes.

02

Score with ISO 31000

Use the built-in 5×5 matrix and appetite settings to produce defensible scores.

03

Map controls and treatments

Link risks to controls, owners and treatment plans across ISO 27001, SOC 2, ISO 42001 and more.

04

Run reports and audits

Generate heatmaps, top-risk reports and evidence packs for leadership and auditors.

FAQ

Common questions about risk management software

What is risk management software?+

Risk management software is a digital platform that helps organisations identify, assess, treat and monitor risks in one place. It replaces scattered spreadsheets with a central risk register, scoring methodology, control mappings, treatment workflow and evidence trail.

Is this the same as enterprise risk management software?+

Yes. ISO-STANDARD.app supports enterprise risk management (ERM) at SME and consultancy scale. You can run one workspace or many isolated workspaces, roll up risk dashboards, and report to leadership and auditors from live data.

Do you support risk assessment software workflows?+

Yes. The platform includes a 5×5 likelihood × impact matrix, configurable risk appetite and tolerance, risk scoring, treatment planning and residual-risk tracking — the core capabilities expected from risk assessment software.

Can consultants use this as a risk management platform for clients?+

Yes. The consultant and partner plans support multi-tenant workspaces with proper isolation, so you can manage risk for multiple clients or group entities from one account without data leakage.

Which standards does the risk management system support?+

The risk register and controls library map to ISO 31000, ISO 27001 Annex A, ISO 42001, SOC 2 TSC, PCI DSS, GDPR and Cyber Essentials. One control can satisfy multiple frameworks, removing duplicate work.

How long does it take to implement?+

Most teams score their first risks within an hour and build a working register within a week. There is no multi-month implementation — the methodology is built in.

Start with a free risk management workspace

No credit card, no sales call, no multi-month implementation. Build your risk register, run your first assessment and see why teams call it the risk management software that finally gets used.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.

© 2026 ISO-STANDARD.app · Intelligent compliance software. Practical governance support. Human-led accountability.