Risk management software for UK organisations

A risk register that stands up to scrutiny: ISO 31000 and ISO 27005 aligned scoring, treatment plans with owners and dates, supplier and AI risk in the same place, and a direct link from every risk to the ISO 27001 controls and evidence that mitigate it.

What you get

Structured register

5×5 inherent and residual scoring with defined criteria, documented appetite, owners, treatment plans and review cadence.

Risk to control traceability

Every risk links to Annex A controls, policies and evidence, so the treatment plan and the audit evidence are the same record.

Board and committee reporting

Heat maps, movement since last review, overdue treatments and key risk indicators ready for the board pack.

Supplier, AI and operational risk

One register covering third-party, AI (ISO 42001), quality and operational risk instead of four disconnected spreadsheets.

Related pages

See risk management software, risk assessment software, GRC software UK, GRC software comparison, and the guides on ISO 31000 and risk appetite statements. For hands-on support, see risk management consultancy.

Answers buyers, procurement and auditors want

What is risk management software?+

Risk management software gives you a structured register: identified risks with owners, inherent and residual scoring, treatment plans, review dates and reporting. Good systems link each risk to the controls that mitigate it and to the evidence that the control works, which is what an ISO 27001 or ISO 9001 auditor tests.

Which risk scoring method should a UK organisation use?+

Most UK organisations use a 5×5 likelihood-by-impact matrix with defined scoring criteria and a documented risk appetite, following ISO 31000 principles and, for information security, ISO 27005 guidance. Quantitative methods are worth adding once you have consistent data, not before.

Does it cover supplier and third-party risk?+

Yes — suppliers and third parties are assessed in the same register, linked to contracts, data flows and the controls you rely on them for, so third-party risk reporting comes out of the same review cycle rather than a separate exercise.

Can the board get reporting from it?+

Risk heat maps, movement since last review, overdue treatments and key risk indicators export for board and audit committee packs, with the underlying register available if anyone wants to drill in.

How does risk management software support ISO 27001 certification?+

Certification requires a documented risk assessment and treatment process, results retained as evidence, and a Statement of Applicability justified by those results. Because risks, controls and the SoA share one data model here, the assessment produces the certification evidence directly.

Is pricing available in pounds?+

Yes — published per-workspace pricing in sterling, with no mandatory sales call, which suits UK SME budgets and below-threshold public sector procurement.

Build your risk register today

Start with a methodology and scoring matrix that already match ISO expectations, then register your first risks and link them to controls within the hour.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.