Service · Web development

Custom risk management software.

A GRC platform that fits your risk taxonomy, your controls and your reporting lines. We build risk management software when Diligent, MetricStream or ServiceNow GRC don't keep up with your reality, or when integration with your core systems solves the pain of off-the-shelf packages.

Risk registerHeatmapsKRI monitoringAudit trail

Standard GRC falls short on sector-specific risk.

Financial risk is not healthcare risk, construction risk or energy risk. The big packages (Diligent (Galvanize), MetricStream, ServiceNow GRC, Resolver, LogicGate, OneTrust, Origami Risk, BWise, Workiva, AuditBoard, NAVEX Global) deliver a generic risk taxonomy that your risk officers work around in Excel, email and scattered SharePoint folders. What started as a package implementation often ends up as custom work anyway.

We don't replace those packages for groups that have been running Diligent or ServiceNow for years. We do build the part of the software they don't deliver: sector-specific heatmaps, real-time KRI integrations with your ERP and case management, AI-driven anomaly detection, and consolidation flows across multiple entities. What is a workaround in standard GRC becomes the core in a custom build.

The organisations we build this for mostly work in heavily regulated sectors. Financial institutions under DNB supervision (banks, insurers, pension funds) have obligations around integrated risk management, ORSA and, more recently, DORA. Energy and utility companies operate under NIS2 and the BIO for critical infrastructure. Healthcare providers report under NEN 7510 and the quality and safety framework. Construction and industry have their own mix of project risk, health and safety, and quality control. Government bodies work under the Wpg, the BIO and audit regimes. Multinationals add ESG, supply chain and geopolitical risks. No single taxonomy fits that diversity, and that is exactly where custom software proves its value.

Three flavours of risk management software.

It depends on what the platform needs to do, how deeply it is embedded in your operations, and which compliance regimes apply. We'll advise which variant fits in the first conversation.

Compact project · fixed sprint budget

Risk register with heatmap

The core for organisations that still do GRC in Excel: a structured risk register with taxonomy, ownership and status, plus an interactive risk heatmap that works on your own impact and likelihood scale. Including controls and a periodic review flow.

Risk registerHeatmapControlsReview cycle
Mid-sized project · fixed sprint budget

Integrated risk + compliance

Integrated risk management where operational risk, compliance mapping and internal control come together in one platform. A single control can map to multiple regulations (NIS2, DORA, ESG/CSRD, GDPR, NEN 7510). With workflow for assessment, escalation and sign-off by the second or third line.

Compliance mappingInternal controlWorkflowAudit trail
Larger project · fixed sprint budget

Multi-entity GRC with AI detection

For groups with multiple entities, divisions or regions: consolidation of risk data up to group level, real-time integrations with ERP, ITSM and incident sources, and AI/ML models for anomaly detection like the ones you know from Zenya AI. With multi-tenant role management and a SOX/SOC2-grade audit trail.

Multi-entityAI anomaly detectionReal-time dataSOX/SOC2

Where custom ends and standard begins.

We're honest about where the line is. If your organisation has a mature GRC function that already runs on Diligent, MetricStream or ServiceNow GRC, a full replacement is rarely the right choice. The package holds years of policy content, mappings, reporting templates and management information that your board relies on. What we do build is a complementary layer: a specific module, an integration layer, or a dashboard the package doesn't offer.

If your organisation doesn't yet have a central GRC platform and currently handles risk and compliance through Excel, SharePoint or a mix of separate tools, custom is often more economical than an enterprise package. You don't pay for functionality you never use, you aren't tied to a vendor's roadmap, and you get a platform that fits your reporting lines exactly. For mid-sized organisations, this is often the tipping point.

That line has been shifting in recent years because of AI. Packages such as Zenya AI, ServiceNow Now Assist and RSA Archer are integrating more and more machine learning, but their models work on a generic dataset. For anomaly detection on your own incident data, your own reporting flows and your own KRIs, trained on patterns that you recognise, a model of your own is almost always more accurate. That is a substantial argument for building your own AI layer alongside your existing GRC package, instead of waiting for a vendor feature.

What a risk management platform does.

The modules we build in almost every project, tailored to your taxonomy, your roles and your regulations.

  • Risk registerCentral recording of risks using your own taxonomy, owner, scope entity and status. Version history per risk, with an audit trail.
  • Risk assessment and heatmapImpact × likelihood with inherent and residual risk. An interactive heatmap you can drill down by division, process or risk category.
  • ControlsPer control: owner, frequency, effectiveness and evidence. Linked to one or more risks and one or more regulations.
  • Incident and report managementWorkflow for incidents, near-misses and reports, with root-cause analysis and automatic linking to the relevant risk.
  • Key Risk Indicators (KRIs)Threshold values per indicator, with real-time data from your ERP, ticketing or HR system and automatic escalation when a threshold is exceeded.
  • Compliance mappingOne control maps to multiple regulations at once. No duplicate administration for NIS2, DORA, ESG, GDPR and sector-specific frameworks.
  • Workflow and sign-offAssess, escalate, accept or mitigate, with digital sign-off by the risk owner, control owner and the second or third line.
  • Multi-entity consolidationAggregation of risk data from operating company to division to group. Including group-level dashboards and board reporting.
  • Audit trail (SOX/SOC2-grade)Immutable log of who changed what, with user, timestamp and before/after values. Exportable for external auditors.
  • Integrations with core systemsIntegrations with ERP (SAP, Oracle), ITSM (ServiceNow, TopDesk), HR, financial data warehouses and sector-specific sources.

When custom risk management is the right choice.

Five patterns in which standard GRC packages hit their limits. If you recognise one, we'd be happy to talk further.

Sector taxonomy

Your risks don't look like anyone else's

Financial institutions, healthcare providers, energy companies and construction firms work with very different risk taxonomies. A generic schema forces you to keep adding custom fields on top of a standard package.

Deep integrations

Real-time data from your core

Standard GRC tools work with periodic imports. When KRIs and incident data need to come live from your ERP, ticketing or SCADA systems, you run into connector limits and latency.

AI and anomaly detection

Pattern recognition on reports

Zenya AI shows what is possible: AI models that automatically detect patterns and anomalies in reports, incidents and KRI data. That kind of intelligence is rarely available out of the box in standard packages for your own domain.

Multi-entity

Group-level consolidation

A holding company with several operating companies needs consolidation across entities, as well as local autonomy for each entity. Striking that balance between group policy and local flexibility is costly in standard packages, in both licences and configuration.

NIS2 and DORA

Getting new regulations in place quickly

Your existing GRC package is often not yet set up for NIS2 (critical infrastructure) and DORA (financial sector). Custom development on top of or alongside your core platform can get these regimes live faster than a vendor roadmap.

Heatmap functionality

Visualisation your board understands

No two risk matrices are alike. Your board or audit committee wants to drill down into specific variables, dimensions and time windows that your current tool doesn't offer, and that is where the heatmap breaks down.

A different risk profile for each sector.

The shape of a GRC platform differs by industry. For financial institutions, the emphasis is on DNB reporting, ORSA, DORA and internal control frameworks such as COSO and ISO 31000. A register links to the three lines of defence, and the second and third lines must be able to sign off everything digitally. Integrations focus mainly on the core banking environment, the credit system and the financial data warehouses. For related topics around financial compliance, see our page on KYC and AML compliance software.

In healthcare, it all comes down to NEN 7510, the quality framework and patient safety. Risks come from incident reports, near-misses, MIM reports and internal audits. The integration is with the EHR and the quality system. Because of the nature of the work, with many reports, many categories and a lot of context, this is one of the sectors where AI anomaly detection delivers the most. Zenya AI leads the way here, but custom development on your own incident corpus can deliver similar or better results, because the model learns from your own terminology and patterns.

In energy, utilities and transport, the focus is on operational risk and NIS2 compliance. KRIs come in real time from SCADA, asset management systems and HSE applications. Multi-site is the norm. Construction and manufacturing centre on project risk and occupational health and safety (ARBO), which calls for a platform that can handle both group level and project level. Government bodies work under the Wpg, BIO and the Comptabiliteitswet (Government Accounts Act), with strict audit regimes and a second line that must be formally independent. For multinationals, ESG reporting (see also our page on CSRD/ESG reporting software), supply chain risk and geopolitical risk come on top of that. One taxonomy, multiple lenses.

How a risk management project works.

1

Introduction and risk scan

A conversation in which we learn which risk categories are in play, which standard packages you currently use, which compliance regimes apply and who the end users are (risk officers, control owners, second and third lines).

2

Taxonomy and workflow design

A workshop with your risk and compliance team to define your own risk taxonomy, impact and likelihood scales and sign-off flows, plus interviews with a few key users from the business. At the end, you have an agreed scope and functional design.

3

Building in sprints

A working build every sprint. We start with the risk register and the heatmap, then controls, then incidents and KRIs, and finally the integrations with your core systems. You test along with us, and so do your risk officers.

4

Compliance validation

Before we go live: a pen test, a DPIA and validation of the audit trail mechanism. For financial or healthcare institutions, we work on this together with your compliance function and, where needed, your external auditor.

5

Rollout and maintenance

A phased rollout per entity or division, training for key users and control owners, and ongoing support for security patches, regulatory updates (such as new NIS2/DORA requirements) and further development.

Frequently asked questions.

What risk and compliance managers usually want to know before we start.

Does custom software replace our Diligent, MetricStream or ServiceNow GRC?
For large corporations: rarely. Those packages are deeply embedded in your board reporting and hold years of policy content. We usually build alongside your existing package: a module for a specific risk category, a deep integration layer, a sector-specific heatmap, or an AI detection layer. For mid-sized organisations without heavy legacy licences, custom software can replace the entire function.
How does heatmap functionality work in custom software versus off-the-shelf packages?
Standard heatmaps are static and work along a single dimension. In custom software, we build drill-down on your own dimensions: business process, location, entity, risk category, owner or regulation. With filters for time window and residual versus inherent risk. The board sees the summary, while the second line clicks through to the details.
How does AI support risk management, similar to Zenya AI?
Zenya AI applies machine learning to reports and incidents to detect patterns and anomalies, for example an increase in near-misses in a specific department, or clusters of reports pointing to an underlying cause. Comparable models can be trained on your own data: anomaly detection on KRI values, incident clustering, and early warning on trends. We use this as support, not as a replacement for human judgement.
What is the difference between integrated risk management and operational risk?
Operational risk is a subset: risks arising from day-to-day processes, IT, people and external events. Integrated risk management also covers strategic risk, financial risk, compliance risk and reputational risk, and looks at how these categories relate to each other. An integrated platform offers a single taxonomy in which all categories fit, plus consolidation at group level.
How do you build for NIS2, DORA and other new regulations?
We map each regulation to controls and evidence requirements. For NIS2, that means an incident reporting process with statutory deadlines, supply chain accountability, and cyber risk reporting. For DORA: an ICT risk register, third-party management and testing regimes for operational resilience. A single control can be linked to multiple regulations, so the administration stays manageable.
What is internal control software and how does it connect to risk?
Internal control is about the execution and effectiveness of control measures, the same controls that appear in your risk register. An integrated platform lets control owners test their controls, upload evidence and assess effectiveness, with direct feedback to the associated risk. No separate tool, no duplicate administration.
Which ERP and case management integrations are standard?
Common integrations include SAP and Oracle ERP for financial KRIs, ServiceNow or TOPdesk for IT incidents, HR systems for turnover and absence KRIs, and sector-specific sources (SCADA for energy, EHR for healthcare, core banking systems for financial services). For specific questions about integrations, see our page on smart API integrations.
What determines the cost of custom risk management software?
The biggest factors are: the number of entities and users, how deeply you integrate with your core systems, whether there are AI components, and the compliance regime (finance and healthcare demand more validation and audit work). A single-entity register with a heatmap is a different project from a multi-entity GRC platform with real-time KRIs and AI detection. After our first conversation, we'll give you a range.

Talk to us about your risk management software.

An introductory half-hour call, no obligation. We'll listen to your risk taxonomy, your current stack and your compliance regimes, and give you direction you can actually use. That includes sparring on a single module (heatmap, KRIs, AI detection or NIS2 mapping) alongside your existing GRC package. For related topics, see KYC/AML compliance software, CSRD/ESG reporting software and custom KPI dashboards.

Edit content