Your risk register lists the risks. Regulators ask what they are connected to.

ERM+ links risks, controls, incidents and third parties in one auditable register, so the evidence comes out of the system, not out of a week of spreadsheet work.

Explore the heat maps, controls, loss events and service mapping. Every screen shares the same risks.

Clients we have worked for or with

PS26/2 takes effect on 18 March 2027

Operational incidents and material third-party arrangements will be reported to the FCA in structured templates. The rules are the easy part. Knowing whether your data can produce the reports takes longer.

Rule
OctONovNDecDJan 27JFebFMarMAprA
PS21/3 Operational resilience
Live and supervised
PS7/24 Critical third parties
Vendor oversight tightening
PS26/2 Incident and third-party reporting
In force 18 Mar 2027

164 days until PS26/2 takes effect on 18 March 2027.

From fragmented risk to integrated control

The old way

  • Third-party risk in one tool, information security in another, financial crime in a third, compliance somewhere else
  • Risks, issues, controls and remediation tracked by hand in spreadsheets and email
  • Links between incidents, controls, services and suppliers held in people’s heads
  • Weeks of consolidation before every board pack, audit or supervisory request

The ERM+ way

  • One platform and one data foundation for every non-financial risk
  • Workflows that assign, remind and record, with a full audit trail
  • Risks linked to controls, incidents, services and third parties
  • Board and regulatory reporting straight from live data

The same register, both ways. Switch between the spreadsheet and ERM+, then select a risk to trace its links.

Risk_Register_v12_FINAL (3).xlsxERM+ · Linked register
RefRiskOwnerScoreControlThird partyIncident
Cloud hosting outage takes the client portal offlineCOO20Failover test (see SharePoint)C-031 Failover test Partial#REF! Cloud hosting Critical#REF!INC-2291 4h outage, Jan
Payments processor fails to settle on timeCFO16Daily rec (Finance team)C-044 Daily reconciliation Effective#REF! Payments processor Critical#REF!INC-2310 Late settlement, Mar
Ransomware reaches shared file storageCTO15Backups (IT to confirm)C-012 Immutable backups Effective#REF! Managed IT service Material—
Client onboarding breaches its impact toleranceHead of Risk20Scenario test, date TBCC-052 Severe scenario test Untested#REF! Cloud hosting Critical—
Outsourced KYC screening misses sanctions hitsCompliance16QA sample (monthly?)C-027 Monthly QA sample Partial#REF! KYC screening Material#REF!INC-2302 Missed alert, Feb
Key-person dependency in fund accountingCOO12Cross-training (HR)C-019 Cross-training plan Partial#REF! Fund administrator Critical—
Market data feed interruption delays pricingCTO9Backup feed (IT)C-038 Secondary data feed Effective#REF! Market data vendor Material—
Illustrative data

One platform, one data foundation

The platform’s own dashboards, recreated with illustrative data: resilience, loss events, and risk measured alongside capital. Select any bar or legend to filter.

Operational Resilience DashboardIllustrative data
Select a bar or a legend item to filter the services below.
Services by Consumer Impact
Services by Market Integrity
Services by Firm's Viability
Severe Scenario Tests
Third-party Concentration

Number of important business services that depend on each supplier.

Important Business Services (4)
  • IBS-01Client portal accessTolerance 4 hoursWithin tolerance
  • IBS-02Client onboardingTolerance 2 daysBreach
  • IBS-03Payments and settlementTolerance 1 dayWithin tolerance
  • IBS-04Portfolio valuation and reportingTolerance 1 dayNot tested

Services rated by impact on consumers, market integrity and firm viability, with scenario test results and supplier concentration.

What sits in ERM+

  • Enterprise risk management

    Risk register, risk appetite, controls, key risk indicators, issues and actions.

    Risk committee and board reporting from live data.

  • Operational resilience

    Important business services, impact tolerances, mapping of people, processes, systems and suppliers, scenarios.

    Self-assessment evidence, tolerance breaches and test results.

  • Third-party risk

    Supplier register, outsourcing and material arrangements, due diligence and reviews.

    An in-scope third-party register and an oversight trail per supplier.

  • Incidents and loss events

    Hits and near misses, root causes, cause types, impacted areas and severity.

    Incident records structured for regulatory reporting as they happen.

  • Risk and capital quantification

    Loss scenarios and aggregated operational and cyber risk in financial terms.

    How much capital keeps the business running when a scenario occurs.

  • Fractional risk management

    Senior risk expertise on demand, from the team that built the platform.

    A risk function that holds up to scrutiny without a full-time CRO.

Built by practitioners. Priced below enterprise GRC.

Years of risk experience between the co-founders
50+
Years with our senior associates
500+
To implement, not months
Weeks
Meet the team

Whose problem is this?

At firms of 100 to 1,000 people, risk, resilience and supplier oversight rarely sit with one person.

Head of Risk / CRO

Also: Head of Operational Resilience, Risk Director

What you are dealing with
The risk register, third-party oversight and the resilience framework sit in separate spreadsheets. There is no single view of risk, and every board pack is assembled by hand.
What ERM+ gives you
One view of every risk type, with controls, incidents and suppliers linked to it. Risk committee reporting straight from live data.
Usually prompted by
A supervisory letter, a third-party incident, or the next board risk committee.

In their words

“ERM PLUS significantly reduced the time and resources for achieving regulatory compliance in risk and prudential management.”

Head of OpRisk · Asset Management Firm

“The expertise and professionalism of the ERM Plus team are unparalleled. Their strategic guidance and hands-on approach have been instrumental in achieving our business goals.”

Head of Risk · Retail Brokerage Firm

How it starts

  1. A 20‑minute call

    We look at where your incident, third-party and risk data sits today and what your regulator will ask for.

  2. A gap map

    If there is something worth solving, we map the gaps between what you capture and what you will need to report.

  3. Weeks, not months

    Implementation in weeks, at a fraction of the cost of incumbent GRC suites.

Twenty minutes will tell us both whether there is anything worth exploring.

We look at what you capture today, what your regulator will ask for, and whether there is a gap. If there is nothing there, no need to take it further.

A gap check, not a pitch. No project, no budget conversation, no access to sensitive data.