Your risk register lists the risks. Regulators ask what they are connected to.
ERM+ links risks, controls, incidents and third parties in one auditable register, so the evidence comes out of the system, not out of a week of spreadsheet work.
14 risks on the register. 9 rated High before controls, 2 after.
Select a cell to see which risks sit there and where their controls move them.
Explore the heat maps, controls, loss events and service mapping. Every screen shares the same risks.
Clients we have worked for or with
PS26/2 takes effect on 18 March 2027
Operational incidents and material third-party arrangements will be reported to the FCA in structured templates. The rules are the easy part. Knowing whether your data can produce the reports takes longer.
164 days until PS26/2 takes effect on 18 March 2027.
From fragmented risk to integrated control
The old way
- Third-party risk in one tool, information security in another, financial crime in a third, compliance somewhere else
- Risks, issues, controls and remediation tracked by hand in spreadsheets and email
- Links between incidents, controls, services and suppliers held in people’s heads
- Weeks of consolidation before every board pack, audit or supervisory request
The ERM+ way
- One platform and one data foundation for every non-financial risk
- Workflows that assign, remind and record, with a full audit trail
- Risks linked to controls, incidents, services and third parties
- Board and regulatory reporting straight from live data
The same register, both ways. Switch between the spreadsheet and ERM+, then select a risk to trace its links.
| Ref | Risk | Owner | Score | Control | Third party | Incident |
|---|---|---|---|---|---|---|
| Cloud hosting outage takes the client portal offline | COO | 20 | Failover test (see SharePoint)C-031 Failover test Partial | #REF! Cloud hosting Critical | #REF!INC-2291 4h outage, Jan | |
| Payments processor fails to settle on time | CFO | 16 | Daily rec (Finance team)C-044 Daily reconciliation Effective | #REF! Payments processor Critical | #REF!INC-2310 Late settlement, Mar | |
| Ransomware reaches shared file storage | CTO | 15 | Backups (IT to confirm)C-012 Immutable backups Effective | #REF! Managed IT service Material | — | |
| Client onboarding breaches its impact tolerance | Head of Risk | 20 | Scenario test, date TBCC-052 Severe scenario test Untested | #REF! Cloud hosting Critical | — | |
| Outsourced KYC screening misses sanctions hits | Compliance | 16 | QA sample (monthly?)C-027 Monthly QA sample Partial | #REF! KYC screening Material | #REF!INC-2302 Missed alert, Feb | |
| Key-person dependency in fund accounting | COO | 12 | Cross-training (HR)C-019 Cross-training plan Partial | #REF! Fund administrator Critical | — | |
| Market data feed interruption delays pricing | CTO | 9 | Backup feed (IT)C-038 Secondary data feed Effective | #REF! Market data vendor Material | — |
One platform, one data foundation
The platform’s own dashboards, recreated with illustrative data: resilience, loss events, and risk measured alongside capital. Select any bar or legend to filter.
Number of important business services that depend on each supplier.
- IBS-01Client portal accessTolerance 4 hoursWithin tolerance
- IBS-02Client onboardingTolerance 2 daysBreach
- IBS-03Payments and settlementTolerance 1 dayWithin tolerance
- IBS-04Portfolio valuation and reportingTolerance 1 dayNot tested
Services rated by impact on consumers, market integrity and firm viability, with scenario test results and supplier concentration.
What sits in ERM+
Enterprise risk management
Risk register, risk appetite, controls, key risk indicators, issues and actions.
Risk committee and board reporting from live data.
Operational resilience
Important business services, impact tolerances, mapping of people, processes, systems and suppliers, scenarios.
Self-assessment evidence, tolerance breaches and test results.
Third-party risk
Supplier register, outsourcing and material arrangements, due diligence and reviews.
An in-scope third-party register and an oversight trail per supplier.
Incidents and loss events
Hits and near misses, root causes, cause types, impacted areas and severity.
Incident records structured for regulatory reporting as they happen.
Risk and capital quantification
Loss scenarios and aggregated operational and cyber risk in financial terms.
How much capital keeps the business running when a scenario occurs.
Fractional risk management
Senior risk expertise on demand, from the team that built the platform.
A risk function that holds up to scrutiny without a full-time CRO.
Built by practitioners. Priced below enterprise GRC.
- Years of risk experience between the co-founders
- 50+
- Years with our senior associates
- 500+
- To implement, not months
- Weeks
Built for your regulator
Each regulator asks the question differently. The underlying problem is the same: can the evidence come out of the system?
- FCA-regulatedHow do you manage your risk register today: one spreadsheet or several?Open
- Energy networksWhen a vendor or contractor fails, how quickly can you see every service that depended on it?Open
- TelecomsIf Ofcom asked for your supplier risk evidence tomorrow, how many places would you pull it from?Open
- Listed companiesWhen the audit committee asks which controls are material, where does the answer come from?Open
Whose problem is this?
At firms of 100 to 1,000 people, risk, resilience and supplier oversight rarely sit with one person.
Head of Risk / CRO
Also: Head of Operational Resilience, Risk Director
- What you are dealing with
- The risk register, third-party oversight and the resilience framework sit in separate spreadsheets. There is no single view of risk, and every board pack is assembled by hand.
- What ERM+ gives you
- One view of every risk type, with controls, incidents and suppliers linked to it. Risk committee reporting straight from live data.
- Usually prompted by
- A supervisory letter, a third-party incident, or the next board risk committee.
COO
Also: Head of Operations
- What you are dealing with
- Third-party management, incident management and resilience land on your desk, and they run on email, spreadsheets and slide decks.
- What ERM+ gives you
- Supplier oversight, incident logging and resilience mapping automated in one place, without hiring a team to run it.
- Usually prompted by
- A vendor incident, board pressure on governance, or another headcount request.
Head of Compliance
Also: Chief Compliance Officer, Head of Regulatory Affairs
- What you are dealing with
- Regulators ask for evidence that controls work, not copies of policies. Evidencing that by hand takes more resource than you have.
- What ERM+ gives you
- A control framework with its testing, owners and outcomes recorded, so the evidence trail already exists when it is requested.
- Usually prompted by
- New guidance, the audit cycle, or a new senior manager joining.
CFO
Also: Finance Director
- What you are dealing with
- You own risk oversight and vendor management alongside liquidity and capital, without a full risk team behind you.
- What ERM+ gives you
- Loss events and risk scenarios quantified in financial terms, so you can see how much capital keeps the business running when things go wrong.
- Usually prompted by
- Headcount cost, a supervisory finding, or a loss event that needs quantifying.
CTO / CIO
Also: Head of IT, Head of Technology Risk
- What you are dealing with
- ICT risk, vendor management, business continuity and incident response are yours, and they are tracked across tools that do not talk to each other.
- What ERM+ gives you
- ICT risks, systems, suppliers and incidents linked to the services they support, with continuity and resilience evidence in the same record.
- Usually prompted by
- An incident, a vendor failure, or a resilience test that exposed a gap.
In their words
“ERM PLUS significantly reduced the time and resources for achieving regulatory compliance in risk and prudential management.”
“The expertise and professionalism of the ERM Plus team are unparalleled. Their strategic guidance and hands-on approach have been instrumental in achieving our business goals.”
How it starts
A 20‑minute call
We look at where your incident, third-party and risk data sits today and what your regulator will ask for.
A gap map
If there is something worth solving, we map the gaps between what you capture and what you will need to report.
Weeks, not months
Implementation in weeks, at a fraction of the cost of incumbent GRC suites.
Twenty minutes will tell us both whether there is anything worth exploring.
We look at what you capture today, what your regulator will ask for, and whether there is a gap. If there is nothing there, no need to take it further.
A gap check, not a pitch. No project, no budget conversation, no access to sensitive data.