Skip to main content
← All chapters

Risk & Compliance

Risk Register

Risks are scored by Probability × Impact (1–25, colour-banded red/orange/yellow/green), with a status (open/mitigating/accepted/closed), category (operational/security/compliance/financial/strategic/technical), an optional linked entity, a mitigation plan and an owner. A 5×5 probability/impact matrix view is also available. Solution Designs and Rules can both create or reference Risk Register entries directly, so a risk raised anywhere in the product still lands in one central register.

The Risk Register showing risks scored by probability and impact with status and mitigation plan.

Obsolescence

An auto-computed report flagging declining or deprecated technologies, with a risk level (Critical/High/Medium/Low) based on lifecycle status, proximity to a recorded end-of-life date, and whether dependent applications exist, including the "blast radius" of affected systems — so an EOL technology with twelve dependent applications is flagged more urgently than one with none.

The Obsolescence report showing technologies flagged by risk level with their dependent-application blast radius.

Completeness

Scores how fully each record's fields are populated (0–100%) across 8 entity types and flags anything under 80% with the specific missing fields, so a catalog that "has" 500 applications but is mostly blank fields is visible as a data-quality problem rather than looking complete on a headline count.

The Completeness report showing a per-entity-type score and the specific fields missing on flagged records.

Data Quality

Two tabs: duplicate detection (name-similarity matching with an adjustable 80–99% threshold, for spotting the same application entered twice under slightly different names) and Validation Rules (8 built-in rules, e.g. "applications must link to a domain", each with a configurable severity) that continuously check the live catalog against those rules rather than only at data-entry time.

The Data Quality page showing duplicate-detection results and validation-rule findings.

Adherence Heatmap

A principle × entity matrix showing adherence levels (weak/partial/moderate/strong/not assessed) with an overall coverage percentage — the aggregate view of the per-entity adherence assessments captured on Principles.

The Adherence Heatmap showing a matrix of principles against entities coloured by adherence level.

Vendor Risk

A read-only rollup per vendor: a computed risk score, counts of critical applications/technologies/contracts tied to that vendor, upcoming contract renewals, total spend, and flags for concentration risk (too much riding on one vendor) — useful for procurement and third-party risk reviews. Clicking a vendor expands a breakdown of how its composite score is calculated: the concentration, renewal, spend and ownership sub-scores, their weights, and each one's contribution to the total.

The Vendor Risk page listing vendors with their computed risk score, dependent entity counts and spend.

Compliance Frameworks

Model compliance frameworks (e.g. NIST, ISO 27001, SOC 2 — one click seeds standard starter frameworks) made up of individual controls, then map each control to the entities that satisfy it as covered, partial, or a gap. A weighted coverage percentage per framework gives an at-a-glance audit-readiness score.

The Compliance Frameworks page showing a framework broken into controls with per-control coverage status.

Drift Alerts

A feed of alerts automatically raised by the scheduled drift-detection job: degrading technical condition on an application, a sudden cost spike, or an overdue recertification review, each with a severity (critical/warning) and a link to the affected entity. Alerts can be resolved individually once actioned, or the whole detection pass can be re-run on demand with "Run now" rather than waiting for the next scheduled sweep.

The Drift Alerts page showing alerts for degrading condition, cost spikes and overdue recertifications.