Risk & Assurance
Assess, test, watch, treat. When you are ready for it.
Four optional modules that sit on the same control library as the rest of the platform. They are licensed per tenant and switch on without a new deployment.
Not switched on in the tenant we reviewed.
These modules returned “Permission Required” in the application we read on 18 September 2026, and Risk Appetite was switched off. They were seen working in an earlier tenant. Everything on this page is described from documentation rather than read from a live screen, and no screenshots appear.
How we know they are licensable rather than absent
- Assurance
- 41permissions listed in the role matrix
- Risk Management
- 5permissions listed in the role matrix
Both areas remain in the permission matrix with the module switched off, which is what a licensable module looks like.
The four modules
Four beats, in the order the Blueprint names them.
Open a module to see what it does and the vocabulary it works in. Each one is licensed separately.
Risk and key control self-assessment campaigns are run department by department, with a maker and a multi-level review behind each submission rather than a single sign-off.
Runs as
- Campaign
- By department
- Maker
- Multi-level review
Licensed per tenant
Recorded in the product
The risk universe, onboarded.
Risks carry inherent and residual ratings, and each one opens to the four pillars its controls sit across.
Risk Repository
On the same foundation
Add-ons, not a second platform.
These modules read the control library and the risk records that Governance and Lumina already hold. Switching one on adds an assessment or a test against controls you have; it does not start a separate programme.
Assurance and Risk Appetite are add-on modules. They are not part of the four the platform ships with.
- Controls come from GovernanceSelf-assessments and control tests are run against the same control library, coded by the same four pillars.
- Risks come from LuminaIndicators and treatment plans attach to risks in the repository rather than to a list kept somewhere else.
- Incidents raise treatmentTreatment plans are where an incident's risk goes once the immediate report is filed.
Quantification is not here yet.Roadmap
Ratings today are ordinal: inherent and residual, on a likelihood-by-impact view. FAIR quantification, value-at-risk and peer benchmarking are on the roadmap rather than in the product.
Switch one on when the programme is ready for it.
The demo covers what each add-on adds to the control library you already run, and what licensing one actually involves.