A unified platform for risk, compliance and audit. Designed so the people who manage risk actually use it — and the people who report on it always have current data.
The problem
The tools available today were built for a different era. The gap between where risk management should be and where it actually is has never been wider.
Risks in Excel. Controls in SharePoint. Audit findings in email. When data lives in disconnected tools, your risk picture is always incomplete — and no one trusts the reports.
Nine-month rollouts driven by consultants. By the time you're live, the regulatory landscape has shifted and the team that scoped the project has moved on.
Complex interfaces built for auditors, not for the people who manage risk day to day. Low adoption means stale data. Stale data means board reports no one believes.
Why Altus GRC
Three principles that guided every decision in the platform, from the data model to the interface.
Every module shares the same data model. A risk links to controls. Controls link to findings. Findings drive remediation plans. Your entire GRC picture is connected, not copy-pasted between tools.
Pre-configured workflows, guided onboarding and sensible defaults mean your team is running real risk cycles within weeks — no months of waiting for a consultant to finish configuring the system.
When logging a risk takes 30 seconds, your data stays current. When your data is current, your reports are credible. When your reports are credible, decisions improve.
Platform modules
From a first risk register to a mature GRC program. Every module shares the same data model, workflow engine and permission layer.
Risk Management available now. Full suite rolling out through 2026.
Centralise your risk register with configurable scoring, ownership and treatment tracking.
Build your control framework. Test it. Map it to ISO 27001, GDPR, NIST and more.
One register for every gap: manual findings, KRI breaches and control failures.
Know who you depend on, and what risk they carry. Assessments, criticality, expiry tracking.
Plan, execute and report on audits. From the annual audit universe to workpaper sign-off.
Full policy lifecycle: drafting, approval, publication, periodic review and regulatory mapping.
Every risk and finding linked to something real: companies, processes, systems, information assets.
Business impact analyses, continuity plans and crisis event tracking. Linked to assets and incidents.
Map your obligations to authoritative sources. Collect evidence. Stay audit-ready at all times.
Platform capabilities
Shared capabilities that make every module more powerful — and make Altus GRC something other than a collection of tools.
Canvas-based workflow builder with conditional routing, parallel branches, timers and automated notifications. No code required.
Role-based and attribute-based permissions down to individual records. Configurable per application, inherited through groups.
Real-time heatmaps, KPI cards, trend charts. A report builder for custom views across any module. Board-ready exports in one click.
Every record change, workflow action and admin operation logged with timestamp and actor. Cannot be disabled. Append-only.
Custom fields, custom layouts and on-demand applications. Extend any module for your organisation's specific processes — without code.
SAML 2.0 and OIDC with Microsoft Entra ID, Okta and generic SAML providers. Attribute mapping included.
Configurable rules triggered by field changes, score thresholds or approaching dates. Delivered in-app and by email, configured by your admin without code.
Security
Security isn't a feature tier. It's the architecture. Every decision about how the platform stores, accesses and protects your data starts from a threat model, not a checklist.
Every organisation is a fully isolated tenant. Row-level security is enforced at the database layer on every query, not in application code alone. One tenant cannot reference, see or access another's data under any circumstances.
Role-based permissions at the application level. Attribute-based rules at the record level: "only the owner can edit", "confidential records visible to risk committee only". All verified server-side on every request.
Every change, workflow transition, admin action and approval is logged with timestamp and actor. Append-only. The log cannot be edited or disabled. Your regulators and auditors will find exactly what they need.
Early access
We're partnering with a small number of organisations to validate the platform before general availability. Design partners get direct access to the founding team, influence over the roadmap, and commercial terms that reflect where we are — not where legacy vendors price the market.
FAQ
Most teams are running their first risk cycle within weeks. The platform ships with pre-configured workflows and sensible defaults. Guided onboarding — no external consultants required.
Yes. Excel and CSV import is standard for the risk register, asset inventory and controls library. We support migration during onboarding and the import tool validates data before it reaches the database.
ISO 27001, ISO 31000, GDPR, NIS2, DORA, NIST CSF, SOX and PCI-DSS natively. Custom frameworks and authoritative sources can be added by your admin without code.
Yes. Custom fields, layouts, views and workflows are configurable by your admin without code. On-demand applications let you build GRC processes specific to your organisation's needs, on top of the shared platform.
The platform models the full organisational hierarchy: companies, divisions, business units and business processes natively. Risks and findings can be scoped and filtered at every level.
All data is stored in the EU (Ireland region). We do not transfer personal data outside the European Economic Area without appropriate safeguards. Full details are in our Data Processing Agreement.
30 minutes. A live walkthrough with the founder. No slides, no scripts. Just the platform.