Early access now open

Govern with clarity.
Act with confidence.

A unified platform for risk, compliance and audit. Designed so the people who manage risk actually use it — and the people who report on it always have current data.

GDPR-first by designISO 27001 alignedISO 31000 alignedMulti-tenant isolation

The problem

Risk programs fail before
they get off the ground.

The tools available today were built for a different era. The gap between where risk management should be and where it actually is has never been wider.

Everything is siloed

Risks in Excel. Controls in SharePoint. Audit findings in email. When data lives in disconnected tools, your risk picture is always incomplete — and no one trusts the reports.

Implementations outlast their purpose

Nine-month rollouts driven by consultants. By the time you're live, the regulatory landscape has shifted and the team that scoped the project has moved on.

Platforms risk owners avoid

Complex interfaces built for auditors, not for the people who manage risk day to day. Low adoption means stale data. Stale data means board reports no one believes.

Why Altus GRC

Built differently.
On purpose.

Three principles that guided every decision in the platform, from the data model to the interface.

One connected platform

Every module shares the same data model. A risk links to controls. Controls link to findings. Findings drive remediation plans. Your entire GRC picture is connected, not copy-pasted between tools.

Operational from day one

Pre-configured workflows, guided onboarding and sensible defaults mean your team is running real risk cycles within weeks — no months of waiting for a consultant to finish configuring the system.

Designed for adoption

When logging a risk takes 30 seconds, your data stays current. When your data is current, your reports are credible. When your reports are credible, decisions improve.

Platform modules

Your entire risk lifecycle.
One platform.

From a first risk register to a mature GRC program. Every module shares the same data model, workflow engine and permission layer.

Risk Management available now. Full suite rolling out through 2026.

Available now

Risk Management

Centralise your risk register with configurable scoring, ownership and treatment tracking.

  • Risk register with custom scoring matrices
  • Periodic risk assessments
  • Key Risk Indicators with breach alerts
  • Risk treatment plans
Coming soon

Controls & Compliance

Build your control framework. Test it. Map it to ISO 27001, GDPR, NIST and more.

  • Master control library
  • Evidence collection and test execution
  • Auto-escalation on test failure
  • Multi-framework mapping
Coming soon

Issues & Findings

One register for every gap: manual findings, KRI breaches and control failures.

  • Findings from all sources unified
  • Remediation plans with action items
  • Verification sign-off workflows
  • Exception request handling
Coming soon

Third Party Risk

Know who you depend on, and what risk they carry. Assessments, criticality, expiry tracking.

  • Vendor and partner register
  • Periodic risk assessments
  • Contract expiry and renewal alerts
  • Automatic finding generation
Coming soon

Audit Management

Plan, execute and report on audits. From the annual audit universe to workpaper sign-off.

  • Audit universe and annual planning
  • Engagements, workpapers, tasks
  • Finding promotion to issues register
  • Audit reporting
Coming soon

Policy & Governance

Full policy lifecycle: drafting, approval, publication, periodic review and regulatory mapping.

  • Policy library with version control
  • Approval and publication workflows
  • Regulatory obligation tracking
  • NIS2, GDPR, DORA alignment
Coming soon

Asset Inventory

Every risk and finding linked to something real: companies, processes, systems, information assets.

  • Organisational hierarchy mapping
  • Business processes and information assets
  • Devices, systems and applications
  • Context across all GRC modules
Coming soon

Business Continuity

Business impact analyses, continuity plans and crisis event tracking. Linked to assets and incidents.

  • BIA with RTO and RPO tracking
  • Continuity plans per process
  • Crisis event register
  • Linked to incidents and assets
Coming soon

Compliance Management

Map your obligations to authoritative sources. Collect evidence. Stay audit-ready at all times.

  • ISO 27001, GDPR, NIST, SOX, PCI-DSS
  • Requirement tracking with evidence
  • Compliance assessment workflows
  • Gap analysis and finding generation

Platform capabilities

The foundation
every module runs on.

Shared capabilities that make every module more powerful — and make Altus GRC something other than a collection of tools.

Visual Workflow Engine

Canvas-based workflow builder with conditional routing, parallel branches, timers and automated notifications. No code required.

Granular Access Control

Role-based and attribute-based permissions down to individual records. Configurable per application, inherited through groups.

Dashboards & Reporting

Real-time heatmaps, KPI cards, trend charts. A report builder for custom views across any module. Board-ready exports in one click.

Immutable Audit Trail

Every record change, workflow action and admin operation logged with timestamp and actor. Cannot be disabled. Append-only.

Application Builder

Custom fields, custom layouts and on-demand applications. Extend any module for your organisation's specific processes — without code.

Single Sign-On

SAML 2.0 and OIDC with Microsoft Entra ID, Okta and generic SAML providers. Attribute mapping included.

Notification & Alerting Engine

Configurable rules triggered by field changes, score thresholds or approaching dates. Delivered in-app and by email, configured by your admin without code.

Security

We manage risk.
So we hold ourselves to it.

Security isn't a feature tier. It's the architecture. Every decision about how the platform stores, accesses and protects your data starts from a threat model, not a checklist.

Tenant isolation by design

Every organisation is a fully isolated tenant. Row-level security is enforced at the database layer on every query, not in application code alone. One tenant cannot reference, see or access another's data under any circumstances.

Layered access control

Role-based permissions at the application level. Attribute-based rules at the record level: "only the owner can edit", "confidential records visible to risk committee only". All verified server-side on every request.

Immutable audit log

Every change, workflow transition, admin action and approval is logged with timestamp and actor. Append-only. The log cannot be edited or disabled. Your regulators and auditors will find exactly what they need.

Early access

Work with us.
Shape the product.

We're partnering with a small number of organisations to validate the platform before general availability. Design partners get direct access to the founding team, influence over the roadmap, and commercial terms that reflect where we are — not where legacy vendors price the market.

You manage risk, compliance or audit for an organisation with real regulatory exposure
You're working from spreadsheets, or outgrowing your current tool
You want direct access to the founding team and influence over the product roadmap

FAQ

Common questions

How long does implementation take?
+

Most teams are running their first risk cycle within weeks. The platform ships with pre-configured workflows and sensible defaults. Guided onboarding — no external consultants required.

Can we import our existing data?
+

Yes. Excel and CSV import is standard for the risk register, asset inventory and controls library. We support migration during onboarding and the import tool validates data before it reaches the database.

Which compliance frameworks are supported?
+

ISO 27001, ISO 31000, GDPR, NIS2, DORA, NIST CSF, SOX and PCI-DSS natively. Custom frameworks and authoritative sources can be added by your admin without code.

Can we customise the platform for our processes?
+

Yes. Custom fields, layouts, views and workflows are configurable by your admin without code. On-demand applications let you build GRC processes specific to your organisation's needs, on top of the shared platform.

How are multi-entity organisations handled?
+

The platform models the full organisational hierarchy: companies, divisions, business units and business processes natively. Risks and findings can be scoped and filtered at every level.

How is data residency handled?
+

All data is stored in the EU (Ireland region). We do not transfer personal data outside the European Economic Area without appropriate safeguards. Full details are in our Data Processing Agreement.

See your risk program, elevated.

30 minutes. A live walkthrough with the founder. No slides, no scripts. Just the platform.