Skip to content
Sentinel Unity

Enterprise Risk (ERM)

A risk register that reflects how you actually score risk

Matrices, formulas, and taxonomy are configuration rather than assumptions baked into the code, so the register matches your methodology instead of the other way round.

  • Versioned taxonomy: type, category, and subcategory, with diff before activation
  • Configurable matrix axes, levels, severity bands, and scoring formulas
  • Appetite definitions and tolerance bands with defined breach actions
  • Quantitative analysis with frequency and magnitude distributions

Privileged accounts without review

KRI · monthly · owner: Security Operations

Within threshold
Critical 65Warning 45Linked to 2 controls and 1 finding

Methodology

Your scoring model, not ours

Matrix definitions carry versions, axes, axis levels, severity bands, and per-cell mappings. Formulas are versioned too, with overrides where a programme needs to diverge.

  • Matrix and formula versions kept side by side so history stays interpretable
  • Normalisation profiles when programmes score on different scales
  • Taxonomy imported as a draft, diffed against the active version, then activated
  • Deletion guarded: a node in use returns a conflict rather than orphaning records
InsignificantMinorModerateMajorSevere
RareUnlikelyPossibleLikelyAlmost certain
LowModerateHighCriticalAxes, levels, and bands are per-company configuration

Treatment

Mitigate, transfer, avoid, or formally accept

Acceptance is a first-class path with a named acceptance authority and an expiry, so accepted risk returns for re-decision instead of quietly persisting.

  • Treatment plans with actions, owners, priorities, and status
  • Reviews and reassessments that recalculate residual exposure
  • Score snapshots and full history retained per risk
  • Board rollup snapshots and hierarchy aggregates for reporting

Treatment decision

  1. 1Treatment planActions with owners, priority, and due dates
  2. 2Action trackingStatus per action, SLA where defined
  3. 3ReassessmentResidual score recalculated after closure

Assurance

RCSA cycles and an attested risk universe

Departmental self-assessment runs as a cycle with its own entries and evidence, and the risk universe is versioned with attestation rather than being an untracked list.

  • RCSA cycles with department assessments, entries, and evidence
  • Risk universe versions, items, and attestation records
  • Loss events with categories and root causes
  • Scenarios with explicit stated assumptions
12345

Stage 1 of 5

Open cycle

Scope and period set by the risk function

Loss events feed the same register, with category and root cause recorded.

Framework alignment

Works with your control frameworks

This module shares the platform control library. Map national frameworks and global standards alongside jurisdiction-specific authorities.

See enterprise risk in your environment

A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.