Skip to main content

Enterprise Risk Management

A risk register your board trusts and your risk owners can use

de.iterate is an Australian GRC platform with enterprise risk management (ERM) built in. Most risk registers are accurate on the day they're drafted and drift from there. de.iterate risks actively link to the rest of your management system from objectives, controls, documentation, findings, assurance and even  suppliers they relate to, so your central risk profile reflects what the business is doing today.

Instead of managing policies in one place, risks in another, evidence in folders, and audits through a last-minute scramble, de.iterate connects the whole system. That means better visibility, clearer ownership, stronger assurance and less time lost to manual admin. The current platform spans policies, assurance tasks, registers, evidence, reporting, Trust Centre capabilities, auditor access and support for multiple frameworks.

We help you get your ducks in a row.

deiterate-platform
deiterate-compliance-calender

Sound familiar?

Risk is a business-wide project but outside the compliance team you can’t seem to get any of the risk owners to update their risk register entries. Three risk owners have changed roles, and one has left the company. The heatmap in the board pack was calculated by hand in PowerPoint, and nobody's quite sure if it’s correct.

Three risk owners have changed roles, one has left the company, and the heatmap in the board pack was put together by hand. The register reflects what the risk team knows and misses what the rest of the business is doing.

Bigger organisations have the opposite problem, with the same result. The risk team runs a proper GRC platform, and they’re the only people who can. Every control, workflow and field was configured by the two people who understand it, so a risk owner in operations who needs to update an entry opens a screen built for a specialist, closes it again and emails the risk team instead. The register ends up maintained by three experts on behalf of three hundred colleagues, and the heatmap is only as current as the last round of emails.

How de.iterate handles enterprise risk management

A register stays current when two things are true: the people who own the risks can update it without a specialist in the room, and the scoring, linking and escalation happen in the system rather than in someone’s head. de.iterate is built around both. Risk owners work in plain screens with your scales already applied, controls and incidents connect to the risks they affect, and KRIs and integrations tell you when a risk moves before the next quarterly review does.

calculated-control

Calculated Control Effectiveness that moves risks

Score risk before and after controls, with residual risk calculated against customisable control effectiveness. Customised risk settings enable you to apply your own likelihood and consequence rules, so everyone scores against the same scale.

see-controls

See which controls are doing the heavy lifting

One risk can have many controls, and one control can protect many risks. Incidents, near misses and assurance results link back to the risks they relate to, so that you can easily trace a weak control to every risk that depends on it.

board-reporting

Put your risk profile on one page for the board

Build custom dashboards with heatmaps for your directors, board and management team, showing the risks that each audience needs to see. de.iterate makes reporting quicker and easier than ever before.

risk-drift

Find out when a risk drifts outside appetite

Determine and then write your risk appetite statements and set your Key Risk Indicator thresholds. de.iterate monitors these and escalates an alert to the right people whenever a risk moves outside the expected tolerance. You won't be caught out again.

key-risk-indicator

Key Risk Indicators

Select a pre-made Key Risk Indicator (KRI) from our library or create your own using the web interface. Connect multiple KRIs to risks and get automated alerting when a threshold is passed. KRIs can automatically raise findings and associate risk owners for corrective actions to begin without manual intervention.

deiterate-integrations

Connect integrations to dynamically monitor enterprise risks

Integrations connect directly to de.iterate and enable dynamic control monitoring. Find out when a risk is moving out of tolerance in real-time through our suite of integrations. Our public API connects the rest of your systems.

assurance-task-mock-up

Also included

  • Enterprise risk register: owners, business units, review periods and treatment plans, linked to assets, suppliers and internal or external issues
  • Risk taxonomies and custom fields, so you can describe risk in your organisation's own terms
  • Incident register: incidents, actions and follow-up in one auditable place
  • Corrective action management: audits, findings and actions in linked registers, tracked to closure
  • Customisable registers for anything else you need to track, linked to the rest of your management system
  • Bulk import for your existing risks, assets, suppliers, documentation and more

Frequently Asked Questions

Most questions we get about the risk module come down to one worry: will we have to change how we already do risk to fit the software? The short answer is no. Your matrix, your register and your appetite statements come with you. The longer answers are below.

Can we use our own risk matrix?

Yes. de.iterate lets you set your own likelihood and consequence scales, taxonomy, custom fields and drop-down options. The de.iterate risk module then calculates scores using your settings.

Can we import our existing risk register?

Yes. de.iterate's dynamic import process brings in all your existing management system documentation, including risks, assets, documents and suppliers.

What's the difference between inherent and residual risk?

Inherent risk is the level of risk before any controls are applied. Residual risk is what's left once your controls are in place. de.iterate shows both, and calculates residual risk from how effective your controls are.

What is enterprise risk management software?

Enterprise risk management (ERM) software gives you one place to identify, assess, treat and monitor risk across the whole organisation. In de.iterate, each risk links to the controls, incidents, assets and suppliers behind it, so your register stays connected to what's happening in the business.

Can we set risk appetite and tolerance levels?

Yes. Write your risk appetite statements and set thresholds. de.iterate monitors them and escalates to the right people when a risk moves outside tolerance.

What is a key risk indicator (KRI)?

A key risk indicator (KRI) is a measurable signal that a risk is becoming more or less likely, such as the number of unpatched servers or overdue access reviews. You set a threshold for each one, so you know a risk needs attention before it turns into an incident.

Can de.iterate monitor KRIs automatically?

Yes. Choose a ready-made KRI from de.iterate's library or build your own, then connect it to one or more risks. Integrations update each KRI at an interval you set, and when a threshold is crossed de.iterate alerts the risk owner and can raise a finding, so corrective action starts without anyone chasing it.

How do we report risk to our board?

de.iterate lets you build custom dashboards with heatmaps for your board and management team, showing the risks each audience needs to see.

Does de.iterate record incidents as well as risks?

Yes. de.iterate's Incident Register captures incidents, near misses and breaches, with actions and follow-up, and links each one to the risks it relates to.

What makes de.iterate different

From setup to scale, every feature is designed to help your team save time, stay focused, and drive meaningful results.

Expert support, not just software

de.iterate combines technology with hands-on support from experienced GRC professionals based in Australia. From onboarding through to certification, our team works with you to build momentum quickly, helping many organisations get audit-ready in less than 12 weeks and providing practical support through external audits and ongoing compliance activities.

Continuous compliance, not annual panic

Great compliance is not built in the two weeks before an audit. de.iterate helps you stay ready year-round with assurance tasks, checklists, live registers, reporting and a compliance calendar that keeps momentum going.

Practical enough to use, powerful enough to scale

From start-ups to enterprise, de.iterate supports multiple frameworks in one system, including ISO 27001, ISO 27701, ISO 9001, ISO 14001, ISO 45001, Privacy Acts, SOC 2, DIP, Essential Eight and more. You can grow your compliance maturity without rebuilding everything from scratch.

Key Features

A smarter way to manage compliance

de.iterate combines policies, training, registers, evidence, reporting and assurance workflows in one integrated management system, helping you reduce complexity, stay audit-ready and turn governance, risk management and compliance into business as usual. Every feature is designed to save time, strengthen accountability and make GRC compliance easier to manage across your organisation.
compliance-management

Compliance Management

Every obligation traced to the evidence that meets it, across 25+ frameworks. 

policy-management

Policy Management

 Plain-English policies, clear approvals and proof your staff have read them. 

controls-management

Controls Management

 Scheduled controls testing, with the evidence ready before your auditor asks. 

audit-management

Audit Management

 Audit programs, findings and corrective actions tracked to closure. 

it-cyber-security-consultants

Cyber and IT Risk

 Your whole ISMS, from asset register to Statement of Applicability. 

AI-gov

AI Governance

 ISO 42001, AI impact assessments and an inventory of the AI in your business. 

data-privacy

Privacy and Data Governance

 Find your personal information, see where it goes and keep your privacy policy current.

quality-safety-enviro

Quality, Safety & Environment

 ISO 9001, ISO 14001 and ISO 45001, running alongside everything else you manage. 

risk-drift

Third Party Risk Management

 Keep tabs on the suppliers holding a slice of your risk. 

Multiple compliance frameworks, without extra effort

 

With de.iterate, the complexity of managing multiple frameworks doesn’t translate into increased workload. Our unified platform serves as a central hub for overseeing all your compliance activities, whether you’re working with bespoke frameworks or seeking to meet the criteria of the most sought-after security and privacy standards and certifications.

ISO 27001

Information Security Management Systems

The international standard that sets out the requirements for data protection systems. It’s all about keeping data safe and secure.
ISO 9001

Quality Management Systems

This standard defines the requirements for quality management. It’s all about ensuring your business consistently delivers high-quality products and services.
ISO 45001

Occupational Health and Safety Management Systems

The standard that specifies the requirements for an effective OH&S management system. Create a safer, healthier workplace.
ISO 14001

Environmental Management Systems

The global standard for building EMS. It gives you a structure to identify environmental impacts, manage obligations, strengthen governance.

ISO 42001

Artificial Intelligence Management Systems

This standard specifies the requirements for managing AI systems responsibly and ethically. It helps ensure trustworthy development and use of AI.

SOC 2

System and Organisation Control 2

This specifies how organisations should manage their customer’s data. It is one of the most sought-after security framework for SaaS companies. 

Privacy Acts

Australia, New Zealand, Canada, France, Italy, US and UK

Country-specific legislative frameworks established to protect individuals’ personal information from misuse, interference, unauthorised access, modification, and disclosure.

RRFR

Right Fit for Risk

The Australian Government’s Department of Employment and Workplace Relations uses the External Systems Accreditation Framework and the RFFR approach to assess and accredit third party service providers and systems.

DISP

Defence Industry Security Program

DISP is a critical initiative that ensures businesses in the defence supply chain meet stringent security requirements. DISP compliance is essential for companies that engage in Defence tenders, contracts and projects.

Simple monthly pricing, based on the frameworks you need

de.iterate pricing is structured around the compliance frameworks you choose to access, giving you the flexibility to build a program that fits your organisation’s needs. Every plan includes access to the de.iterate platform and its feature set, from automated and expert-led onboarding, through to migration support, assurance workflows, live registers, compliance reporting and the core documentation needed to run and maintain your management system with confidence.

AUD
GBP
Starter (per month)

$179£100

  • Essential Eight

  • SMB 1001

  • Privacy Acts

  • DISP

  • Cyber Essentials

Business (per month)

$2,100£1,250

  • ISO 27001

  • ISO 27701

  • ISO 42001

  • ISO 9001

  • ISO 45001

  • ISO 14001

  • SOC 2

  • NIST CSF 2.0

  • NIST 800-53

  • NIST 800-172

  • NIST 800-172

  • GDPR

  • Essential Eight

  • SMB 1001

  • Privacy Acts

  • DISP

  • Cyber Essentials

  • DORA

  • NIS2

  • CIS v8

  • EU AI Act

  • TISAX

Enterprise (per month)

$3,500£2,000

  • ISO 27001

  • ISO 27701

  • ISO 42001

  • ISO 9001

  • ISO 45001

  • ISO 14001

  • SOC 2

  • NIST CSF 2.0

  • NIST 800-53

  • NIST 800-171

  • NIST 800-172

  • GDPR

  • Essential Eight

  • SMB 1001

  • Privacy Acts

  • DISP

  • ISM

  • SOCI

  • Right Fit for Risk (RFFR)

  • Cyber Essentials

  • DORA

  • NIS2

  • CIS c8

  • EU AI Act

  • TISAX

Ready to give your risk register a pulse?