de.iterate is an Australian GRC platform with enterprise risk management (ERM) built in. Most risk registers are accurate on the day they're drafted and drift from there. de.iterate risks actively link to the rest of your management system from objectives, controls, documentation, findings, assurance and even suppliers they relate to, so your central risk profile reflects what the business is doing today.
Instead of managing policies in one place, risks in another, evidence in folders, and audits through a last-minute scramble, de.iterate connects the whole system. That means better visibility, clearer ownership, stronger assurance and less time lost to manual admin. The current platform spans policies, assurance tasks, registers, evidence, reporting, Trust Centre capabilities, auditor access and support for multiple frameworks.
We help you get your ducks in a row.
Risk is a business-wide project but outside the compliance team you can’t seem to get any of the risk owners to update their risk register entries. Three risk owners have changed roles, and one has left the company. The heatmap in the board pack was calculated by hand in PowerPoint, and nobody's quite sure if it’s correct.
Three risk owners have changed roles, one has left the company, and the heatmap in the board pack was put together by hand. The register reflects what the risk team knows and misses what the rest of the business is doing.
Bigger organisations have the opposite problem, with the same result. The risk team runs a proper GRC platform, and they’re the only people who can. Every control, workflow and field was configured by the two people who understand it, so a risk owner in operations who needs to update an entry opens a screen built for a specialist, closes it again and emails the risk team instead. The register ends up maintained by three experts on behalf of three hundred colleagues, and the heatmap is only as current as the last round of emails.
A register stays current when two things are true: the people who own the risks can update it without a specialist in the room, and the scoring, linking and escalation happen in the system rather than in someone’s head. de.iterate is built around both. Risk owners work in plain screens with your scales already applied, controls and incidents connect to the risks they affect, and KRIs and integrations tell you when a risk moves before the next quarterly review does.
Score risk before and after controls, with residual risk calculated against customisable control effectiveness. Customised risk settings enable you to apply your own likelihood and consequence rules, so everyone scores against the same scale.
One risk can have many controls, and one control can protect many risks. Incidents, near misses and assurance results link back to the risks they relate to, so that you can easily trace a weak control to every risk that depends on it.
Build custom dashboards with heatmaps for your directors, board and management team, showing the risks that each audience needs to see. de.iterate makes reporting quicker and easier than ever before.
Determine and then write your risk appetite statements and set your Key Risk Indicator thresholds. de.iterate monitors these and escalates an alert to the right people whenever a risk moves outside the expected tolerance. You won't be caught out again.
Select a pre-made Key Risk Indicator (KRI) from our library or create your own using the web interface. Connect multiple KRIs to risks and get automated alerting when a threshold is passed. KRIs can automatically raise findings and associate risk owners for corrective actions to begin without manual intervention.
Integrations connect directly to de.iterate and enable dynamic control monitoring. Find out when a risk is moving out of tolerance in real-time through our suite of integrations. Our public API connects the rest of your systems.
Most questions we get about the risk module come down to one worry: will we have to change how we already do risk to fit the software? The short answer is no. Your matrix, your register and your appetite statements come with you. The longer answers are below.
Yes. de.iterate lets you set your own likelihood and consequence scales, taxonomy, custom fields and drop-down options. The de.iterate risk module then calculates scores using your settings.
Yes. de.iterate's dynamic import process brings in all your existing management system documentation, including risks, assets, documents and suppliers.
Inherent risk is the level of risk before any controls are applied. Residual risk is what's left once your controls are in place. de.iterate shows both, and calculates residual risk from how effective your controls are.
Enterprise risk management (ERM) software gives you one place to identify, assess, treat and monitor risk across the whole organisation. In de.iterate, each risk links to the controls, incidents, assets and suppliers behind it, so your register stays connected to what's happening in the business.
Yes. Write your risk appetite statements and set thresholds. de.iterate monitors them and escalates to the right people when a risk moves outside tolerance.
A key risk indicator (KRI) is a measurable signal that a risk is becoming more or less likely, such as the number of unpatched servers or overdue access reviews. You set a threshold for each one, so you know a risk needs attention before it turns into an incident.
Yes. Choose a ready-made KRI from de.iterate's library or build your own, then connect it to one or more risks. Integrations update each KRI at an interval you set, and when a threshold is crossed de.iterate alerts the risk owner and can raise a finding, so corrective action starts without anyone chasing it.
de.iterate lets you build custom dashboards with heatmaps for your board and management team, showing the risks each audience needs to see.
Yes. de.iterate's Incident Register captures incidents, near misses and breaches, with actions and follow-up, and links each one to the risks it relates to.
From setup to scale, every feature is designed to help your team save time, stay focused, and drive meaningful results.
de.iterate combines technology with hands-on support from experienced GRC professionals based in Australia. From onboarding through to certification, our team works with you to build momentum quickly, helping many organisations get audit-ready in less than 12 weeks and providing practical support through external audits and ongoing compliance activities.
Great compliance is not built in the two weeks before an audit. de.iterate helps you stay ready year-round with assurance tasks, checklists, live registers, reporting and a compliance calendar that keeps momentum going.
From start-ups to enterprise, de.iterate supports multiple frameworks in one system, including ISO 27001, ISO 27701, ISO 9001, ISO 14001, ISO 45001, Privacy Acts, SOC 2, DIP, Essential Eight and more. You can grow your compliance maturity without rebuilding everything from scratch.
Many tools stop at storage. de.iterate goes further by connecting your policies, controls, evidence, registers and assurance activity in context. That means your documentation is not just centralised, it is structured, linked and easier to defend.
We believe compliance should be simpler, clearer and more achievable. That is why de.iterate combines structured workflows, smart documentation, migration support and guided onboarding with a platform that is intuitive enough for teams to use every day.
de.iterate is designed for the way organisations actually work. Policies, risks, assets, incidents, suppliers, evidence, audits and reporting all sit in one integrated platform, so compliance becomes part of business as usual.
Every obligation traced to the evidence that meets it, across 25+ frameworks.
Plain-English policies, clear approvals and proof your staff have read them.
Scheduled controls testing, with the evidence ready before your auditor asks.
ISO 42001, AI impact assessments and an inventory of the AI in your business.
Find your personal information, see where it goes and keep your privacy policy current.
ISO 9001, ISO 14001 and ISO 45001, running alongside everything else you manage.
With de.iterate, the complexity of managing multiple frameworks doesn’t translate into increased workload. Our unified platform serves as a central hub for overseeing all your compliance activities, whether you’re working with bespoke frameworks or seeking to meet the criteria of the most sought-after security and privacy standards and certifications.
The global standard for building EMS. It gives you a structure to identify environmental impacts, manage obligations, strengthen governance.
This standard specifies the requirements for managing AI systems responsibly and ethically. It helps ensure trustworthy development and use of AI.
This specifies how organisations should manage their customer’s data. It is one of the most sought-after security framework for SaaS companies.
Country-specific legislative frameworks established to protect individuals’ personal information from misuse, interference, unauthorised access, modification, and disclosure.
The Australian Government’s Department of Employment and Workplace Relations uses the External Systems Accreditation Framework and the RFFR approach to assess and accredit third party service providers and systems.
DISP is a critical initiative that ensures businesses in the defence supply chain meet stringent security requirements. DISP compliance is essential for companies that engage in Defence tenders, contracts and projects.
de.iterate pricing is structured around the compliance frameworks you choose to access, giving you the flexibility to build a program that fits your organisation’s needs. Every plan includes access to the de.iterate platform and its feature set, from automated and expert-led onboarding, through to migration support, assurance workflows, live registers, compliance reporting and the core documentation needed to run and maintain your management system with confidence.
Essential Eight
SMB 1001
Privacy Acts
DISP
Cyber Essentials
ISO 27001
ISO 27701
ISO 42001
ISO 9001
ISO 45001
ISO 14001
SOC 2
NIST CSF 2.0
NIST 800-53
NIST 800-172
NIST 800-172
GDPR
Essential Eight
SMB 1001
Privacy Acts
DISP
Cyber Essentials
DORA
NIS2
CIS v8
EU AI Act
TISAX
ISO 27001
ISO 27701
ISO 42001
ISO 9001
ISO 45001
ISO 14001
SOC 2
NIST CSF 2.0
NIST 800-53
NIST 800-171
NIST 800-172
GDPR
Essential Eight
SMB 1001
Privacy Acts
DISP
ISM
SOCI
Right Fit for Risk (RFFR)
Cyber Essentials
DORA
NIS2
CIS c8
EU AI Act
TISAX