Scrutineer · Platform
Enterprise risk management software and ERM risk registers
Your board wants one view of enterprise risk. The evidence lives in eleven places, and the register gets refreshed the week before the meeting by whoever has the spreadsheet.
Scrutineer keeps the enterprise risk register on the same controls and evidence your framework work already runs on, so a rating changes when the control behind it changes.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with enterprise risk management
Reputation risk left the federal bank rulebook on June 9, 2026
Almost every published risk taxonomy, register template and ERM product demo still opens with a reputation risk category. For OCC and FDIC supervised institutions that category no longer sits in the rule. On April 10, 2026 the two agencies published a joint final rule, Prohibition on the Use of Reputation Risk by Regulators, at 91 FR 18279, effective June 9, 2026. One of its amendments changes the risk categories a covered bank framework has to cover in 12 CFR part 30, appendix D, section II, paragraph (B), by removing the phrase "compliance risk, strategic risk, and reputation risk" and adding in its place "compliance risk, and strategic risk". The list now reads credit risk, interest rate risk, liquidity risk, price risk, operational risk, compliance risk, and strategic risk. Seven categories, not eight. The rule also stops the agencies criticizing or downgrading an institution on that basis, and it defines reputation risk to catch relabeling: any risk, regardless of how the risk is labeled by the institution or regulators, that an activity could negatively impact public perception for reasons not clearly and directly related to financial or operational condition. Nothing stops a bank tracking reputation internally. What changed is that no examiner can hold you to it, and appendix D no longer asks for it.
No US mandate asks you for a risk register. Each one asks for a signed document
The category sells registers, heat maps and dashboards. Read the rules and none of them name any of those. Appendix D asks a covered bank for a formal, written risk governance framework designed by independent risk management and approved by the board or the board risk committee, plus a comprehensive written statement articulating risk appetite that contains both qualitative components and quantitative limits, reviewed and approved at least annually. The SEC asks public companies, in Item 106(b) of Regulation S-K, to describe their processes for assessing, identifying and managing material risks from cybersecurity threats in sufficient detail for a reasonable investor to understand those processes, and specifically whether those processes have been integrated into the registrant overall risk management system or processes. State insurance regulators want a confidential ORSA Summary Report once a year. In all three the register is an input. The deliverable is a narrative that a named human approved on a fixed date, which is why the hard part of ERM tooling is provenance and sign-off, not visualization.
There is no certification in either framework the whole category is built on
Buying committees ask vendors for COSO or ISO 31000 certification, and plenty of marketing implies it exists. It does not. The COSO 2017 framework, Enterprise Risk Management: Integrating with Strategy and Performance, sets out twenty principles across five components: governance and culture, strategy and objective-setting, performance, review and revision, and information, communication and reporting. Those principles are written as outcomes an organization achieves, not clauses an auditor ticks, and no accredited body certifies a company against them. ISO 31000:2018 is published as guidelines and is not written for certification purposes, so no certificate exists for an organization either. Individual certificate programs from training providers do exist and are a different thing: they say something about a person, nothing about a program. The practical consequence is that nobody will ever hand you paper proving your ERM program is adequate. What gets tested instead is the written framework, the appetite statement, the minutes, and whether the risks you wrote down match the controls you actually operate.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Keeps one enterprise risk register rather than four, with each risk tied to the specific controls that are supposed to reduce it
- Recalculates a residual rating when the evidence behind a control goes stale, so the register ages honestly instead of silently
- Carries the risk categories a US bank framework actually names: credit, interest rate, liquidity, price, operational, compliance and strategic
- Records who approved the risk appetite statement and when, because approval and date are what an examiner asks for first
- Links vendor and third-party findings straight into enterprise operational risk, so supplier failures stop living in a separate tool
- Produces the cybersecurity risk narrative Item 106(b) asks for, including how the process is integrated into the wider risk system
- Maps the same control library to SOC 2, ISO 27001, HIPAA, PCI DSS and FedRAMP, so ERM and framework work share one evidence base
- Exports a board pack that shows the trend and the exceptions, with a trail back to the underlying evidence for anyone who asks
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Enterprise risk mandate reference
What each US risk mandate actually demands, and who has to sign it
Published ERM tables almost always compare frameworks: COSO against ISO 31000 against NIST, component by component. That comparison never tells you what you owe anyone. This one runs on the artifact and the signature, because that is what an examiner, an auditor or a plaintiff asks to see, and it is the part a dashboard cannot produce.
| What actually forces ERM on you | Who it covers | The document it demands | Who has to approve or sign it | How often |
|---|---|---|---|---|
| OCC Heightened Standards, 12 CFR part 30, appendix D | National banks and federal savings associations averaging $50 billion or more in total consolidated assets, plus smaller banks whose parent controls a covered bank | A formal, written risk governance framework, and a written risk appetite statement carrying both qualitative components and quantitative limits | Designed by independent risk management, approved by the board or the board risk committee | Framework reviewed and updated at least annually; appetite statement approved at least annually |
| SEC Regulation S-K, Item 106(b) and 106(c) | Public companies filing an annual report with the SEC | A description of the processes for assessing, identifying and managing material cybersecurity risk, including whether they are integrated into the overall risk management system | The officers who certify the annual report, over board oversight described under Item 106(c) | Every annual report |
| NAIC ORSA, Model Act #505 as enacted by your state | US insurers writing more than $500 million, and groups writing more than $1 billion, in annual direct written and assumed premium | A confidential ORSA Summary Report covering the risk management framework, the risk assessment and group solvency | The insurer, filed with the lead state commissioner | At least annually |
| Sarbanes-Oxley section 404 | Public companies, with an external auditor attestation on top for accelerated filers | Management assessment of internal control over financial reporting, which is a controls conclusion and not a risk list | The CEO and the CFO personally | Annually, with the 10-K |
| COSO ERM 2017, adopted voluntarily | Anyone who tells a board, an auditor or a customer that they follow it | Evidence that twenty principles across five components are being achieved as outcomes | Nobody outside the organization. No accredited certification against it exists | Whatever cadence you set, and then have to defend |
| ISO 31000:2018, adopted voluntarily | Anyone, in any sector, at any size | Guidance only. It is not written for certification, so there is no certificate and no audit report to collect | Nobody. Individual training certificates exist and say nothing about the organization | Not applicable |
| Reputation risk as a required bank risk category | OCC and FDIC supervised institutions, until June 9, 2026 | Nothing now. The phrase was struck from appendix D and the agencies are barred from acting on it | Not applicable. You may still track it internally, but no examiner can hold you to it | Removed by final rule published April 10, 2026 at 91 FR 18279 |
Sources: 12 CFR part 30, appendix D as currently in force; the OCC and FDIC final rule Prohibition on the Use of Reputation Risk by Regulators, 91 FR 18279, published April 10, 2026 and effective June 9, 2026; 17 CFR 229.106; the NAIC Risk Management and Own Risk and Solvency Assessment Model Act #505 as adopted in your state; and the published descriptions of COSO ERM 2017 and ISO 31000:2018. Thresholds and filing duties turn on your charter, your regulator and your state, so confirm your own position with counsel. Scrutineer organizes readiness evidence and does not issue attestations or certifications.
Good questions
Questions about enterprise risk management
Keep reading
Guides that go deeper on enterprise risk
Best enterprise risk management software
How the four real categories of ERM tool differ, what each one can produce, and which fits a mid-market versus a bank buyer.
Read the guideBest GRC software
A working comparison of the GRC platforms that carry the control library your risk register should inherit from.
Read the guideHow to run a cybersecurity risk assessment
The assessment that feeds the technology rows of an enterprise register, step by step.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification