Scrutineer.ai

Scrutineer · Platform

Enterprise risk management software and ERM risk registers

Your board wants one view of enterprise risk. The evidence lives in eleven places, and the register gets refreshed the week before the meeting by whoever has the spreadsheet.

Scrutineer keeps the enterprise risk register on the same controls and evidence your framework work already runs on, so a rating changes when the control behind it changes.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with enterprise risk management

Reputation risk left the federal bank rulebook on June 9, 2026

Almost every published risk taxonomy, register template and ERM product demo still opens with a reputation risk category. For OCC and FDIC supervised institutions that category no longer sits in the rule. On April 10, 2026 the two agencies published a joint final rule, Prohibition on the Use of Reputation Risk by Regulators, at 91 FR 18279, effective June 9, 2026. One of its amendments changes the risk categories a covered bank framework has to cover in 12 CFR part 30, appendix D, section II, paragraph (B), by removing the phrase "compliance risk, strategic risk, and reputation risk" and adding in its place "compliance risk, and strategic risk". The list now reads credit risk, interest rate risk, liquidity risk, price risk, operational risk, compliance risk, and strategic risk. Seven categories, not eight. The rule also stops the agencies criticizing or downgrading an institution on that basis, and it defines reputation risk to catch relabeling: any risk, regardless of how the risk is labeled by the institution or regulators, that an activity could negatively impact public perception for reasons not clearly and directly related to financial or operational condition. Nothing stops a bank tracking reputation internally. What changed is that no examiner can hold you to it, and appendix D no longer asks for it.

No US mandate asks you for a risk register. Each one asks for a signed document

The category sells registers, heat maps and dashboards. Read the rules and none of them name any of those. Appendix D asks a covered bank for a formal, written risk governance framework designed by independent risk management and approved by the board or the board risk committee, plus a comprehensive written statement articulating risk appetite that contains both qualitative components and quantitative limits, reviewed and approved at least annually. The SEC asks public companies, in Item 106(b) of Regulation S-K, to describe their processes for assessing, identifying and managing material risks from cybersecurity threats in sufficient detail for a reasonable investor to understand those processes, and specifically whether those processes have been integrated into the registrant overall risk management system or processes. State insurance regulators want a confidential ORSA Summary Report once a year. In all three the register is an input. The deliverable is a narrative that a named human approved on a fixed date, which is why the hard part of ERM tooling is provenance and sign-off, not visualization.

There is no certification in either framework the whole category is built on

Buying committees ask vendors for COSO or ISO 31000 certification, and plenty of marketing implies it exists. It does not. The COSO 2017 framework, Enterprise Risk Management: Integrating with Strategy and Performance, sets out twenty principles across five components: governance and culture, strategy and objective-setting, performance, review and revision, and information, communication and reporting. Those principles are written as outcomes an organization achieves, not clauses an auditor ticks, and no accredited body certifies a company against them. ISO 31000:2018 is published as guidelines and is not written for certification purposes, so no certificate exists for an organization either. Individual certificate programs from training providers do exist and are a different thing: they say something about a person, nothing about a program. The practical consequence is that nobody will ever hand you paper proving your ERM program is adequate. What gets tested instead is the written framework, the appetite statement, the minutes, and whether the risks you wrote down match the controls you actually operate.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Keeps one enterprise risk register rather than four, with each risk tied to the specific controls that are supposed to reduce it
  • Recalculates a residual rating when the evidence behind a control goes stale, so the register ages honestly instead of silently
  • Carries the risk categories a US bank framework actually names: credit, interest rate, liquidity, price, operational, compliance and strategic
  • Records who approved the risk appetite statement and when, because approval and date are what an examiner asks for first
  • Links vendor and third-party findings straight into enterprise operational risk, so supplier failures stop living in a separate tool
  • Produces the cybersecurity risk narrative Item 106(b) asks for, including how the process is integrated into the wider risk system
  • Maps the same control library to SOC 2, ISO 27001, HIPAA, PCI DSS and FedRAMP, so ERM and framework work share one evidence base
  • Exports a board pack that shows the trend and the exceptions, with a trail back to the underlying evidence for anyone who asks
ENTERPRISE RISK MANAGEMENT readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Enterprise risk mandate reference

What each US risk mandate actually demands, and who has to sign it

Published ERM tables almost always compare frameworks: COSO against ISO 31000 against NIST, component by component. That comparison never tells you what you owe anyone. This one runs on the artifact and the signature, because that is what an examiner, an auditor or a plaintiff asks to see, and it is the part a dashboard cannot produce.

What actually forces ERM on you Who it covers The document it demands Who has to approve or sign it How often
OCC Heightened Standards, 12 CFR part 30, appendix D National banks and federal savings associations averaging $50 billion or more in total consolidated assets, plus smaller banks whose parent controls a covered bank A formal, written risk governance framework, and a written risk appetite statement carrying both qualitative components and quantitative limits Designed by independent risk management, approved by the board or the board risk committee Framework reviewed and updated at least annually; appetite statement approved at least annually
SEC Regulation S-K, Item 106(b) and 106(c) Public companies filing an annual report with the SEC A description of the processes for assessing, identifying and managing material cybersecurity risk, including whether they are integrated into the overall risk management system The officers who certify the annual report, over board oversight described under Item 106(c) Every annual report
NAIC ORSA, Model Act #505 as enacted by your state US insurers writing more than $500 million, and groups writing more than $1 billion, in annual direct written and assumed premium A confidential ORSA Summary Report covering the risk management framework, the risk assessment and group solvency The insurer, filed with the lead state commissioner At least annually
Sarbanes-Oxley section 404 Public companies, with an external auditor attestation on top for accelerated filers Management assessment of internal control over financial reporting, which is a controls conclusion and not a risk list The CEO and the CFO personally Annually, with the 10-K
COSO ERM 2017, adopted voluntarily Anyone who tells a board, an auditor or a customer that they follow it Evidence that twenty principles across five components are being achieved as outcomes Nobody outside the organization. No accredited certification against it exists Whatever cadence you set, and then have to defend
ISO 31000:2018, adopted voluntarily Anyone, in any sector, at any size Guidance only. It is not written for certification, so there is no certificate and no audit report to collect Nobody. Individual training certificates exist and say nothing about the organization Not applicable
Reputation risk as a required bank risk category OCC and FDIC supervised institutions, until June 9, 2026 Nothing now. The phrase was struck from appendix D and the agencies are barred from acting on it Not applicable. You may still track it internally, but no examiner can hold you to it Removed by final rule published April 10, 2026 at 91 FR 18279

Sources: 12 CFR part 30, appendix D as currently in force; the OCC and FDIC final rule Prohibition on the Use of Reputation Risk by Regulators, 91 FR 18279, published April 10, 2026 and effective June 9, 2026; 17 CFR 229.106; the NAIC Risk Management and Own Risk and Solvency Assessment Model Act #505 as adopted in your state; and the published descriptions of COSO ERM 2017 and ISO 31000:2018. Thresholds and filing duties turn on your charter, your regulator and your state, so confirm your own position with counsel. Scrutineer organizes readiness evidence and does not issue attestations or certifications.

Good questions

Questions about enterprise risk management

Enterprise risk management software is a system of record for the risks an organization has decided to track at company level, the controls meant to reduce them, the owners accountable for each one, and the evidence that any of it works. Good ERM tools produce the written framework, appetite statement and board reporting that regulators and auditors actually ask to see.
ERM is the discipline of identifying and rating risk across the whole enterprise and reporting it to the board. GRC is the operating machinery underneath: policies, controls, frameworks, evidence and issues. In practice ERM answers what could hurt us and how much, while GRC answers what we do about it and whether it worked. They share a control library or they drift apart.
Risk management is usually run inside one function: credit risk in lending, security risk in IT, safety risk in operations. Enterprise risk management aggregates those views so a board can see the total position, compare risks against one appetite statement, and spot the ones that only look small inside a single department. The aggregation is the whole point.
ERM stands for enterprise risk management. In software listings it also gets confused with ERP, which stands for enterprise resource planning and is a completely different category. ERP runs finance, supply chain and HR transactions. ERM runs the risk register, risk appetite, control linkage and board reporting on top of whatever transactional systems you already have.
Not as a supervisory requirement. A joint OCC and FDIC final rule published April 10, 2026 at 91 FR 18279 and effective June 9, 2026 removed reputation risk from the risk categories in 12 CFR part 30, appendix D and prohibits the agencies from taking adverse action on that basis. A bank may still track reputation internally, but examiners can no longer act on it.
The COSO 2017 framework has five components: governance and culture, strategy and objective-setting, performance, review and revision, and information, communication and reporting. Twenty principles sit across those five. They are written as outcomes to achieve rather than controls to test, which is why two organizations can both follow COSO and look nothing alike.
No. ISO 31000:2018 is published as guidelines and is not intended for certification purposes, so no accredited body issues an ISO 31000 certificate to an organization. Individual training providers offer personal certificates to risk practitioners, which is a credential for a person and not evidence about a program. If you need a certifiable standard, ISO 27001 is one.
In the US it depends on charter and size rather than on any general ERM law. Large national banks fall under the OCC Heightened Standards, insurers above the ORSA premium thresholds must file an ORSA Summary Report, and every SEC registrant has to describe its cybersecurity risk processes and board oversight in the annual report. Everyone else adopts ERM voluntarily.
For a covered bank, appendix D requires both qualitative components and quantitative limits. The qualitative part describes a safe and sound risk culture and how the bank assesses and accepts risks that are hard to quantify. The quantitative part sets limits addressing earnings, capital and liquidity, informed by stress testing, at levels that trigger action before buffers are threatened.
A risk register is the list of risks an organization is tracking, each with a description, an owner, an inherent rating, the controls applied, a residual rating and a review date. It is an input to reporting rather than a deliverable in itself. The test of a register is whether the residual ratings change when the underlying controls or evidence change.
Pricing is rarely public in this category and usually lands as an annual subscription scaled by modules, users and entity count, with implementation quoted separately. Legacy enterprise GRC suites sit at the top of that range, integrated compliance platforms below it. Ask any vendor what happens to the price when you add a framework, an entity or an auditor seat.
Usually not two systems. If your GRC platform already holds the control library, evidence and issues, the cheaper path is to add the enterprise register on top of that same data so ratings inherit from real control state. Buying a separate ERM tool normally means someone re-keys the same risks twice and the two copies disagree within a quarter.
They sound alike and solve unrelated problems. ERP, enterprise resource planning, runs transactions: general ledger, procurement, inventory, payroll. ERM, enterprise risk management, runs the register of things that could go wrong, the appetite against which they are judged, and the reporting to the board. An ERP is a source of risk data. It is not an ERM system.

Keep reading

Guides that go deeper on enterprise risk

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification