Scrutineer.ai

Scrutineer · Platform

Integrated risk management software and IRM platform

Six risk registers, six owners, six spreadsheets, and a board pack that reconciles none of them. That is the problem integrated risk management was invented to solve.

Scrutineer integrates the part that can genuinely be integrated: one control library, one evidence store, one set of owners, feeding every domain that has to report to somebody.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with integrated risk management

Gartner created the IRM category, then retired it as a market

The label almost every vendor in this lane uses came from Gartner. It published the first Magic Quadrant for Integrated Risk Management Solutions in 2018 and a second on July 15, 2019, written by analysts Jie Zhang and Brian Reed. There was never a third. In 2020 Gartner told the vendors it had evaluated that it was retiring the IRM market category, and the reported reason was not that the idea was wrong. It was that there is no single buying center for IRM with a consolidated view of risk and a consolidated budget, which makes integrated risk a strategy rather than a market. Gartner still runs an Integrated Risk Management page on Peer Insights, so a buyer who goes looking for the IRM Magic Quadrant today finds product reviews and no quadrant. What Gartner publishes instead is the Magic Quadrant for Governance, Risk and Compliance Tools, Assurance Leaders, and the 2025 edition is worth knowing about for one detail: the Visionaries quadrant was empty, the first time that has happened since Gartner started covering this market. The retirement itself is corroborated across industry reporting rather than posted publicly by Gartner, so treat the date as reported. The practical lesson for a buyer is simple. The category name on the website tells you nothing about the product. Ask instead which of your risk domains the platform can carry with real evidence behind them.

The US government already wrote the spec, and replaced it in December 2025

If you want a definition of integrated risk you can be measured against rather than sold, it exists and it is free. NIST IR 8286, Integrating Cybersecurity and Enterprise Risk Management, has been the working US definition since October 2020. It was withdrawn on December 18, 2025 and superseded by IR 8286 Revision 1, published December 2025, which means most integrated risk content on the web is now citing a withdrawn document. The rest of the series carries the actual mechanics: 8286A on identifying and estimating cybersecurity risk for ERM, 8286B on prioritizing it, 8286C on staging risks for governance oversight, 8286D on using business impact analysis to inform prioritization, plus SP 800-221 and SP 800-221A on governing ICT risk programs inside an enterprise risk portfolio. The method they describe is concrete rather than conceptual: keep a cybersecurity risk register at the system and organization level, then roll it up into an enterprise risk profile. NIST CSF 2.0, published February 26, 2024 as NIST CSWP 29, made the same idea testable. Its new GOVERN function includes GV.RM-03, which reads: cybersecurity risk management activities and outcomes are included in enterprise risk management processes. GV.RM-02 asks for written risk appetite and tolerance statements. GV.RM-07 asks that strategic opportunities, meaning positive risks, be included in the discussion, which almost no risk register in the wild does. Federal agencies have carried a version of this since OMB Circular A-123 was revised in 2016 and required an ERM capability and an annual risk profile.

Integration breaks at the unit of measure, not at the software

Every serious standards body says integrate. ISO 31000:2018 makes it the first of its eight principles: risk management is an integral part of all organizational activities, including governance, planning, reporting and decision making. COSO published its 2017 enterprise risk management framework under the subtitle Integrating with Strategy and Performance. Gartner defines IRM as a set of six attributes, strategy, assessment, response, communication and reporting, monitoring, and technology, and says all six have to run from the business unit up to the C-suite. None of that is controversial, and none of it is where programs fail. They fail at arithmetic. A regulatory obligation is binary: the written program exists or it does not. An operational loss is a dollar distribution with a fat tail. A cybersecurity control is a pass or a fail against a criterion on a date. A vendor is a tier. Average those four into one enterprise risk score and you have destroyed the only useful fact in each of them, which is why the single number on the board slide is usually the least trustworthy object in the pack. What genuinely integrates is the layer underneath the scores. One control, evidenced once, satisfying four owners and four different outside audiences. One register with one set of owners and due dates. Then report each domain in its own unit, side by side, on the same page. That is achievable this quarter. A single enterprise risk number is not, and a platform that promises one is quietly adding things that cannot be added.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Keeps one control library behind every domain, so a single access review evidences SOX 404, SOC 2 and ISO 27001 at once instead of three separate times
  • Holds one register with real owners, due dates and status, and lets each domain report in its own unit instead of forcing everything onto a common score
  • Carries NIST CSF 2.0 GOVERN outcomes, including GV.RM-03, as controls you can evidence rather than a slide asserting that risk is integrated
  • Rolls system-level and vendor-level risk up into an enterprise view the way the NIST IR 8286 series describes, without anyone retyping a register
  • Tracks written risk appetite and tolerance statements against the decisions actually taken, so the appetite document stops being decorative
  • Puts third-party and fourth-party risk in the same register as internal risk, because that is where most enterprise exposure now sits
  • Produces the dated, approved artifact each audience asks for: control matrices for auditors, a risk profile for the board, completed questionnaires for customers
  • Shows which risks have no control behind them and which controls have no current evidence, which is the honest version of a maturity score
INTEGRATED RISK MANAGEMENT readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Integrated risk reference

The domains an IRM platform claims to unify, and why each one resists the roll-up

Most comparisons of integrated risk management define GRC, IRM and ERM against each other. That is a vocabulary problem, not a buying problem. What actually decides whether integration works is who owns each domain, who outside the company asks for it, which artifact it has to produce, and what unit that artifact is measured in. Domains that share a unit merge. Domains that do not, will not.

Risk domain Who owns it inside Who asks for it from outside Artifact it has to produce Why it resists the enterprise roll-up
Cybersecurity and IT risk Security lead or CISO SOC 2 and ISO 27001 auditors, enterprise customers, and CSF 2.0 GV.RM-03 A control set with dated evidence, plus a cybersecurity risk register Measured pass or fail against a criterion, so it carries no dollar value to add to anything else
Third-party and vendor risk Vendor risk, security or procurement Enterprise customers, and bank examiners under the 2023 interagency guidance A vendor inventory with tiers, dated assessments and contract terms The population changes weekly, so a quarterly enterprise roll-up is stale the day it is published
Regulatory compliance Compliance officer or general counsel The specific regulator: HHS OCR, the SEC, NYDFS, state attorneys general A written program, policies, training records and signed attestations Obligations are binary, and scoring a binary obligation on a five point heat map deletes the only fact that matters
Financial reporting and ICFR Controller and internal audit The external auditor and the SEC, under SOX 404 Management assertion on internal control plus ITGC testing evidence It runs on the fiscal calendar and the auditor testing plan, a clock no other domain shares
Privacy and data protection Privacy lead, often the compliance officer wearing a second hat State attorneys general, the CPPA, and customers through data processing agreements Records of processing, assessments, and a defensible response clock for individual requests Measured in statutory deadlines and individual rights, not in likelihood times impact
Operational risk The business unit in theory, nobody in practice Bank and insurance regulators. Outside those sectors, no external party ever asks Loss event data and risk and control self-assessments The domain with the least tooling and no outside forcing function, so it decays first and takes the integration story with it
Enterprise and strategic risk The board and the chief executive The board itself, rating agencies, and OMB Circular A-123 for federal agencies A risk profile or top risk report, reviewed annually Qualitative and annual, so everything beneath it is too granular to aggregate upward without inventing a scale

The operational risk row is the one to test a vendor on. Every other domain here has an outside party that will eventually ask for the artifact, and that pressure is what keeps the work honest. Operational risk, outside banking and insurance, has none. If a platform cannot tell you who will ask for that output and when, your integrated program will quietly become five working domains plus an empty module within a year.

Good questions

Questions about integrated risk management

Integrated risk management is the practice of running cybersecurity, third-party, compliance, financial reporting, privacy, operational and strategic risk off one set of controls, owners and evidence rather than in separate silos. Gartner, which coined the term, describes it through six attributes: strategy, assessment, response, communication and reporting, monitoring, and technology.
Integrated risk management software is a platform that holds one control library, one risk register and one evidence store, and then serves several risk domains from them. In practice the useful ones share controls and evidence across domains and report each domain in its own unit. The weak ones just put six modules behind one login.
GRC describes the disciplines you run, governance, risk and compliance, and it grew out of audit and compliance departments. IRM was Gartner language for the same work organized around risk rather than around compliance, with more emphasis on operational and strategic risk. The buying reality: most products sold as IRM and most sold as GRC now overlap heavily, so compare capabilities and not labels.
No. ERM is the board-level discipline of identifying and reporting the risks that could stop the company achieving its objectives, and its artifact is a risk profile or top risk report. IRM is the operating layer beneath that, covering IT, vendor, compliance and operational risk in enough detail to be actionable. A good IRM program feeds ERM; it does not replace it.
Gartner names strategy, assessment, response, communication and reporting, monitoring, and technology. Strategy is the framework aligned to business objectives. Assessment identifies and prioritizes risk across functions. Response implements mitigation with named accountability. Communication and reporting informs stakeholders. Monitoring tracks whether governance objectives and ownership actually hold. Technology unifies the risk data.
No. Gartner published an IRM Magic Quadrant in 2018 and again on July 15, 2019, then retired the IRM market category in 2020, reportedly because there is no single buying center for IRM with a consolidated budget. Gartner Peer Insights still carries an Integrated Risk Management market page, and the current Magic Quadrant in this space covers Governance, Risk and Compliance Tools for assurance leaders.
An IRM platform is a system of record for risk: a control library mapped across frameworks, a register of risks with owners and due dates, an evidence store, and reporting that reaches both an auditor and a board. The test of whether it deserves the name is whether one piece of evidence can satisfy several domains at once, or whether each module quietly keeps its own copy.
Published pricing in this category is rare and the range is genuinely wide, so anyone quoting you a single figure is guessing. The drivers that move the number are the count of frameworks in scope, the number of vendors in the register, how many integrations pull evidence automatically, whether risk quantification is included, and how much implementation help you buy. Ask for pricing against your actual scope and confirm what renewal looks like.
The measurable ones are evidence reuse, fewer duplicate control tests, one owner per control instead of one per department, and a board report assembled from live data rather than retyped from spreadsheets. The benefit most often claimed and least often delivered is a single enterprise risk score, because the domains being combined are measured in incompatible units.
Start with the control library, not the risk register. Map the controls you already run to every framework and obligation they satisfy, so evidence collected once counts several times. Then add risks on top with named owners and dates. Pick the two domains with real outside pressure first, usually cybersecurity and vendor risk, prove the reuse, and only then extend to operational and strategic risk.
IT risk management covers technology risk: systems, access, change, availability and the controls behind them. IRM is the wider program that takes IT risk as one input alongside vendor, compliance, privacy, operational and strategic risk. Gartner ran a separate Magic Quadrant for IT Risk Management after the IRM one was retired, which tells you the market really does buy those separately.
Effectively, yes. NIST IR 8286, Integrating Cybersecurity and Enterprise Risk Management, plus 8286A through 8286D and SP 800-221 and 800-221A describe how to keep cybersecurity risk registers and roll them into an enterprise risk profile. IR 8286 was withdrawn on December 18, 2025 and replaced by Revision 1. NIST CSF 2.0 adds GV.RM-03, which requires cybersecurity risk outcomes to be included in enterprise risk management processes.
A spreadsheet works while one person owns every domain and no outside party audits the result. It stops working the moment two people have to agree on the same control, or an auditor asks when a piece of evidence was collected and by whom. The signal to move is not company size, it is the first time you cannot answer who owns this control and when it was last tested without asking around.

Keep reading

Guides that go deeper on integrated risk

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification