Scrutineer · Platform
Integrated risk management software and IRM platform
Six risk registers, six owners, six spreadsheets, and a board pack that reconciles none of them. That is the problem integrated risk management was invented to solve.
Scrutineer integrates the part that can genuinely be integrated: one control library, one evidence store, one set of owners, feeding every domain that has to report to somebody.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with integrated risk management
Gartner created the IRM category, then retired it as a market
The label almost every vendor in this lane uses came from Gartner. It published the first Magic Quadrant for Integrated Risk Management Solutions in 2018 and a second on July 15, 2019, written by analysts Jie Zhang and Brian Reed. There was never a third. In 2020 Gartner told the vendors it had evaluated that it was retiring the IRM market category, and the reported reason was not that the idea was wrong. It was that there is no single buying center for IRM with a consolidated view of risk and a consolidated budget, which makes integrated risk a strategy rather than a market. Gartner still runs an Integrated Risk Management page on Peer Insights, so a buyer who goes looking for the IRM Magic Quadrant today finds product reviews and no quadrant. What Gartner publishes instead is the Magic Quadrant for Governance, Risk and Compliance Tools, Assurance Leaders, and the 2025 edition is worth knowing about for one detail: the Visionaries quadrant was empty, the first time that has happened since Gartner started covering this market. The retirement itself is corroborated across industry reporting rather than posted publicly by Gartner, so treat the date as reported. The practical lesson for a buyer is simple. The category name on the website tells you nothing about the product. Ask instead which of your risk domains the platform can carry with real evidence behind them.
The US government already wrote the spec, and replaced it in December 2025
If you want a definition of integrated risk you can be measured against rather than sold, it exists and it is free. NIST IR 8286, Integrating Cybersecurity and Enterprise Risk Management, has been the working US definition since October 2020. It was withdrawn on December 18, 2025 and superseded by IR 8286 Revision 1, published December 2025, which means most integrated risk content on the web is now citing a withdrawn document. The rest of the series carries the actual mechanics: 8286A on identifying and estimating cybersecurity risk for ERM, 8286B on prioritizing it, 8286C on staging risks for governance oversight, 8286D on using business impact analysis to inform prioritization, plus SP 800-221 and SP 800-221A on governing ICT risk programs inside an enterprise risk portfolio. The method they describe is concrete rather than conceptual: keep a cybersecurity risk register at the system and organization level, then roll it up into an enterprise risk profile. NIST CSF 2.0, published February 26, 2024 as NIST CSWP 29, made the same idea testable. Its new GOVERN function includes GV.RM-03, which reads: cybersecurity risk management activities and outcomes are included in enterprise risk management processes. GV.RM-02 asks for written risk appetite and tolerance statements. GV.RM-07 asks that strategic opportunities, meaning positive risks, be included in the discussion, which almost no risk register in the wild does. Federal agencies have carried a version of this since OMB Circular A-123 was revised in 2016 and required an ERM capability and an annual risk profile.
Integration breaks at the unit of measure, not at the software
Every serious standards body says integrate. ISO 31000:2018 makes it the first of its eight principles: risk management is an integral part of all organizational activities, including governance, planning, reporting and decision making. COSO published its 2017 enterprise risk management framework under the subtitle Integrating with Strategy and Performance. Gartner defines IRM as a set of six attributes, strategy, assessment, response, communication and reporting, monitoring, and technology, and says all six have to run from the business unit up to the C-suite. None of that is controversial, and none of it is where programs fail. They fail at arithmetic. A regulatory obligation is binary: the written program exists or it does not. An operational loss is a dollar distribution with a fat tail. A cybersecurity control is a pass or a fail against a criterion on a date. A vendor is a tier. Average those four into one enterprise risk score and you have destroyed the only useful fact in each of them, which is why the single number on the board slide is usually the least trustworthy object in the pack. What genuinely integrates is the layer underneath the scores. One control, evidenced once, satisfying four owners and four different outside audiences. One register with one set of owners and due dates. Then report each domain in its own unit, side by side, on the same page. That is achievable this quarter. A single enterprise risk number is not, and a platform that promises one is quietly adding things that cannot be added.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Keeps one control library behind every domain, so a single access review evidences SOX 404, SOC 2 and ISO 27001 at once instead of three separate times
- Holds one register with real owners, due dates and status, and lets each domain report in its own unit instead of forcing everything onto a common score
- Carries NIST CSF 2.0 GOVERN outcomes, including GV.RM-03, as controls you can evidence rather than a slide asserting that risk is integrated
- Rolls system-level and vendor-level risk up into an enterprise view the way the NIST IR 8286 series describes, without anyone retyping a register
- Tracks written risk appetite and tolerance statements against the decisions actually taken, so the appetite document stops being decorative
- Puts third-party and fourth-party risk in the same register as internal risk, because that is where most enterprise exposure now sits
- Produces the dated, approved artifact each audience asks for: control matrices for auditors, a risk profile for the board, completed questionnaires for customers
- Shows which risks have no control behind them and which controls have no current evidence, which is the honest version of a maturity score
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Integrated risk reference
The domains an IRM platform claims to unify, and why each one resists the roll-up
Most comparisons of integrated risk management define GRC, IRM and ERM against each other. That is a vocabulary problem, not a buying problem. What actually decides whether integration works is who owns each domain, who outside the company asks for it, which artifact it has to produce, and what unit that artifact is measured in. Domains that share a unit merge. Domains that do not, will not.
| Risk domain | Who owns it inside | Who asks for it from outside | Artifact it has to produce | Why it resists the enterprise roll-up |
|---|---|---|---|---|
| Cybersecurity and IT risk | Security lead or CISO | SOC 2 and ISO 27001 auditors, enterprise customers, and CSF 2.0 GV.RM-03 | A control set with dated evidence, plus a cybersecurity risk register | Measured pass or fail against a criterion, so it carries no dollar value to add to anything else |
| Third-party and vendor risk | Vendor risk, security or procurement | Enterprise customers, and bank examiners under the 2023 interagency guidance | A vendor inventory with tiers, dated assessments and contract terms | The population changes weekly, so a quarterly enterprise roll-up is stale the day it is published |
| Regulatory compliance | Compliance officer or general counsel | The specific regulator: HHS OCR, the SEC, NYDFS, state attorneys general | A written program, policies, training records and signed attestations | Obligations are binary, and scoring a binary obligation on a five point heat map deletes the only fact that matters |
| Financial reporting and ICFR | Controller and internal audit | The external auditor and the SEC, under SOX 404 | Management assertion on internal control plus ITGC testing evidence | It runs on the fiscal calendar and the auditor testing plan, a clock no other domain shares |
| Privacy and data protection | Privacy lead, often the compliance officer wearing a second hat | State attorneys general, the CPPA, and customers through data processing agreements | Records of processing, assessments, and a defensible response clock for individual requests | Measured in statutory deadlines and individual rights, not in likelihood times impact |
| Operational risk | The business unit in theory, nobody in practice | Bank and insurance regulators. Outside those sectors, no external party ever asks | Loss event data and risk and control self-assessments | The domain with the least tooling and no outside forcing function, so it decays first and takes the integration story with it |
| Enterprise and strategic risk | The board and the chief executive | The board itself, rating agencies, and OMB Circular A-123 for federal agencies | A risk profile or top risk report, reviewed annually | Qualitative and annual, so everything beneath it is too granular to aggregate upward without inventing a scale |
The operational risk row is the one to test a vendor on. Every other domain here has an outside party that will eventually ask for the artifact, and that pressure is what keeps the work honest. Operational risk, outside banking and insurance, has none. If a platform cannot tell you who will ask for that output and when, your integrated program will quietly become five working domains plus an empty module within a year.
Good questions
Questions about integrated risk management
Keep reading
Guides that go deeper on integrated risk
Best integrated risk management software
The four kinds of product sold as IRM, what each one can actually produce, and which fits a mid-market team versus a bank.
Read the guideBest GRC software
A working comparison of the GRC platforms that carry the control library an integrated program has to inherit from.
Read the guideBest enterprise risk management software
The board-level layer above IRM: which tools produce a risk profile a director will actually read.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification