From process drawing to risk and control matrix, in a single place.
Draw the process, record the controls per step with code, frequency and evidence, and approve the process under the four-eyes principle. The process manual and the RCM come from the same source. Built and hosted in the EU.
From now to next
Fewer loose drawings, a firmer grip on process control
Process descriptions live in a drawing tool, the controls in a spreadsheet and the manual in Word. Every change pulls them apart, and nobody knows which version applies.
Drawing and RCM live apart
The flowchart sits in Visio, the risk and control matrix in Excel. A new step in the chart reaches the matrix later, or never.
A control belongs to a step
Every control hangs on a process step in the drawing and carries its own RCM fields: code, type, execution, frequency, key control, objective and evidence.
Which version applies?
A manual circulates in several versions. Whether the process owner ever approved it cannot be traced.
Draft, under review, approved
A process has a status. Approval follows the four-eyes principle, with a review date, and readers always see the approved version.
The manual is an afterthought
After every change someone rewrites the Word document, and the RCM for the auditor is compiled separately.
Manual and RCM from one source
Export a process description or a complete manual to Word and the risk and control matrix to Excel, in your organisation's house style.
No view of the gaps
Which steps have no control, which key controls lack evidence, which processes have not been touched for a year? You find out during the audit.
A cockpit that counts the gaps
One figure for process control, the open items ranked by severity and per person what carries their name. Every number drills down to the rows it refers to.
This is what it looks like
A selection from Flowmap
Click a thumbnail for that screen, or the image itself for the full-size view.
Frequently asked questions
What you want to know about Flowmap beforehand
What is Flowmap?
Flowmap is a web application by Audirium for drawing business processes while documenting internal control at the same time. You attach controls with the fields of a risk and control matrix to every process step. Processes sit in a process landscape, are approved under the four-eyes principle and can be exported as a manual in Word and as an RCM in Excel.
Who is Flowmap for?
Flowmap is built for process owners who want to describe their process, for risk managers and compliance officers who record controls at RCM level, and for internal auditors who need a current risk and control matrix for their testing. Consultants use Flowmap to turn existing manuals into a maintainable process register.
What does Flowmap do in practice?
You draw processes in a draw.io-based editor, record controls per process step with code, frequency, execution and evidence, and organise processes in a landscape from L0 to L3. A process has a status and is approved under the four-eyes principle. Flowmap imports manuals and BPMN 2.0 files and exports to Word and Excel.
How does Flowmap differ from Visio plus a spreadsheet?
In Flowmap the drawing and the risk and control matrix are one data source. A control belongs to a process step, so a step without a control stands out immediately in the cockpit. A process has a status with an approved version and a version history. The manual and the RCM are exports of that source, not documents maintained separately.
How does AI work in Flowmap, and who decides?
AI in Flowmap turns a text, image or manual into a draft diagram, suggests controls per process step that fit the whole process, and writes a process description in prose. Every result is a proposal in an editable window. Nothing is saved until a user adopts it, and Flowmap itself determines which steps lack a control.
How are data and hosting handled in Flowmap?
Flowmap runs on Audirium servers in the EU (Hetzner). Each organisation has its own separate database; other organisations cannot see your processes. Access is governed by roles for reading, editing and administration. Links with other Audirium apps go through a secured service route and never through direct access to each other's database.
What Flowmap offers
Process control you can show
Flowmap brings drawing, documenting and accountability together, so the process owner, the risk manager and the auditor look at the same source.
AI built in, not bolted on
AI turns a manual, a text or a photo of a flowchart into a diagram, suggests controls per step and drafts a process description. Everything stays a proposal: you choose what to adopt.
Drawing on draw.io
The editor runs on draw.io, hosted on our own servers. Swimlanes, process steps and decision points as you know them, without your diagram leaving the building.
Controls at RCM level
Each control has a code, type, execution, frequency, key control flag, control objective, assertions and evidence. The matrix shows every control in the organisation in one table, editable in place.
Process landscape L0-L3
Process areas, sub-areas and processes in a tree, classified as primary, supporting or steering. A step can itself be a sub-process.
Starter sets to begin with
Load five core processes with drawing and controls (from procure-to-pay to incident management) or a sector add-on, then adjust what does not fit. Nothing is ever overwritten.
Four-eyes approval
Whoever submitted the draft cannot approve it. The review window shows exactly what changed compared with the approved version.
Import manuals and BPMN
Import a Word, PDF or text file as a process tree, or a BPMN 2.0 file from Signavio, Camunda or ARIS. Re-import an updated BPMN file without losing your controls.
Connected to the suite
Have a control tested in PROOF, link a risk from Risk Heat Map and see which bowties use a control as a barrier. The result comes back on the control card.
Data sovereignty
A separate database per organisation, hosted in the EU. Roles for reading, editing and administration, and a version history that records who changed what.
How it works
From first sketch to approved process in six steps
Draw or import
Draw the process in the editor, load a starter set, or import a manual or BPMN file.
Record the controls
Select a step, add a control and fill in the RCM fields. Or adopt an AI suggestion.
Place it in the landscape
Hang the process under the right process area and assign a process owner.
Submit for review
Pick a reviewer and see what changed. The reviewer approves or rejects with an explanation.
Test and link
Send a control to PROOF for a test of design or operating effectiveness and link the risk from Risk Heat Map.
Export and account
Take the manual in Word and the RCM in Excel from the approved version, in your organisation's house style.
Your processes described, controlled and approved in one place?
Request a demo or get in touch for more information about Flowmap for your organisation.