GRC Cockpit

Fewer apps to walk through, more grip on what is still open.

One management-level view across every risk, control and findings register your organisation keeps. The cockpit reads everywhere, translates to a single vocabulary and never writes into a source application. Built and hosted in the EU.

From adding up eight registers to one answer

Every GRC application keeps its own register, its own status words and its own audience. For someone working inside one app, that is fine. For a board member who wants to know what is open, it means walking through every app and adding up by hand.

Now

Each register speaks its own language

Open, in progress, ongoing, planned, settled: dozens of words are in use for the status of an action, and no two apps mean the same thing.

With GRC Cockpit

Three states, one meaning

Every status word is translated to open, in progress or closed. An unknown word counts as open, and the original word stays visible.

Now

The same finding counts twice

An audit finding handed over to the follow-up application sits in both registers, with two different statuses.

With GRC Cockpit

Deduplicated, with the count shown

The cockpit keeps the row where the workflow lives and reports how many it deduplicated. The management total adds up.

Now

An empty field looks green

A track that records no evidence shows a hundred percent in a spreadsheet, or zero. Neither says anything.

With GRC Cockpit

Honest blanks

What does not apply is shown as not applicable. A percentage without a denominator is not calculated. A control that is mapped but not tested yields no coverage.

Now

No yesterday

What came in this week and what was closed cannot be answered across the apps: every reading is a snapshot.

With GRC Cockpit

A register with memory

Every source row gets a fixed number. Each round, the cockpit records what is new, what changed in status, severity or owner, and what disappeared from the source.

A selection from GRC Cockpit

Click a thumbnail for that screen, or the image itself for the full-size view.

The key figures from fifteen databases, the Progress card with its formula and the risk profile from the Risk Heat Map alongside.1 / 6 shown

What you want to know about GRC Cockpit beforehand

What is GRC Cockpit?

GRC Cockpit is the management-level reading layer of the Audirium suite. It reads the risk, control, findings and planning registers of the applications your organisation works in, translates them into one vocabulary and shows them in six domains. The cockpit never writes into a source application and keeps its own register with history.

Who is GRC Cockpit for?

For board members, risk and compliance managers and heads of audit who want to know what is open across all registers without walking through eight applications. GRC Cockpit shows only the tracks in which the user holds a role in the source app.

What does GRC Cockpit actually do?

GRC Cockpit answers four questions: what is open, where do we stand per accountability track, what is overdue and which evidence is missing. It also places six risk registers on one map, calculates framework coverage from what has actually been tested, merges five calendars into one schedule and marks what is new since your last visit.

How does GRC Cockpit differ from a spreadsheet or a GRC package?

GRC Cockpit migrates nothing. The apps keep their own registers and report to the cockpit, which deduplicates, translates and records the differences each round. A percentage without a denominator is not calculated, direct and indirect testing are not added together, and every row links to the place where you edit it.

How do I know the figures in GRC Cockpit are right?

Every row shows where it comes from and which word the source app itself uses. GRC Cockpit reports how many findings it deduplicated, marks tracks that do not apply as not applicable, and never draws a point in the trend that did not come from the database.

Where is the data in GRC Cockpit stored?

GRC Cockpit runs on servers in the EU and reads only the databases of the organisation you are logged into. Its own register lives in a separate database per organisation. Which organisation you see follows from your session, never from anything you send along in a request.

Six domains across the whole GRC chain

The cockpit reads the registers of the Audirium applications your organisation works in and places them side by side: overview, risk, frameworks and controls, planning, context and governance. Editing happens in the source app; the cockpit links you there.

Four questions for the board

What is open, where do we stand per accountability track, what is overdue and which evidence is missing. Across thirteen tracks, most urgent first.

Direction over twelve weeks

Every key figure shows its trend over the last twelve weeks and the difference with the first week. A week without a measurement is a gap in the line, not an invented point.

Six risk registers on one map

Risks from Risk Heat Map, CRAFT, Privorium, TPRM, Flowmap and TRIAS, each normalised on its own scale. A ranking of three words is not sold as a number.

Framework coverage that counts fairly

Directly tested and indirectly reached through a cross-reference are never added together. Only a performed test counts, and every link says how it was made.

One calendar from five apps

Audit plan, testing calendar, file deadlines, model validations and supplier reviews in one schedule, overdue items first, and per subject when it was last examined.

Click through to the row

For Action Tracking, the Audit Suite and CRAFT you land on the finding itself, not on the front door of the app. The link label tells you beforehand what you will get.

New since your last visit

Rows that entered the register since your previous visit are marked. One filter shows only what is unread, and what you have read is remembered per user.

You see what you may see in the apps

A track appears only if you hold a role in that source app. Tracks you may not see are reported as a count, never silently dropped.

Built and hosted in the EU

Every organisation has its own separate database on servers in the EU. The cockpit reads only your organisation and writes solely to its own register.

From scattered registers to a management view in five steps

1

Keep working in your own apps

Nothing changes in the source applications. Risks, controls, findings and actions stay where they are.

2

The cockpit reads and translates

Every night and on every visit, the cockpit reads your organisation's registers and translates the status words to open, in progress and closed.

3

Apps report themselves

A new finding, action or test in a connected app lands in the register straight away, with a dedicated token per app as the gate.

4

Read the picture per domain

Open the boardroom for the narrative, the control room for the list, or one of the domains risk, frameworks, planning and context.

5

Annotate and click through

Give a finding a management priority and a note, then click through to the source app to act on it.

Want to know what is open without walking through eight apps?

Request a demo or get in touch for more information about GRC Cockpit for your organisation.