Fewer apps to walk through, more grip on what is still open.
One management-level view across every risk, control and findings register your organisation keeps. The cockpit reads everywhere, translates to a single vocabulary and never writes into a source application. Built and hosted in the EU.
From now to next
From adding up eight registers to one answer
Every GRC application keeps its own register, its own status words and its own audience. For someone working inside one app, that is fine. For a board member who wants to know what is open, it means walking through every app and adding up by hand.
Each register speaks its own language
Open, in progress, ongoing, planned, settled: dozens of words are in use for the status of an action, and no two apps mean the same thing.
Three states, one meaning
Every status word is translated to open, in progress or closed. An unknown word counts as open, and the original word stays visible.
The same finding counts twice
An audit finding handed over to the follow-up application sits in both registers, with two different statuses.
Deduplicated, with the count shown
The cockpit keeps the row where the workflow lives and reports how many it deduplicated. The management total adds up.
An empty field looks green
A track that records no evidence shows a hundred percent in a spreadsheet, or zero. Neither says anything.
Honest blanks
What does not apply is shown as not applicable. A percentage without a denominator is not calculated. A control that is mapped but not tested yields no coverage.
No yesterday
What came in this week and what was closed cannot be answered across the apps: every reading is a snapshot.
A register with memory
Every source row gets a fixed number. Each round, the cockpit records what is new, what changed in status, severity or owner, and what disappeared from the source.
This is what it looks like
A selection from GRC Cockpit
Click a thumbnail for that screen, or the image itself for the full-size view.
Frequently asked questions
What you want to know about GRC Cockpit beforehand
What is GRC Cockpit?
GRC Cockpit is the management-level reading layer of the Audirium suite. It reads the risk, control, findings and planning registers of the applications your organisation works in, translates them into one vocabulary and shows them in six domains. The cockpit never writes into a source application and keeps its own register with history.
Who is GRC Cockpit for?
For board members, risk and compliance managers and heads of audit who want to know what is open across all registers without walking through eight applications. GRC Cockpit shows only the tracks in which the user holds a role in the source app.
What does GRC Cockpit actually do?
GRC Cockpit answers four questions: what is open, where do we stand per accountability track, what is overdue and which evidence is missing. It also places six risk registers on one map, calculates framework coverage from what has actually been tested, merges five calendars into one schedule and marks what is new since your last visit.
How does GRC Cockpit differ from a spreadsheet or a GRC package?
GRC Cockpit migrates nothing. The apps keep their own registers and report to the cockpit, which deduplicates, translates and records the differences each round. A percentage without a denominator is not calculated, direct and indirect testing are not added together, and every row links to the place where you edit it.
How do I know the figures in GRC Cockpit are right?
Every row shows where it comes from and which word the source app itself uses. GRC Cockpit reports how many findings it deduplicated, marks tracks that do not apply as not applicable, and never draws a point in the trend that did not come from the database.
Where is the data in GRC Cockpit stored?
GRC Cockpit runs on servers in the EU and reads only the databases of the organisation you are logged into. Its own register lives in a separate database per organisation. Which organisation you see follows from your session, never from anything you send along in a request.
What GRC Cockpit offers
Six domains across the whole GRC chain
The cockpit reads the registers of the Audirium applications your organisation works in and places them side by side: overview, risk, frameworks and controls, planning, context and governance. Editing happens in the source app; the cockpit links you there.
Four questions for the board
What is open, where do we stand per accountability track, what is overdue and which evidence is missing. Across thirteen tracks, most urgent first.
Direction over twelve weeks
Every key figure shows its trend over the last twelve weeks and the difference with the first week. A week without a measurement is a gap in the line, not an invented point.
Six risk registers on one map
Risks from Risk Heat Map, CRAFT, Privorium, TPRM, Flowmap and TRIAS, each normalised on its own scale. A ranking of three words is not sold as a number.
Framework coverage that counts fairly
Directly tested and indirectly reached through a cross-reference are never added together. Only a performed test counts, and every link says how it was made.
One calendar from five apps
Audit plan, testing calendar, file deadlines, model validations and supplier reviews in one schedule, overdue items first, and per subject when it was last examined.
Click through to the row
For Action Tracking, the Audit Suite and CRAFT you land on the finding itself, not on the front door of the app. The link label tells you beforehand what you will get.
New since your last visit
Rows that entered the register since your previous visit are marked. One filter shows only what is unread, and what you have read is remembered per user.
You see what you may see in the apps
A track appears only if you hold a role in that source app. Tracks you may not see are reported as a count, never silently dropped.
Built and hosted in the EU
Every organisation has its own separate database on servers in the EU. The cockpit reads only your organisation and writes solely to its own register.
How it works
From scattered registers to a management view in five steps
Keep working in your own apps
Nothing changes in the source applications. Risks, controls, findings and actions stay where they are.
The cockpit reads and translates
Every night and on every visit, the cockpit reads your organisation's registers and translates the status words to open, in progress and closed.
Apps report themselves
A new finding, action or test in a connected app lands in the register straight away, with a dedicated token per app as the gate.
Read the picture per domain
Open the boardroom for the narrative, the control room for the list, or one of the domains risk, frameworks, planning and context.
Annotate and click through
Give a finding a management priority and a note, then click through to the source app to act on it.
Want to know what is open without walking through eight apps?
Request a demo or get in touch for more information about GRC Cockpit for your organisation.