Everything you need to managerisk, compliance and ESG
Risk, compliance, ESG, third-party risk and reporting — connected in one platform, so every signal feeds one view of your organisation. Explore the capabilities below, organised by what you need to manage.
One platform for enterprise risk, compliance and ESG
Explore the platform's capabilities — risk management, compliance, security, policy, third-party risk, ESG, assurance, reporting and AI assistance — all connected in one place.
A real-time executive view of your organisation's risk, compliance and trust posture, with recommended actions in one place.
Live trust score
One live score that captures your organisation's risk, compliance, ESG and vendor health.
The trust score combines Risk Score, Compliance Rate, ESG Progress, and Vendor Health into a single real-time indicator. Colour changes flag deterioration as it happens, and every hub shows it persistently.
- Weighted composite of GRC + ESG + vendor health
- Liquid-glass breathing animation (amber = warning, red = critical breach)
- Drill-down into any GTI sub-area on click
- Role-contextual lenses: Board → GTI Halo; Auditor → Evidence Lineage
- Real-time propagation from every entity change across the Nervous System
- Starter: composite score | Professional: full halo | Enterprise: role lenses
Financial risk quantification
ResidualVaR = Impact × Probability × (1 − ControlEffectiveness) — deterministic, audit-ready.
Every risk translates to a monetised, audit-ready financial exposure figure. The Confidence Engine (DataFreshness 30% + SourceReliability 40% + ModelCompleteness 30%) weights each score. Aging Factor raises priority 5% every 7 days unresolved.
- Deterministic VaR formula — no black-box AI inference
- Confidence Multiplier badge (0.0–1.0) on every Decision Card
- Aging Factor: +5% priority escalation per 7 days unresolved
- Financial exposure in £/$ alongside percentage risk score
- Full formula displayed for full regulatory explainability
- Cross-sector contagion VaR modelling for supply chain events
AI Prescriptive Decision Cards Engine
Every risk surfaces with [Approve] [Simulate] [Delegate] — one click to resolution.
Decision Cards replace static risk lists. Each card shows VaR score, Confidence Badge, Aging Indicator, and an AI Narrative synthesised for executive context. Decisions are stored in the immutable audit vault.
- Priority-sorted by ResidualVaR × AgingFactor
- AI Narrative Synthesis — board-ready context in one paragraph
- ⚡ EXT SIGNAL badge when geopolitical data adjusts probability
- [Approve] [Simulate] [Delegate] one-click executive actions
- Contextual Side Panel — vendors, controls & ESG impact on demand
- Every decision logged to immutable audit vault
External Signal Foresight Engine
Geopolitical & sanctions signals adjust VaR probability before internal data reflects it.
Global intelligence signals — geopolitical risk, market volatility, sanctions, ESG controversy — are wired to inject probability offsets into Decision Cards. Reg-Delta Visualisation highlights controls affected by new regulations in real time.
- Geopolitical, sanctions, and market volatility signal ingestion
- ESG controversy and adverse media feed monitoring
- Automated probability offset injection into affected VaR scores
- ⚡ EXT SIGNAL badge on every influenced Decision Card
- Reg-Delta Visualisation — new regulation → affected controls highlighted
- Enterprise exclusive | integrated with Nervous System
Decision Feedback Vault Engine
Every Approve/Reject trains the scoring model — immutable closed-loop AI refinement.
Every executive decision is logged as feedback to the Sovereign AI. Rejected recommendations are tagged 'Over-Sensitive' to recalibrate the model's sensitivity. The vault is tamper-proof and audit-ready for regulatory submission.
- Immutable proof-of-integrity for every Decision Card action
- 'Over-Sensitive' tagging on rejected AI recommendations
- Continuous AI model recalibration from executive feedback
- Full audit trail with timestamp, user, and rationale
- Exportable for regulatory and board submissions
- Enterprise exclusive
Risk and compliance, tailored to your sector
Select your industry. ThinkGRC activates the relevant compliance frameworks, risk-scoring models and monitoring thresholds for your sector's regulatory and operational reality.
Platform capabilities
Connected capabilities that set ThinkGRC apart — not available on legacy GRC tools
Live trust score
A live, real-time score combining your GRC, ESG and vendor health into one trust indicator
Financial risk quantification
Translate every risk into a monetary, audit-ready exposure figure — deterministic and explainable
Decision Feedback Vault
Every Approve/Reject trains the AI — immutable closed-loop audit trail for continuous model recalibration
External risk intelligence
Geopolitical, sanctions and ESG controversy signals become evidence with a confidence score and an explainable recommendation — a human decides
Regulatory change tracking
New regulations instantly highlight all affected controls, policies and risks across the entire platform
Predictive GRC Forecasting
6–12 month GRC and ESG trajectory forecasting with AI confidence scoring and driver analysis
Multi-tenant security
Strict data isolation between tenants, dedicated cluster options, and regional data residency enforcement
Zero-Trust Security Layer
256-bit AES encryption, architecture aligned to SOC 2 and ISO 27001, BYOK, and immutable audit vault
SSO & Identity Federation
SAML 2.0, LDAP, OAuth 2.0, Active Directory, Okta, and Azure AD with MFA enforcement
REST API and webhooks
Full REST API plus webhook streaming for programmatic access to all platform capabilities
White-Label & Custom Domain
Enterprise white-labelling with custom branding, colours, logo, and domain configuration
Cross-Framework Control Mapping
Collect once, satisfy many — AI maps controls across all active frameworks simultaneously
Evidence Automation Bot
Automated evidence collection with configurable cadence and audit-readiness scoring
Double materiality assessment
CSRD-ready matrix linking ESG and GRC data for financial and impact materiality assessment
Risk cascade visualiser
See how a failure in one asset or control flows through to risks and compliance — the full chain at a glance
AI Remediation Playbooks
5-step AI playbooks per issue with auto task assignment — from diagnosis to verified closure
Live Regulatory Intelligence Feed
Real-time CISA, GDPR, CSRD, SEC, NIS2, FCA alerts with AI-powered impact summaries
AI Board Report Generation
One-click AI synthesis of live platform data into a professional PDF board report
Vendor Certificate Intelligence
AI extracts expiry dates and security exceptions from uploaded vendor PDF certificates
Integration SDK
Custom SDK for two-way data flow between ThinkGRC and any enterprise system or data source
