A virtual technology
risk manager and auditor
for the regulated estate.
AuditRiskNet runs your technology RCSAs and audits front-to-back – collecting evidence across AWS, Azure, Google Cloud and the data centre, testing controls as code, and mapping every result to DORA, EBA and NIST.
Two products. One assurance graph.
The risk manager and the auditor are separately permissioned and never share a workspace; the same agent should not operate a control and then independently audit it. The EBA Guidelines expect internal audit to review outsourced critical functions independently. We enforce that in software.
First and second line
Run technology RCSAs and continuous assurance for cloud and ICT outsourcing – scope to sign-off, with evidence collected and controls tested automatically.
- Cloud & ICT outsourcing assessments
- Critical-or-important-function reviews
- Continuous control monitoring
- Outsourcing registers & concentration risk
- Risk acceptance & management reporting
Third line
Plan risk-based audits, build work programmes, request and test evidence, and follow issues to closure – drawing on the same accumulated control history, independently.
- Risk-based planning & scoping
- Work programmes & independent sampling
- Automated workpapers & testing
- Findings, actions & follow-up
- Audit-ready evidence packs
Six layers, read-only at the edge.
Everything resolves to one atomic unit – a control tested against evidence, mapped to an obligation. That is why the risk manager and the auditor can share a single engine.
Front-to-back, every time.
A real sequence, not a dashboard. Each step leaves a trail the next one – and any future audit – can rely on.
Scope
Pick a service, platform or outsourcing arrangement; the agent resolves systems, accounts, dependencies, providers and applicable obligations.
Assess risk
Relevant technology and outsourcing scenarios are proposed; a human owner confirms likelihood, impact and appetite.
Map controls
Scenarios map to the canonical control set – objective, owner, frequency, mechanism, evidence and test procedure.
Collect evidence
Read-only pulls from cloud APIs, identity, config, tickets and document stores – each item hashed and timestamped.
Test controls
Deterministic policy tests, AI-assisted document review, and human-performed steps where judgement is material.
Evaluate
Design and operating effectiveness, evidence sufficiency and residual risk are proposed; humans approve material conclusions.
Manage issues
Failed tests open findings with root cause, impact, owner, target date and required closure evidence.
Produce outputs
RCSA report, control-effectiveness view, regulatory mapping, evidence pack and change history since last time.
One control, every obligation.
Controls map to a canonical set expressed in OSCAL. A single operating-effectiveness result discharges obligations across every framework at once – so you maintain one control set, not five overlapping ones.
The moat isn't the model.
Everyone has an LLM. Few have a governed control ontology, an executable test library and defensible evidence lineage across a hybrid estate.
Canonical control ontology
One OSCAL-grounded model separating what's required, intended, implemented, tested and observed – so evidence is reusable, not re-collected per framework.
The assurance graph
Obligation → risk → control → asset → evidence → test → finding. Traversal drives impact analysis, control criticality and concentration risk.
Executable test library
Controls tested as policy-as-code – deterministic, versioned, reproducible. The engine explains, but the rules decide.
Evidence lineage
Hash-chained, bitemporal evidence: what was true, and when we knew it. Defensible to an external auditor or a regulator.
Hybrid by default
One control plane across AWS, Azure, Google Cloud and the data centre – the estates cloud-native tools structurally can't reach.
Regulated-FS native
DORA, EBA outsourcing and the CTP regime modelled first-class – not bolted onto a US-centric SOC 2 tool.
Assurance that holds up.
When you sell assurance into regulated financial services, the tool itself is scrutinised. So we made it answer for its own outputs.
Rules decide
Pass/fail comes from evidence and policy-as-code alone. No model sets a control rating.
Every finding cited
Each conclusion traces to specific evidence objects, with provenance and transformation history.
Humans approve
Material effectiveness conclusions and finding closures require recorded human sign-off.
OSCAL end to end
Catalogues, plans and results in machine-readable OSCAL – portable, interoperable, inspectable.
Bring your hardest estate.
We're onboarding a small number of UK and European financial-services teams with real hybrid estates and real DORA and outsourcing obligations.
Request early access