Controls intelligence · cloud + on‑premise

A virtual technology
risk manager and auditor
for the regulated estate.

AuditRiskNet runs your technology RCSAs and audits front-to-back – collecting evidence across AWS, Azure, Google Cloud and the data centre, testing controls as code, and mapping every result to DORA, EBA and NIST.

Models interpret. Rules decide. People sign off.
OSCAL-native Rego policy-as-code DORA (EU) 2022/2554 DORA RTS 2024/1774 EBA GL/2019/02 NIST RMF · CSF 2.0 ISO 27001 · 42001
One estate · two lines of defence

Two products. One assurance graph.

The risk manager and the auditor are separately permissioned and never share a workspace; the same agent should not operate a control and then independently audit it. The EBA Guidelines expect internal audit to review outsourced critical functions independently. We enforce that in software.

ARN Risk Manager

First and second line

Run technology RCSAs and continuous assurance for cloud and ICT outsourcing – scope to sign-off, with evidence collected and controls tested automatically.

  • Cloud & ICT outsourcing assessments
  • Critical-or-important-function reviews
  • Continuous control monitoring
  • Outsourcing registers & concentration risk
  • Risk acceptance & management reporting
ARN Auditor

Third line

Plan risk-based audits, build work programmes, request and test evidence, and follow issues to closure – drawing on the same accumulated control history, independently.

  • Risk-based planning & scoping
  • Work programmes & independent sampling
  • Automated workpapers & testing
  • Findings, actions & follow-up
  • Audit-ready evidence packs
Segregation by design. Separate roles · immutable evidence & activity history · auditors cannot modify control-owner records · every rating and finding carries recorded human approval.
The platform

Six layers, read-only at the edge.

Everything resolves to one atomic unit – a control tested against evidence, mapped to an obligation. That is why the risk manager and the auditor can share a single engine.

ExperienceARN Risk Manager & Auditor
RCSAs, control monitoring, audits, issues, risk acceptance and board-ready reporting.
IntelligenceARN Assurance Graph
Connects obligations, risks, scenarios, controls, assets, third parties, evidence, tests and findings.
AutomationARN Agent Workforce
Specialist agents – scoping, mapping, evidence, testing, findings, challenge – under a governed orchestrator with human approval gates.
ExecutionARN Control Engine
Deterministic control tests and continuous monitoring, run as policy-as-code. Rules decide the pass/fail; models never touch it.
IntegrationARN Evidence Fabric
Read-only connectors to cloud, on-premise, SaaS, identity, ticketing and security platforms – into a hash-chained, bitemporal store.
How an assessment runs

Front-to-back, every time.

A real sequence, not a dashboard. Each step leaves a trail the next one – and any future audit – can rely on.

01

Scope

Pick a service, platform or outsourcing arrangement; the agent resolves systems, accounts, dependencies, providers and applicable obligations.

02

Assess risk

Relevant technology and outsourcing scenarios are proposed; a human owner confirms likelihood, impact and appetite.

03

Map controls

Scenarios map to the canonical control set – objective, owner, frequency, mechanism, evidence and test procedure.

04

Collect evidence

Read-only pulls from cloud APIs, identity, config, tickets and document stores – each item hashed and timestamped.

05

Test controls

Deterministic policy tests, AI-assisted document review, and human-performed steps where judgement is material.

06

Evaluate

Design and operating effectiveness, evidence sufficiency and residual risk are proposed; humans approve material conclusions.

07

Manage issues

Failed tests open findings with root cause, impact, owner, target date and required closure evidence.

08

Produce outputs

RCSA report, control-effectiveness view, regulatory mapping, evidence pack and change history since last time.

Test once, satisfy many

One control, every obligation.

Controls map to a canonical set expressed in OSCAL. A single operating-effectiveness result discharges obligations across every framework at once – so you maintain one control set, not five overlapping ones.

ARN-IAM-04
Privileged accounts require phishing-resistant MFA
1 test · 5 obligations
NIST 800-53 Rev 5IA-2(1)equivalent
NIST CSF 2.0PR.AA-03broader
DORA (EU) 2022/2554Art. 9(4)(d)supports
DORA RTS 2024/1774Art. 21supports
EBA/GL/2019/02§13.2 · 81–84supports
Why it holds

The moat isn't the model.

Everyone has an LLM. Few have a governed control ontology, an executable test library and defensible evidence lineage across a hybrid estate.

Canonical control ontology

One OSCAL-grounded model separating what's required, intended, implemented, tested and observed – so evidence is reusable, not re-collected per framework.

The assurance graph

Obligation → risk → control → asset → evidence → test → finding. Traversal drives impact analysis, control criticality and concentration risk.

λ

Executable test library

Controls tested as policy-as-code – deterministic, versioned, reproducible. The engine explains, but the rules decide.

Evidence lineage

Hash-chained, bitemporal evidence: what was true, and when we knew it. Defensible to an external auditor or a regulator.

Hybrid by default

One control plane across AWS, Azure, Google Cloud and the data centre – the estates cloud-native tools structurally can't reach.

§

Regulated-FS native

DORA, EBA outsourcing and the CTP regime modelled first-class – not bolted onto a US-centric SOC 2 tool.

Built to be audited

Assurance that holds up.

When you sell assurance into regulated financial services, the tool itself is scrutinised. So we made it answer for its own outputs.

Deterministic

Rules decide

Pass/fail comes from evidence and policy-as-code alone. No model sets a control rating.

Traceable

Every finding cited

Each conclusion traces to specific evidence objects, with provenance and transformation history.

Governed

Humans approve

Material effectiveness conclusions and finding closures require recorded human sign-off.

Standards-based

OSCAL end to end

Catalogues, plans and results in machine-readable OSCAL – portable, interoperable, inspectable.

Early access

Bring your hardest estate.

We're onboarding a small number of UK and European financial-services teams with real hybrid estates and real DORA and outsourcing obligations.

Request early access