Risk & Compliance
Framework coverage, control status, evidence and the enterprise risk register with remediation dates.
Compliance score
60%9/15 controls
Risk heatmap
I1I2I3I4I5L5
2
1
1
L43
1
1
L32
1
1
L21
1
L11
1
1
Remediation
- Risks tracked18
- Critical3
- Past due date3
- Accepted3
Risk register (18)
| Risk | Asset | Category | L × I | Severity | Treatment | Owner | Due | Frameworks |
|---|---|---|---|---|---|---|---|---|
| Hallucinated advice reaching customers | Document Extraction Service | ai | 5 × 4 | critical | transfer | S. Nakamura | 2026-08-28 | SOC 2 Type II, GDPR |
| Key rotation gaps in payments path | CRM Core | cyber | 4 × 5 | critical | mitigate | M. Haddad | 2026-11-19 | ISO 27001, SOC 2 Type II |
| Privileged access sprawl | Reporting Warehouse | cyber | 4 × 4 | critical | mitigate | L. Marchetti | 2026-12-03 | EU AI Act |
| Unregistered AI usage bypasses governance | Backup & Recovery | ai | 5 × 3 | warning | mitigate | A. Petrova | 2026-12-16 | NIST AI RMF, ISO 27001 |
| Cross-border data transfer exposure | Container Platform | regulatory | 3 × 4 | warning | transfer | C. Iversen | 2027-01-14 | GDPR |
| Single-region dependency for billing | Reporting Warehouse | operational | 5 × 2 | warning | accept | A. Petrova | 2026-12-28 | SOC 2 Type II, ISO 27001 |
| Shadow MCP connection to internal API | Service Deflection Assistant | cyber | 5 × 2 | warning | mitigate | E. Moreau | 2026-09-10 | NIST AI RMF, SOC 2 Type II |
| Insufficient human oversight at high autonomy | Element Manager | ai | 2 × 5 | warning | mitigate | L. Marchetti | 2026-08-14 | SOC 2 Type II, EU AI Act |
| Ransomware exposure on file estate | CRM Core | cyber | 3 × 3 | warning | mitigate | M. Haddad | 2027-01-16 | NIST AI RMF, SOC 2 Type II |
| Model provider concentration risk | Access Aggregation | third-party | 4 × 2 | informational | mitigate | M. Haddad | 2026-12-13 | EU AI Act, GDPR |
| Legacy platform end-of-support | Partner B2B Gateway | operational | 4 × 2 | informational | mitigate | A. Petrova | 2026-11-25 | NIST AI RMF, PCI DSS |
| Change failure rate above appetite | Event Streaming Bus | operational | 4 × 2 | informational | mitigate | E. Moreau | 2027-01-24 | PCI DSS, ISO 27001 |
| Token cost overrun on AI programme | Monitoring Platform | operational | 2 × 4 | informational | mitigate | C. Iversen | 2027-01-04 | ISO 27001, SOC 2 Type II |
| Insufficient audit evidence for AI decisions | Knowledge Search (RAG) | regulatory | 3 × 2 | informational | mitigate | E. Moreau | 2026-08-22 | ISO 27001, EU AI Act |
| Third-party settlement feed reliability | Network Inventory | third-party | 3 × 2 | informational | mitigate | L. Marchetti | 2026-10-16 | PCI DSS, GDPR |
| Agent over-permissioning on billing tools | Event Streaming Bus | ai | 1 × 5 | informational | accept | D. Okonkwo | 2026-12-17 | EU AI Act, PCI DSS |
| Incomplete DPIA for a customer-facing model | ERP Financials | regulatory | 1 × 4 | informational | mitigate | E. Moreau | 2026-10-17 | ISO 27001, PCI DSS |
| Retrieval corpus contains stale policy | Mobile App Backend | ai | 1 × 3 | informational | accept | C. Iversen | 2026-09-18 | PCI DSS, ISO 27001 |
Controls & evidence (15)
- ISO 27001A.8.16 Monitoring activitiesevidence: Guardrail event logtested 2026-05-31compliantPartner B2B GateDocument Extract
- ISO 27001A.5.15 Access controlevidence: Guardrail event logtested 2026-08-06non-compliantEmail Security GWeb CDN EdgeBackup & Recover
- ISO 27001A.8.9 Configuration managementevidence: Audit trail exporttested 2026-06-06compliantCRM CoreFraud Signal Sum
- SOC 2 Type IICC6.1 Logical accessevidence: Guardrail event logtested 2026-04-20compliantVirtualisation CKnowledge Search
- SOC 2 Type IICC7.2 Anomaly detectionevidence: Guardrail event logtested 2026-06-04partialCRM CoreService Desk
- SOC 2 Type IICC8.1 Change managementevidence: Access review recordtested 2026-07-13compliantDocument StoreEmail Security GPrototype Sales
- NIST AI RMFGOVERN 1.2 Roles & accountabilityevidence: Access review recordtested 2026-06-28compliantHR SuiteEmail Security GInvoice Archive
- NIST AI RMFMAP 2.3 System documentationevidence: Access review recordtested 2026-06-22partialCustomer PortalField Engineer A
- NIST AI RMFMEASURE 2.7 Trustworthiness metricsevidence: Config baseline reporttested 2026-05-30compliantRevenue AssurancDocument ExtractAccess Aggregati
- NIST AI RMFMANAGE 4.1 Post-deployment monitoringevidence: Audit trail exporttested 2026-06-04partialEndpoint FleetBilling Dispute Container Platfo
- GDPRArt. 32 Security of processingevidence: Config baseline reporttested 2026-04-29not-assessedCloud Landing ZoData LakehouseWeb CDN Edge
- GDPRArt. 35 Data protection impact assessmentevidence: Guardrail event logtested 2026-06-03compliantMobile App BackeRevenue AssurancSIEM Platform
- EU AI ActArt. 14 Human oversightevidence: Guardrail event logtested 2026-06-10compliantMonitoring PlatfPrototype Sales Document Extract
- EU AI ActArt. 12 Record-keepingevidence: Access review recordtested 2026-07-12compliantSIEM PlatformDocument Store
- PCI DSSReq. 10 Log and monitor accessevidence: Guardrail event logtested 2026-09-02not-assessedContainer Platfo