Crisam Logo
  • Solutions
    Solutions
    • Risk & Resilience
    • Compliance, Controls & Security
    • Audit, Assurance & Reporting
    • Integrated Risk Management
    • Enterprise Risk Management
    • Operational Risk Management
    • Business Continuity Managament
    • Project Risk Management
    • Third Party Risk
    • Compliance Management
    • Policy Management
    • Internal Control System
    • Information Security Management
    • Data Protection Management
    • Standards & Frameworks
    • Cyber & ICT Risk
    • Audit Managament
    • Internal Audit
    • Control Testing
    • Evidence Management
    • Board & Executive Reporting
    • Whistleblowing & Case Management
    • ESG Governance
  • Industries
    Industries
    • Financial Services
    • Energy & Utilities
    • Healthcare & Pharmaceuticals
    • Industrial & Manufacturing
    • Public Sector & Infrastructure
    • Technology & Telecommunications
  • Platform
    Platform
    • Platform Capabilities
    • Oversight & Governance
    • Configurable workflows
    • Centralised GRC data model
    • Risk & control libraries
    • Evidence management
    • Action tracking
    • Automated reports
    • Board reporting
    • Roles & permissions
    • Audit trails
    • Multi-entity structures
  • Process
  • Customers
  • About CRISAM®
  • en-gb
    • de
    • en
Request demo
  • Sprache
    • de
    • en
  • Solutions
    • Risk & Resilience
      • Integrated Risk Management
      • Enterprise Risk Management
      • Operational Risk Management
      • Business Continuity Managament
      • Project Risk Management
      • Third Party Risk
    • Compliance, Controls & Security
      • Compliance Management
      • Policy Management
      • Internal Control System
      • Information Security Management
      • Data Protection Management
      • Standards & Frameworks
      • Cyber & ICT Risk
    • Audit, Assurance & Reporting
      • Audit Managament
      • Internal Audit
      • Control Testing
      • Evidence Management
      • Board & Executive Reporting
      • Whistleblowing & Case Management
      • ESG Governance
  • Industries
    • Financial Services
    • Energy & Utilities
    • Healthcare & Pharmaceuticals
    • Industrial & Manufacturing
    • Public Sector & Infrastructure
    • Technology & Telecommunications
  • Platform
    • Platform Capabilities
      • Configurable workflows
      • Centralised GRC data model
      • Risk & control libraries
      • Evidence management
      • Action tracking
    • Oversight & Governance
      • Automated reports
      • Board reporting
      • Roles & permissions
      • Audit trails
      • Multi-entity structures
  • Process
  • Customers
  • About CRISAM®
  • Request demo
CRISAM HG dunkel
CRISAM UK

Risk & Resilience

  • Integrated Risk Management
  • Enterprise Risk Management
  • Operational Risk
  • Business Continuity Management
  • Operational Resilience
  • Third-Party Risk

Compliance, Controls & Security

  • Compliance Management
  • Internal Control System
  • Information Security Management
  • Data Protection / UK GDPR
  • Policy Management
  • Cyber & ICT Risk

Audit, Assurance & Reporting

  • Audit Management
  • Internal Audit
  • Evidence Management
  • Board & Executive Reporting
  • Whistleblowing
  • ESG Governance

UK Sectors

  • Financial Services
  • Energy & Utilities
  • Healthcare & Pharmaceuticals
  • Industrial & Manufacturing
  • Public Sector & Infrastructure
  • Technology & Telecommunications
Platform Process FAQ

Get in touch

  • Learn more
  • Learn more
  • sales@crisam.net
Contact Sales
CRISAM® · World’s leading GRC platform · United Kingdom

Connected GRC platform for risk, controls and audit teams

We help risk teams turn complex GRC data into clear, defensible board reporting without replacing existing systems.

CRISAM® is an enterprise GRC software platform for risk management, internal controls, audit and board reporting. It is used by more than 500 organisations including BASF, Dräger, Hapag-Lloyd, STADA and Vossloh.

CRISAM® supports more than 40 standards and frameworks, including ISO 31000, COSO ERM, ISO 27001, DORA, NIS 2, IDW PS 340 n.F. and the UK-specific requirements under FCA, PRA, SMCR and PS21/3 Operational Resilience. It includes integrated Monte Carlo risk quantification, Bow-Tie analysis, scenario testing and FMEA.

Contact Sales See board reporting in action

Trusted across regulated UK sectors. Spend less time building reports. More time managing risk.

Value flow · One source of truth
Live
Fragmented systems unified through CRISAM into board-ready reporting Eight fragmented input systems on the left converge through CRISAM in the centre, producing eight automated report outputs on the right. Fragmented Inputs Connected Intelligence Automated Outputs Risk registers Controls library Internal audit files Spreadsheets Email workflows Compliance tools Third-party data Operational systems World's leading GRC platform One source of truth Board reports Risk reports Audit reports Control assurance Regulatory reports Compliance reports Executive briefings ESG reports Chaotic · Manual Defensible · On Demand
Fragmented Inputs
Risk registers
Controls library
Internal audit files
Spreadsheets
Email workflows
Compliance tools
Third-party data
Operational systems
Chaotic · Manual
CRISAM
World’s leading GRC platform
One source of truth
Automated Outputs
Board reports
Risk reports
Audit reports
Control assurance
Regulatory reports
Compliance reports
Executive briefings
ESG reports
Defensible · On Demand
Fragmented in. Connected through CRISAM. Board-assured out. See the platform →
0
National and international customers
Regulated
Used across risk-critical sectors
Recognised
GRC standards and frameworks
Integrated
Disciplines in one GRC platform
Customers

Trusted by 500+ organisations across regulated sectors

From DAX-listed corporations to mid-market leaders — CRISAM® supports risk, controls and audit teams in pharma, financial services, energy, manufacturing, logistics, public sector and beyond.

BASF
Hapag-Lloyd
Dräger
STADA
Vaillant
Vossloh
Lenzing
Pfeiffer Vacuum
BASF
Hapag-Lloyd
Dräger
STADA
Vaillant
Vossloh
Lenzing
Pfeiffer Vacuum
Strategic partners

An ecosystem of advisory, audit and technology partners

CRISAM® works alongside Big-4 audit firms, cybersecurity specialists and compliance partners to deliver complete GRC solutions for UK organisations.

EY
Deloitte
HAYS
For UK corporate risk managers
“Defensible evidence beats elegant slides every time.” — The principle CRISAM® was built around
01 · Role

You answer to the board, the regulator and the CFO — often in the same week. Your tooling should help, not slow you down.

02 · Frameworks

ISO 31000, COSO, the Three Lines Model and UK-specific obligations under FCA, PRA, SMCR and Operational Resilience.

03 · Data

Risk, controls, audit and reporting data belong in one connected source of truth — not fragmented across spreadsheets and inboxes.

04 · Output

Board-ready reporting on demand, with traceable evidence that holds up to FCA, PRA and internal audit scrutiny.

Solutions

Explore CRISAM® solutions

Choose the area of governance, risk and compliance you want to strengthen.

01 · Solution

Risk & Resilience

Connect enterprise risk, operational resilience, BCM and project risk in a structured GRC environment.

02 · Solution

Compliance, Controls & Security

Manage compliance, policies, internal controls, ISMS and data protection with clearer ownership and evidence.

03 · Solution

Audit, Assurance & Reporting

Support audit planning, control testing, evidence management and executive reporting across the organisation.

Platform overview · maturity journey

From compliance to visibility to predictability.

CRISAM® helps risk, controls and audit teams mature from compliance management to connected governance intelligence and quantified decision support.

01
Stage 01

Compliance

Centralise frameworks, controls, policies, attestations, audit trails and evidence so teams can meet governance and regulatory requirements with greater structure.

  • Frameworks and obligations
  • Controls and policies
  • Attestations
  • Audit trails
  • Evidence management
  • Compliance alignment
02
Stage 02

Visibility

Connect enterprise risk, internal controls and internal audit data so teams can identify control gaps, emerging issues and reporting inconsistencies before they reach the board pack.

  • Connected risk, controls and audit data
  • Real-time governance visibility
  • Control gaps and emerging issues
  • Reduced manual reporting effort
  • Board-level transparency
  • Greater reporting consistency
03
Stage 03

Predictability

Support a move beyond subjective scoring towards scenario-based forecasting, risk quantification and data-driven prioritisation where relevant.

  • Risk quantification
  • Scenario-based forecasting
  • Operational risk impact modelling
  • Data-driven prioritisation
  • Predictive risk intelligence
  • Executive decision support

The goal is not another dashboard. The goal is defensible board intelligence.

Industries

GRC for complex and regulated sectors.

CRISAM® supports organisations where governance, risk, compliance and assurance need to be structured, visible and defensible.

Financial Services

FS

Banking, insurance and asset management firms managing operational resilience, third-party risk and senior management accountability.

Energy, Utilities & Critical Infrastructure

EU

Utilities, energy providers and infrastructure operators managing resilience, cyber risk and supplier assurance.

Healthcare & Pharmaceuticals

HP

Healthcare providers, pharmaceutical and life sciences organisations managing quality, data protection and audit readiness.

Industrial, Manufacturing & Automotive

IM

Manufacturing, automotive and industrial groups managing supply-chain risk, internal controls, ESG and business continuity.

Public Sector & Infrastructure

PS

Public institutions, transport and infrastructure operators managing governance, accountability and operational resilience.

Technology & Telecommunications

TT

Telecoms and technology providers managing ICT risk, information security, third-party risk and incident reporting.

Risk methods

Risk methods, connected to action.

CRISAM® supports structured risk thinking while keeping the focus on ownership, evidence and reporting.

01 · Method

Bow-Tie Analysis

Map threats, controls, events and consequences in a clear cause-to-impact view.

Supports
ISO 31000 IEC 31010 COSO ERM HSE
02 · Method

Monte Carlo Simulation

Explore uncertainty and potential ranges where quantitative risk modelling is required.

Supports
IDW PS 340 n.F. Basel III Solvency II ORSA PRA SS3/17 DORA
03 · Method

Scenario Analysis

Test plausible future events and assess potential operational, financial or regulatory impact.

Supports
PS21/3 Op Resilience PRA SS1/21 BCBS 239 ICAAP / ILAAP TCFD EBA stress tests
04 · Method

FMEA & Control Analysis

Identify failure modes, control gaps and actions across processes, systems and suppliers.

Supports
ISO 9001 IEC 60812 SOX COSO IC IDW PS 982 Three Lines
Connected GRC

Built for connected GRC, not disconnected silos

Risk teams do not need another isolated system of record. They need a connected view of obligations, risks, controls, evidence, actions and reporting that supports confident decisions and defensible board packs.

Aligned with modern GRC thinking around integration, context and defensible decision-making. Inspired by connected GRC perspectives championed by Michael Rasmussen and GRC 20/20.

Connected GRC Obligations Controls Evidence Actions Board packs KRIs RCSA Three Lines Risk appetite ISO 31000 COSO
The CRISAM® engagement process

How we work with governance, risk and assurance teams.

A structured five-stage process that helps organisations build a defensible business case and gain executive approval for governance, risk and assurance transformation.

Designed to help risk teams secure executive buy-in

Many risk teams already know they can work more efficiently, improve governance visibility, and increase the accuracy of board reporting. Securing executive funding approval for governance transformation can often be the harder step.

The CRISAM® engagement process is designed to help organisations build a comprehensive, defensible business case that answers the questions executives will ask before approving investment.

Without those questions answered clearly, governance transformation projects can struggle to gain approval regardless of the operational benefits.

01
Stage 01

Executive buy-in to change

02
Stage 02

Discovery workshop

03
Stage 03

Business case

04
Stage 04

Prototype review and reference site visit

05
Stage 05

Proposal and implementation plan

The questions executives ask before approving investment

Each stage of the engagement process gives boards and executive committees a concrete answer to one of the four questions they will always raise.

02
Stage 02

Discovery workshop

“What are we trying to achieve?”

A clear scope, ownership map and success criteria — defined together with your risk, controls and audit leads in a structured discovery workshop.

03
Stage 03

Business case

“How much will it cost?”

A detailed business case covering software, implementation services and the expected return on security investment over a three to five year horizon.

04
Stage 04

Prototype review and reference site visit

“Have we seen it working elsewhere?”

A tailored prototype using your own data — plus a reference visit to a comparable CRISAM® customer in your sector, so the board can see it before signing.

05
Stage 05

Proposal and implementation plan

“When can we start?”

A staged implementation plan with realistic milestones — typically first reports live within 90 days, full platform value within twelve months.

Frequently asked questions

The questions UK risk managers ask first.

Direct answers to the questions corporate risk leaders ask before booking a call.

What is CRISAM and what does it do for UK corporate risk managers?

CRISAM® is an enterprise GRC platform that connects risk management, internal controls, audit and reporting in one defensible system. UK corporate risk managers use it to consolidate fragmented spreadsheets and disconnected tools, produce board-ready risk reports on demand, and support FCA, PRA, SMCR and Operational Resilience evidence requirements.

How does CRISAM support Operational Resilience under PS21/3?

CRISAM® lets organisations map important business services to underlying processes, controls, third parties and assets in a connected data model. Impact tolerances, scenario testing and lessons learned are tracked over time, supporting defensible PS21/3 evidence for board and regulators.

Is CRISAM aligned with ISO 31000, COSO and the Three Lines Model?

Yes. CRISAM® supports ISO 31000, COSO, the Three Lines Model, ISO 27001, ISO 22301, IDW PS 340 n.F. with integrated Monte Carlo simulation, and more than 40 standards and frameworks.

Can CRISAM be deployed without replacing existing systems?

Yes. CRISAM® has a REST API for integration with HRIS, identity providers, ticketing systems, third-party risk feeds and existing data warehouses. Connections can be event-based, scheduled or fully synchronous, depending on the use case.

Next step

Ready to move from fragmented governance data to automated board reporting?

Speak with the CRISAM® team about how a structured engagement can support your governance, risk and assurance transformation.

Contact Sales See platform overview
!
Personalised consultation
30-minute platform walkthrough plus a CRISAM® UK GRC briefing for risk, controls and audit teams.

Learn more

Tell us about your organisation. A member of the CRISAM® UK team will be in touch to arrange a personalised walkthrough and share the GRC briefing relevant to your sector.

Please use your work email address.
Gemeinsame Nutzung CRISAM

CRISAM GRC Limited

20 Red Lion Street

London

+44 20 4634 5000 andreas.schmitz@crisam.net

CALPANA business consulting GmbH

Blumauerstrasse 45-47

4020 Linz

+43 732 601 216-0 office@crisam.net

CRISAM GRC Limited

20 Red Lion Street

London

+44 20 4634 5000 andreas.schmitz@crisam.net

CALPANA business consulting GmbH

Blumauerstrasse 45-47

4020 Linz

+43 732 601 216-0 office@crisam.net
Solutions
  • Risk & Resilience
  • Compliance & Controls
  • Audit, Assurance & Reporting
Industries
  • Financial Services
  • Energy & Utilities
  • Healthcare & Pharmaceuticals
  • Industrial & Manufacturing
  • Industrial & Manufacturing
  • Technology & Telecommunications
Company
  • About CRISAM®
Legal
  • Data Policy
  • Imprint

© 2026 CRISAM GRC Limited