RiskWatch
RiskWatch International · Founded 1993 · Annapolis, MD, USA
Multi-framework physical security assessment platform for multi-location retail.
Summary
RiskWatch ships a physical security and compliance assessment platform with the ASIS International Facility Physical Security Control Standards, NATF CIP-014, NIST SP 800-53 physical and environmental controls, PCI DSS v4 physical-access controls (Requirement 9), and a Cal/OSHA SB 553 workplace-violence-prevention plan library pre-mapped in one tenant. The platform runs a survey-based assessment engine, an evidence vault, and a cross-mapped control library so a regional security manager can score every store on the same rubric and roll up a chain-level risk number. Customers include US state governments in all 50 states, healthcare networks, financial-services holding companies, and multi-location retail operators. Pricing is partial-transparency: typical contract bands are published below; enterprise deployment topology varies materially so the top tier is quote-only.
Strengths
- ASIS Facility Physical Security Control Standards library is pre-built, not hand-mapped; same goes for NATF CIP-014, NIST 800-53 PE controls, and PCI DSS v4 Requirement 9
- Cal/OSHA SB 553 workplace-violence-prevention plan library shipped post-July-2024 to cover the California GI standard buyers already need to evidence
- Store-level risk scoring rolls up to chain-level dashboards, useful for VP Asset Protection reporting to a board
- 33-year operating history with federal, state, and healthcare customers (US Department of Defense, VA, DOJ, NSA per public press)
- Survey-based assessment engine works for non-technical store managers and regional security leads; no SQL or workflow-builder skills required
- Single-tenant deployment with customer-owned data residency, an advantage for chains with employee-personal-data exposure under state privacy law (CCPA, NYDFS Part 500)
- Cross-mapping engine auto-detects shared controls across ASIS, NIST 800-53, PCI DSS v4, and HIPAA Security Rule physical safeguards
Weaknesses
- Not a video-management system; RiskWatch does not record or analyse camera feeds, so retailers who want a single pane for both assessment and live video need to pair it with Verkada, Genetec, March Networks, or Sensormatic IQ
- No POS exception-based-reporting module out of the box; Appriss Retail, Solink, and ThinkLP own that workflow
- No native ORC intelligence-sharing network; Auror is the cross-retailer suspect-sharing layer for that use case
- Public pricing is partial-transparency (Standard and Professional bands published; Enterprise quote-only); fully-published list prices are not yet on the site
- Brand awareness on G2 / Capterra in the retail-loss-prevention category is lower than Verkada or Solink; total third-party review volume sits below 100
- UI shows its operational-heritage in places; competing newer entrants (Solink, Verkada) have a more polished first-run experience
Multi-location retail chains (25-5,000 stores) running a control-mapped AP programme that has to evidence ASIS, PCI DSS v4, and Cal/OSHA SB 553 simultaneously, plus chains that want a chain-level risk score to brief the board.
Single-store independents who only need a camera and a POS-linked clip search; Verkada or Solink fit that brief better and ship cameras as well as software.
Key features
- ASIS Facility Physical Security Control Standards library
- Cal/OSHA SB 553 workplace-violence-prevention plan library
- NATF CIP-014 physical security library for critical-infrastructure retail
- PCI DSS v4 Requirement 9 physical-access controls library
- Store-level risk scoring with chain-level rollup
- Cross-mapping engine across ASIS, NIST 800-53, PCI DSS v4, HIPAA
- Evidence vault with versioning and audit-ready export
- Survey-based assessment engine for store managers and regional security leads
- Single-tenant deployment with customer-owned data residency
Integrations
25+ native. Notable: Microsoft Entra ID (SAML SSO), Okta, Microsoft 365 / SharePoint, Slack, Jira, Salesforce, Custom REST API.
Target size
250 to 1,00,000 employees · US · Canada · EU · UK · AU