RiskWatch
RiskWatch International · Founded 1993 · Annapolis, MD, USA
Mid-market construction risk and compliance platform with 40+ examiner-recognised libraries.
Summary
RiskWatch ships a risk and compliance assessment platform built around pre-mapped control libraries for 40+ regulatory frameworks including OSHA 29 CFR 1926 (Construction Industry Standards), OSHA 1910 General Industry, ISO 45001-aligned controls, ISO 14001-aligned controls, ISO 27001:2022, NIST 800-53, NIST 800-171 / CMMC 2.0 (relevant for federal construction contractors), PCI DSS, GDPR, CPTED for site security, and Davis-Bacon and Service Contract Act compliance documentation. The platform runs on a survey-based assessment engine plus an evidence vault and a cross-mapped control library. Construction customers include regional GCs, heavy-civil contractors, and specialty-trade firms running multi-state projects. The pricing model is opaque on the public site, but the published support tiers and the single-tenant deploy-as-tenant architecture mean buyers retain full control of their project data and can answer owner-audit and surety-underwriter data-locality questions without a vendor escalation.
Strengths
- 40+ pre-built framework libraries with cross-mapping covering OSHA 1926 Subparts L / M / P / Q, OSHA 1910, ISO 45001-aligned controls, ISO 14001-aligned controls, NIST 800-171 / CMMC 2.0 (federal-contracting GCs), PCI DSS v4, and CPTED site-security
- 33-year operating history with state and federal customers; owner-audit and surety-underwriter export packs are first-class output, not a custom report build
- Project-site physical security assessment software is in the same tenant as cyber and compliance risk, useful for lay-down yards, materials storage, and federal-secure-facility construction (ICD 705)
- Single-tenant deployment with customer-owned data residency, an advantage for ITAR-controlled federal construction and ENR Top-400 multi-region rollups
- Survey-based assessment engine works for non-technical control owners (project-site safety managers, superintendents, foremen) without a workflow-builder learning curve
- Subcontractor risk module assesses prequalification + insurance + BAA / safety record without forcing subs onto a $400 / yr ISN or Avetta seat (keeps the bidder pool open)
- Published support tier ladder, not gated demos before you see what comes with each tier
Weaknesses
- No native EHS-specific modules at the depth of HSI Donesafe, Intelex, or VelocityEHS; OSHA 300 / 300A recordkeeping is supported via the assessment engine but is not a turnkey logbook the way it is in a dedicated EHS platform
- No native chemical inventory / SDS management at the VelocityEHS or EcoOnline depth; pair RiskWatch with a dedicated chemical platform if site-level SDS access is the load-bearing requirement
- No native claims management module; pair RiskWatch with Origami Risk or Riskonnect if workers-comp, GL, builder's risk, or surety claims are the load-bearing brief
- No native Procore tie; sits alongside Procore rather than inside it, which adds a tab for project managers who live in Procore daily logs
- Public pricing is opaque (we are working on it; for now this listicle marks the category transparency problem with a partial badge for RiskWatch)
- Brand awareness on G2 and Capterra is lower than HSI Donesafe, Intelex, or Procore for the construction-buyer cohort; total third-party review volume sits below 100
Mid-market GCs, CMs, and specialty trades (200-5,000 employees) running 3+ regulatory frameworks (OSHA 1926 + ISO 45001 + PCI or CMMC) who want one tenant covering project-site physical security, cyber risk, and subcontractor risk plus an owner-audit and surety-underwriter response pack.
Frontline-only EHS buyers whose single load-bearing requirement is mobile JHA / toolbox-talk capture at scale across 1,000+ field workers; HSI Donesafe or EcoOnline fit that brief better.
Key features
- Pre-built control libraries for OSHA 29 CFR 1926 Construction Industry Standards, OSHA 1910 General Industry, ISO 45001-aligned occupational safety, ISO 14001-aligned environmental, ISO 27001:2022, NIST 800-171 / CMMC 2.0, PCI DSS v4, GDPR, CPTED site-security
- Cross-mapping engine that auto-detects shared controls across frameworks (OSHA 1926 to ISO 45001 to CCIP requirements)
- Survey-based assessment engine for non-technical control owners (project-site safety managers, foremen, superintendents)
- Evidence vault with versioning and owner-audit / surety-underwriter export
- Subcontractor risk module with prequalification + insurance + safety record tracking (no per-sub seat fees)
- Physical security assessment module (ASIS-aligned and CPTED) for lay-down yards and materials storage
- Policy management with approval and attestation workflows for safety SOPs and toolbox-talk content
- Single-tenant deployment for data-residency requirements (federal construction and ENR multi-region)
Integrations
25+ native. Notable: Microsoft Entra ID (SAML SSO), Okta, Microsoft 365 / SharePoint, Slack, Jira, Salesforce, Custom REST API.
Target size
100 to 25,000 employees · US · Canada · EU · UK · AU