RiskWatch
RiskWatch International · Founded 1993 · Sarasota, FL, USA
Enterprise risk platform: one global register from threat to treatment, with KRI auto-escalation.
Summary
RiskWatch is an enterprise risk management platform built around a Global Risk Register that rolls up enterprise, IT, vendor, and physical risk into one view, with business-unit-to-enterprise aggregation for the board. It runs a risk assessment engine with a KRI (Key Risk Indicator) library and auto-escalation when a risk breaches its threshold, a treatment workflow with owner assignment and tasks, and native threat and vulnerability libraries that feed risk scores. Its differentiator is Risk-to-Compliance bi-directional mapping: audit findings flow back into risk scores and the register feeds control-assessment scope, so risk and compliance are not two disconnected tools. Pre-built control libraries for 40+ frameworks (ISO 27001, HIPAA, PCI DSS, SOC 2, NIST 800-53, GDPR, CMMC) sit underneath. In the field since 1993 with state-government and federal customers; single-tenant deployment keeps data in the customer's control.
Strengths
- Global Risk Register consolidates enterprise, IT, vendor, and physical risk into one register with business-unit-to-enterprise rollup for the board
- Risk assessment engine with a KRI (Key Risk Indicator) library and auto-escalation when a risk crosses its threshold, so breaches surface between annual cycles
- Risk treatment workflow with owner assignment, tasks, and recommendations; mitigation is tracked to closure, not just logged
- Risk-to-Compliance bi-directional mapping: audit findings flow back into risk scores and the register feeds control-assessment scope (competitors usually split this across two products)
- Native threat and vulnerability libraries plus heat maps and executive risk dashboards for board-ready reporting
- Enterprise, IT, vendor, and physical risk run in one tenant, useful for facilities-heavy and regulated buyers
- 33-year operating history with federal customers (US Department of Defense, VA, DOJ, NSA per public press)
- Single-tenant deployment with customer-owned data residency, an advantage in regulated industries with data-locality requirements
Weaknesses
- Pricing is quote-only across all tiers; buyers cannot self-serve a list price and must book a call to scope a quote
Mid-market and regulated-industry risk teams that want one global register for enterprise, IT, vendor, and physical risk, with KRI-driven escalation, treatment workflows, and board-ready heat maps, plus compliance mapping built in.
Pure SaaS-startup SOC 2 single-framework buyers who need a $6K under-30-day path to first audit; Sprinto or Hyperproof fit that brief better.
Key features
- Global Risk Register with business-unit-to-enterprise rollup
- Risk assessment engine with a KRI (Key Risk Indicator) library and threshold auto-escalation
- Risk treatment workflow with owner assignment, tasks, and recommendations
- Threat and vulnerability libraries that feed risk scores
- Heat maps, risk dashboards, and executive / board risk reporting
- Risk-to-Compliance bi-directional mapping (audit findings update risk scores)
- Pre-built control libraries for 40+ frameworks (ISO 27001:2022, HIPAA, PCI DSS v4, SOC 2, NIST 800-53 r5, NIST 800-171, GDPR, CMMC 2.0)
- Physical security assessment module (ASIS-aligned)
- Vendor risk management and policy management as first-party modules
- Single-tenant deployment for data-residency requirements
Integrations
25+ native. Notable: Microsoft Entra ID (SAML SSO), Okta, Microsoft 365 / SharePoint, Slack, Jira, Salesforce, Custom REST API.
Target size
100 to 25,000 employees · US · Canada · EU · UK · AU