AI-Powered Governance · Risk · Compliance

Assurance that keeps up with the business.

RegRisk unifies enterprise risk, controls, audit, segregation of duties and vendor risk on a single register — and reads your ERP directly, so a failed control test and an SoD violation roll up to the same board-level score.

Register · live01 sync02 detect03 proposelast sync 06:35 · +00:00 · read-only
Entitlement graph · P2PLIVE
user · 001user · 002user · 003AP ManagerROLEVendor DataDUTYSupplier MaintenanceApprove PaymentENTITLEMENTS

High

exposure rank

3

users affected

0

mitigating controls

SoD Analyst · proposalSCANNING

Recommended fix

Remove Supplier Maintenance from the AP Manager role; assign it to the Vendor Data duty instead.

Least-disruptive — affects 3 users, no approval-path change. Simulated: resolves 3/3, adds 0 new conflicts.

rule · SOD-P2P-014role · AP Managersource · Fusion sync 06:35
Audit trailempty

No decisions recorded in this session. Approve, edit or reject the proposal above and the entry is written here.

11

GRC modules, one register

8+

ERP & SaaS connectors

6

AI agents, human-approved

48h

To first SoD finding

02 · The register

Every risk sits in one cell of one matrix

Likelihood × impact, scored by the model in Master Setup. A failed control test and an SoD violation roll up to the same board-level score.

L5
L4
L3
L2
L1
I1I2I3I4I5

Impact

Low 1–4Medium 5–9High 10–16Critical 17–25
Filtered register9 of 9

All plotted risks

9 plotted · 41 monitored

Hover or arrow through the grid to read a cell; select one to filter the register to it.

residual · across all cells

SOD-P2P-014 sits at L4 × I5 · score 20 · critical. Approving the fix above re-scores it here.

Residual scores across 41 monitored risks · updated on last ERP sync. Risk titles are held in the tenant, not in this public view.

03 · The data model

One data model for the entire GRC lifecycle

Risks, controls, tests, issues, incidents, policies, entitlements and vendors are all objects in the same register. Four verbs, one source of truth.

01 / GOVERN

Govern

Risk taxonomy, hierarchy, appetite, policies and board reporting in one governance layer.

02 / ASSESS

Assess

RCSA cycles, likelihood × impact scoring, control design and testing across every business unit.

03 / DETECT

Detect

Continuous monitoring of KRIs, SoD conflicts, sensitive access and control failures — not quarterly sampling.

04 / RESPOND

Respond

Issues, incidents and remediation plans tracked to closure, with a full evidence trail for the auditor.

04 · Modules

Eleven modules. Licence what you need.

The data model is shared from day one, so every module you add makes the others richer. Select one to see which agents operate on it and which connectors feed it.

05 · Agents

Six agents that do the work — not just summarise it

Each agent is scoped to a module, grounded in your own register, and gated by human approval. They propose; your team disposes.

See all six in detail

Ground

Reads your data

Register, ERP metadata, policies, prior cycles — never a generic corpus.

Reason

Applies your rules

Your scoring model and rule library produce a ranked, cited conclusion.

Propose

Writes the draft

A risk, a control, a role fix — with its rationale and citations attached.

Approve

You decide

Accept, edit or reject. Nothing is committed without a human.

Learn

Tunes to you

Accept / reject decisions sharpen suggestions for that entity and taxonomy.

The film

Sixty seconds, connector to closed issue

Connect, normalise, detect, propose, approve — the same loop the hero runs, end to end. Scrub it, jump a chapter, or read it in captions.

REGRISK · SEGREGATION OF DUTIESt 0.0sOracle E-Business SuiteR12 · 12.1 · 12.2ROread-only credential · no prod footprintrows read · 0ResponsibilitiesMenusFunctionsuser – role – entitlementone normalised modeluser · 001user · 002user · 003AP ManagerSupplier MaintenanceApprove PaymentVendor DataSOD-P2P-014 · 3 users · 0 mitigationsSOD ANALYST · PROPOSAL
resolves 3/3, adds 0 new conflicts
APPROVED · HUMANaudit trail · approved · remediation issue openedL4×I5 · CRITICAL

ConnectA read-only credential attaches to Oracle E-Business Suite. The sync starts; rows stream in.

0:00 / 1:00

The film pauses when it scrolls out of view. Captions are on by default.

06 · Coverage

Connectors for the systems your controls actually live in

Read-only, credential-scoped connectors. No agents installed on production application servers.

PlatformScopeWhat RegRisk ingestsStatus
Oracle E-Business SuiteR12 · 12.1 · 12.2Users, responsibilities, menus, functions, org accessAvailable
Oracle NetSuiteSuiteCloudEmployees, roles, permissions, subsidiaries, approvalsAvailable
Oracle Fusion CloudERP · HCM · SCMUsers, roles, duty roles, privileges, data access setsAvailable
SAPS/4HANA · ECCUsers, roles, profiles, t-codes, authorisation objectsAvailable
WorkdayHCM · FinancialsWorkers, security groups, domains, business processesQ3 2026
Microsoft Dynamics 365F&O · CEUsers, security roles, duties, privilegesQ3 2026
SalesforceSales · ServiceUsers, profiles, permission sets, object accessQ4 2026
Entra ID · Okta · Ariba · CoupaIdentity · S2PIdentity, group membership, joiner-mover-leaver eventsRoadmap

Sync jobs run on schedule or on demand — with completion tracking, delta detection and a full run history per profile. Readiness uses the same four-step scale as severity.

Full connector catalogue →

Connector catalogue

Oracle-first, in priority order

We built where the reference customers are. E-Business Suite leads, then NetSuite and Fusion Cloud — with the rest of the estate close behind.

Readiness
Family

Showing 8 of 8 connectors

Sync console

Every stage of a sync is observable

Each sync job records its start, end and completion percentage — with a full run history per profile.

ERP Sync JobIDLE
ERP ApplicationStartedCompletion
Oracle E-Business Suite06:34 PM0%
Oracle NetSuite06:35 PM0%
Oracle Fusion Cloudqueued— waiting —
profile · Oracle HCM & ERP · delta sync · initiated by admin@regriskin progress
Run history · Oracle HCM & ERPno runs yet

The first run is recorded here when it completes. Run it again to add another line.

How a sync works

Connector to dashboard, every stage observable

Each sync job records its start, end and completion percentage — with a full run history per profile, exactly like the console above.

01

Connect

Read-only, credential-scoped account per application.

02

Sync job

Scheduled or on-demand, with completion tracking.

03

Normalise

Vendor objects mapped to one user–role–entitlement model.

04

Rules & agents

SoD rules, KRI thresholds and agent analysis run on it.

05

Dashboards

Findings surface in the SoD dashboard and alerts.

Security posture

What we touch — and what we never do

The answers your IT and security teams ask for before a single credential changes hands.

Read-only

Connectors have read access only. RegRisk never writes back to your ERP.

Least privilege

Credential-scoped service accounts, secrets held in a managed vault.

IP allow-listing

Egress restricted to known ranges; SSO and SCIM for platform access.

No prod footprint

Nothing is installed on your production application servers.

07 · In the field

Oracle Fusion access governance for a SOX audit

Global manufacturer · 12,000 employees · Fusion ERP + HCM. Drag the scrubber through two assessment cycles.

Cycle 0 · before RegRisk

Before · the challenge

Access review that was always six weeks stale

  • Reviews ran on spreadsheets exported quarterly — the data aged before anyone signed.
  • Auditors raised a significant deficiency on SoD monitoring two years running.
  • No way to test a proposed role change before it hit production.

100

critical conflicts, indexed to the first cycle

6wk

access review cycle time

open

SoD findings at the audit

modules · RCSA / SoD / Access Review / AI agents

End states are the reported figures: 78% fewer critical conflicts, 6wk → 2d review cycle, 0 SoD findings at the next audit. Intermediate positions are interpolated for the scrub.

Questions

What teams ask before the first sync

The answers your risk, audit and security leads want on the record. Every question here is linkable.

5 of 5 questions

08 · Start here

See your own conflicts in two weeks

The free SoD assessment needs only read-only credentials. We connect, run a sync, and hand back your real conflicts — ranked, explained, and mapped to the roles that cause them.

Request the assessment

We'll only use this to contact you about the assessment.

ERP stack — select all that apply
01Discovery workshop90 minutes with risk, audit and the ERP owner.
02Read-only connectionOne service account and a single sync job — nothing on production servers.
03Findings reviewYour own conflicts, ranked and explained, inside two weeks.

First conflicts inside two weeks · first SoD finding within 48 hours of the read-only connection.