Skip to main content

Help us improve the Digital Marketplace - send your feedback

Riskonnect Active Risk Limited trading as Riskonnect. Historic trading names include Xactium, Active Risk Manager (ARM), Castellan Solutions Ltd, ClearView and CAM Management Solutions Limited (CAMMS)

Riskonnect Governance, Risk and Compliance (formerly Xactium)

Riskonnect GRC is a cloud-based SaaS suite delivering AI-powered integrated solutions for governance, risk, and compliance. From enterprise risk and regulatory compliance to audits, policies, and third-party management, it streamlines workflows, enhances visibility, and automates processes—empowering organizations to manage risk proactively and maintain regulatory confidence.

Features

  • Enterprise Risk Management. Identify, assess, and mitigate enterprise risks
  • Regulatory Compliance. Centralize compliance tracking and regulatory management
  • Internal Audit. Optimize audit planning and execution processes
  • IT Risk Management. Manage cybersecurity and technology-related risks
  • Third-Party Risk Management. Monitor and manage vendor risk effectively
  • Internal Controls Create and execute control testing and monitoring activities
  • Policy Management. Monitor Policy compliance and distribution
  • AI Governance. Govern AI risk, ethics, and compliance
  • ESG Risk Management. Materiality, program management, and GHG calculations

Benefits

  • Integrated approach. Unified data improves decisions and enterprise-wide clarity
  • Comprehensive coverage. Broad suite of integrated solutions for maturing needs
  • Real-time visibility. Single source of truth for risk data
  • Efficiency gains. Automated workflows reduce burden and improve collaboration
  • Rapid adoption. Intuitive design for quick onboarding and efficiency
  • Scalable and secure. Built on trusted Salesforce.com platform
  • Regulatory confidence. Demonstrates compliance with industry standards and frameworks
  • Expert support. Dedicated teams ensure success and best practices
  • 100% cloud-based SaaS. No software installation required

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at legal@riskonnect.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 3 7 6 4 5 5 5 5 3 1 8 6 5 7

Contact

Riskonnect Active Risk Limited trading as Riskonnect. Historic trading names include Xactium, Active Risk Manager (ARM), Castellan Solutions Ltd, ClearView and CAM Management Solutions Limited (CAMMS) Shane Yeeda
Telephone: +1 770 790 4683
Email: legal@riskonnect.com

About your service

Service categories

Applications

Enterprise resource management

  • Enterprise performance management

Financial

  • Treasury and Risk Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
No, the majority of planned maintenance is undertaken with no client impact.
System requirements
Software license for users

User support

Email or online ticketing support
Yes
Support response times
Riskonnect provides 24x7 support for urgent issues, a global hotline and online support portal. Details on response times are included in our SLAs: https://riskonnect.com/legal-sla/.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
All customers have access to technical and functional documentation through our Customer Success Portal 24x7 with UK based email and telephone support staff. All support related issues are logged on the portal with full visibility to the client. Each client will have a dedicated Account Executive and Customer Success Manager (CSM) for additional assistance and support as required. The CSM will hold a regular business reviews and maintain a Rolling Action Item Log to ensure you are always getting the very best out of your subscription.
Support available to third parties
No

Onboarding and offboarding

Getting started
Training includes standard training guides and a full suite of standard videos that are available on the Riskonnect Success Portal (RSP) as Knowledge Articles. Riskonnect provides basic training materials online and updated in conjunction with each platform upgrade. System documentation related to client-specific configuration is posted and available online in our Customer Success Portal. Initial documentation will be posted throughout the implementation process. All enhancements provided by Riskonnect personnel are documented and added to the client reference library. Additional training is available via Riskonnect University. For our current online course schedule, visit https://riskonnect.com/resources/riskonnect-university/
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
  • Other
Other documentation formats
  • Excel
  • CSV
  • Word
  • PowerPoint
  • XML
End-of-contract data extraction
On contract termination, Riskonnect makes available a CSV file of all client data for download by client via SFTP with PGP encryption, and Riskonnect disables the client's database. Separate transition services are available in unique circumstances for a fee.
End-of-contract process
Customers have access to a global export function to obtain all their data at the end of the contract. Once this has been carried out the org will be decommissioned and all data deleted. If customer requires data in a different format to that provided by the global export, this would be chargeable.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Riskonnect provides a comprehensive range of documentation, including installation guides, user manuals, training materials, support manuals and quick reference guides through our Customer Success Portal as well as downloadable material through the product’s built-in Help facility.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
While the mobile app replicates the key functions of the product, the limitations of a mobile display mean that some custom components will not display on mobile devices. Administrators can configure dedicated mobile layouts to maximise the usability of the format. The mobile app is intended to compliment rather than replace desktop use
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
All Riskonnect platform objects, fields, workflows etc. are automatically exposed to APIs. Any action that a user can take in the environment can be automated via an API.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The simple point and click interface to create objects, fields, workflows, validations, reporting and drag and drop page layouts.

Scaling

Independence of resources
The Riskonnect platform's infrastructure can scale both vertically and horizontally due to its unique pod architecture. A pod is a set of industry standard resource (high-performance database, Web Application, Search, Email, Storage, Backup Servers, Load Balancers, etc.) that work together to serve the needs of a limited collection of organizations and applications. To prevent demand overload of any one pod's resources, the platform provisions a new pod when existing pods are at or nearing predefined capacity thresholds.

Analytics

Service usage metrics
Yes
Metrics types
The system offers standard functionality to retail logs reflecting level of usage including number of logins, downloads, and system changes (such as created by, modified by, etc.). Tracking of users, data and storage used against the amount licensed is provided in the system
Reporting types
  • API access
  • Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Data at rest is encrypted using AES 256. Additional field level security can be added for an additional cost.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Riskonnect has a wide array of powerful ETL Data tools and integration capabilities that allows us to convert/import/export data in and out of our system in just about any format. Data integration is common and accomplished via simple spreadsheet upload, batched interval uploads via SFTP, APIs (SOAP and REST), web services, email integration (TLS).
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • PDF
  • HTML
  • XML
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • Excel
  • HTML

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Riskonnect provides robust security measures like encryption, strong authentication, access controls, etc. Compliance checks include verifying adherence to relevant industry standards, such as ISO 27001 and SOC2, along with conducting regular security audits and monitoring.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Data encryption at rest utilizes AES 256. The infrastructure is segmented and network traffic is controlled through a combination of logical and physical network separation, access controls, and continuous monitoring. We leverage industry-standard cloud infrastructure that enforces network segmentation between production, staging, and development environments to prevent unauthorized access or data crossover.

Availability and resilience

Guaranteed availability
https://riskonnect.com/legal-sla/
Approach to resilience
The Riskonnect service is built for high availability in the primary and disaster recovery sites. Data centers are backed up to secondary data centers in near real-time frequency. All servers are backed up to a secondary server within each data center. In the event that a failover is required, the secondary server will be used. If both servers are down, the platform will switch over the backup data center.
Outage reporting
Scheduled maintenance is planned for off-peak hours to minimize disruption to our clients. Any non-emergency shutdown that requires the Riskonnect Services and/or In the unlikely event of an interruption in service as soon as we are aware of an issue, our Technical Operations team sends out an Email with information regarding the outage as well as ETA's if they're available.

Software to be unavailable will be scheduled with written notice at least ten (10) business days in advance of the interruption time. Software patches and upgrades notifications are presented upon login to the system as well as direct communications via Riskonnect's Customer Success Team. All planned maintenance or outages are scheduled/reported on the Salesforce Trust site (https://status.salesforce.com/products/all/instances).

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
All access to the underlying infrastructure is via two-factor VPN, and limited to users who require access to undertake their role. (RBAC)
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
SOC 1, SOC 2 Type II, ISO 22301, GDPR, NIST
Information security policies and processes
Riskonnect maintains a NIST / ISO27001 / SOC II aligned Information Security and Compliance environment that enforces strict access controls, data protection, system integrity, and continuous monitoring to safeguard confidentiality, integrity, and availability of all information assets.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Components of the service are tracked within our asset register which is reviewed every three months. When components near end of life a migration plan is created to move to new components prior to the end of life date.

All changes to software and components are tracked via a ticketing system with appropriate sign-offs by different teams. This includes security and risk assessments, confidentiality, integrity, availability, alignment to product roadmap and rollback plans.

Customers are communicated to via predefined channels prior to any changes which could impact the availability of the solution.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Patch management is a standard component of our SaaS model, which provides for patches to be applied as needed via the web, with no impact to our clients. Riskonnect ensures that all patches are deployed in a timely manner. In addition, Riskonnect utilizes IDS/IPS technology and vulnerability scanning, and penetration testing is done at least annually which is attested to in our 3rd party audits
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Riskonnect aligns with ISO 27001, ISO 22301, and SOC II frameworks, ensuring that monitoring and incident response processes meet recognized security standards.
The Resilience environment is monitored in real time.
Response to Potential Compromises:
Immediate alerting and triage by the Security Operations team.
Containment and isolation of affected systems to prevent further impact.
Remediation actions executed based on predefined criteria and tracked until closure.
Post-incident review to capture lessons learned and strengthen controls.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
As a NIST aligned organization, Riskonnect maintains a mature well developed Incident Management program. All incidents are logged and tracked in our Riskonnect official system of record. In the unlikely event of a breach, the client would be notified within 24-48 hrs. of the event in question with direct follow up from Riskonnect after initial notification.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Access to a demonstration version of the software can be made available after a mutual non disclosure agreement has been signed.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
2%
Between £2,500,001 and £5,000,000
2%
Over £5,000,001
1%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
A-Lign
ISO/IEC 27001 accreditation date
Tuesday 19 December 2023
What the ISO/IEC 27001 doesn’t cover
None
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Fdf9abb4-76f7-4cfa-8f6e-3c86afef4729
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
Yes
Any other security certifications
  • ISO 22301
  • HIPPA / HITECH
  • SOC II

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at legal@riskonnect.com. Tell them what format you need. It will help if you say what assistive technology you use.