E2ERisk GRC - Governance, Risk, Compliance (GRC) Platform
E2E Risk – GRC tool is a cost-effective governance, risk and compliance (GRC) software suite from E2E Security Consulting (E2E SC). It provides a highly configurable platform to manage risk, controls, assurance and compliance, actions, policies and performance, enabling consistent processes, clear ownership and improved organisational oversight.
Features
- Integrated view of governance, risk, compliance and controls
- End-to-end risk assessments across strategic, project and operations
- Assign, track and manage risks with clear ownership
- Centralised management of controls, actions and assurance
- Evidence compliance against regulatory and standards requirements
- Policy management with ownership, review cycles and attestation
- Real-time dashboards for enterprise GRC and risk performance
- Outcome-focused GRC improving accountability and decision-making
- Proactive risk insight reduces unexpected loss and liability
- Increased assurance for leadership and external stakeholders
Benefits
- Provides a single, trusted source for enterprise GRC information
- Reduces administrative effort through streamlined GRC processes
- Improves risk visibility, enabling informed and timely decisions
- Strengthens accountability through clear ownership of risks and actions
- Supports demonstrable compliance with regulations and standards
- Reduces likelihood of unexpected financial or operational losses
- Enhances assurance for senior management and external stakeholders
- Enables consistent risk assessment across the organisation
- Improves governance maturity and control effectiveness
- Scales easily to support changing organisational needs
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 5 9 5 5 9 9 5 0 4 9 1 8 0 1
Contact
E2E SECURITY CONSULTING LTD
dave mccaw
Telephone: 07502142901
Email: dave.mccaw@e2esc.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- E2ERisk GRC platform can be used as a fully standalone service. Where required, it may optionally integrate with the wider E2ERisk GRC platform or other governance, risk, and compliance tools, but it does not depend on any other software service to operate.
- Cloud deployment model
- Public cloud
- Service constraints
- The service is designed to deliver 99.9% availability, with scheduled maintenance outside normal business hours and customers notified in advance. Users must access the service using a modern, supported web browser. No other material constraints apply.
- System requirements
-
- Access requires a modern, supported browser (Chrome, Edge)
- Multi-factor authentication (MFA) is required via SMS or authenticator app
User support
- Email or online ticketing support
- Yes
- Support response times
- All support requests are acknowledged and responded to within four business hours of receipt
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- All support is available via email or telephone. Requests are categorised as general queries or support tickets (P1–P4) in line with our terms and prioritised accordingly. Support is included in the standard subscription at no additional cost. Enterprise customers are assigned a dedicated technical Customer Success Manager.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Our dedicated Customer Success team ensures a seamless onboarding experience and delivers expert virtual training. We provide comprehensive onboarding documentation, access to an in-house consultant for tailored support during client adoption, and a rich, continuously updated knowledgebase. This combination of personalised guidance, expert advice, and self-service resources ensures organisations can embed the platform quickly, confidently, and effectively—delivering a superior onboarding and support experience compared to other providers.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- Users can export data directly from the platform in CSV, ODF, or PDF formats, or request a full CSV data dump via their Customer Success Manager. All data export options are included within the standard subscription at no additional cost.
- End-of-contract process
- At the end of the contract, clients who choose not to renew can export their data—either directly or with assistance from their Customer Success Manager—and have their accounts suspended or deleted. The entire process is managed by the Customer Success team to ensure a smooth transition.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- EN 301 549
- Description of service interface
- Users access the platform via a web browser through an intuitive graphical interface
- Accessibility standards
- EN 301 549
- Accessibility testing
- We conducted accessibility testing with users, including those using assistive technologies, to evaluate color contrast and keyboard navigation. Users interacted with the platform while our product team observed and collected feedback on any challenges. Identified issues were addressed through subsequent product improvements.
- API
- No
- Customisation available
- Yes
- Description of customisation
- The platform offers a configurable GRC tool, enabling organisations to tailor risk, control, and compliance settings to their specific needs. Users can define risk categories, scoring criteria, thresholds, and approval workflows to align with internal policies and regulatory obligations. This flexibility helps organisations prioritise risks according to their risk appetite and operational context. Configuration changes are applied in real time, ensuring assessments always reflect current organisational preferences. An intuitive interface with guidance and tooltips allows adjustments without technical expertise, while role-based access ensures only authorised personnel can modify settings. Customisable dashboards and reporting views focus teams on the most critical risks while maintaining consistency across the organisation. Automated monitoring and alerts complement these capabilities, helping teams track emerging risks and remediate issues efficiently. By combining flexibility with control, the platform enables organisations to manage risk, compliance, and assurance effectively, aligning with internal frameworks, regulatory requirements, and operational priorities, and providing clear visibility across the enterprise.
Scaling
- Independence of resources
- The platform is designed to maintain consistent performance for all users, regardless of demand. It leverages scalable cloud infrastructure, load balancing, and resource isolation to ensure that one user’s activity does not impact others. System performance and usage are continuously monitored, and built-in redundancy and failover mechanisms ensure the service remains reliable even during periods of high demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide a range of service metrics, including platform availability, supplier management and onboarding performance, and client-specific insights on how users manage their suppliers.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export their data directly from the platform in multiple formats, including CSV, ODF, and PDF. Exports are performed via the platform’s intuitive interface, allowing users to select specific datasets or full reports. For larger or full data exports, users can request assistance from their Customer Success Manager, who can provide a complete CSV data dump
- Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- E2ERisk web-based services are guaranteed to be available for at least 98% of each calendar month, excluding scheduled maintenance. “Available” means the platform is operational and core assessment, collaboration, and reporting functions are accessible to users. Availability is measured on a monthly basis. Where the availability target is not met, service credits may apply in accordance with the service level agreement and contractual terms agreed with the customer.
- Approach to resilience
- The platform is designed for resilience using cloud-native capabilities, including deployment across multiple availability zones and automated failover. Redundancy is built into core components to reduce the risk of service disruption. Detailed configuration and resilience information can be provided to customers under appropriate assurance arrangements.
- Outage reporting
- Service outages and significant service degradation are communicated to customers via email alerts as the primary notification method. Phone-based notifications can also be provided on request through the Customer Success team. All outage alerting options are included within the standard subscription at no additional cost.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted to authorised personnel only and controlled through role-based access and formal approval processes. Administrative access is protected using secure access controls and network restrictions appropriate to the hosting environment. Support channels are secured using strong authentication controls, including multi-factor authentication. Access permissions are reviewed on a regular basis to ensure continued appropriateness.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus. Governance is aligned with NCSC guidance, the Software Security Code of Practice, and CDDO secure-by-design principles.
- Information security policies and processes
- Our information security policies are fully aligned with ISO 27001 standards, ensuring that all aspects of the platform, data handling, and organisational processes meet internationally recognised security requirements. We maintain a comprehensive suite of policies covering areas such as data protection, access control, incident response, risk management, and supplier security. These policies are reviewed annually and formally approved by the board, ensuring they remain current, effective, and fully integrated with business operations. Compliance with these policies is closely monitored by the senior leadership team, who receive extensive and ongoing training in information security best practices, regulatory obligations, and emerging threats. Staff across the organisation are regularly trained and assessed to ensure adherence to security policies and procedures. Our approach combines policy, process, and culture to embed security across every level of the organisation. Regular audits, risk assessments, and internal reviews are conducted to identify gaps and implement improvements proactively. This structured, multi-layered approach ensures that client data is consistently protected, operational risk is minimised, and the organisation maintains a robust security posture that exceeds standard compliance requirements.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Configuration and change management is governed through defined processes to ensure the secure and controlled deployment of infrastructure and application changes. Infrastructure is built and maintained using approved, hardened configurations, with an up-to-date software bill of materials maintained. Changes are version controlled and reviewed prior to deployment, and automated tooling is used to identify vulnerable dependencies. Regular vulnerability scanning is performed to support timely remediation and maintain a secure hosting environment.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Vulnerabilities are identified through multiple inputs, including scheduled vulnerability scanning, additional scanning in response to emerging threats, automated monitoring of software dependencies, and monitoring of underlying cloud infrastructure. Identified vulnerabilities are risk assessed and prioritised based on severity and impact. Remediation actions are tracked and implemented in line with defined vulnerability management processes to maintain a secure and resilient service.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Protective monitoring is implemented using security monitoring and detection controls to identify indicators of suspicious or unauthorised activity within the hosting environment. Alerts are reviewed by authorised personnel and investigated in line with defined incident management procedures. Where required, incident response actions are initiated to contain and remediate security events. Monitoring outputs and response actions are logged and reviewed to support continuous improvement of security controls and service resilience.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- A documented incident management process is in place to identify, triage, and respond to incidents. Security incidents are prioritised and handled in line with defined incident response procedures. Customers can report incidents via support channels or through their Customer Success Manager. Following resolution, customers are notified and, where appropriate, provided with a summary of the incident, including root cause information and recommended remediation actions, in line with contractual terms.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- The service offers a free, time-limited trial providing access to the full feature set for evaluation purposes. The trial period lasts up to three months, allowing users to explore the platform, test functionality, and assess suitability before committing to a paid subscription.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 7.5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 11%
- Between £2,500,001 and £5,000,000
- 12%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-