Active Risk Manager (ARM)
Active Risk Manager (ARM) is Riskonnect’s advanced, web-based solution for Enterprise, Programme, and Project Risk Management, designed to deliver proactive, integrated, and intelligent risk oversight. ARM empowers organizations to identify, assess, and mitigate risks, ensuring projects stay on track with resilience and global standard Compliance.
Deployment via cloud or on-premise.
Features
- Interactive Dashboards. Real-time insights with drill-down analytics and reporting
- Bowtie Analysis. Visualize cause-effect relationships for complex risk scenarios
- Monte Carlo Simulation. Predict cost, schedule impacts using probabilistic modelling
- Integrated Risk Frameworks. Supports ISO31000, COSO, Orange MoR compliance
- Schedule Risk and Impact Analysis. Integrates with PrimaveraP6, MSProject seamlessly
- Dynamic heat-map visualization for enterprise-wide risk visibility
- API Integration. Enhanced interoperability with external systems and data sources
- Accessibility Enhancements. Modernized UX with improved accessibility and usability features
- Aggregates project risks for holistic enterprise risk oversight
Benefits
- Improved Decision-Making. Real-time insights enable faster, informed choices
- Enterprise-Wide Visibility. Consolidates risks across projects for holistic oversight
- Regulatory Compliance. Aligns with ISO 31000, COSO, and Orange MoR
- Enhanced Collaboration. Shared dashboards foster teamwork and accountability
- Cost and Schedule Control. Monte Carlo predicts project impact accurately
- Streamlined Integration. APIs connect seamlessly with enterprise systems and tools
- Accessible User Experience. Modern interface improves usability and inclusivity
- Dynamic Risk Visualization. Heat maps simplify complex risk relationships
- Continuous Improvement. Advanced analytics drive ongoing process optimization
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 8 7 6 6 3 4 0 9 1 1 1 8 9 4
Contact
Riskonnect Active Risk Limited trading as Riskonnect. Historic trading names include Xactium, Active Risk Manager (ARM), Castellan Solutions Ltd, ClearView and CAM Management Solutions Limited (CAMMS)
Shane Yeeda
Telephone: +1 770 790 4683
Email: legal@riskonnect.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
- Project and portfolio management
Financial
- Treasury and Risk Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- Prerequisites for client machines and local hosting are published. Well within normal industry standard specifications.
- System requirements
-
- No client side installation required
- SSO with SAML 2 IDP
- MS SQL/SSRS for local hosting
User support
- Email or online ticketing support
- Yes
- Support response times
-
Urgent – 1 business hour
High – 2 business hours
Medium – 8 business hours
Low – 16 business hours - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- All customers have access to technical and functional documentation through our Customer Success Portal 24x7 with UK based email and telephone support staff. All support related issues are logged on the portal with full visibility to the client. Each client will have a dedicated Account Executive and Customer Success Manager (CSM) for additional assistance and support as required. The CSM will hold a regular business reviews and maintain a Rolling Action Item Log to ensure you are always getting the very best out of your subscription.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Full project initiation and structured implementation walk through of installation, process mapping, configuration, data migration and training is including in the service proposals.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- A database back-up will be provided on request, or customers can export their data out using the tools provided in the software or via the API.
- End-of-contract process
- Database backup will be provided to the client, hosted services will be disabled and data destroyed.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Riskonnect provides a comprehensive range of documentation, including installation guides, user manuals, training materials, support manuals and quick reference guides through our Customer Success Portal as well as downloadable material through the product’s built-in Help facility.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Same user experience. User interface has been designed to be adaptive to device size.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
Read/Write functions via REST API including GET, PUT. POST and PATCH commands. Full swagger documentation and tech support provided.
Manage users/resources
Manage/update static data. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Application code cannot be customised but ARM has a highly configurable interface that allows admin users to configure which fields are available to and write and set rules for mandatory fields and workflow. All field labels and risk scoring metrics are customisable to support multiple processes and matrices. Users can also build customised public and private dashboards.
Email alerts and reports are customisable. ARM is supplied with a suite of standard reports that can be customised to support the client requirements.
Scaling
- Independence of resources
- ARM is designed to be scalable from a few users to thousands of users. All releases are load tested. Each client has a dedicated application server, CPU and memory loads are monitored. A fully dedicated sole sue environment can be provided if required.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Session histories and user activity is available in the admin screens and can standard admin reports.
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Other
- Other data at rest protection approach
- For hosted clients - AES 256 Disk Encryption. Physically protected in AWS data centre. Locally hosted is under client arrangements.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Data can be exported into MS Excel, via reporting services or extracted through the API.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- .rtf
- .ppt
- JSON via API
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- All data is protected in transit using https protocols. Hosted data is encrypted at rest. A document detailing our approach to applying the NCSC 14 Cloud Security Principles is available to clients and prospects under NDA as part of our security documentation pack.
Availability and resilience
- Guaranteed availability
- The Riskonnect Service shall be available to Users at least 99.7% of the time measured on a quarterly basis for the 3-month period ending on the last day of each calendar quarter.
- Approach to resilience
- Available on request
- Outage reporting
- Automatic email alerts to support desk, who will contact affected customers individually.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Only dedicated members of the TechOps team have access to hosted servers, and the AWS management console requires multi-factor authentication for access. Development, QA, and support environments are hosted on completely separate AWS accounts, so user cannot access areas they do not have permissions for.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- ISO27001, ISO22301, GDPR, CCPA
- Information security policies and processes
- We follow ISO 27001 standards and requirements. Allocated Information Security Manager is a VP of the company, and Information Security Officer reports directly to him. Where possible, physical or logical controls are in place to ensure policy compliance, and regular training and checks are made for ongoing compliance. Additionally there are regular internal audits, as well as six monthly Surveillance Visits from independent auditors.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All changes to hosted infrastructure or configuration must go though our change management process, which is a required control in our ISO 27001 implementation. A change request must be submitted and approved before a change can be made. The change control system requires details of the change, a risk assessment of the impact of the change, rollback and testing details, and communication requirements. The person raising the change cannot approve their own change.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Weekly vulnerability scans are performed using Tenable.io. Any critical patches are applied immediately (out of hours), and all servers are patched monthly to resolve any other issues.
We receive regular industry feeds from suppliers and independent providers. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Resilience aligns with ISO 27001, ISO 22301, and SOC II frameworks, ensuring that monitoring and incident response processes meet recognized security standards.
The Resilience environment is monitored in real time.
Response to Potential Compromises:
Immediate alerting and triage by the Security Operations team.
Containment and isolation of affected systems to prevent further impact.
Remediation actions executed based on predefined criteria and tracked until closure.
Post-incident review to capture lessons learned and strengthen controls. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Immediate alerting and triage by the Security Operations team.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Access to a demonstration version of the software can be made available after a mutual non disclosure agreement has been signed
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 2%
- Between £2,500,001 and £5,000,000
- 2%
- Over £5,000,001
- 1%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- A-Lign
- ISO/IEC 27001 accreditation date
- Tuesday 19 December 2023
- What the ISO/IEC 27001 doesn’t cover
- None
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Fdf9abb4-76f7-4cfa-8f6e-3c86afef4729
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 22301
- HIPPA / HITECH
- SOC II
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-