Skip to main content

Help us improve the Digital Marketplace - send your feedback

Riskonnect Active Risk Limited trading as Riskonnect. Historic trading names include Xactium, Active Risk Manager (ARM), Castellan Solutions Ltd, ClearView and CAM Management Solutions Limited (CAMMS)

Active Risk Manager (ARM)

Active Risk Manager (ARM) is Riskonnect’s advanced, web-based solution for Enterprise, Programme, and Project Risk Management, designed to deliver proactive, integrated, and intelligent risk oversight. ARM empowers organizations to identify, assess, and mitigate risks, ensuring projects stay on track with resilience and global standard Compliance.

Deployment via cloud or on-premise.

Features

  • Interactive Dashboards. Real-time insights with drill-down analytics and reporting
  • Bowtie Analysis. Visualize cause-effect relationships for complex risk scenarios
  • Monte Carlo Simulation. Predict cost, schedule impacts using probabilistic modelling
  • Integrated Risk Frameworks. Supports ISO31000, COSO, Orange MoR compliance
  • Schedule Risk and Impact Analysis. Integrates with PrimaveraP6, MSProject seamlessly
  • Dynamic heat-map visualization for enterprise-wide risk visibility
  • API Integration. Enhanced interoperability with external systems and data sources
  • Accessibility Enhancements. Modernized UX with improved accessibility and usability features
  • Aggregates project risks for holistic enterprise risk oversight

Benefits

  • Improved Decision-Making. Real-time insights enable faster, informed choices
  • Enterprise-Wide Visibility. Consolidates risks across projects for holistic oversight
  • Regulatory Compliance. Aligns with ISO 31000, COSO, and Orange MoR
  • Enhanced Collaboration. Shared dashboards foster teamwork and accountability
  • Cost and Schedule Control. Monte Carlo predicts project impact accurately
  • Streamlined Integration. APIs connect seamlessly with enterprise systems and tools
  • Accessible User Experience. Modern interface improves usability and inclusivity
  • Dynamic Risk Visualization. Heat maps simplify complex risk relationships
  • Continuous Improvement. Advanced analytics drive ongoing process optimization

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at legal@riskonnect.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 8 7 6 6 3 4 0 9 1 1 1 8 9 4

Contact

Riskonnect Active Risk Limited trading as Riskonnect. Historic trading names include Xactium, Active Risk Manager (ARM), Castellan Solutions Ltd, ClearView and CAM Management Solutions Limited (CAMMS) Shane Yeeda
Telephone: +1 770 790 4683
Email: legal@riskonnect.com

About your service

Service categories

Applications

Enterprise resource management

  • Enterprise performance management
  • Project and portfolio management

Financial

  • Treasury and Risk Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
Prerequisites for client machines and local hosting are published. Well within normal industry standard specifications.
System requirements
  • No client side installation required
  • SSO with SAML 2 IDP
  • MS SQL/SSRS for local hosting

User support

Email or online ticketing support
Yes
Support response times
Urgent – 1 business hour
High – 2 business hours
Medium – 8 business hours
Low – 16 business hours
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
All customers have access to technical and functional documentation through our Customer Success Portal 24x7 with UK based email and telephone support staff. All support related issues are logged on the portal with full visibility to the client. Each client will have a dedicated Account Executive and Customer Success Manager (CSM) for additional assistance and support as required. The CSM will hold a regular business reviews and maintain a Rolling Action Item Log to ensure you are always getting the very best out of your subscription.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Full project initiation and structured implementation walk through of installation, process mapping, configuration, data migration and training is including in the service proposals.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
A database back-up will be provided on request, or customers can export their data out using the tools provided in the software or via the API.
End-of-contract process
Database backup will be provided to the client, hosted services will be disabled and data destroyed.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Riskonnect provides a comprehensive range of documentation, including installation guides, user manuals, training materials, support manuals and quick reference guides through our Customer Success Portal as well as downloadable material through the product’s built-in Help facility.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Same user experience. User interface has been designed to be adaptive to device size.
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
Read/Write functions via REST API including GET, PUT. POST and PATCH commands. Full swagger documentation and tech support provided.
Manage users/resources
Manage/update static data.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Application code cannot be customised but ARM has a highly configurable interface that allows admin users to configure which fields are available to and write and set rules for mandatory fields and workflow. All field labels and risk scoring metrics are customisable to support multiple processes and matrices. Users can also build customised public and private dashboards.
Email alerts and reports are customisable. ARM is supplied with a suite of standard reports that can be customised to support the client requirements.

Scaling

Independence of resources
ARM is designed to be scalable from a few users to thousands of users. All releases are load tested. Each client has a dedicated application server, CPU and memory loads are monitored. A fully dedicated sole sue environment can be provided if required.

Analytics

Service usage metrics
Yes
Metrics types
Session histories and user activity is available in the admin screens and can standard admin reports.
Reporting types
Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Other
Other data at rest protection approach
For hosted clients - AES 256 Disk Encryption. Physically protected in AWS data centre. Locally hosted is under client arrangements.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Data can be exported into MS Excel, via reporting services or extracted through the API.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • .rtf
  • .ppt
  • JSON via API
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
All data is protected in transit using https protocols. Hosted data is encrypted at rest. A document detailing our approach to applying the NCSC 14 Cloud Security Principles is available to clients and prospects under NDA as part of our security documentation pack.

Availability and resilience

Guaranteed availability
The Riskonnect Service shall be available to Users at least 99.7% of the time measured on a quarterly basis for the 3-month period ending on the last day of each calendar quarter.
Approach to resilience
Available on request
Outage reporting
Automatic email alerts to support desk, who will contact affected customers individually.

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Only dedicated members of the TechOps team have access to hosted servers, and the AWS management console requires multi-factor authentication for access. Development, QA, and support environments are hosted on completely separate AWS accounts, so user cannot access areas they do not have permissions for.
Access restriction testing frequency
At least once a year
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
ISO27001, ISO22301, GDPR, CCPA
Information security policies and processes
We follow ISO 27001 standards and requirements. Allocated Information Security Manager is a VP of the company, and Information Security Officer reports directly to him. Where possible, physical or logical controls are in place to ensure policy compliance, and regular training and checks are made for ongoing compliance. Additionally there are regular internal audits, as well as six monthly Surveillance Visits from independent auditors.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All changes to hosted infrastructure or configuration must go though our change management process, which is a required control in our ISO 27001 implementation. A change request must be submitted and approved before a change can be made. The change control system requires details of the change, a risk assessment of the impact of the change, rollback and testing details, and communication requirements. The person raising the change cannot approve their own change.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Weekly vulnerability scans are performed using Tenable.io. Any critical patches are applied immediately (out of hours), and all servers are patched monthly to resolve any other issues.
We receive regular industry feeds from suppliers and independent providers.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Resilience aligns with ISO 27001, ISO 22301, and SOC II frameworks, ensuring that monitoring and incident response processes meet recognized security standards.
The Resilience environment is monitored in real time.
Response to Potential Compromises:
Immediate alerting and triage by the Security Operations team.
Containment and isolation of affected systems to prevent further impact.
Remediation actions executed based on predefined criteria and tracked until closure.
Post-incident review to capture lessons learned and strengthen controls.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Immediate alerting and triage by the Security Operations team.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Access to a demonstration version of the software can be made available after a mutual non disclosure agreement has been signed

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
2%
Between £2,500,001 and £5,000,000
2%
Over £5,000,001
1%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
A-Lign
ISO/IEC 27001 accreditation date
Tuesday 19 December 2023
What the ISO/IEC 27001 doesn’t cover
None
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Fdf9abb4-76f7-4cfa-8f6e-3c86afef4729
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
Yes
Any other security certifications
  • ISO 22301
  • HIPPA / HITECH
  • SOC II

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at legal@riskonnect.com. Tell them what format you need. It will help if you say what assistive technology you use.