Home / Core

MyRISK Core

Define controls and evidence once. Reuse them everywhere they're asked for.

Core is the assurance layer Trace and Essentials both sit on — one record of controls, evidence, owners and reporting that many different requests draw from, instead of each one being assembled by hand. If that sounds like what a GRC or compliance platform is meant to do, you're not wrong — what's different is how the record gets reused.

The problem

The same controls and evidence, assembled by hand, one request at a time.

Reporting, research, credentialing, accreditation, shared-service and supplier questions all ask for versions of the same thing — and most organisations answer each one from scratch, because nothing connects the answer they gave last time to the one they're being asked for now.

Core maps controls, evidence, owners and reporting onto the entities an organisation already uses, so a definition agreed once can serve many requests instead of one.

A shared record doesn't answer every question by itself. It stops every question starting from zero.

Define once, reuse many

  • Controls and evidence attached to the entities the organisation already uses
  • Owners and review cadence on each definition
  • One definition serving reporting, research, credentials and supplier assurance
  • Trace attaches where a sign-off must be defended
  • Essentials attaches where owners and actions must keep moving

What Core does

Visibility, vigilance and value

01

Visibility

One record of your IT services, suppliers, controls and risks, with the detail needed to tier and prioritise them.

02

Vigilance

Assess once against every framework you answer to, keep it current, and see it at every level — up the organisation or down to each supplier and service.

03

Value

Quantify the scenarios that matter with FAIR, rank the control changes that bring risk down most, and report the risk bought down each period.

Every Core feature →

The differentiator

The reuse comes from where the record lives, not from a bigger checklist.

Controls and evidence are vectorised inside the governed enterprise database, on Oracle AI Database 26ai — so matching a framework or analysing a control doesn't mean exporting data out to an external AI service first.

That's the mechanism behind the reuse: the record stays in one governed place, in a form that can be searched and matched directly, so the next request draws on it instead of starting a new document.

What this is, and isn't

  • Live today, inside Core
  • A platform capability MyRISK has built on, not invented from nothing
  • Not an accreditation, a certification, or a claim about any other vendor's approach

Where it's proven today

One live implementation: higher education, through MCDS.

MCDS gives higher education a shared data language for entities, reporting and implementation patterns. MCDS is the sector's data standard — Core is what turns that standard into working assurance operations on top of it. It's the sector Core has an active, time-bound partner route into, and where the pattern below is furthest along.

Core is sold to organisations that already think of this as a GRC problem — including those replacing a platform at renewal. We don't claim the scale of the largest enterprise suites; where one of them is the better fit, the comparison says so.

See the higher education entry point →

MyRISK and MCDS

MyRISK is an MCDS Implementation Partner in the MortarCAPS ecosystem. That is an ecosystem role, not an accreditation or an endorsement — and we will always describe it exactly that way.

Where are you starting from?

Three situations, three ways in.

01

New obligations are landing faster than you can answer them.

Assess once against every framework you answer to, keep suppliers current through a portal that is free for them, and put risk in financial terms the board can act on.

See Core features →

02

You already have a GRC, and it isn't doing the work.

Extend what you already own rather than ripping it out: fix the workflow that fails, and keep the platform. If the platform itself is the problem, bring your records across at renewal.

Fix the workflow →

Switch from another GRC →

03

You need capability fast, without a big budget.

Start on the Free Tier and grow, from one person running risk to a team of twenty, on plans priced by the people who run it, not everyone who uses it. Or start with one painful use case in an Opportunity Scan.

See plans, from free →

Book an Opportunity Scan →

The Opportunity Scan can start from sector and regulatory reporting, research governance, credentialing and accreditation, shared services, or supplier assurance. It needs one named use case, someone senior to back it, and someone who lives with the problem.

If you are running a shortlist

Core is meant to be compared, not taken on trust.

Seven categories of alternative, each stated from its own published pages, and where an incumbent is the better fit we say so. Core is the route that belongs in the enterprise GRC, compliance automation and register comparisons — including the one thing none of those categories does, which is matching one control set automatically against any framework you work to — ISO 27001, NIST CSF, the Essential Eight, the ISM, or one you supply.

Read the comparison →

For your reviewers

The boundaries, in writing

Where Core stops

  • Not a sector-wide integration programme. One named use case, bounded, first.
  • Not MCDS accreditation, certification or endorsement — the implementation-partner classification is an ecosystem role and nothing more.
  • Not binding on any institution that has not agreed to a definition.
  • Not a substitute for your own risk decisions about your own suppliers.

Which assurance question is painful now?

Reporting, research, credentials, accreditation, shared services or supplier assurance. Start on the Free Tier, or let the Opportunity Scan begin with the one that keeps being assembled by hand.