Core · features
Everything Core does, in one place.
Core is organised around three needs: see what you run and who you rely on, keep watch over it, and spend where the risk comes down most. This is the full list, in the terms a reviewer will check it against.
01 · Visibility
One record of what you run and who you rely on
Incomplete or inconsistent information about services, suppliers and their controls means protection that misses and response that starts late.
IT services
- Internal and third-party IT service assessments
- Data types and data classification
- RTO and RPO, and CIA ratings
- Platform, hosting and ownership
- CMDB references and tiering
- An architectural view of each service
Organisation and suppliers
- Enterprise, business unit and business process records
- Supplier corporate, contract, sizing, financial and insurance data
- Supplier tiering
- Entity-level risk and control assessments
- External scorecards recorded against suppliers
Frameworks, controls and evidence
- Framework, control and policy library
- Load your own frameworks alongside the standard ones
- Custom fields and lists in every function
- Evidence attached to suppliers, services, risks and controls
- Documents searchable across the whole account
02 · Vigilance
Assess once, keep it current, see it at every level
A backlog of assessments across several frameworks leads to inconsistent advice, missed obligations and risk nobody is managing.
Assessments
- Design and operating effectiveness, maturity and compliance
- Any scope — enterprise, unit, process, IT service, supplier — and any period, with history
- Every framework vectorised on Oracle AI Database 26ai, so controls match across them automatically
- Assess once, and carry the result to every other framework
- Uploaded documents read by AI, and drafted into the assessment
- Statement of Applicability at any level of the organisation
Questionnaires
- Questionnaire Builder, with question libraries for any framework
- Simple or audit-grade questionnaires from one framework or several
- A responder portal, free and unlimited for respondents
- Evidence upload, reminders and bulk import
- Evidence documents read by AI, and drafted into findings for review
- Observations and findings recorded against each response
Risk and workflow
- Risk and issue registers at enterprise, unit, process and service level
- Configurable risk matrices; actions with history
- Issues raised automatically from failed controls
- Aggregate up the organisation, or cascade down to suppliers and services
- Workflow Builder and predefined workflows, with tasks, forms, email, reminders and an audit trail
03 · Value
Spend where the risk comes down most
Remediation set by vendor roadmaps rather than business risk loses the business's attention and the budget's return.
Scenarios
- Scenario Builder: actor types and motivations
- MITRE ATT&CK tactics and techniques
- The data types and critical services each scenario touches
- MITRE ATT&CK simulation on a service's architecture
Quantification
- FAIR, with the Open FAIR algorithms or your own financial and statistical models
- Projected and actual risk by scenario and period, with the options considered
- Risk bought down, measured each assessment period
Control what-if
- The effect on risk of one control change, or a group of them
- Ranked by key-control weighting, MITRE simulation, scorecards or control analytics
- The return on each option, and the best order to make them in
Platform
What sits underneath
Data and integration
- Full referential integrity; a rename carries to every linked record
- CSV import on every form
- CSV, Excel, PDF and PowerPoint export
- REST APIs and Office 365
- Optional Oracle Integration Cloud, with over 400 adapters
Hosting and security
- Oracle Autonomous Database, in Oracle Cloud's Sydney region
- Delivered as a service: you need nothing from Oracle, and no Oracle licence or skills, to use it.
- TLS 1.2 in transit; encrypted at rest
- Immutable backups
- Web application firewall
- Separate development, test and production
Access and tenancy
- Sign in with your Google or Microsoft tenancy, and its MFA
- Role-based access with custom roles, down to screen region
- Sub-accounts per engagement for consultants and partners
- The assistant built into every page
- Licences only for the people who run risk and compliance
- Dashboards for each functional area; deeper reporting through Power BI or Oracle Analytics
Not in Core today
Said up front, so it is not found later
- Key risk indicators (on the roadmap)
- Skip logic in questionnaires (on the roadmap)
- SAML and SCIM as standard; SAML and LDAP today as customisation
- Incident management
- Full policy lifecycle
myrisk.io/core/features · [email protected] · As at October 2026
See it on your own frameworks
Start on the Free Tier, or map your current records into Core with an Opportunity Scan.