Home / Essentials
MyRISK Essentials · practical risk management for growing organisations
Know where you stand, and show it when someone asks.
Insurers, customers, banks, tenders and the board all ask for proof. But what you know about your risks lives in people’s heads, so the answer gets rebuilt every time. And somewhere, something important is sitting in someone’s inbox, or has been forgotten. A growing organisation deserves to see its risks the way the large ones do, without hiring a risk team.
How it works for you
Three steps to knowing where you stand
Tell us about your organisation
What you do, where, who you depend on and what worries you. A short form, saved as you go.
Get your First Risk Baseline
Built from what you already know about your organisation: what matters, who owns it, what has not moved and where the evidence is thin.
Keep it current every month
A monthly refresh shows what changed, so the next request is a retrieval rather than a scramble.
We have answered these requests from both sides of the table: the one asking for proof, and the one who has to find it. Built by a team with over 40 years in technology, risk and governance, and named a Cool Vendor™ in Gartner Coolest Vendor Innovations for Assurance: GRC and TPRM, 9 September 2026†. Read more
The offer
A fifteen-minute baseline, then a monthly rhythm
MyRISK Essentials builds a First Risk Baseline from a short profile of your organisation, in about fifteen minutes: what matters, who owns it, what has not moved and where the evidence is thin.
A monthly refresh keeps it current, so the next request is a retrieval rather than a scramble. The baseline shows position; the refresh is what shows change.
Cadence, not register.
The 90-day rhythm
- First Risk Baseline from a short profile of your organisation — the first one free*
- Monthly refresh: what closed, what aged, what stalled, what evidence arrived
- A monthly leadership summary the meeting actually uses
- Three review cycles, then a decision: continue, adjust, or stop
- A reusable proof pack for the next insurer, customer or tender request
* Free until 31 December 2026. From 1 January 2027 the First Risk Baseline is A$495.
Who runs it
Built for the person who gets the proof request
One condition applies to every sale: a named person on your side will keep the rhythm running. We do not sell a rhythm nobody will run.
Introducing a client rather than buying for yourself? For advisers and brokers →
The honest comparison
You could put your spreadsheet through an AI tool today
Many teams already have. It produces a plausible register that reads well and cannot be shown to anyone, because nothing traces to a source and nobody owns any line of it.
We have run it both ways on fourteen sector cases built from public information — a custom GPT or Copilot against a full Essentials baseline, from the same starting profile. It returned thirty ranked risks and 270 actions in every single case, and in all fourteen, no sourced observation, no modelled scenario and no traceability row.
More risks is the problem, not the selling point. Thirty risks times nine actions is two hundred and seventy things to do, and nobody sequences two hundred and seventy things. Deciding which eight to twelve actually matter here is the work, and a list of thirty has handed that decision straight back to you.
Most risk lists show risks one at a time. Your baseline shows which ones collide. Every risk is traced to the areas it spans and how it spreads into the others — a supplier failure that turns into a cashflow problem, or a cyber incident that becomes a regulatory one.
30 RANKED RISKS · 9 ACTIONS EACH · 0 SOURCED · 0 SCENARIOS
What a custom GPT or Copilot returns
- One risk of thirty: cyberattack compromising banking services and customer data
- Patch internet-facing vulnerabilities to risk-based deadlines. Harden privileged access with phishing-resistant multi-factor authentication. Segment critical systems, deploy behavioural detection, adopt zero trust
- Every one of those is good advice, and every one of them would appear for any bank on earth
- Nothing says this is where your exposure is. The ranking is by plausibility, not by anything measured about you
- And it costs you the capacity you needed elsewhere. For this bank the material exposure was regulatory, and a cyber programme of that size consumes exactly the control-delivery effort the regulatory remediation was short of
Correct advice, pointed at the wrong risk, is not a neutral outcome.
6–15 BOARD RISKS · 4 SCENARIOS · 6–15 TRACED ROWS
What Essentials gives instead
- One page: what moved this month, and why
- Actions closed, actions aged, and the named owner of each stalled item
- Where the evidence is thin, stated plainly
- The proof request received this month, and how it was answered from the pack
- The one decision the meeting is being asked to make
Every line traces back to the baseline underneath it.
For your reviewers
The boundaries, in writing
Where Essentials stops
- Not assurance, not certification, and not a compliance opinion — and it must never be presented as one.
- Not a risk register you file and forget. If a register or a framework library is the need, that is MyRISK Core.
- Not automatic: action closure and follow-through improve because the rhythm runs, not because software promises it.
- Not a managed service by stealth. That person owns the rhythm; we support it.
See how it works
Six flows, fourteen stages, one assessment
What runs between the profile you fill in and the pack that reaches the meeting.
Fourteen typed stages, each one recording what it produced, what it assumed, what it was built from and what it is uncertain about. That is how a line in the pack traces back to the material it came from months later.
It also shows the point the engine stops: every generated risk arrives awaiting a decision, and the only ways out are accept it, change it, throw it out, or add the one it missed.
- Observe — your inputs normalised, the current environment scanned, both grouped
- Name — what carries forward, what is new, and what did not resurface
- Explain — root conditions, triggers, and what each one would set off
- Test — transient, patchable or structural, and who is most exposed
- Consequence — scenarios, business impact, and a ranked plan where every risk has an action
- Report — the board view, rendered without re-analysing it
†
Gartner, Coolest Vendor Innovations for Assurance: GRC and TPRM, Jie Zhang, Antonia Donaldson, Zachary Ginsburg, 9 September 2026.GARTNER, Cool Vendors is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Gartner does not endorse any company, vendor, product, or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner's business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
Who asked you to prove something in the last 90 days?
Book a First Risk Baseline: a short form about your organisation, then about fifteen minutes to run — so the risk that matters is not the one nobody owned, and the next time someone asks, you can say: we have this under control, and everyone knows who owns what, and what questions still need to be answered.