Home / Industries / Higher education & MCDS

MyRISK Core · higher education and research

Make assurance work in higher education's own data language.

MCDS gives you shared entities and definitions. It doesn't stop your team assembling the same answer by hand every cycle. MyRISK Core turns one painful assurance question into a working pattern of controls, evidence, owners, sign-off and reporting.

Why now

The same evidence, assembled by hand, every cycle.

MCDS-engaged institutions already have the shared data language for entities, reporting and implementation patterns. What it doesn't do is stop reporting, research, credentialing, accreditation, shared-service and supplier questions from being answered from scratch each time they come up.

The strain isn't a lack of frameworks or committees — it's that nothing connects the answer given last cycle to the one being asked for now.

What's driving the conversation

  • An active MCDS adoption or sector-directory conversation
  • Reporting assurance pain across faculties or entities
  • Research project cyber and data-governance assurance
  • Credential or HCR issuer assurance
  • Accreditation evidence burden
  • AI or data-governance pressure on a specific use case

The use-case map

Six places this usually starts

01

Reporting

Sector and regulatory reporting cycles, assembled fresh each round instead of drawn from one definition.

02

Research assurance

Research project cyber, data and identity governance, evidenced per project rather than reused across them.

03

Credentials and HCR

Credential and HCR issuer assurance — who attests what, and what evidence backs it.

04

Accreditation

Accreditation evidence, rebuilt for each cycle instead of maintained as a standing record.

05

Shared services

Shared-service assurance across faculties or entities that each currently answer for themselves.

06

Supplier assurance

Supplier and third-party assurance questions, answered against the same controls and evidence rather than a fresh questionnaire each time.

Reporting, credentials, accreditation and shared services are assurance problems in their own right, which is why this is not a cyber conversation with a sector label on it.

Every path above leads to the same next step — naming the one question that's most painful right now, not the whole list at once.

What MCDS does, and what MyRISK does

A shared language is not the same as an operating model.

MCDS supplies the sector's shared data language — the entities, reporting shapes and implementation patterns institutions already recognise.

MyRISK Core maps controls, evidence, owners, decisions and reporting onto those entities for one assurance operation at a time, so the definition agreed once can answer the question again next cycle.

How the other routes attach

  • Core leads — this is where the pattern gets built
  • Trace attaches for report sign-off, and for research, AI or supplier decisions that need to be explained later
  • Essentials attaches for programme and audit-action follow-through across faculties
  • Consulting attaches where the implementation workflow itself needs separate, scoped work

Who needs to be behind it

The Scan tests for people, not just a use case

Before a Scan is worth funding

  • A named sponsor
  • The functional owner who lives with the problem day to day
  • The committee that would need to agree the definition
  • A budget route
  • Architecture and data contacts who can confirm what's actually available

This is what the readiness check is for — it names which of these are already in place and which aren't, before anyone commits to a Scan.

Take the readiness check

For your reviewers

Partner status and boundaries, in writing

What we will and won't say

  • MyRISK is an MCDS Implementation Partner in the MortarCAPS ecosystem — an ecosystem role, confirmed against current standing, never described as accreditation, certification, endorsement, preference or exclusivity.
  • Not an MCDS compliance or certification claim of any kind.
  • Not a sector-wide integration programme — one named use case, bounded, first.
  • No named institution, and no claim of sector-wide adoption. Where a worked example would sit, this page shows none — the sample outputs are on the Core and route pages.

Does Core replace your SIS, ERP or GRC?

No — it maps controls, evidence, owners and reporting onto entities you already use. It sits alongside those systems, not instead of them. Trace and Essentials attach for sign-off and follow-through; Consulting scopes implementation work separately.