Not a tool list, a capability map, in the spirit of a business capability model: what a GRC and resilience function must be able to do, from governance through detection, response, recovery, and assurance. Explore it below. It's opinionated and best-practice-aligned, and it's a starting point we shape to your organization, together.
Each box is a capability, something the function must be able to do. Click any one and the panel below fills with its best-practice alignment, the AI agent that operates it, its data flows, and ownership (RACI), all at once. Where PivotRisk ships a template for a capability, the panel links to it.
Click any capability to see its full profile below, definition, how it fits the model, best-practice alignment, AI agent, ownership (RACI), data flows, and related terms, and to spotlight how it connects. Switch to Data Flows to see the whole network at once. Boxes are colored by accountable owner.
Pick any box above and this panel fills with its description, the template that implements it, best-practice frameworks, the AI agent that operates it, its data flows (click those to jump), and the full RACI, all at once. Clicking also spotlights how it connects to the rest of the model.
The capabilities are a synthesis of the frameworks that define good governance, risk, resilience, and service practice, so one model satisfies many of them at once.
Built around control catalogs. Compliance is the goal. Work flows to whoever is available. Escalation is ad hoc. Progress is measured by documentation completeness.
Built around capabilities, ownership, and outcomes. Performance is the goal. Work has named owners and clear cadences. Escalation paths are defined and tested. Progress is measured by risk posture.
Named owners for every capability, shown as the owner colors and full RACI in the model above.
Defined handoffs so work doesn't fall through the seams, the Data Flows view above draws every one.
Each capability defines outcomes, not just tasks, see its definition and how it fits when you click it.
Feedback loops keep it from becoming shelfware, Reporting flows back into the Operating Model.
The connections between capabilities become live calculations, incidents driving likelihood, controls driving residual, issues degrading controls. Evidence in, ratings out.
A shared risk and control taxonomy lets every capability (and every template) speak the same language and roll up into one enterprise view.
Once the model is connected, agents can operate it (re-rating risks, triaging findings, answering questionnaires) over a deterministic engine. How that works →