Risk management doesn't mean filling in a spreadsheet once a year. It means having a process that continuously captures new risks and assigns someone to own them.
As a foundation for BCM and information security, when implementing a management system, or when a company only has an informal, undocumented overview of its risks.
We build on the ISO 31000 standard and the assessment methods of ISO 31010. We help identify, analyze and evaluate risks, build a risk register, and design how risks will continue to be monitored and reviewed.