For the governance and ERM leader
Committees, decisions, policies, risks, issues and evidence in one model, so oversight reads the rationale, not a summary of it.
In one sentence
AlignX gives governance and risk leaders one control library, one risk view across the enterprise, and every decision recorded with the authority it was taken under.
Written forChief Risk OfficerHead of Governance and ERMCompany SecretaryInternal Audit Director
The challenge
If any of these takes a week to answer, the rest of this page is for you.
The solution
Committee authority
Policies, standards, risks, guidelines. Formal or delegated, enterprise or divisional, with the role that holds it, on the committee's own record.

Decision log
Type, status, date, committee and meeting on every decision, so the context behind an approval is one click, not one archive search.

Policy lifecycle
Not a PDF in a folder. Status, description, approving committee and owner on the record, with the controls and attestations that enforce it.

Issues and remediation
Closed means the retest passed, and the remediation is on the same record as the finding that raised it.

Risk register
Treating, assessed, monitoring or closed. Architecture review, audit finding, self assessment or incident. The board pack is a view of this, not a retyping of it.

Appetite and tolerance
Twenty-three risks placed on residual likelihood against impact, coloured by treatment. Four still sit outside appetite, and the matrix says which four.

Day to day
The AlignX technology
Questions
AlignX brings overall governance and risk management into one enterprise view. Where you run standard GRC/IRM functionality (ServiceNow IRM, Archer, LogicGate, MetricStream), ERM spreadsheets, policy attestation and control testing workpapers, AlignX consolidates them. Where you use a specialised GRC tool for deep category-specific work, AlignX augments and extends rather than replaces. The result is fewer tools, one taxonomy, one source of truth.
For most customers, yes, where the platform is being used for standard GRC functionality that AlignX delivers. Standalone GRC licences (typically 150k to 500k AUD annually depending on scale) come out. Where deep specialised functionality is genuinely used, AlignX integrates and extends. Consolidation usually pays for AlignX within the first year.
Risk appetite and tolerance are configured per risk category with automated breach detection. Every risk carries appetite, tolerance, treatment strategy (accept, avoid, reduce, transfer) and treatment plan with owner and due date. Appetite breaches escalate automatically to the right forum.
Yes. Risk taxonomies, likelihood and impact scales, and heat maps are fully configurable to your framework. AlignX ships with ISO 31000 and COSO ERM templates. You configure once, then every risk anywhere in the enterprise uses the same framework.
All risk categories live in one register with category-specific views. Cyber risks flow in from the CISO workflow, financial risks from finance, compliance from legal, without duplication. Enterprise risk reports the aggregate; category leaders see their slice.
Yes. The board risk view is live. Appetite breaches, top risks by residual impact, treatment progress and control effectiveness all refresh on demand. Audit committees get evidence in real time, which shortens their meetings and reduces surprise findings.
Configurable attestation and testing workflows with evidence capture and audit trail. Every control test result, every policy attestation and every audit finding lives on the connected record. When auditors ask for evidence, you filter, export and hand it over in minutes.
Ten minutes, twenty-one questions, an instant maturity score.