Use cases

How organisations like yours deploy KRIogene.

Seven sector scenarios, one platform — and ready-to-use packs that preload risks, controls, obligations and indicators so you start in days, not months.

Ready-to-use packs

You never start from a blank page.

Every setup described below relies on packs: preconfigured GRC content that we provide and install for you. Rather than building your mapping standard by standard, you start from a proven base, which you then adapt to your organisation.

Regulatory packs

For a given standard or regulation, the pack preloads the obligations, standard controls, risk scenarios and associated KRIs — already mapped to one another.

DORANIS2GDPRISO 27001Solvency IISapin IICSRDBasel III/IV

Sector packs

Aligned with the 21 sections of the European nomenclature, they combine a reference risk map, a control library and the obligations specific to your business.

IndustryTechBankingInsuranceHealthPublic sectorRetail & logistics

What a pack contains

  • A pre-filled, structured risk map
  • A library of controls linked to risks
  • Obligations mapped, standard by standard
  • KRIs with default alert thresholds
  • Campaign and reporting templates
  • The segregation of the three lines of defence already in place

Packs are accelerators: 100% customisable, kept current by the built-in regulatory watch, and combinable when your organisation falls under several frameworks.

— Sector 01 / Industry & energy

Master operational and HSE risks.

An industrial group with several production sites, a structured HSE function, regular internal audits and ISO 9001, ISO 14001 and ISO 45001 requirements. The risk department must consolidate multi-site mapping and produce quarterly group reporting.

Dominant GRC challenges

  • HSE, industrial and environmental risks
  • ISO 9001 / 14001 / 45001 compliance
  • Multi-site with uneven maturity
  • Incidents with regulatory traceability

KRIogene modules involved

Risks, Scenarios, Controls, Incidents, Actions, Audit, Obligations

Observable benefits

  • Consolidated group view in real time
  • Methodological consistency enforced across all sites
  • Committee reporting prepared in half the time
  • Faster internal audits
Recommended packs
Industry PackISO 9001/14001/45001 Pack
— Sector 02 / Tech & digital services

Secure DORA, NIS2 and ISO 27001.

A growing tech company operating across several European jurisdictions, with security-demanding clients. The CISO must demonstrate compliance with ISO 27001, NIS2 and DORA, manage third-party assessments and track security incidents.

Dominant GRC challenges

  • Cyber and third-party risks, DORA / NIS2 compliance
  • ISO 27001 certification to maintain
  • Recurring client assessments and tenders
  • Security incidents to be notified

KRIogene modules involved

Risks, Scenarios, Controls, Incidents, KRI, Obligations, Actions

Observable benefits

  • Obligations × controls mapping directly usable in client audits
  • DORA / NIS2 notification prepared natively
  • Consolidated security dashboard for the executive committee
  • Reduced preparation time for external audits
Recommended packs
ISO 27001 PackPack DORAPack NIS2
— Sector 03 / Banking & finance

Keep permanent control and prudential requirements on track.

A bank or financing company subject to prudential requirements (Basel III/IV), to a permanent and periodic control framework, to anti-money-laundering rules and now to DORA for digital operational resilience.

Dominant GRC challenges

  • Operational risk and compliance risk
  • Permanent control (levels 1 and 2) and periodic control
  • AML/CFT: due diligence, alerts, reporting
  • Digital resilience and third-party management (DORA)

KRIogene modules involved

Risks, Controls, Campaigns, KRI, Incidents, Audit, Obligations

Observable benefits

  • Industrialised, traced permanent-control plan
  • Segregation of the lines of defence required by the ACPR
  • AML/CFT alerts linked to controls and incidents
  • Consolidated DORA resilience file
Recommended packs
Basel III/IV PackAML/CFT PackPack DORA
— Sector 04 / Insurance & mutuals

Steer non-financial risks and Solvency II.

A mid-sized mutual or non-life insurer subject to Solvency II, with an ORSA framework to maintain, structured permanent controls and an independent internal-audit function.

Dominant GRC challenges

  • Operational, compliance, cyber and third-party risks
  • Solvency II compliance (qualitative pillar)
  • ORSA and Pillar 3 reporting
  • LoD2 oversight and LoD3 independence

KRIogene modules involved

Risks, Scenarios, Controls, KRI, Incidents, Audit, Obligations, Campaigns

Observable benefits

  • Multi-scope mapping tailored to the structure
  • LoD segregation enforced for EIOPA and the ACPR
  • KRIs monitored continuously with alerts
  • Faster ORSA preparation
Recommended packs
Solvency II PackNon-financial Risks Pack

KRIogene covers non-financial risks. Financial risks (credit, market, liquidity, underwriting) remain managed by your actuarial tools.

— Sector 05 / Health & medico-social

Secure health data and care quality.

A hospital, clinic group or medico-social organisation handling sensitive health data, subject to HDS hosting, GDPR, quality certification and, for medical devices, ISO 13485.

Dominant GRC challenges

  • Health-data protection (HDS, GDPR)
  • Care quality and safety, management of adverse events
  • Continuity of critical systems
  • ISO 13485 compliance for medical devices

KRIogene modules involved

Risks, Controls, Incidents, Obligations, Audit, Actions

Observable benefits

  • GDPR register and HDS hosting evidence centralised
  • Adverse events traced and linked to actions
  • Simplified preparation for quality certifications
  • A single view of compliance across all sites
Recommended packs
HDS PackHealth GDPR PackISO 13485 Pack
— Sector 06 / Public sector & local authorities

Structure internal control and GDPR.

A local authority, public body or administration subject to a formalised internal-control framework, to GDPR and to audits by the regional audit chamber or the IGF.

Dominant GRC challenges

  • Mapping of risks and processes
  • GDPR compliance (DPO, register, DPIA)
  • Accounting and financial internal control
  • External audits (court of auditors, IGF, etc.)

KRIogene modules involved

Risks, Controls, Incidents, Obligations, Audit, Actions

Observable benefits

  • Compliance with the internal-control reference framework
  • Consolidated external-audit recommendations
  • DPO equipped for their register and evidence
  • Traceability usable in administrative litigation
Recommended packs
Internal Control PackGDPR Pack
— Sector 07 / Retail, logistics & transport

Master the supply chain, third parties and continuity.

A retail or logistics player highly dependent on suppliers and flows, with a structured operational-risk function and business-continuity and compliance challenges (GDPR, Sapin II, duty of vigilance).

Dominant GRC challenges

  • Third-party and supply-chain risks
  • Business continuity and resilience
  • GDPR, Sapin II, duty-of-vigilance compliance
  • Internal audits and fraud risks

KRIogene modules involved

Risks, Scenarios, Controls, Incidents, KRI, Audit, Obligations, Actions

Observable benefits

  • Structured third-party mapping and periodic assessments
  • Continuity plans linked to risk scenarios
  • Whistleblowing-alert tracking with traceability
  • Duty-of-vigilance reporting prepared natively
Recommended packs
Third Parties & Continuity PackDuty of Vigilance PackPack Sapin II

What about your organisation?

Whatever your size or sector, we start from the pack closest to your reality, then adapt it to your GRC maturity and regulatory context. Let's talk.

Book a personalised demo