The product
One platform, nine connected modules.
KRIogene is a GRC platform structured around the three-lines-of-defence model, designed to steer risks, controls, compliance, incidents and audit in a single, auditable framework.
The product
KRIogene is a GRC platform structured around the three-lines-of-defence model, designed to steer risks, controls, compliance, incidents and audit in a single, auditable framework.
Methodological architecture
Most GRC tools let users mix roles freely: an operator can test their own control, a risk manager can validate their own mapping. The framework then loses its credibility with auditors and regulators.
KRIogene enforces the segregation of the three lines of defence at product level. Separation of duties is no longer an organisational discipline: it is guaranteed by the platform.
— LoD1
Execution of permanent controls, incident logging, handling of operational actions.
— LoD2
Framework design, oversight, periodic controls, obligation mapping, framework facilitation.
— LoD3
Independent assessment of the framework's effectiveness, recommendations, verification of corrective plans.
Family 1 — Identify
Map your operational, cyber, legal, third-party, ESG and compliance risks in a hierarchical structure tailored to your organisation. Each risk is assessed through three readings:
Each risk is attached to scopes (legal entities × organisational units × processes) that enable a multi-axis reading.
Anticipate chains of failure. Each scenario describes an event, its possible causes, its expected consequences and the risks it materialises. Scenarios feed your impact analyses and prepare your continuity plans.
Family 2 — Control
Define your permanent and periodic controls, assign them to the relevant people and schedule their testing. KRIogene supports both families of controls:
Each control is linked to the risks it covers and the obligations it proves. The effectiveness of the framework is measured continuously.
Set up Key Risk Indicators with configured alert thresholds. KRIogene computes your values continuously, triggers notifications on drift and stores your trends for committee analysis.
Family 3 — Execute
Log your operational, IT, security, compliance or third-party incidents. Each incident is automatically linked:
Your auditors reconstruct the failure chain in one click, from the incident back to the upstream risk — that's native top-down traceability.
All the actions in your framework (arising from risks, controls, incidents, audits) are consolidated in a single module. Each action is tied to its cause, an owner and a due date. Its completion automatically updates the enriched net score of the relevant risk.
Family 4 — Steer
Schedule your internal and external audit assignments, capture your findings, track your recommendations and verify the implementation of corrective plans. Audit conclusions feed the continuous assessment of your control framework — LoD3 in full.
The Obligations module is at the heart of KRIogene's value. It turns your compliance from a declaration into proof.
You no longer declare your compliance — you prove it.
Orchestrate periodic assessments over defined scopes: annual mapping review, quarterly control campaign, half-yearly compliance attestation. Each campaign is traced, its results stored, and its deliverables consolidated automatically.
The platform's strength
In most GRC setups, risks, controls, incidents and obligations live in separate tools. Consistency then depends on human discipline — and on teams being available to maintain the links.
KRIogene enforces consistency through its structure. Every object is linked to the others by design.
Each risk points to the controls that cover it
Each control proves the obligations it addresses
Each incident materialises a risk and identifies a control failed
Each action remediates a cause identified
Each audit assignment consolidates the findings and feeds the action plans
The framework stays consistent because the tool enforces it.
Differentiator
Most GRC tools measure gross risk (before control) and net risk (after controls). KRIogene adds a third reading that changes the quality of steering: the enriched net score.
| Score | What it measures | Why it's useful |
|---|---|---|
| Gross | Theoretical exposure with no control framework | Measure the absolute stake |
| Net | Exposure after applying controls | Measure coverage |
| Enriched net | Real exposure, factoring in ongoing actions and incidents that have occurred | Measure operational reality |
You steer what actually happens, not what should happen in theory.
Artificial intelligence
KRIogene includes a conversational AI that lets you query your framework in natural language. Users get contextualised answers without navigating dozens of screens.
Example queries
“Which GDPR controls are overdue?”
“Give me the critical incidents from last quarter”
“Which risks are not covered by a control?”
“Show actions overdue by more than 30 days”
The AI speeds up use of the framework without replacing it: it remains a tool for fast access to already-structured data.