The product

One platform, nine connected modules.

KRIogene is a GRC platform structured around the three-lines-of-defence model, designed to steer risks, controls, compliance, incidents and audit in a single, auditable framework.

Methodological architecture

The three-lines-of-defence model, enforced by design.

Most GRC tools let users mix roles freely: an operator can test their own control, a risk manager can validate their own mapping. The framework then loses its credibility with auditors and regulators.

KRIogene enforces the segregation of the three lines of defence at product level. Separation of duties is no longer an organisational discipline: it is guaranteed by the platform.

— LoD1

Business lines

Execution of permanent controls, incident logging, handling of operational actions.

— LoD2

Risk, Compliance, Internal Control

Framework design, oversight, periodic controls, obligation mapping, framework facilitation.

— LoD3

Internal & external audit

Independent assessment of the framework's effectiveness, recommendations, verification of corrective plans.

Family 1 — Identify

Map your risks and anticipate shocks.

Risks — Structured mapping

Map your operational, cyber, legal, third-party, ESG and compliance risks in a hierarchical structure tailored to your organisation. Each risk is assessed through three readings:

  • Gross — theoretical exposure before any control framework
  • Net — exposure after applying existing controls
  • Enriched net — real exposure factoring in ongoing actions and incidents that have occurred

Each risk is attached to scopes (legal entities × organisational units × processes) that enable a multi-axis reading.

Scenarios — Anticipating shocks

Anticipate chains of failure. Each scenario describes an event, its possible causes, its expected consequences and the risks it materialises. Scenarios feed your impact analyses and prepare your continuity plans.

Family 2 — Control

Design your controls and monitor your indicators.

Controls — Control framework

Define your permanent and periodic controls, assign them to the relevant people and schedule their testing. KRIogene supports both families of controls:

  • Permanent controls (LoD1) — embedded in the daily work of operations
  • Periodic controls (LoD2) — campaigns orchestrated by internal control

Each control is linked to the risks it covers and the obligations it proves. The effectiveness of the framework is measured continuously.

KRI — Continuous monitoring

Set up Key Risk Indicators with configured alert thresholds. KRIogene computes your values continuously, triggers notifications on drift and stores your trends for committee analysis.

Family 3 — Execute

Track your incidents and steer your remediations.

Incidents — Top-down traceability

Log your operational, IT, security, compliance or third-party incidents. Each incident is automatically linked:

  • to the risks it materialises
  • to the controls that should have prevented it
  • to the impacted scopes

Your auditors reconstruct the failure chain in one click, from the incident back to the upstream risk — that's native top-down traceability.

Actions — Remediation loop

All the actions in your framework (arising from risks, controls, incidents, audits) are consolidated in a single module. Each action is tied to its cause, an owner and a due date. Its completion automatically updates the enriched net score of the relevant risk.

Family 4 — Steer

Audit, prove, assess.

Audit — LoD3 peace of mind

Schedule your internal and external audit assignments, capture your findings, track your recommendations and verify the implementation of corrective plans. Audit conclusions feed the continuous assessment of your control framework — LoD3 in full.

Obligations — Proven compliance

The Obligations module is at the heart of KRIogene's value. It turns your compliance from a declaration into proof.

  • Each regulatory obligation is mapped to one or more controls (N:M relationship)
  • Applicability is computed automatically from your organisation's characteristics
  • Each executed control becomes obligation evidence, timestamped and traceable

You no longer declare your compliance — you prove it.

Campaigns — Periodic assessments

Orchestrate periodic assessments over defined scopes: annual mapping review, quarterly control campaign, half-yearly compliance attestation. Each campaign is traced, its results stored, and its deliverables consolidated automatically.

The platform's strength

Everything is connected, by design.

In most GRC setups, risks, controls, incidents and obligations live in separate tools. Consistency then depends on human discipline — and on teams being available to maintain the links.

KRIogene enforces consistency through its structure. Every object is linked to the others by design.

→

Each risk points to the controls that cover it

→

Each control proves the obligations it addresses

→

Each incident materialises a risk and identifies a control failed

→

Each action remediates a cause identified

→

Each audit assignment consolidates the findings and feeds the action plans

The framework stays consistent because the tool enforces it.

Differentiator

Triple gross / net / enriched scoring.

Most GRC tools measure gross risk (before control) and net risk (after controls). KRIogene adds a third reading that changes the quality of steering: the enriched net score.

Score What it measures Why it's useful
Gross Theoretical exposure with no control framework Measure the absolute stake
Net Exposure after applying controls Measure coverage
Enriched net Real exposure, factoring in ongoing actions and incidents that have occurred Measure operational reality

You steer what actually happens, not what should happen in theory.

Artificial intelligence

A conversational AI in the service of GRC.

KRIogene includes a conversational AI that lets you query your framework in natural language. Users get contextualised answers without navigating dozens of screens.

Example queries

“Which GDPR controls are overdue?”

“Give me the critical incidents from last quarter”

“Which risks are not covered by a control?”

“Show actions overdue by more than 30 days”

The AI speeds up use of the framework without replacing it: it remains a tool for fast access to already-structured data.

See KRIogene in action.

A personalised demo on your business context, in 45 minutes.

Book a demo