Risk Management

Risk Management Toolkit

Desktop risk management application with AI-powered risk assessment, business impact analysis, vendor risk management, and scenario modelling. 6 AI providers, 20 professional documents, 12 framework mappings, 10 export formats — the full risk lifecycle in one installed application.

ISO 27001ISO 22301ISO 31000NIST CSF 2.0CIS v8SOC 2CMMC 2.0GDPRDORAPCI-DSS 4.0NIST AI RMFNIST 800-171 26 documents
$997 One-time purchase · 12 months of updates Buy Now
Risk Management Toolkit
Available Now

Risk Management Toolkit

ISO 27001ISO 22301ISO 31000NIST CSF 2.0CIS v8SOC 2CMMC 2.0GDPRDORAPCI-DSS 4.0NIST AI RMFNIST 800-171
26 documents included
$997

One-time purchase · Instant download · 12 months of updates

Buy Now

Refund policy

Your board wants a risk picture. Your auditor wants evidence. Your insurer wants controls.

Right now you’re pulling numbers from three separate spreadsheets, hoping they’re consistent, and building a board deck by hand. When someone asks “how does this risk affect our critical processes?” — you don’t have a quick answer.

This toolkit gives you a desktop application where risk assessment, business impact analysis, and vendor management are connected — plus 20 professional documents. When someone asks about your risk posture, you open the dashboard and show them.

What’s inside

Show your risk posture

The tools and evidence auditors, boards, and customers ask for first.

Risk Register

170+ pre-loaded risks filtered by your industry. 5×5 scoring, treatment plans, owners, review dates, and risk library. Global search across all risks.

The first thing every auditor and customer asks for

Security Controls

93 ISO 27001 Annex A controls with implementation status tracking, coverage metrics, and framework cross-mapping to NIST CSF 2.0, CIS v8, and SOC 2.

Show exactly where you stand against each framework

Dashboard & Board Deck

Risk heatmap, control coverage, BIA readiness, vendor exposure, evidence gaps — one screen. One-click PPTX export with your branding for board presentation.

Present to the board from real data, not a slide you built by hand

Evidence Tracker

Unified compliance artefacts across all modules with automatic gap detection. Evidence mapped to controls, risks, vendors, and processes.

Know exactly what evidence you have and what's missing

Prove you understand your dependencies

Business impact analysis and vendor risk management — connected to your risk register.

Business Impact Analysis

Critical processes scored across 6 dimensions with RTO/RPO targets, dependency mapping, and recovery prioritisation.

Answer "what happens if this goes down?" with data, not guesses

Vendor Risk Management

4 pre-built questionnaires covering 243 controls. Tiered classification, weighted scoring, and risk-rated vendor register.

Show your board and insurer how you manage third-party risk

Scenario Modelling

What-if scenarios linking risks, processes, and vendors. Cascade analysis showing how one failure propagates. AI-generated narratives for tabletop exercises.

Board-ready scenario analysis, not hypothetical hand-waving

AI-Powered Analysis

BYOK integration with 6 providers — Claude, ChatGPT, Gemini, Grok, DeepSeek, and local LLMs. Dynamic model selection. AI assists risk scoring, treatment recommendations, scenario narratives, and board reporting.

AI that uses your API key on your machine — no data leaves your device

Professional desktop application

Not a browser file — a proper installable application with encrypted storage and professional UI.

Desktop Application

Native Windows application with installer. Sidebar navigation, global search, command palette, light theme with brand headers. No browser required.

Opens like any desktop app — professional, fast, offline

Encrypted Storage

All data stored locally in SQLite. API keys secured via OS keychain (Windows Credential Manager). No cloud, no server, no data transmission.

Your risk data never leaves your machine

10 Export Formats

XLSX, PPTX, DOCX, CSV, JSON, PDF. Board deck with your branding. Export Centre with all formats in one view.

Get data out in whatever format the recipient needs

20 Professional Documents

Governance policies, BC/DR plans, vendor communication templates, workshop kits, and a 12-framework cross-mapping spreadsheet. Plus user guide and quick start guide.

The documentation set that operationalises the application data
Documents included: Governance (3 docs — policy, methodology, RACI matrix), Business Continuity (8 docs — BC/DR plans, crisis comms, test procedures), Vendor Risk (2 docs — communications pack, assessment report), Reference (4 docs + guides — workshop kit, framework mapping, risk appetite, user guide).

What the application looks like

A professional desktop application with a brand-blue sidebar, section-grouped navigation, global search, and a clean light-themed content area. Risk register, BIA, vendor management, scenario modelling, evidence tracking, and dashboard — all accessible from one sidebar.

One system. Risk, BIA, vendors, controls, evidence — connected.

$997 · One-time purchase · Desktop application · No data leaves your device · 12 months of updates

Why the integration matters

A vendor scores poorly on their assessment

The linked risk in your register is flagged. Your dashboard updates. The board deck reflects the change. You didn't open a second spreadsheet.

A critical risk affects a business process

The BIA module highlights it. RTO/RPO targets are visible alongside the risk score. When you present to the board, the connection is already there.

Your auditor asks for evidence across all domains

One view shows compliance artefacts across risks, controls, vendors, and processes. Where evidence is expected but missing, it tells you.

The cost comparison

GRC platform $10,000–$100,000/year Subscription + lock-in + implementation project
Buy 3 separate toolkits $795 + manual integration 20–40 hours cross-referencing spreadsheets
Build internally $30,000–$60,000 3–6 months specialist time

Who this is for

✓ Right fit

Organisations that need to demonstrate risk maturity to boards, auditors, insurers, or customers — and want risk, BIA, and vendor management in one system instead of three spreadsheets.

✗ Not the right fit

Enterprises with existing GRC platforms. Organisations that only need a basic risk register without BIA or vendor management — the Security Program Foundation Toolkit covers that at $497.


Common questions

Is this a desktop application or a browser app?

Desktop application. You download and install it like any software. It runs natively on Windows with no browser required. All data is stored locally on your machine — nothing is transmitted to any server.

Which AI providers are supported?

Six providers: Anthropic (Claude), OpenAI (ChatGPT), Google (Gemini), xAI (Grok), DeepSeek, and local LLMs (Ollama, LM Studio, or any OpenAI-compatible endpoint). You bring your own API key — it's stored encrypted in your OS keychain. The app dynamically fetches available models from your provider.

Do I need AI to use this?

No. Every feature works without AI. The AI integration is optional — it assists with risk scoring, treatment recommendations, scenario narratives, and board reporting. If you don't configure an API key, the app works fully without it.

How is this different from buying three separate toolkits?

The standalone products have no data integration. This product unifies them — risk data flows to your BIA, vendor findings create risk entries, evidence tracks across all domains, and one dashboard shows your complete posture. Plus AI features and 12 framework mappings that don't exist in the individual products.

How does this compare to GRC platforms?

GRC platforms cost $10K–$100K+/year with implementation projects, per-seat pricing, and lock-in. Your data lives on their servers. This is a one-time purchase desktop application — your data stays on your machine, no subscription, no per-seat fees. Everything exports to standard formats if you outgrow it.

Does this satisfy ISO 27001 requirements?

It covers ISO 27001:2022 risk assessment (6.1.2), risk treatment (6.1.3), Statement of Applicability, and ISO 22301 BIA requirements. The evidence tracking produces the documentation set certification auditors expect.

Is my data secure?

All data is stored locally in an encrypted SQLite database on your machine. API keys are stored in your OS keychain (Windows Credential Manager). No data is transmitted to any server — AI calls go directly from your machine to your chosen provider using your own API key.

Do I get updates if the product is improved?

Yes. If we update this product within 12 months of your purchase — framework changes, new features, content improvements — you receive the updated version automatically at no additional cost. After 12 months, you keep everything you have permanently. Future updates are available at a renewal discount.

Is AI used in creating these documents?

Ridgeline uses AI tools in the research and drafting process. All documentation is written, reviewed, and validated by a security practitioner to ensure it is operationally sound and aligned with current frameworks.

What if we need help setting it up?

Our Implementation Services team will configure the app with your data and customise all 20 documents. Suite tier is $5,997, delivered in 1–2 weeks.

How does this compare?

CapabilityFree templatesRisk Management ToolkitGRC platform ($15K+/yr)
Framework-aligned documentationSome Full coverage
Editable Word/Excel files✗ Locked in platform
Interactive browser app Included
One-time cost Free $997✗ Annual subscription
Implementation timeWeeks HoursMonths
Audit-ready formatting✗ Inconsistent Professional

Get notified about updates to this toolkit

Get notified when we launch new toolkits

Product launches only · No spam · Unsubscribe anytime

Implementation Services

Need this customised to your organisation?

We'll customise any product to your organisation and deliver in 1–2 weeks. Fixed price, fully async. You review it, your team runs it.

Learn More → Start Intake →

Foundation $1,997 · Toolkit $2,997 · Suite $5,997 · Program $8,997

Ready to strengthen your security program?

Get started with professional, audit-ready documentation today.

Instant download · Framework-aligned · Refund policy