The product

The first AI-native platform for Enterprise Risk Management.

Prism Layer is a single governed-assessment architecture. We tailor it to your risk domain, your frameworks, and the people who own the decision. The engine is the same. The fit is yours.

The workspace

A live register, not a quarterly binder.

Every assessment in one operating picture: what sits above appetite, what's ready to commit, where the control gaps are, and what's still moving.

Above risk appetite36
Ready to commit32
Control gaps25
In progress956

Market infrastructure expansion review

DraftStep · Target risk & alignment
5 of 6 steps confirmedResume →

High-valuation milestone review

In reviewStep · Commit
6 of 6 steps confirmedResume →

Geographic market expansion

DraftStep · Identify key risks
1 of 6 steps confirmedResume →

Third-party vendor risk

DraftStep · Define scope
Scope in progressResume →

The engine

One governed engine. Full stack of precision capabilities.

The governed execution layer for enterprise risk: precision tools trained on your frameworks and your logic, wrapped in one control plane.

Prism LayerGoverned execution
Reason
Score
Control
Audit
Trade-off
Escalate
Route
Report

Risk intelligence outputs

  • Risk assessment
  • Control map
  • Evidence pack
  • Decision log
  • Reviewer escalation

Audit trail preserved from source evidence to final decision.

New assessment

Start from a sentence.

Type what you need to assess, in plain language. The engine scopes it, proposes the methodology, and pulls the right records from your library.

Let's manage some risk.

AI-native risk assessment with human oversight and full audit provenance.

Review cybersecurity posture for our AI platform
Market expansion risk assessmentThird-party & vendor riskCybersecurity posture reviewRegulatory compliance gap analysis

The one architecture

A complete assessment, scope to signed record.

From scope to signed record, every step produces an artifact you can hand to a committee, an auditor, or a regulator.

1

Define Scope

Set the boundaries, objectives, jurisdictions, and assessment statement.

Artifact

A scoped record: in-scope entities, jurisdictions, and success criteria.

2

Identify Key Risks

Surface the risk areas in scope, mapped to your taxonomy.

Artifact

A structured set of risk areas.

3

Assess Baseline Risk

Score inherent likelihood and impact per scenario, with the reasoning behind each call.

Artifact

Scored scenarios, each with a reasoning card.

4

Controls & Mitigation

Map existing and gap controls, with a mitigation percentage per scenario.

Artifact

A control map with mitigation applied.

5

Residual Risk

Residual risk, computed deterministically from baseline minus mitigation. No black box on the math.

Artifact

A residual-risk score and band per scenario.

6

Target Risk & Alignment

Set target bands from averse to opportunistic. Alignment status and the governance response surface automatically.

Artifact

Alignment status with a governance response per scenario.

7

Review Pack

Assemble the full record for review, ready to export.

Artifact

An exportable review pack.

8

Commit

Formal sign-off with expert approval on material decisions.

Artifact

A signed, immutable record: ID, hash fingerprint, and reasoning trace.

The output, in full

Every number traceable to the signed record.

An illustrative enterprise assessment: five risks scored, ten controls evaluated, each residual measured against the appetite you set. This is the shape of what Prism Layer hands a committee, in minutes.

Escalated · Key decisions required
5Risks assessed
10Controls evaluated
2Residual above target
~7mEngagement
R1Input-cost & consumption exposure
−45%
Conservative · 1.5–2.0Within target
R2Operations resilience
−42%
Conservative · 1.5–2.0Within target
R3Capacity & network planning
−48%
Balanced · 2.5Within target
R4Asset & fleet strategy
−40%
Conservative · 1.5–2.0One band above
R5Single-supplier dependency
−50%
Averse · 1.0One band above
ΔCost to Carry
R4 + R5, projected to the peak
Carry · on current controls≈320 bps
Deploy · controls fundedheld <100 bps
Margin compression · bpsDecision pending

Path A · Deploy

Fund the Mitigation Now

Commit targeted capital against the two risks sitting above appetite, closing the gap before the peak. Higher cash outlay, exposure retired.

Path B · Carry

Hold and Monitor

Run on current controls and accept 200–400 bps of margin exposure if they slip under sustained stress. Capital preserved, the risk stays live.

Signed recordTR-5F0C-A2E1Hash 6dad…8203Reasoning · claude mythosConfidence 90%Committed 22:03 UTC

The deliverable

Your report, print-ready for the room that matters.

Export the signed assessment to a paginated PDF for your committee, board, auditors, or regulators. Cover to signature, on Letter or A4, with a repeating header and footer.

Eight sections, then four appendices: the full reasoning passes, control detail, the run log and document manifest, and a signature page with the hash fingerprint.

Prism Layer · Signed Assessment

AML & Sanctions Program Risk Assessment

Committed · REC-2A9F-4C21 · Confidence 92%

Executive summary01
Scope & operating model02
Risk register03
Baseline heatmap04
Controls & mitigation05
Residual risk06
Target alignment07
Escalation & recommended action08
Signed · Hash 4f9c…a210 · 4 appendices attached

The assurance plane

Every acceleration runs inside a control.

Identity Permissions Task scope Guardrails Validation Approval Audit capture

Role-based identity, least-privilege retrieval, bounded task scope, policy guardrails, evidence-linked reasoning, expert approval, immutable capture. Every output links back to policy context, source evidence, and reviewer action.

The methodology layer

Your methodology, versioned like software.

Develop, tweak, test, and refine the methodologies your assessments run on. Clone the Prism methodology, adjust the bands, weights, and steps to your program, and every new assessment inherits the version you committed.

Prism Risk Assessmentv1.0 · ActiveClone & edit for your org

Target risk bands

Averse0.1 – 1.0
Conservative1.1 – 2.0
Balanced2.1 – 3.0
Progressive3.1 – 4.0
Opportunistic4.1 – 5.0

Three data layers

Grounded in the frameworks, your history, and your live systems.

Industry Frameworks

Basel III, NIST, ISO 31000, the EU AI Act, GDPR, and others, kept current so you don't have to.

Your Internal Data

Policies, prior assessments, audit results, and your own taxonomy. The system is trained on you.

Live Integrations

GRC platforms, control repositories, incident systems, and data lakes, read in place.

Confidence scoring

See exactly how much of every output rests on your data versus industry defaults. Internal documents raise confidence, so you always know what's grounded in your program and what's a framework starting point.

Observable reasoning

Every decision auditable, replayable, defensible.

A specialized agent runs each step and shows its work. You keep the judgment. The system keeps the record.

A Reasoning Agent per Step

Scope, baseline, residual-risk, and target agents run each step and name the reasoning behind every call.

Confidence Scoring

Every output shows how much rests on your data versus industry defaults. Add a foundation document to raise confidence, up to 20%.

Deterministic Where It Counts

Residual risk is computed deterministically from confirmed baselines and controls. No black box on the math.

Appetite Bands & Alignment

Target bands from averse to opportunistic. Scenarios over appetite surface an alignment status and a governance response.

Full Provenance

Reasoning, references, execution trace, and decision trace on every output. Replay any conclusion.

Signed & Exportable

Formal sign-off with a hash fingerprint, and a report you can export for the committee.

Every confirmed step carries

Committed outputReasoning cardsInput snapshotPrior confirmed dataHuman judgment

Risk appetite bands

AverseConservativeBalancedProgressiveOpportunistic

The document library

Source your records once. Cite them everywhere.

Three shelves feed every assessment: canonical regulatory documents vetted by Prism, industry standards surfaced for matching assessments, and your own policies scoped to your org. Foundation documents raise confidence, and every citation traces back to its shelf.

PrismFFIEC BSA/AML examination manualCanonicalCompleted
IndustryGambling Commission LCCPSurfacedCompleted
CompanyAnnual report (10-K)FoundationCompleted
CompanyAudit committee charterFoundationCompleted
CompanyCode of conductFoundationCompleted

Same rigor. Shorter path to evidence.

Run the engine on your scenario.

On a use case from your world. Nothing required in advance.

See a Live Assessment