ERM Risk Assessment
A free, browser-based Enterprise Risk Management assessment tool. Identify and score risks across your organisation, map controls, calculate residual exposure, and generate a visual heat map with an exportable risk register — no installation, no registration, no data stored.
The ERM Risk Assessment tool is a free, browser-based application that guides risk and compliance professionals through a structured Enterprise Risk Management assessment. Instead of starting from a blank spreadsheet, users follow a clear methodology: define the scope, identify risks across the organisation, map existing controls, score likelihood and impact, calculate residual risk, and generate a visual heat map. Enterprise risk assessments are a core part of any ERM framework, yet most organisations run them in spreadsheets that vary by department, assessor, and cycle — with no consistency in how risks are identified, controls are rated, or residual exposure is calculated. This tool enforces a clean, repeatable methodology in a guided browser interface, making the output defensible and comparable across assessments. Everything runs in the browser — no data is stored on any server, no registration required.
- Guided ERM risk assessment — scope definition through residual risk scoring
- Risk identification with likelihood and impact scoring matrix
- Control mapping — link existing controls to each identified risk
- Residual risk calculation based on control effectiveness ratings
- Visual risk heat map — inherent vs. residual risk positioning
- Exportable risk register for governance reporting
- Fully browser-based — no data stored or transmitted, free
Enterprise risk assessments are a core obligation for risk and compliance functions, yet most organisations conduct them in spreadsheets that differ by department, assessor, and review cycle. There is no consistency in how risks are identified, how controls are rated, or how residual risk is calculated. The result is outputs that are hard to compare, difficult to defend in front of risk committees, and of limited use for trend analysis or reporting. This tool solves the problem by encoding a structured ERM methodology into a guided browser interface — so any user, regardless of background, can produce a consistent and defensible risk assessment with a visual heat map and an exportable register.
Status
LiveCategory
Step-by-step guide to get started with this project.
All IddiLabs projects are open-source and free to use. You can review the code, modify it for your needs, and deploy it on your own infrastructure.
IddiLabs on GitHubBuilt with ❤️ for SMEs, compliance teams, and professionals who value privacy and control.