The portfolio
One suite for every GRC discipline
Most organisations buy governance, risk and compliance software one tool at a time: a policy system here, a risk register there, a separate audit tool, a board portal that talks to none of them. Ridisa takes a different path. Every GRC solution in the suite is built on the same platform, with shared identity, in-tenant AI and a single audit-grade trail, so adding a discipline means adding value, not another silo.
Below are the solutions available today and coming to the suite, grouped across the four pillars of governance, legal, risk and compliance. Each one is native to Microsoft 365 and links through to its own product detail, so you can start with the discipline you need most and grow from there.
The GRC Universe
Four Pillars. One Platform.
The whole Governance, Legal, Risk and Compliance mandate: 17 products across four pillars, every one built on the same Microsoft 365-native spine.
Pillar 1
Policy liveGovernance
Govern with Confidence
How the organisation makes, records and proves its decisions, from the policy library to the boardroom.
Pillar 2
Legal & Compliance
Run the Legal Function
Give legal teams a system of record for the work they do every day: matters, contracts and obligations.
Pillar 3
Risk, Audit & ERM
See and Control Risk
Connect risks to the policies and controls that mitigate them, and to the audits that test them.
Pillar 4
Training liveCompliance & Ethics
Stay Ahead of Regulators
Turn obligations into action, and keep the timestamped evidence regulators actually accept.
Governance
4 productsDocBrilliant
Policy Management
Policy management, native to Microsoft 365
Ridisa's flagship, live in production. Centralised policy management with versioning, multi-step approvals, attestation campaigns and a complete audit trail. Built natively on SharePoint and Azure AD.
- Policy library with versioning, locking & automatic numbering
- Multi-step approval workflows with delegation & templates
- Read → quiz → sign acknowledgement campaigns
- Yara AI assistant: in-tenant, no data egress
BoardBrilliant
Board & Committee
The modern boardroom, end to end
Run the full board lifecycle in one place: schedule meetings, build agendas and board packs, capture minutes, and pass resolutions with secure e-voting. Built on Microsoft 365 with Azure AD sign-in.
- Meetings, agendas & calendar with attendance tracking
- Versioned board packs with read receipts & attestation
- Minutes with review, approval & digital sign-off
- Resolutions with FOR/AGAINST/ABSTAIN e-voting & quorum rules
EntityBrilliant
Entity Governance
Every legal entity, audit-ready
A single source of truth for every legal entity: the corporate register, statutory records, officers and ownership, filing calendars and group structure, all kept audit-ready and connected to the rest of your governance stack.
- Central entity register with statutory records & key dates
- Officers, directors and authorised signatories
- Ownership, shareholdings and group structure
- Filing calendar with deadline reminders
DiscloseBrilliant
Disclosures & Conflicts of Interest
Declarations, gifts and related-party sign-off
Capture conflict-of-interest declarations, the gifts and hospitality register, and related-party approvals in one disclosures hub, with Azure AD sign-in and a timestamped audit trail that proves every interest was disclosed and reviewed.
- Annual and event-driven conflict-of-interest declarations
- Gifts & hospitality register with thresholds and approvals
- Related-party transaction review and sign-off
- Automated reminders and renewal campaigns
Legal & Compliance
4 productsMatterBrilliant
Matter Management
A system of record for legal work
Give the legal team a single matter file for everything they touch: intake and triage, deadlines, documents and legal spend. Native to Microsoft 365, with Azure AD sign-in and a full audit trail.
- Structured intake and triage of new requests
- Matter files with documents, contacts and deadlines
- Legal-spend tracking against budgets and panels
- Deadline and key-date reminders
ContractBrilliant
Contracts (CLM)
Contract lifecycle, drafting to renewal
Manage the full contract lifecycle on Microsoft 365: draft from a clause library, route for approval, sign electronically, and never miss a renewal or obligation deadline again.
- Clause library and templated drafting
- Approval workflows with delegation and send-back
- Built-in e-signature for fast execution
- Renewal and obligation reminders
DiscoverBrilliant
Legal Hold & eDiscovery
Defensible holds and discovery
Issue legal holds, track custodians and preserve a defensible chain of custody across your Microsoft 365 estate, so when litigation or investigation hits, the evidence is intact and the process is provable.
- Legal holds with custodian notifications
- Custodian acknowledgement tracking
- Defensible, end-to-end chain of custody
- Scoped collection across Microsoft 365
IPBrilliant
Intellectual Property
Protect the portfolio, hit every deadline
Manage your trademark and patent portfolio in one register on Microsoft 365, with renewal deadlines, jurisdictions and ownership tracked, so valuable IP is never lost to a missed date.
- Trademark and patent portfolio register
- Renewal and maintenance deadline reminders
- Jurisdiction and class tracking
- Ownership and licensing records
Risk, Audit & ERM
4 productsRiskBrilliant
Enterprise Risk
See and control enterprise risk
Build a living risk register that connects risks to the policies and controls that mitigate them, with RCSA, heatmaps, appetite and KRIs, all on the same Microsoft 365-native spine as your governance stack.
- Risk register with owners and assessments
- RCSA and control self-assessment
- Heatmaps, appetite and tolerance thresholds
- KRIs with owners and monitoring
AuditBrilliant
Internal Audit
From audit plan to closed finding
Plan and run the internal audit function on Microsoft 365, from a risk-based audit universe through fieldwork to findings and follow-up, with workpapers, evidence and sign-off kept audit-ready by default.
- Risk-based audit universe and annual plan
- Fieldwork with workpapers and evidence
- Findings with ratings and recommendations
- Management actions and follow-up tracking
VendorBrilliant
Third-Party Risk
Know and monitor every third party
Run vendor due diligence, risk assessments and ongoing monitoring from one register on Microsoft 365, so every third party is scored, reviewed and watched across the relationship lifecycle.
- Vendor register with risk tiering
- Due-diligence questionnaires and assessments
- Risk scoring across the relationship
- Continuous monitoring and reassessment
ResilientBrilliant
Continuity & Incidents
Stay resilient when things break
Plan for disruption and respond when it comes: business impact analysis, continuity plans, and incident and loss-event capture in one place on Microsoft 365, with a complete audit trail of every response.
- Business impact analysis (BIA)
- Continuity plans with owners and playbooks
- Incident capture and response tracking
- Loss-event register
Compliance & Ethics
5 productsComplyBrilliant
Compliance Management
One control framework, every regulation
The control backbone of the suite: a single library of controls mapped to every regulation and framework you answer to, tested once and satisfied many times. Design and operating tests, self-assessments, and a full deficiency-to-remediation lifecycle, all on Microsoft 365.
- Unified control framework: test once, satisfy many regulations
- Controls mapped to SOX, PCI, ISO 27001, SOC 2 and internal policy
- Design tests, operating tests and self-assessments with evidence
- Deficiency lifecycle: remediation plans or exceptions with compensating controls
TrainBrilliant
Compliance Training
Read, quiz, sign: proven per employee
Run compliance training the way regulators expect: read, quiz then e-sign, with a per-employee attestation trail. Live in production today on the same Microsoft 365-native spine as the rest of the platform.
- Read → quiz → e-sign training campaigns
- Per-employee, timestamped attestation trail
- Course assignment by role and audience
- Automated reminders and completion tracking
RegBrilliant
Regulatory Change
Stay ahead of every new rule
Scan the horizon for regulatory change and map new rules to the policies and controls they touch, turning obligations into action on Microsoft 365, with the timestamped evidence regulators accept.
- Horizon scanning for regulatory change
- Map rules to policies and controls
- Impact assessment and action assignment
- Owners, due dates and progress tracking
SpeakBrilliant
Whistleblower & Case Management
Speak up, securely and anonymously
Give people a safe way to raise concerns and give investigators a secure place to act on them: an anonymous hotline, confidential intake and structured case management, all on Microsoft 365 with a protected audit trail.
- Anonymous, confidential reporting hotline
- Secure intake with two-way messaging
- Structured investigation case files
- Strict access controls and confidentiality
PrivacyBrilliant
Privacy & DSAR
Privacy obligations, handled on time
Operationalise data privacy on Microsoft 365: maintain your record of processing, handle data-subject access requests within deadline, and run DPIAs and consent, with the timestamped evidence regulators accept.
- Record of processing activities (RoPA)
- DSAR intake and deadline tracking
- DPIA workflows for new processing
- Consent capture and management
How it all connects
Enter it once. It works everywhere.
Because every product runs on one Microsoft 365-native spine, a single record (a policy, a risk, an obligation, an entity) is shared across the suite instead of re-keyed. The products don't just sit side by side; they organically complete each other.
A policy becomes proof
Publish a policy in DocBrilliant and it auto-launches a read-quiz-sign campaign in TrainBrilliant and maps to the controls in ComplyBrilliant that prove it operates. Update the policy once. Everyone who must re-attest and every control to retest moves with it.
A new rule turns into work
A regulatory change tracked in RegBrilliant maps straight to the policies, controls and training it touches, so an incoming obligation becomes assigned, owned work, not a PDF sitting in someone's inbox.
Risk, control and audit in lockstep
A risk in RiskBrilliant links to the controls that mitigate it and the audits that test them. When a test fails in AuditBrilliant, the deficiency and the heightened risk are raised automatically. One connected loop, not three spreadsheets.
A third party is more than a record
A vendor scored in VendorBrilliant carries into the contracts it signs in ContractBrilliant, the continuity plans that depend on it in ResilientBrilliant, and the personal data it processes in PrivacyBrilliant. One profile, reused everywhere it matters.
Every legal entity is the backbone
The register in EntityBrilliant scopes every policy, matter, contract and risk to a real legal entity, so the group structure is always reflected across the suite, never maintained twice.
A concern becomes a case
A report raised in SpeakBrilliant can escalate into a legal matter in MatterBrilliant or an internal audit, with a defensible chain of custody preserved by DiscoverBrilliant from the first day it's anticipated.
And every attestation, vote, sign-off and test result lands in one append-only, 7-year audit trail, so a single export answers any regulator.