OMNIA
GOVERNANCE · RISK · COMPLIANCE
VIEW MODULE
Governance · Risk · Compliance

Risk that gets governed, compliance that gets proven.

A modular platform to manage enterprise risk, governance, third parties, and compliance in one environment. Activate the capabilities your organization needs—from ERM, continuity, and controls to Compliance AML for regulated operations.

Standalone GRC · expand capabilities when you need them
What it solves

Risk, governance, and evidence in an operation you can demonstrate.

OMNIA GRC lets you start with risk management, controls, continuity, third parties, or audit. Compliance AML is activated when your organization is subject to that regulation; it is not required to benefit from GRC.

Today · without unified GRC

Risk and evidence scattered

  • Manual or outsourced screening against watchlists that change without notice.
  • Client risk matrix in spreadsheets, with no versioning or historical traceability.
  • Enterprise risk (ERM) in a KRI spreadsheet, disconnected from real operational monitoring.
  • Vendor risk assessed informally, with no tier or gate before signing a contract.
  • Continuity, quality, and audit evidence rebuilt by hand for every request.
With OMNIA GRC

One engine, three fronts

  • Automatic, daily screening against official watchlists + 775,000+ PEP.
  • Versioned client risk matrix by cutoff date: it never overwrites the past.
  • Institutional risk with a factor-weighted methodology, aligned with the regulator's framework: inherent → exposure → residual → net.
  • Vendor risk by criticality (CRITICAL/RELEVANT/STANDARD) and LOW/MEDIUM/HIGH level, with a "cleared to sign / ERP onboarding" gate.
  • Native audit trail: who, when, and why, with nothing to rebuild.
Capabilities

Three domains. One modular GRC solution.

Start with Risk Management or Governance and add Compliance AML only when it applies to your organization. Each domain brings controls, evidence, and traceability to better decisions.

CMP

Compliance AML

for organizations subject to regulation

Individual client risk

Version-configurable matrix

Custom factors and subfactors, with weights configurable by the organization. LOW / MEDIUM / HIGH / VERY HIGH tiers, triggers that force an immediate review in extreme cases, and tiered due diligence (simplified, normal, enhanced) based on the client's risk. Version history by cutoff date: the past is never overwritten.

Institutional risk

Factor-weighted methodology

Factor-weighted institutional risk methodology, aligned with the regulator's framework. Inherent → Exposure → Residual → Net, with Low/Medium/High bands.

AML alert engine

Configurable rules, not fixed ones

An alert engine with configurable rules: politically exposed persons (PEP), watchlists, unusual behavior and patterns, and per-product thresholds, each with its own severity and frequency. See the full engine ↓.

Economic activity

Risk-weighted catalog

A catalog of thousands of economic activities weighted by risk level, feeding directly into the Product/Client factor in both matrices.

KYC · Screening

Official watchlists + 775K+ PEP

FATF, UN, OFAC, INTERPOL, and internal watchlists, with politically exposed persons and their relatives/associates, synced daily.

Due diligence

3 tiers, based on risk

Simplified, Normal, or Enhanced, assigned by the client's risk category, with periodic review when the transactional profile departs from what was declared.

Onboarding · Documents

Third-party KYC with a gate and a regulator-grade file

Client and vendor KYC with documents defined by role and criticality before the relationship is enabled. Contracts and supporting documents stay organized with retention and traceability for review.

GDR

Risk Management

for any organization managing enterprise risk

Risk by project

Bounded scope, 4 domains

Each risk is identified within a Project and a domain: PROJECT, OHS, RECURRING, or ADMINISTRATIVE. Structured identification as Risk / Trigger / Cause / Consequence, with inherent → controls → residual/net.

Action plan

Tasks with an owner and deadline

Owner, deadline, currency, and reserve per mitigation task, not a list of good intentions.

Live risk

KRIs from real monitoring

Indicators for continuous exposure follow-up and better prioritization, not a quarterly report that's already stale.

RCSA · Appetite

Self-assessment + regulatory mapping

Risk & control self-assessment, the organization's risk appetite, and mapping to regulatory requirements.

Quantitative models

VaR · BowTie

Value at Risk for financial risk and BowTie diagrams for cause-barrier-consequence analysis.

Lifecycle

Submit → Approve → Materialize

Staged approval workflow; loss events originate from real incidents, not a manual report.

GOB

Governance

operational control and traceability for the whole organization

Third-party risk

Criticality + risk, with a document gate

Vendor classification by criticality (CRITICAL/RELEVANT/STANDARD) and LOW/MEDIUM/HIGH risk level, periodic evaluation and vendor KYC, with a "cleared to sign / ERP onboarding" gate that requires the actual documentation uploaded, not a checked box.

Continuity

BCP with runbook

Business continuity plan with activation and an operational runbook, not a PDF nobody opens during the crisis.

Quality

CSI · nonconformities

Continual service improvement and nonconformity management, aligned to the same risk dashboard.

AML alert engine

Alerts that run every day, not once a quarter.

The engine evaluates configurable rules (threshold, severity, frequency) grouped by risk type: politically exposed persons (PEP), watchlists, unusual behavior and patterns, and per-product thresholds. Each trigger feeds the client's risk score, which is placed on the organization's configurable matrix.

Risk matrix · 5×5

Inherent (dark dot) vs. residual after controls (cyan dot), risk appetite configurable per organization.

Impact
Probability
Inherent risk Residual risk (post-control)

Institutional risk

Factor-weighted institutional risk methodology, aligned with the regulator's framework. It combines inherent risk with exposure to arrive at a residual risk and a net score by band Low / Medium / High.

Positioning

Start with the controls your organization needs.

OMNIA GRC works on its own. Start with risk management or governance, add Compliance AML for regulatory obligations, and expand capabilities when the business requires it.

Disconnected toolsseparate products and manual follow-up OMNIA GRC modularstart with the domains you need
AML/PEP screening ◐ Separate tool, result that has to be re-entered into the file. ● Native, the hit feeds directly into the client's score.
Enterprise risk matrix ◐ Spreadsheet or CRM module, with no version history. ● Versioned by cutoff date, own factors/weights.
Institutional risk ○ Not covered by a CRM or by most AML suites. ● Configurable, according to the organization’s methodology.
Configurable alert engine ◐ Fixed rules from the vendor, hard to adjust by country. ● Own rules, configurable and supported by evidence.
ERM / KRIs ○ Separate GRC suite, updated by hand every quarter. ● Continuous, visible for ongoing follow-up.
Vendor risk ◐ Ecosystem of the CRM, requires custom objects and flows. ● Criticality + risk (CRITICAL/RELEVANT/STANDARD · LOW/MEDIUM/HIGH) with an ERP onboarding gate.
Continuity / quality ○ GRC suite additional, separate license. ● Included, BCP + CSI + nonconformities.
Document file ◐ Another repository to integrate and keep in sync. ● Single record, with organized evidence and traceability.
Total cost $$$ license per product + integration across all three. ● Single module, no per-seat license.
Sellable on its own

GRC to govern better today and expand when you need it.

Use it standalone for risk, governance, and operational control. Activate Compliance AML if your organization is subject to regulation, or expand with other OMNIA capabilities when it adds value.

ERM · KRIs · RCSAControls and evidenceContinuity and qualityThird parties and vendorsOptional Compliance AMLAudit and traceability
ESEN
Get a quote