A modular platform to manage enterprise risk, governance, third parties, and compliance in one environment. Activate the capabilities your organization needs—from ERM, continuity, and controls to Compliance AML for regulated operations.
OMNIA GRC lets you start with risk management, controls, continuity, third parties, or audit. Compliance AML is activated when your organization is subject to that regulation; it is not required to benefit from GRC.
Start with Risk Management or Governance and add Compliance AML only when it applies to your organization. Each domain brings controls, evidence, and traceability to better decisions.
for organizations subject to regulation
Custom factors and subfactors, with weights configurable by the organization. LOW / MEDIUM / HIGH / VERY HIGH tiers, triggers that force an immediate review in extreme cases, and tiered due diligence (simplified, normal, enhanced) based on the client's risk. Version history by cutoff date: the past is never overwritten.
Factor-weighted institutional risk methodology, aligned with the regulator's framework. Inherent → Exposure → Residual → Net, with Low/Medium/High bands.
An alert engine with configurable rules: politically exposed persons (PEP), watchlists, unusual behavior and patterns, and per-product thresholds, each with its own severity and frequency. See the full engine ↓.
A catalog of thousands of economic activities weighted by risk level, feeding directly into the Product/Client factor in both matrices.
FATF, UN, OFAC, INTERPOL, and internal watchlists, with politically exposed persons and their relatives/associates, synced daily.
Simplified, Normal, or Enhanced, assigned by the client's risk category, with periodic review when the transactional profile departs from what was declared.
Client and vendor KYC with documents defined by role and criticality before the relationship is enabled. Contracts and supporting documents stay organized with retention and traceability for review.
for any organization managing enterprise risk
Each risk is identified within a Project and a domain: PROJECT, OHS, RECURRING, or ADMINISTRATIVE. Structured identification as Risk / Trigger / Cause / Consequence, with inherent → controls → residual/net.
Owner, deadline, currency, and reserve per mitigation task, not a list of good intentions.
Indicators for continuous exposure follow-up and better prioritization, not a quarterly report that's already stale.
Risk & control self-assessment, the organization's risk appetite, and mapping to regulatory requirements.
Value at Risk for financial risk and BowTie diagrams for cause-barrier-consequence analysis.
Staged approval workflow; loss events originate from real incidents, not a manual report.
operational control and traceability for the whole organization
Vendor classification by criticality (CRITICAL/RELEVANT/STANDARD) and LOW/MEDIUM/HIGH risk level, periodic evaluation and vendor KYC, with a "cleared to sign / ERP onboarding" gate that requires the actual documentation uploaded, not a checked box.
Business continuity plan with activation and an operational runbook, not a PDF nobody opens during the crisis.
Continual service improvement and nonconformity management, aligned to the same risk dashboard.
The engine evaluates configurable rules (threshold, severity, frequency) grouped by risk type: politically exposed persons (PEP), watchlists, unusual behavior and patterns, and per-product thresholds. Each trigger feeds the client's risk score, which is placed on the organization's configurable matrix.
Inherent (dark dot) vs. residual after controls (cyan dot), risk appetite configurable per organization.
Factor-weighted institutional risk methodology, aligned with the regulator's framework. It combines inherent risk with exposure to arrive at a residual risk and a net score by band Low / Medium / High.
OMNIA GRC works on its own. Start with risk management or governance, add Compliance AML for regulatory obligations, and expand capabilities when the business requires it.
| Disconnected toolsseparate products and manual follow-up | OMNIA GRC modularstart with the domains you need | |
|---|---|---|
| AML/PEP screening | ◐ Separate tool, result that has to be re-entered into the file. | ● Native, the hit feeds directly into the client's score. |
| Enterprise risk matrix | ◐ Spreadsheet or CRM module, with no version history. | ● Versioned by cutoff date, own factors/weights. |
| Institutional risk | ○ Not covered by a CRM or by most AML suites. | ● Configurable, according to the organization’s methodology. |
| Configurable alert engine | ◐ Fixed rules from the vendor, hard to adjust by country. | ● Own rules, configurable and supported by evidence. |
| ERM / KRIs | ○ Separate GRC suite, updated by hand every quarter. | ● Continuous, visible for ongoing follow-up. |
| Vendor risk | ◐ Ecosystem of the CRM, requires custom objects and flows. | ● Criticality + risk (CRITICAL/RELEVANT/STANDARD · LOW/MEDIUM/HIGH) with an ERP onboarding gate. |
| Continuity / quality | ○ GRC suite additional, separate license. | ● Included, BCP + CSI + nonconformities. |
| Document file | ◐ Another repository to integrate and keep in sync. | ● Single record, with organized evidence and traceability. |
| Total cost | $$$ license per product + integration across all three. | ● Single module, no per-seat license. |
Use it standalone for risk, governance, and operational control. Activate Compliance AML if your organization is subject to regulation, or expand with other OMNIA capabilities when it adds value.