Aeion Governance for Enterprise Risk Management
Enterprise Risk Management (ERM) programs need an operational-risk backbone: change impact assessment before something breaks, per-framework compliance findings with owners and deadlines, an audit trail that proves what happened when something did, and approval workflows that escalate instead of stalling. Legacy GRC platforms — RSA Archer, MetricStream, ServiceNow GRC, LogicGate — charge $200K-2M+/year for full ERM suites (including risk-register, KRI, and vendor-risk modules Aeion does not replicate feature-for-feature). Aeion Governance covers the operational core — change impact analysis, compliance findings, tamper-evident audit, approval escalation — natively, and is a genuine cost alternative for teams whose ERM needs center on those controls rather than a dedicated quantitative risk register.
What Aeion Governance Actually Provides for Risk Programs
`
Walkthrough — Public Company Change & Compliance Program
`
FAQ
Not today. Change requests carry a risk-level impact assessment, and compliance findings carry severity — but there's no dedicated risk-register collection with likelihood/impact/velocity/tolerance-threshold fields per named risk.
Aeion Singularity has connectors for common GRC data exports. Expect to migrate compliance findings and audit history in full; risk-register records won't have a like-for-like destination collection until Aeion ships one.
Not as a dedicated vendor-risk-assessment workflow today. Vendor contracts and SOC2/ISO27001 report references can be tracked as documents/policies, but there's no purpose-built vendor-risk collection.
Not built in. Compliance framework status and change-request impact levels are the closest reportable signals available today.
No — Governance and Sentinel don't share events today. Incident data would need to be manually referenced in a compliance finding or change request.
Aeion Governance ships a general governance dashboard (policies, requests, audit, compliance-framework status). It is not a purpose-built quarterly ERM board report with top-10-risks ranking.
Yes. Every audit entry embeds a SHA-256 hash of the previous entry and is chain-verified on read (`auditService.ts`). This is genuinely implemented, not a marketing description.
Each change request stores an impact assessment (risk level + affected resources) attached at creation. It's a structured field, not an automated dependency-graph computation.
RSA Archer: $300K-2M/year for full ERM. Aeion Governance: $0, included free with any Aeion module, but scoped to change control + compliance findings + audit + approvals — not a full risk-register replacement.
Yes for the change-management and audit-trail components SOX testing typically examines. Aeion doesn't model financial-statement-risk assessment itself.