Skip to main content
NOVACompliance

Features

Available now

Risk management

Record risks with owners, assess them consistently, assign treatment, and capture acceptance as an explicit decision.

The problem it solves

Risk registers are often assembled for an audit and abandoned afterwards. Treatment plans have no owner, and acceptance is implied by silence rather than recorded as a decision someone made.

How it works

  1. 1

    Identify and assess

    Risks are recorded against the assets, controls or processes they affect, and assessed using a consistent methodology so scores can be compared.

  2. 2

    Treat or accept, explicitly

    Each risk carries a treatment decision. Acceptance is a recorded action with a named accepter and a date, not an absence of activity.

    • Treatment plans with owners and target dates
    • Explicit acceptance records retained in history
    • Residual risk visible alongside inherent risk
  3. 3

    Review on a cadence

    Risks are reviewed on a schedule and when their context changes, with the review history retained for assurance.

Capabilities

Risk register

Central register linked to controls, assets and frameworks.

Consistent assessment

One methodology applied across the register.

Treatment tracking

Plans with owners, dates and progress.

Acceptance records

Who accepted what, when, and on what basis.

What people remain responsible for

  • Assessing likelihood and impact
  • Choosing treatment over acceptance
  • Accepting residual risk on behalf of the organisation

See NOVA against your own compliance obligations

Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.