What is Axiom Risk?
Axiom Risk is an enterprise risk management platform developed by Digital Marque Solutions. It provides organisations with a structured, live system for managing risk: from identification and assessment through to treatment, monitoring, and governance reporting.
It is aligned to ISO 31000:2018 and built on Airtable, meaning it delivers the structure of a proper risk management system with the accessibility of a platform people will actually use.
Axiom Risk is not a self-serve product. It is configured and implemented for each client organisation, scoped to your risk profile, governance structure, and reporting requirements.
| Axiom Risk | |
|---|---|
Standard | ISO 31000:2018 |
Platform | Airtable |
Module | 1 of the Axiom Suite |
Delivery | Implemented, not self-serve |
Market | South African businesses and regulated organisations |
What Axiom Risk delivers
Live Risk Register
A structured, always-current register capturing risk descriptions, categories, likelihood, consequence, inherent and residual ratings, and risk owners. One source of truth, visible to the right people at all times.
Treatment Plan Tracking
Every risk above appetite threshold has a treatment plan. Axiom Risk tracks treatment actions, owners, deadlines, and status, surfacing what's overdue and what's on track without a manual chase.
Risk Appetite Framework
Your organisation's risk appetite expressed as explicit thresholds, not a narrative statement. Every risk is interpreted against the appetite, producing a clear signal: tolerate, monitor, or treat.
Governance and Reporting Views
Pre-configured views for different audiences. Operational detail for risk owners. Management summaries for leadership. Strategic overviews for the board. Same data, right level of detail for each reader.
ISO 31000 Alignment
Axiom Risk is structured around the ISO 31000 risk management process.
Read the White PaperSupported through the Interested Party Directory, which registers all internal and external parties relevant to the risk management process. The assessment voting mechanism provides a formal, documented channel through which multiple stakeholders contribute to control effectiveness ratings. Assessment records capture all participants, creating a traceable record of who was consulted in each evaluation.
Established through the Context section of the interface. The Objectives page formalises the organisational context by requiring that objectives are registered, described, assigned to an organisational level, and owned before risk identification begins. The Criteria tables (CER scale, CRC taxonomy, Treatment Types, Risk Matrix, Organisational Levels) define the measurement and classification framework that will be applied consistently across the register. The ongoing monitoring of the external context required by clause 6.3 is operationalised through the Risk Horizon, described in Section 4.7: a continuously running intelligence layer that scans the external environment, governs detected signals, and provides the traceable pathway through which emerging external risks enter the register.
Supported through the Risks and Contributing Factors pages. Each risk is defined as the negative effect of uncertainty on a specific objective. Contributing Factors capture the causal pathways through which the risk can materialise, providing the granular layer that connects the risk to its controls. This two-layer structure (risk and contributing factor) produces a richer and more actionable identification record than a flat risk description alone.
The calculation chain described in the white paper. The analysis is not assessors’ judgment applied after the fact; it is the mathematical output of the CES values flowing from completed control assessments through contributing factors to the risk and objective level. The analysis is continuous, automatic, and fully traceable.
Supported through the Risk Criteria table, which maps every RRS value from 1 to 25 to a risk category (Low, Medium, Significant, or High) and a corresponding %RE value. The risk category is updated automatically when the RRS changes. No manual categorisation is required. The Risks Dashboard and Objectives Dashboard present the evaluated risk position at summary and detail level for governance review.
Managed through the Actions and Treatment Decisions pages. Mitigating actions (linked to controls or contributing factors) represent the decision to invest in control improvement. Formal treatment decisions (Accept, Transfer, Avoid, Escalate) are recorded as separate records linked to the risk, with the treatment type drawn from the Criteria: Treatment Types table. The two surfaces are deliberately separated: improvement actions drive %AC upward through the calculation chain; formal treatment decisions are governance positions that sit outside the calculation.
Continuous by design. Because residual risk recalculates automatically from the most recent completed assessment for each control, the register reflects the current state of the control environment at all times. The Last Assessed field on each control record makes it immediately visible when a control has not been assessed within an expected period, prompting review without requiring a scheduled audit cycle.
Delivered through the Reporting section of the interface: the Objectives Dashboard, Risks Dashboard, and Controls Dashboard. These three views provide the board and governance layer with a current, objective, and auditable summary of the organisation’s risk position. Every number on every dashboard is derived from the same unbroken calculation chain. There are no manually entered summary figures.
How implementation works
1. Discovery
We scope your GRC-A requirements, governance structure, existing risk practices, and reporting obligations.
2. Configuration
We build and configure your Axiom Risk instance: risk categories, appetite scales, assessment methodology, and reporting views, all tailored to your organisation.
3. Population
We facilitate a risk identification workshop and populate your initial risk register. You don't start with a blank system.
4. Training
Risk owners learn to manage their risks. Leadership learns to read the reporting. Administrators learn to maintain the system.
5. Ongoing Support
We're available for review cycles, register updates, system changes, and expansion to additional Axiom modules as they release.
Part of Something Bigger
Axiom Risk is the first module of the Axiom suite. As Axiom Comply and Axiom Assure release, they connect directly to your risk register, building a unified GRC-A system rather than isolated tools.
Explore the Axiom SuiteInterested in Axiom Risk?
We work with a limited number of implementation clients per quarter to ensure quality.