A structured technology risk register and a recurring reporting cadence to your board — set up once, maintained continuously, so technology risk stops being an occasional agenda item and becomes something the board actually tracks.
Most boards get a technology update when something has gone wrong, or once a year as part of a broader risk review. What’s missing is a genuine, structured, recurring register — the kind that lets a board see technology risk trending up or down over time, rather than being surprised by it. What you don’t have is that register, built properly and maintained on a cadence the board can actually rely on.
That is what this engagement is.
Two stages. A fixed-fee setup engagement to build the register and reporting structure, followed by an ongoing maintenance retainer quoted on the cadence and depth your board wants.
No implementation work beyond the register itself. No commissions. No product recommendations influenced by suppliers.
Why boards commission this
- Technology risk currently reaches the board only when something has already gone wrong, and the board wants visibility before that point instead.
- A recent incident, at this business or a peer, has prompted the board to want a genuine standing risk process rather than an ad hoc conversation.
- An investor, insurer, or regulator has asked what the board’s ongoing technology risk oversight process actually looks like, and the honest answer is currently “there isn’t one.”
- DORA’s requirement for board-level ICT risk understanding, or an equivalent obligation, has made the case for formal structure explicit.
Who this is for
Boards wanting a genuine, structured technology risk reporting process, not just an occasional briefing.
Regulated entities needing to demonstrate documented, ongoing board-level ICT risk oversight, not a one-off presentation.
Who this is not for
Boards wanting a single, comprehensive baseline assessment rather than an ongoing process — that’s the Technology Control Review, which pairs well as the starting evidence base for the register.
Stage one: register setup
€15,000. Three to four weeks. Design and build of a structured technology risk register specific to your business, a reporting template and cadence agreed with the board, and the initial population of the register from a genuine risk-gathering exercise across the business.
Stage two: ongoing maintenance retainer
The register only has value if it’s kept genuinely current. Ongoing maintenance — updating the register, preparing the recurring board report, flagging emerging risks between cycles — is quoted separately, based on the reporting cadence and depth the board wants.
What this is not
A one-off risk assessment. The register is designed to be a living document, reported against on a recurring cadence, not a point-in-time snapshot.
A remediation engagement. The register identifies and tracks risk; addressing individual risks is separate work.
Proof
References available on request.
What happens next
Start a ConversationThirty minutes. We confirm what your board currently sees, and whether to start with register setup or a Technology Control Review as the evidence base first.