Risk management and internal control
Risk belongs inside the governance.
BlueJam brings risk management, internal control and objective follow-up into one solution. Risk can be connected to objectives where that is relevant, or followed up on its own by the risk owners.

Used by organizations with complex governance needs


Challenges
Risk work that stops in the spreadsheet.
The requirements vary between central government, municipalities and public enterprises. The need is the same: systematic, risk-based and documented follow-up that supports governance.
Risk on its own track
The risk register lives outside the management system.
When risk is followed up separately, the connection to objectives, tasks and decisions disappears. Risk management becomes a periodic exercise rather than part of governing.

Hard to prioritize
A five does not always mean the same thing.
Financial, operational and sustainability consequences have to be assessed against relevant criteria. Without clear scales and tolerance limits, prioritization gets vague.

Actions without follow-up
The risk is mapped, but not reduced.
Actions and control activities get decided, but accountability, deadlines and effect are not followed up in the same structure. The next review starts from scratch.

Solution
Risk as part of the governance logic.
Handle risk on its own or connected to objectives, indicators, tasks, initiatives, actions and organizational units.

How it works
Identify. Assess. Treat.
Integrate risk and internal control into the governance, tailored to the organization’s character, risk and materiality.

Identify what matters
Record risk against objectives, tasks and areas, or as standalone risk where that is right.

Assess the consequences
Use relevant categories, consequence scales and tolerance limits to prioritize follow-up.

Treat and improve
Assign ownership, track actions and control activities, and assess whether the risk is actually reduced.


Identify what matters
Record risk against objectives, tasks and areas, or as standalone risk where that is right.

Treat and improve
Assign ownership, track actions and control activities, and assess whether the risk is actually reduced.

Assess the consequences
Use relevant categories, consequence scales and tolerance limits to prioritize follow-up.
Features
Tools for risk owners and internal control.
Configure the risk model yourself and track risk, actions and control activities in one structure.

The framework you govern by
Support ISO 31000, COSO ERM or your own combination of frameworks.

Flexible risk categories
Define categories such as strategic, financial, operational, sustainability, security and compliance to suit the organization.

Tailored consequence scales
Define what levels 1-5 mean for different consequence categories, so assessments rest on explicit criteria.

Standalone and connected risks
Track risk on its own, or tie it to objectives, indicators, tasks, initiatives, actions and units.

Risk tolerance and acceptance
Define tolerance limits and make it visible which risks require actions, escalation or particular attention.

Inherent and residual risk
Track risk before and after actions, and compare it with the level the organization wants to reach.

Actions and control activities
Document accountability, deadlines and status, and assess whether the actions and controls work as intended.

AI support for risk work
Get suggestions for risks and actions based on objectives, governance information and your documented context.

Benefits
Risk as a basis for decisions.
Risk inside continuous governance
Follow the risk picture together with objectives, tasks and results, not only in a separate annual review.
Systematic internal control
Document the connection between risk, control activities, actions, accountability and follow-up over time.
Better prioritization
Direct governance attention to the areas that are most material and carry the most risk.

Make risk an active part of the governance.
See how BlueJam adapts to your risk model and brings risk, internal control and follow-up together.
Platform
Enterprise Strategy
Function-Level Strategy
Multi-Business Strategy
AI for Strategy
Integrations & API
Security & Identity
Pricing
Solutions
Strategy Development
Strategy Execution
Strategy Engagement
Strategy Insights
Results-Based Management
Strategic Risk Management
OKRs
Balanced Scorecard
Public Sector
BlueJam for the Public Sector
Public Sector Governance
Managing for Results
Strategy Execution
Risk Management & Internal Control
The world’s most fun and engaging strategy platform for all employees.
Follow us
Platform
Enterprise Strategy
Function-Level Strategy
Multi-Business Strategy
AI for Strategy
Integrations & API
Security & Identity
Pricing
Solutions
Strategy Development
Strategy Execution
Strategy Engagement
Strategy Insights
Results-Based Management
Strategic Risk Management
OKRs
Balanced Scorecard