Risk management and internal control
Risk belongs inside the management system.
BlueJam integrates risk management and internal control with objectives, outcomes and delivery. Risks can be connected directly to the objectives and activities they may affect, or managed independently where appropriate.

Used by organizations with complex needs


Challenges
Risk work that stops in the spreadsheet.
The requirements vary between central government, municipalities and public enterprises. The need is the same: systematic, risk-based and documented follow-up that supports governance.
Risk on its own track
The risk register lives outside the management system.
When risk is managed separately, the connection to objectives, impact and decisions is lost. Risk management becomes a periodic exercise rather than part of everyday management.

Hard to prioritize
A five does not always mean the same thing.
Strategic, financial, operational, compliance and other consequences need to be assessed against relevant criteria. Without clear scales, risk appetite and tolerance, prioritization becomes inconsistent.

Actions without follow-up
The risk is mapped, but not reduced.
Actions and control activities get decided, but accountability, deadlines and effect are not followed up in the same structure. The next review starts from scratch.

Solution
Risk as part of the management logic.
Manage risks independently or connect them directly to strategic objectives and organizational units.

How it works
Identify. Assess. Treat.
Integrate risk and internal control into the governance, tailored to the organization’s character, risk and materiality.

Identify what matters
Identify uncertainty that could affect strategy, operations or compliance, and connect risks to the areas they may affect.

Assess the consequences
Assess likelihood and impact using relevant categories, consequence scales, risk appetite and tolerance to prioritize attention.

Treat and improve
Assign ownership, track treatments and controls, and review whether risk exposure is actually changing.


Identify what matters
Identify uncertainty that could affect strategy, operations or compliance, and connect risks to the areas they may affect.

Treat and improve
Assign ownership, track treatments and controls, and review whether risk exposure is actually changing.

Assess the consequences
Assess likelihood and impact using relevant categories, consequence scales, risk appetite and tolerance to prioritize attention.
Features
Tools for risk owners and internal control.
Configure the risk model yourself and track risk, actions and control activities in one structure.

The framework you govern by
Support ISO 31000, COSO ERM or your own combination of frameworks.

Flexible risk categories
Define categories such as strategic, financial, operational, sustainability, security and compliance to suit the organization.

Tailored consequence scales
Define what levels 1-5 mean for different consequence categories, so assessments rest on explicit criteria.

Standalone and connected risks
Track risk on its own, or tie it to defined categories or strategy and objectives.

Risk tolerance and acceptance
Define risk appetite and tolerance levels, and make it clear which risks require treatment, escalation or particular management attention.

Inherent and residual risk
Track risk before and after actions, and compare it with the level the organization wants to reach.

Actions and control activities
Document accountability, deadlines and status, and assess whether the actions and controls work as intended.

AI support for risk work
Get suggestions for risks and actions based on objectives, governance information and your documented context.

Benefits
Risk as a basis for decisions.
Risk inside continuous governance
Follow the risk picture together with objectives, tasks and results, not only in a separate annual review.
Systematic internal control
Document the connection between risk, control activities, actions, accountability and follow-up over time.
Better prioritization
Direct governance attention to the areas that are most material and carry the most risk.

Make risk an active part of the governance.
See how BlueJam adapts to your risk model and brings risk, internal control and follow-up together.
Platform
Enterprise Strategy
Function-Level Strategy
Multi-Business Strategy
AI for Strategy
Integrations & API
Security & Identity
Pricing
Solutions
Strategy Development
Strategy Execution
Strategy Engagement
Strategy Insights
Strategic Performance Management
Strategic Risk Management
OKRs
Balanced Scorecard
Public Sector
BlueJam for the Public Sector
Public Sector Governance
Managing for Results
Strategy Execution
Risk Management & Internal Control
The world’s most fun and engaging strategy platform for all employees.
Follow us
Platform
Enterprise Strategy
Function-Level Strategy
Multi-Business Strategy
AI for Strategy
Integrations & API
Security & Identity
Pricing
Solutions
Strategy Development
Strategy Execution
Strategy Engagement
Strategy Insights
Strategic Performance Management
Strategic Risk Management
OKRs
Balanced Scorecard