Platform overview

One operating platform for the governance, risk, and oversight work credit unions already have to run.

CU Risk connects the risk register, vendor oversight, findings and remediation, policy governance, evidence retrieval, board reporting, and global search so teams can work from one source of truth instead of a patchwork of spreadsheets and file shares.

Platform summary

Modules active

5

Connected reporting

Documents linked

186

Evidence in context

Tasks open

23

Owned and tracked

Cross-platform control view

Risk, vendors, findings, and policies aligned

Risk changes roll into board summaries automatically.
Vendor exceptions stay visible to operational owners.
Policy milestones stay linked to governance reporting.
Evidence is accessible without leaving the workflow.

Next actions

Refresh vendor review packet
Close two moderate findings
Approve revised policy version

Control signal

Leadership reporting is aligned with current operating data.

Core modules

Coverage across the workflows leadership depends on.

Each module is designed to stand on its own while feeding shared reporting, auditability, and operational context across the platform.

Risk Management

Core

Run an institution-wide risk register with ownership, scoring, trends, controls, and mitigation tracking.

  • Centralized risk register with inherent and residual scoring
  • Control mapping and treatment planning
  • Trending views for executives and risk committees

Vendor Management

Third party

Organize vendor inventories, due diligence, questionnaire workflows, and renewal oversight in a single process.

  • Due diligence requests and evidence collection
  • Renewal planning and review checkpoints
  • Defensible third-party documentation

Policy Governance

Governance

Coordinate policy lifecycles from drafting and committee review through board approval and version history.

  • Version control and approval routing
  • Review calendars and accountability
  • Connected evidence for auditors and examiners

Findings & Exam Management

Assurance

Track internal audit findings, examiner requests, remediation tasks, and supporting documents with clear ownership.

  • Finding lifecycle tracking with severity and due dates
  • Task assignment and status management
  • Exam response organization and evidence capture

Board Reporting

Executive

Deliver consistent dashboards and narrative summaries that connect operational detail to board-level oversight.

  • Board packet metrics and risk summaries
  • Leadership-ready issue escalation views
  • Repeatable reporting structure for committees and boards

Risk register

Track enterprise risks with scoring, ownership, and defensible context.

Maintain a live risk register with inherent and residual scoring, accountable owners, mitigation activity, and linked records so leadership can see what has changed and why.

Inherent and residual scoring with treatment tracking
Owner accountability, due dates, and mitigation notes
Board-worthy top risk visibility and concentration views
Linked findings, vendors, and evidence in context
Executive dashboard

Active risks

42

+3 this quarter

Critical vendors

9

2 under review

Open findings

17

7 due in 30 days

Policies due

11

4 at committee

Risk register summary

Residual risk posture across top categories

Cybersecurity

Elevated

8 linked controls

Third-party

Moderate

3 renewals in review

Liquidity

Within tolerance

No change

Vendor review queue

Core processor

High

Awaiting SOC 2

Card dispute tool

Moderate

Renewal review

Statement vendor

Low

Evidence complete

Board packet

Prepared from live risk and findings data

Ready for committee review

Vendor oversight

Coordinate vendor reviews, due diligence, and renewals without spreadsheet sprawl.

Standardize criticality, contracts, SOC review follow-up, due diligence requests, and renewal checkpoints so third-party oversight is easier to run and defend.

Due diligence workspaces with checklist and evidence collection
Contract, renewal, and review-date visibility
Escalations for incomplete, overdue, or high-risk reviews
Risk-linked vendor oversight for executives and operators
Vendor oversight

Reviews in flight

14

5 due this month

Evidence gaps

6

2 escalated

Renewals

3

Within 60 days

Review stages

Intake

4 vendors

Evidence collection

6 vendors

Risk assessment

2 vendors

Approval

2 vendors

Due diligence workspace

Checklist status, document gaps, and renewal timing

Core processor

SOC 2 requested

Awaiting response

Digital banking

BCP reviewed

Needs updated insurance

Card network partner

High-risk review

Committee sign-off

Collections tool

Renewal packet

Ready for legal review

Findings and remediation

Keep open issues moving with visible ownership and supporting evidence.

Track findings from audits, exams, policy reviews, and security assessments with clear ownership, due dates, and the records needed to demonstrate progress.

Finding status, severity, source, and due-date tracking
Remediation ownership and follow-up accountability
Documented closure support for internal and external review
Connected context across risks, vendors, and exam work
Security operations

Audit activity

Access events and workflow changes

Role update

Vendor manager added to due diligence review group

MFA challenge

Successful privileged sign-in for board reporting

Document access

Exam evidence packet retrieved by auditor

Workflow change

Finding severity updated with linked justification

Control checks

Access review

Current

Backup status

Healthy

Audit logs

Retained

Alerting

Privileged access changes flagged for review.

Policy governance

Run policy reviews, approvals, and version history with less manual coordination.

Support drafting, committee review, board approval, and controlled publication with a clear record of what changed, when review is due, and who approved it.

Policy review calendars and upcoming approval milestones
Versioned records with supporting artifacts
Committee and board workflow examples
Visibility into policies due soon or pending approval
Governance workspace

Policy lifecycle management

Drafting, review, and approval workflow

Drafting

3

Committee

4

Board review

2

Published

48

Acceptable Use Policy

Board review scheduled

May 30

Third-Party Risk Policy

Committee approved

June 4

Incident Response Standard

Annual refresh

June 18

Findings status

High

2

Moderate

8

Low

7

Review cadence

Quarterly policy agenda synced with committee and board deadlines.

Evidence repository

Organize supporting documents where teams can actually retrieve them during reviews.

Keep board packets, exam responses, vendor evidence, policy acknowledgements, and remediation support linked to the records that reference them.

Structured document records with version history
Searchable evidence tied to risks, vendors, policies, and findings
Better retrieval during exams, audits, and committee prep
Downloadable support without losing record context
Security operations

Audit activity

Access events and workflow changes

Role update

Vendor manager added to due diligence review group

MFA challenge

Successful privileged sign-in for board reporting

Document access

Exam evidence packet retrieved by auditor

Workflow change

Finding severity updated with linked justification

Control checks

Access review

Current

Backup status

Healthy

Audit logs

Retained

Alerting

Privileged access changes flagged for review.

Board reporting

Translate live operating data into board-ready reporting without rebuilding the story each quarter.

Summarize top risks, open findings, vendor concerns, policy status, and upcoming deadlines in a format executives and directors can review quickly.

Executive packet views grounded in live register data
Period-based reporting for current quarter, prior quarter, YTD, and trailing 12 months
Supporting drill-down links when detail is needed
Repeatable reporting cadence for committees and boards
Board reporting

Risk trend

Stable

Down from Q1

Open issues

17

5 closing soon

Board packet

Q3 ready

Narrative aligned

Quarterly board summary

Top risks, findings, and vendor concentrations

Residual cyber risk moderating after control remediation.
Two critical vendors in enhanced review before renewal.
Seven findings carry due dates before next committee cycle.
Policy refresh calendar remains on schedule.

Committee packet checklist

Risk heatmap exported
Finding narrative refreshed
Vendor exception memo attached

Leadership focus areas

Third-party concentration
Residual fraud exposure
Overdue issue remediation

Global search and connected records

Find the right record fast and move directly to the related evidence, issue, or vendor.

Search across tenant-scoped operational records and preserve the relationships between risks, findings, policies, vendors, exam requests, and documents.

Global search across major governance and risk records
Cross-linked records that reduce context switching
Faster response time for executives, auditors, and exam teams
Less dependence on separate trackers and file shares
Platform summary

Modules active

5

Connected reporting

Documents linked

186

Evidence in context

Tasks open

23

Owned and tracked

Cross-platform control view

Risk, vendors, findings, and policies aligned

Risk changes roll into board summaries automatically.
Vendor exceptions stay visible to operational owners.
Policy milestones stay linked to governance reporting.
Evidence is accessible without leaving the workflow.

Next actions

Refresh vendor review packet
Close two moderate findings
Approve revised policy version

Control signal

Leadership reporting is aligned with current operating data.

Foundational capabilities

Shared capabilities that make the entire platform more defensible.

CU Risk is designed to improve consistency across every workflow, not just store records in separate modules.

Board reporting dashboards

Summarize open risks, issues, and trends for leadership review without stitching together separate reports.

Audit trails

Maintain a defensible record of updates, assignments, approvals, and document activity across the platform.

Document repository

Organize governance evidence, vendor records, and supporting files where teams can find them quickly.

Cross-module context

See how policies, vendors, findings, documents, and board reporting relate instead of managing them in isolation.