One operating platform for the governance, risk, and oversight work credit unions already have to run.
CU Risk connects the risk register, vendor oversight, findings and remediation, policy governance, evidence retrieval, board reporting, and global search so teams can work from one source of truth instead of a patchwork of spreadsheets and file shares.
Modules active
5
Connected reporting
Documents linked
186
Evidence in context
Tasks open
23
Owned and tracked
Cross-platform control view
Risk, vendors, findings, and policies aligned
Next actions
Control signal
Core modules
Coverage across the workflows leadership depends on.
Each module is designed to stand on its own while feeding shared reporting, auditability, and operational context across the platform.
Risk Management
CoreRun an institution-wide risk register with ownership, scoring, trends, controls, and mitigation tracking.
- Centralized risk register with inherent and residual scoring
- Control mapping and treatment planning
- Trending views for executives and risk committees
Vendor Management
Third partyOrganize vendor inventories, due diligence, questionnaire workflows, and renewal oversight in a single process.
- Due diligence requests and evidence collection
- Renewal planning and review checkpoints
- Defensible third-party documentation
Policy Governance
GovernanceCoordinate policy lifecycles from drafting and committee review through board approval and version history.
- Version control and approval routing
- Review calendars and accountability
- Connected evidence for auditors and examiners
Findings & Exam Management
AssuranceTrack internal audit findings, examiner requests, remediation tasks, and supporting documents with clear ownership.
- Finding lifecycle tracking with severity and due dates
- Task assignment and status management
- Exam response organization and evidence capture
Board Reporting
ExecutiveDeliver consistent dashboards and narrative summaries that connect operational detail to board-level oversight.
- Board packet metrics and risk summaries
- Leadership-ready issue escalation views
- Repeatable reporting structure for committees and boards
Risk register
Track enterprise risks with scoring, ownership, and defensible context.
Maintain a live risk register with inherent and residual scoring, accountable owners, mitigation activity, and linked records so leadership can see what has changed and why.
Active risks
42
+3 this quarter
Critical vendors
9
2 under review
Open findings
17
7 due in 30 days
Policies due
11
4 at committee
Risk register summary
Residual risk posture across top categories
Cybersecurity
Elevated
8 linked controls
Third-party
Moderate
3 renewals in review
Liquidity
Within tolerance
No change
Vendor review queue
Core processor
HighAwaiting SOC 2
Card dispute tool
ModerateRenewal review
Statement vendor
LowEvidence complete
Board packet
Prepared from live risk and findings data
Vendor oversight
Coordinate vendor reviews, due diligence, and renewals without spreadsheet sprawl.
Standardize criticality, contracts, SOC review follow-up, due diligence requests, and renewal checkpoints so third-party oversight is easier to run and defend.
Reviews in flight
14
5 due this month
Evidence gaps
6
2 escalated
Renewals
3
Within 60 days
Review stages
Intake
4 vendors
Evidence collection
6 vendors
Risk assessment
2 vendors
Approval
2 vendors
Due diligence workspace
Checklist status, document gaps, and renewal timing
Core processor
SOC 2 requested
Digital banking
BCP reviewed
Card network partner
High-risk review
Collections tool
Renewal packet
Findings and remediation
Keep open issues moving with visible ownership and supporting evidence.
Track findings from audits, exams, policy reviews, and security assessments with clear ownership, due dates, and the records needed to demonstrate progress.
Audit activity
Access events and workflow changes
Role update
Vendor manager added to due diligence review group
MFA challenge
Successful privileged sign-in for board reporting
Document access
Exam evidence packet retrieved by auditor
Workflow change
Finding severity updated with linked justification
Control checks
Access review
Current
Backup status
Healthy
Audit logs
Retained
Alerting
Policy governance
Run policy reviews, approvals, and version history with less manual coordination.
Support drafting, committee review, board approval, and controlled publication with a clear record of what changed, when review is due, and who approved it.
Policy lifecycle management
Drafting, review, and approval workflow
Drafting
3
Committee
4
Board review
2
Published
48
Acceptable Use Policy
Board review scheduled
Third-Party Risk Policy
Committee approved
Incident Response Standard
Annual refresh
Findings status
High
2
Moderate
8
Low
7
Review cadence
Evidence repository
Organize supporting documents where teams can actually retrieve them during reviews.
Keep board packets, exam responses, vendor evidence, policy acknowledgements, and remediation support linked to the records that reference them.
Audit activity
Access events and workflow changes
Role update
Vendor manager added to due diligence review group
MFA challenge
Successful privileged sign-in for board reporting
Document access
Exam evidence packet retrieved by auditor
Workflow change
Finding severity updated with linked justification
Control checks
Access review
Current
Backup status
Healthy
Audit logs
Retained
Alerting
Board reporting
Translate live operating data into board-ready reporting without rebuilding the story each quarter.
Summarize top risks, open findings, vendor concerns, policy status, and upcoming deadlines in a format executives and directors can review quickly.
Risk trend
Stable
Down from Q1
Open issues
17
5 closing soon
Board packet
Q3 ready
Narrative aligned
Quarterly board summary
Top risks, findings, and vendor concentrations
Committee packet checklist
Leadership focus areas
Global search and connected records
Find the right record fast and move directly to the related evidence, issue, or vendor.
Search across tenant-scoped operational records and preserve the relationships between risks, findings, policies, vendors, exam requests, and documents.
Modules active
5
Connected reporting
Documents linked
186
Evidence in context
Tasks open
23
Owned and tracked
Cross-platform control view
Risk, vendors, findings, and policies aligned
Next actions
Control signal
Foundational capabilities
Shared capabilities that make the entire platform more defensible.
CU Risk is designed to improve consistency across every workflow, not just store records in separate modules.
Board reporting dashboards
Summarize open risks, issues, and trends for leadership review without stitching together separate reports.
Audit trails
Maintain a defensible record of updates, assignments, approvals, and document activity across the platform.
Document repository
Organize governance evidence, vendor records, and supporting files where teams can find them quickly.
Cross-module context
See how policies, vendors, findings, documents, and board reporting relate instead of managing them in isolation.