Take back controlof your operations

    Automated alerting and continuous monitoring across all your governance, compliance, control, risk management and fraud detection needs — on one platform, connected to your own data.

    Trusted by
    • FirstLight
    • PSP Investments

    SOC-2 Type II reported · SaaS, private cloud, hybrid or on-premise

    SOC-2 Type II — audited by BDO
    Architecture certified by Microsoft Azure architects
    Available on the Microsoft Azure Marketplace

    Governance, risk and compliance still runs on spreadsheets

    Most GRC programmes are assembled from disconnected tools and workbooks. The cost is not the licence — it is that nobody can answer a simple question about risk without a project.

    Risk and controls never meet

    The risk register lives in one place and the control inventory in another, so no one can say which risks are actually covered.

    Evidence is collected once a year

    Control testing is a point-in-time exercise. Between two campaigns, nothing is observed and nothing is proven.

    Findings outlive the fix

    Recommendations and action plans are tracked in email and slide decks, so closure is asserted rather than evidenced.

    Reporting is rebuilt every quarter

    Each committee gets its own hand-built pack, assembled from exports, and none of them reconcile.

    The whole framework, not one corner of it

    An internal control system is many components that only work when they are connected. Select a segment to see what it has to cover — and what falls through when it is run on spreadsheets.

    Risk ManagementFunctionRisk Identification& AssessmentCommitteesKPI MonitoringDashboardsControlsAction PlansLosses &IncidentsContinuousImprovementAuditManagementGovernanceOrganization Scope& PerimeterBusiness ActivityFramework

    Operating layer

    Risk Management Function

    We need to consider all levers to setup an efficient, exhaustive, consistent, sustainable risk management framework across the Group. Internal control systems are made of many components that need to be connected: - Scope management / know your business (perimeter & framework) - Governance (decision making – committees – action plan) - Reporting (dashboard KRI KPI) - Role and organisation (perimeter ownership, delegation, performers, who does what – access right, prompt – to do/action plan) - Risk assessment (carto risk – risk scenario (top down / forward looking) – RCSA (bottom up / backward looking) - KRI) - Control (control needs, design, deployment, execution, results, action plan) - Alert, Findings Failure, incident, losses - Action plan (decision, deliverable, target date, Action validation and closure) - Audit (control plan – testing - control assessment) - Information system 💡 IS is what brings all the pieces to communicate together to give a holistic risk management system

    Five modules on one platform

    A modern GRC platform that connects to your data and adapts to your organisation. Modelled on hierarchical, overlapping perimeters — subsidiaries, divisions, business lines, teams — so every risk, control and finding has an owner.

    Enterprise risk management

    One taxonomy, with mapping, assessment, appetite and limits built on top of it — a register you steer with rather than maintain.

    • Risk taxonomy and risk mappings, on hierarchical perimeters and heatmaps.
    • RCSA campaigns built on your own models and calculation formulas.
    • Scenarios, events, operational losses and incident management.
    • Risk appetite and risk limit monitoring, with dashboards and data-driven KRIs.
    • Third-party and project risk management, with automatic questionnaires.
    The QuartzIQ risk register: 44 risks filtered by risk, parent risk and level, each showing probability, severity, inherent, mitigation and residual ratings for two quarters.

    Enterprise governance

    The governance layer most GRC tools leave out: the committees, policies and third-party diligence that decide how the rest of it is run.

    • Committees and workgroups, policies and procedures, code of conduct.
    • Questionnaires, background checks and due diligence.
    • Third-party risk and ESG.
    • Business continuity — impact analysis, continuity plans and testing.
    A supplier onboarding and know-your-supplier due-diligence procedure being edited in QuartzIQ, with its issuing perimeter, draft status, version and a table of contents.

    Internal control and internal audit

    Every control documented against the perimeter that owns it and the risks it covers, so a risk-and-control matrix means something and its gaps are visible.

    • Control documentation and inventory — manual, automated, semi-automated, checklist or committee.
    • Execution, alerts and tasks, generated and tracked in the platform.
    • An intelligent risk and control matrix that suggests gaps from your own data.
    • Internal audit campaigns, recommendations and action plans.
    The QuartzIQ risks and controls matrix: counts of control nodes, requirements without controls and controls without risks, above perimeters linked to their frameworks, requirements and controls.

    Regulatory compliance

    Obligations expressed as controls on the inventory you already keep, so compliance is evidenced by work you already do rather than a parallel exercise.

    • A control library covering a wide range of regulations.
    • Automated compliance controls with alerts, tasks and workflows.
    • Control and compliance programme deployment tracking.
    • The risk and control matrix linked to different regulations.
    • Regulatory reporting.
    The QuartzIQ programs and frameworks library, listing published standards such as COBIT 2019, the UAE Information Assurance Regulation and NIST SP 800-53.

    Continuous monitoring and fraud detection

    Automated controls running against live data with thresholds you set, so an exception surfaces when it happens rather than at the next campaign.

    • Automated controls with customisable detection thresholds.
    • A plug-and-play control library for fraud detection.
    • AI-assisted real-time detection.
    • AI for creating and improving controls.
    The QuartzIQ data workbench: a query over connected data sources, an AI-improved version of it, and a preview of average availability by software class, ready to become an alert rule.

    Differentiator

    A non-relational ingestion engine, because GRC data does not stay small

    The established GRC platforms are built on relational engines. That is a frequent cause of low-ROI or failed programmes: customers hit a wall at a moderate volume of data, and the programme narrows to fit the tool rather than the risk.

    • Built for the volume the programme actually generatesHigh-performance handling of large datasets, so scope is a business decision rather than a technical ceiling.
    • AI-authored KRIs and alert rulesRules and indicators configured with AI assistance, so the platform is productive from the first weeks rather than after a build phase.
    • Data-driven risk assessmentsAssessments that draw on every GRC data point already in the platform, which is what makes a risk-acceptance decision defensible.

    Perimeters

    Every risk, control and finding, scoped to who owns it

    Model the organisation as hierarchical, overlapping perimeters — subsidiaries, divisions, business lines, teams — and link legal entities to them. Roles are assigned per perimeter, and risks, controls and frameworks are mapped onto it.

    • Ownership is explicitOwner, delegate, data manager and performers are recorded on the perimeter, not implied by a distribution list.
    • Coverage is visibleUncovered risks, critical items and testing progress show on every perimeter in the hierarchy, so gaps are a number rather than a feeling.
    • The trail stays attachedAlerts, tasks and observations accumulate against the perimeter over 30 days and 12 months, which is the evidence an auditor asks for.
    The QuartzIQ perimeter explorer: an organisation’s perimeter hierarchy, each node showing its status, critical items, uncovered risks, RCSA completion and testing progress.

    What a control looks like in your sector

    The control library is generic; the controls you run are not. These are the ones customers ask for most often.

    Asset management

    Risk limit monitoring, ESG compliance verification, conflicts of interest detection, liquidity control, portfolio surveillance.

    Investment banking

    Risk limit monitoring, ESG compliance, conflicts of interest detection, liquidity ratios, portfolio monitoring.

    Retail banking

    Transaction monitoring, AML and KYC compliance, loan analysis, credit procedure compliance, complaint management.

    Retail

    Sales and refund anomalies, supplier compliance assessment, inventory level monitoring, supply chain traceability.

    Public sector

    Expenditure audits, grant management, detection of conflicts of interest among officials, citizen data security.

    Everywhere else

    Expense reports, environmental management, workplace safety, financial irregularities, regulatory compliance.

    What the Enterprise service commits to

    99.7%
    Platform availability
    Target for Enterprise customers.
    15 min
    Initial response
    Target time to first response on a request.
    < 8 h
    Resolution
    Average for non-urgent requests.
    24/7
    Dedicated assistance
    Support portal, chat, callback or video.

    Ease of implementation is at the heart of our solution

    A SaaS platform with a connector library, so onboarding is configuration rather than a technical implementation project.

    Onboard without a build phase

    SaaS, with the Azure Marketplace available as an option under your existing Microsoft agreement.

    Connect what you already run

    Connectors and data forwarders for market applications and in-house systems — files, SQL, REST API.

    Manage your own connections

    A configuration interface for managing connectors and forwarders autonomously.

    Start small, scale

    Progressive, modular deployment with robust APIs into your existing GRC and reporting stack.

    Integrations

    Standard connectors available for all your applications

    A set of plug-and-play connectors for the vast majority of solutions on the market, plus generic connectors — files, SQL, REST API — for any type of application. The platform can therefore be connected to any system, and each customer gets their own console to manage that configuration autonomously.

    • Business and finance systemsSAP, Microsoft Dynamics 365, Workday, Salesforce, eFront, Bloomberg, Open Banking.
    • IT service and securityServiceNow, Jira, Splunk, Active Directory, Azure.
    • Anything else you runGeneric connectors for SQL, XML and CSV files, and REST APIs — including in-house systems.
    QuartzIQ connectors: SQL, XML and CSV files and REST APIs, including in-house systems.

    Built by people who have run these programmes

    QuartzIQ is designed by former Big-4 and GRC specialists to address the shortcomings of legacy offers.

    Framework and policy management

    Inter-framework requirement mappings, guided framework upgrades and migrations, and tracking of control delegation, outsourcing and mutualisation.

    Third-party and supplier risk

    Tailored workflows, custom scoring and remediation tracking for vendors, suppliers and partners.

    Collaboration and evidence gathering

    Custom questionnaires, surveys, risk assessments, certification and secure data exchange.

    Azure-based architecture

    Reviewed and certified by Microsoft Azure architects, for scalability and standards compatibility.

    SOC-2 Type II, audited by BDO

    Attesting to the security of the platform and the controls around its operation and governance.

    Deploy where you have to

    SaaS, private cloud, hybrid or on-premise, with SSO over SAML and multi-IdP, and log export to your SIEM.

    Frequently asked questions

    Trusted by

    FirstLight
    PSP Investments

    See QuartzIQ against your own framework

    A walkthrough using your risk taxonomy, perimeters and control inventory, rather than a generic demo environment.

    Or contact us directly: +1 888.526.1830

    Security and compliance

    • SOC 2 Type IIAudited by Sensiba LLP.
    • ISO/IEC 27001Certified by Sensiba LLP, an ANAB-accredited certification body.
    • GDPRCompliant with the EU General Data Protection Regulation.
    • PIPEDAReady for Canada's Personal Information Protection and Electronic Documents Act.

    Reports available upon request