12 applications.
The enterprise risk backbone.

From Monte Carlo economic capital modeling to SCADA anomaly detection to SR 11-7 model risk management — GRC Core covers every dimension of enterprise risk, compliance, and operational safety.

12Applications
42+Embedded AI Agents
50+Compliance Frameworks
SHA-256Evidence Integrity

Every GRC discipline. Every risk domain.

Enterprise Risk Management (ERM)

4-Factor Scoring · Monte Carlo · Basel III

Unified risk registry with 4-factor scoring (Severity, Likelihood, Vulnerability, Speed of Impact). 3-step approval lifecycle, inherent/residual heat maps, Monte Carlo Economic Capital modeling, 6-step treatment plan workflow, and 12-month net loss trending.

Agents: Risk Scoring · Correlation · KRI Monitoring

Regulatory Reporting (RegRPT)

PHMSA · EPA · State Agencies

Centralized filing calendar with Calendar/Grid/Timeline tri-view, automated instance creation, AI-powered 7-rule-type validation agent, $266k/day penalty exposure calculator, Industry Pack system, SFTP/REST/Webhook scheduled imports, and Enterprise Copilot.

Agents: Filing Compiler · Validation · Penalty Calculator

Operational Risk — Petroleum & Gas (OpRisk P&G)

API RP 754 · SCADA · LDAR · MOC

API RP 754 PSE tracking (Tier 1–4), daily production monitoring with >15% deviation flagging, SCADA telemetry with BRIN indexing, pipeline integrity (API 580/581), LDAR emissions (NSPS OOOOa), MOC with PHA/HAZOP/What-If reviews, and 6-axis Risk Compass scorecard.

Agents: SCADA Anomaly · Production Optimization · Predictive Integrity · PSE Analysis

Information Security (InfoSec)

NIST CSF 2.0 · ISO 27001 · CIS v8

NIST CSF 2.0, ISO 27001, GDPR, and CIS Controls v8 alignment. CVSS/EPSS/Asset Criticality weighted vulnerability prioritization, 5-dimension security posture scoring, access reviews with SOD/dormant account auto-flagging, and 15-minute CVE/IOC threat detection.

Agents: Incident Response Orchestrator · Threat Detection · Compliance Scanner

Third-Party Risk Management (TPRM)

Security 30% · Financial 25% · Compliance 20%

Unified Vendor Registry with multi-dimensional weighted scoring: Security 30%, Financial 25%, Compliance 20%, Operational 15%, ESG 10%. AI-driven monitoring, performance tracking, and full lifecycle governance.

Agents: Vendor Risk Scoring · Monitoring · Performance

Model Risk Management (MRM)

SR 11-7 · OCC 2011-12

SR 11-7 / OCC 2011-12 aligned. 9-factor weighted risk tiering (Tier 1–4), quantitative testing (KS statistic, Gini coefficient, PSI, backtesting), weekly drift detection (PSI thresholds), and documentation completeness monitoring (50% threshold alerts).

Agents: Model Drift Detection · Performance · Documentation

Business Continuity & Disaster Recovery (BCP/DR)

Tabletop · RTO/RPO · Recovery Agents

Tabletop Exercise Agent for Cyber, Natural Disaster, Pandemic, and Vendor Failure scenarios. Recovery Orchestration Agent for communication cascades and system recovery sequencing. Dependency mapping (processes → systems → vendors) with RTO/RPO validation.

Agents: Tabletop Exercise · Recovery Orchestration

Internal Audit (AUD)

SOX · ISO · NIST Aligned

Full audit lifecycle from planning through fieldwork, reporting, and follow-up. Control testing with SHA-256 evidence integrity hashing. Framework-aligned audit plans for SOX, ISO, and NIST. Issue tracking with remediation workflows and escalation management.

Agents: Audit Planning · Evidence Collection · Finding Analysis

HR Service Delivery (HRSD)

Cross-Module Onboarding/Offboarding

Onboarding and offboarding workflows that automatically trigger cross-module tasks — WSD workspace provisioning, ITSM equipment requests, and InfoSec access task creation — all from a single HRSD event.

Agents: Onboarding Orchestrator · Offboarding Coordinator

Customer Service Management (CSM)

Case Management · Field Escalation

Case management with intelligent field service escalation. CSM cases requiring on-site visits automatically generate FSM work orders, update CSM records, and trigger customer satisfaction surveys on resolution.

Agents: Case Routing · Escalation · Satisfaction

Field Service Management (FSM)

Work Orders · CSM/SOM Integration

Work order management natively linked to CSM and SOM. FSM work orders sync bidirectionally with CSM case status and connect to SOM deal data for customer context throughout the service delivery lifecycle.

Agents: Work Order Optimization · Scheduling

Sales & Order Management (SOM)

Pipeline → CSM Onboarding Chain

Pipeline and deal management with a closed-won trigger that automatically creates a CSM onboarding case, initiates WSD workspace setup, and generates ITSM equipment requests — zero manual handoffs from sales to operations.

Agents: Deal Analysis · Onboarding Orchestration

50+ frameworks. Pre-mapped. Ready on day one.

Every framework ships with pre-configured controls, automated tests, and evidence templates — no expensive professional services to get started.

NIST CSF 2.0
NIST 800-53
ISO 27001:2022
ISO 27002
ISO 31000
COBIT 2019
SOX/ICFR
COSO
PCI DSS v4.0
HIPAA
GDPR
CCPA/CPRA
LGPD
PIPEDA
DORA
EU AI Act
NERC CIP
FERC
FedRAMP
FISMA
CMMC 2.0
DFARS
ITAR
FDA 21 CFR
GxP
Basel III
BSA/AML
FFIEC
SR 11-7
OCC 2011-12
API RP 754
OSHA PSM
PHMSA
EPA Subpart W
NSPS OOOOa
SOC 2
SOC 1
ISO 9001
ISO 14001
ISO 45001
TCFD
GRI Standards
SASB
NAIC
Solvency II
FERPA
Title IX
Clery Act
GLBA
FCRA

See GRC Core in action

Watch how Remedy's GRC applications and agents work together to deliver always-on enterprise risk management.

Book a GRC Demo