Your organisation reviewed on the risk themes that matter now .

The ONE Risk Health Check reviews your organisation in three weeks on the risk themes that matter now: AI-powered and senior-judged, at a fixed price, with a scorecard you can act on immediately. From cyber resilience to AI governance and supply-chain continuity, each theme assessed against the relevant framework (NIS 2, EU AI Act, DORA, ISO, COSO ERM).

// 01When relevant

When is a Risk Health Check useful?

When you, as a board member, CFO or CRO, want to know where your organisation stands on the risks that matter now, without immediately setting up a large programme. Cyber has topped the international risk rankings for the fifth year running, AI governance is the fastest riser and in the Netherlands business interruption including supply chain is even the number one risk.

  • When the supervisory board or audit committee asks where you stand on cyber, AI or supply-chain dependencies
  • For a new board member, CFO or CRO who quickly wants an independent view
  • When supervisory pressure (DNB, AFM, ECB, DORA) requires demonstrable insight
  • As a baseline before you invest in control or start a programme
// 02Our approach

From intake to boardroom readout in five steps

A fixed, repeatable approach per theme: AI does the heavy lifting, a senior specialist reviews and signs off.

  1. Intake (workshop, 2 hours): theme selection and scoping
  2. Document study with AI analysis: your policies, procedures and registers assessed against the framework per theme
  3. In-depth interviews: 2 to 4 conversations per theme, deliberately including the first line
  4. Reporting: a scorecard per theme, a risk radar across the whole and a 90-day roadmap
  5. Boardroom readout: discussion with the board or executive team

No AI finding reaches you without review by a senior specialist.

// 03What does it deliver

What does it deliver?

A scorecard you can act on immediately.

  • A maturity score per theme with evidence and recommendations
  • A risk radar that makes all reviewed themes comparable
  • A prioritised 90-day roadmap with effort and impact
  • A basis for a repeat measurement after twelve months that makes your progress visible
// 05Frequently asked questions

Frequently asked questions

Which themes does the Risk Health Check cover?

The core themes are cyber resilience, AI governance and operational continuity including supply chain. For financial institutions, DORA and financial-economic crime are added. Additional themes, such as geopolitical resilience, risk culture or privacy, can be added as extra modules.

Which packages are there and how long does it take?

Three packages: Focus (one theme, in depth, two weeks), Core (three themes with a risk radar, three to four weeks) and 360 (five to six themes with a benchmark and an extended board readout, five to six weeks). Each package has a fixed price, known to you in advance.

What do you assess against?

Per theme against the relevant framework: NIS 2 and ISO 27001 for cyber, the EU AI Act and NIST AI RMF for AI governance, DORA for digital resilience of financial institutions, and COSO ERM and ISO 31000 for the overarching risk picture.

Is it an audit or a formal assurance report?

No. The Risk Health Check is an independent diagnosis, not an assurance opinion. You receive a scorecard with findings and a roadmap you can act on immediately.

What happens after the review?

You decide the follow-up: a deep dive per theme, support with the roadmap, or a repeat measurement after twelve months that makes progress visible. The review is not a disguised pre-sale of implementation work.

Start with a Risk Health Check.

A first conversation is quickly arranged. We discuss which themes take priority for your organisation.

Schedule a Risk Health Check