A risk register that lives in your operating system
Risks, controls and reviews on hardware you own, drawn from the Open Audit Record and joined to the rest of the business. No certification claimed.

A risk register on MICKAI lives inside your operating system, on hardware you own, next to the work it describes. The risk studio holds your risks, your controls and your reviews, and it draws its evidence from the Open Audit Record that the rest of the platform is already writing. You are not maintaining a spreadsheet that drifts away from reality. The register sits on the same machines as the business it governs.
That is the difference. Most risk tools are a separate place you go to describe what is happening somewhere else. Ours is joined to the thing itself, so a control can point at the actual events that prove it works, on your own system, with nothing sent out to a vendor to hold on your behalf.
What the risk studio does
The risk studio is a live register of the things that could go wrong, the controls you have put in place against them, and the reviews that check those controls are still doing their job.
You record a risk with an owner, a likelihood and an impact, and the studio scores it and places it on a heat map. You attach controls, mark them as designed, in place or overdue, and set the cadence at which they get reviewed. When a review falls due the assistant raises it, gathers the evidence and walks the owner through it. The register updates as the business changes rather than once a year when someone remembers.
The work happens on your hardware. The scoring, the reminders, the reporting and the assistant all run locally. There is no round trip to a vendor cloud, because the studio and the evidence are in the same building on the same machines.
Controls that point at evidence, not claims
A control is only worth the evidence behind it. On most systems that evidence is a document someone uploaded and a date someone typed. It says the control was tested. It does not show the testing.
This is where running everything on one operating system pays off. Every meaningful action across the platform is written to the Open Audit Record on your own hardware, at the level of the action rather than a vague access log. Who opened which file. Who approved which payment. Who changed which permission, and when. The risk studio reads that record directly, so a control can be tied to the events that actually demonstrate it.
Take a control that says privileged access is reviewed every quarter. Instead of a note claiming it happened, the studio can point at the record of the review being run, the access that was checked and the changes that followed, drawn straight from the audit trail rather than retyped into a form. Take a control over payment approvals. The register can show the approvals themselves, from the finance studio, with the audit record standing behind each one.
The evidence is not assembled after the fact to satisfy a question. It is a byproduct of the work, captured as the work happens, sitting in a store you own.
Where the risk picture comes from
A register is only as good as the data it can reach. Your email system holds correspondence and the record of what was agreed. Your meetings platform holds decisions. Your document store holds contracts and policies. Your CRM holds customer commitments. Your team management holds who has access to what.
On most stacks these live in separate products from separate vendors, and building a single risk picture means chasing exports and hoping the join is clean. On MICKAI they are studios on one operating system, sharing one data layer the company owns. The risk studio reads across them. A risk about a key supplier can pull the contract terms from the document store, the recent correspondence from email and the payment history from finance, without a single export, because they all sit in the same store. The assistant is the same assistant across every studio, so it already understands the shape of your business.
That shared foundation is why the register stays live. It is a view onto work the rest of the business is already doing, not a parallel record you have to keep in step by hand.
Reviews that hold themselves
Reviews are where risk management usually decays. The register is built with good intentions and then the review dates slip, the controls go stale, and by the time anyone looks again the document describes a company that no longer exists.
The risk studio treats reviews as a running process. The assistant tracks the cadence for every control, raises the review when it is due, collects the supporting evidence from the audit record and the other studios, and puts it in front of the owner to sign off. What was reviewed, by whom, and on what basis is itself written to the Open Audit Record. So the act of governing the business is governed too, and you can show not just the current state of a control but the history of it being checked.
For a regulated firm this is the difference between hoping you can answer a question from your auditor and being able to show them the trail. You are not reconstructing what happened. You are reading it.
Compliance, without a claim we cannot make
The register connects to the compliance work a regulated firm has to do. Controls can be mapped to the obligations they satisfy, and the evidence behind each one is there to be shown. When a client or an auditor asks how you manage a particular risk, you can produce the register, the controls, the review history and the underlying record in one place.
We are precise about what this is and is not. The risk studio helps you run your own risk work well and evidence it clearly. It does not grant a certification and it does not represent one. We hold no certifications and we claim none, neither as held nor as in progress. What the studio gives you is your own house in order, on your own hardware, in a form you can stand behind.
Why keeping risk in-house matters
Your risk register is a map of your own weaknesses. It names what could hurt you and where your controls are thin. That is precisely the document you least want sitting in someone else's cloud.
Private deployment where the vendor cannot see your data is the baseline we start from. We go past it. The risk studio is air-gapped by default, so the record of your vulnerabilities lives on machines that are not reaching out to anyone. There is no vendor with a copy of your weak points. There is no telemetry describing what you are worried about. The whole picture, the thing that would be most useful to an attacker or a rival, never leaves the building in the first place.
The cost of renting governance
Cloud governance, risk and compliance software is sold per user per month, and the published prices add up. Where a mid-market GRC seat is listed at, say, 30 US dollars per user per month, a firm putting 40 people in front of it pays 40 times 30 times 12, which is 14,400 US dollars a year, every year, for the licences alone. Scale it to 100 users and the same arithmetic gives 36,000 US dollars a year. These figures use a stated list price and a flat headcount assumption set out here so you can check them; your real number depends on your seat count and tier.
That is a recurring rent to keep a record of your own risks. And it usually sits on top of the separate per-seat bills for the email, the documents and the finance tools that hold the evidence in the first place, each from a different vendor, each with its own annual increase.
We do not publish our pricing, and this is not a price comparison of us against them. The point is structural. When the risk studio is part of an operating system you run on hardware you own, you are not paying a per-seat rent to describe your own exposures, and the evidence it needs is already there in the audit record you own.
One assistant, one operating system
The assistant in the risk studio is the same assistant you use everywhere else. Ask it in the finance studio whether a large payment fits your approval controls and it can check the register. Ask it in the risk studio what evidence stands behind a control and it can reach into the audit record and the other studios to show you. It is not a chatbot bolted onto a form. It is the operating system's assistant, and risk management is one of the things it can do because it can see, with your permission and on your hardware, the record the rest of the business is writing.
This is the shape of the whole product. MICKAI is the sovereign operating system a company runs on, spanning 87 studios, not a model you integrate into a stack you already rent. It rests on 104 filed UK patent applications covering 2,340 claims. Clients onboard onto an initial focused set of studios and grow from there. The risk studio is one among them, and it earns its place by drawing on the rest.
Your risks are made in your building. They should be recorded there too.
FAQ
Where does the risk studio get its evidence? From the Open Audit Record and the other studios on the same operating system. Every action across email, meetings, documents and the rest is recorded on your own hardware, so a control can point at the actual events that show it is working rather than at a claim in a spreadsheet.
Does any of our risk data leave the building? No. The risk studio runs on hardware you own and is air-gapped by default. The register, the controls, the reviews and the assistant all execute locally. Nothing about your risks or your weaknesses is sent to a vendor cloud.
Does this give us a certification? No. The risk studio helps you run a register, track controls and hold reviews. It does not grant or represent any certification. We hold none and claim none. What you get is a clear, evidenced record of your own risk work that you can put in front of an auditor or a client.
How is this different from a cloud GRC tool? Cloud governance, risk and compliance tools hold your register and your control evidence in the vendor's environment. Ours keeps all of it on hardware you own, and it draws evidence directly from the Open Audit Record rather than from documents someone uploaded. You own the data, the software and the trail.
Is this built for large enterprises only? No. It is built for the regulated small and mid-sized firm that has to manage risk seriously but cannot staff a full risk function. The assistant does the heavy lifting, so a small team can keep a live register without a dedicated department.
Is this one of many studios? Yes. The platform spans 87 studios on one sovereign operating system with one assistant across all of them. Clients onboard onto an initial focused set, and the risk studio draws on whichever studios hold the relevant evidence.
Frequently asked questions
Where does the risk studio get its evidence?
From the Open Audit Record and the other studios on the same operating system. Every action across email, meetings, documents and the rest is recorded on your own hardware, so a control can point at the actual events that show it is working rather than at a claim in a spreadsheet.
Does any of our risk data leave the building?
No. The risk studio runs on hardware you own and is air-gapped by default. The register, the controls, the reviews and the assistant all execute locally. Nothing about your risks or your weaknesses is sent to a vendor cloud.
Does this give us a certification?
No. The risk studio helps you run a register, track controls and hold reviews. It does not grant or represent any certification. We hold none and claim none. What you get is a clear, evidenced record of your own risk work that you can put in front of an auditor or a client.
How is this different from a cloud GRC tool?
Cloud governance, risk and compliance tools hold your register and your control evidence in the vendor's environment. Ours keeps all of it on hardware you own, and it draws evidence directly from the Open Audit Record rather than from documents someone uploaded. You own the data, the software and the trail.
Is this built for large enterprises only?
No. It is built for the regulated small and mid-sized firm that has to manage risk seriously but cannot staff a full risk function. The assistant does the heavy lifting, so a small team can keep a live register without a dedicated department.
Is this one of many studios?
Yes. The platform spans 87 studios on one sovereign operating system with one assistant across all of them. Clients onboard onto an initial focused set, and the risk studio draws on whichever studios hold the relevant evidence.