Risk + compliance,
on one screen.

AI-grounded risk register, obligations tracker, controls library, and document analysis — built for Australian operators. TCFD-aligned disclosures, ASX CGP 4th Edition, NGER Act + Determination shipped pre-loaded. Hosted in Australia.

TCFD/ISSB · ASX CGP 4th Edition · NGER Act + Determination

Operators juggle dozens of compliance obligations across Federal, State, and industry frameworks. Spreadsheets break. Things slip. Regulators notice.

Fragmented registers

Obligations in spreadsheets, risks in one system, controls in another. No single source of truth. Audit season is a scramble.

Regulatory change blindness

New legislation drops, amendments take effect, your register doesn't update. You find out from the regulator, not before.

Board reporting burden

Assembling ESG reports takes weeks. Data from five different systems, manual consolidation, no confidence in the numbers.

Everything in one platform

From risk identification to board reporting — VigilRisk replaces spreadsheets, fragmented tools, and guesswork.

Risk Register

Likelihood × impact heatmap, E/S/G pillar views, and AI-powered document analysis that maps evidence to risks. Mandatory control linkage and an immutable hash-chained audit trail.

Obligations Register

Track every compliance requirement from environmental approvals to NGER reporting. Assessment history, evidence linking, and compliance status dashboard.

Control Library

Reusable control templates (Preventive, Detective, Corrective) mapped to risks and obligations. Track effectiveness and testing dates.

Ask VIGIL AI

Context-aware compliance assistant that knows your entire register. Ask about obligations, draft controls, check framework requirements — instant, accurate answers.

Workshops

Structured risk workshops with AI-generated briefing packs, participant voting, decision tracking, and auto-generated minutes.

Regulatory Scanning

AI monitors legislative changes across Federal, State, and industry frameworks. Flags affected obligations for review before you hear from the regulator.

Built for Australian operators

The platform ships with the publicly-licensed Australian frameworks below pre-loaded. Bring your own additional PDFs and the AI generates obligations from them on import.

TCFDASX CGP 4th Ed.NGER Act + Determination
· TCFD-aligned disclosures ·· ASX CGP 4th Edition ·· NGER Act + Determination ·· AI-generated obligations ·

Three steps to full visibility

1

Subscribe to frameworks

Pick the standards and legislation that apply — the platform ships with TCFD, ASX CGP, and NGER pre-loaded, and accepts your own PDFs to extend the corpus.

2

Generate obligations

Ask VIGIL reads each framework and produces specific obligations with clause references and owners. You verify before publishing into your register.

3

Run the register

Risks with E/S/G pillars, controls mapped to obligations, document evidence linked, workshops, regulatory change scanning. Export reports without the spreadsheet rebuild.

Simple, transparent pricing

Two plans. Same feature surface — Operator+ adds room to grow on storage and AI usage. Prices in AUD, GST added at checkout.

Operator
$1,990/mo
$19,900 /yr with annual billing
  • 2M AI tokens / mo
  • 50 GB document storage
  • Unlimited risks
  • Unlimited documents
  • Unlimited users
  • Risk + obligations register
  • Framework library
  • Workshops + AI briefings
  • AskVigil RAG + document analysis
  • Regulatory change scanning
  • Microsoft Entra SSO
Get started
Most Popular
Operator+
$4,490/mo
$44,900 /yr with annual billing
  • 10M AI tokens / mo
  • 250 GB document storage
  • Unlimited risks
  • Unlimited documents
  • Unlimited users
  • Risk + obligations register
  • Framework library
  • Workshops + AI briefings
  • AskVigil RAG + document analysis
  • Regulatory change scanning
  • Microsoft Entra SSO
Get started

Built on industry standards

TCFD-aligned disclosuresASX CGP 4th EditionNGER Act + DeterminationAI-generated obligations

Frequently asked

The short version of what buyers ask before they sign up.

What does VigilRisk replace?

Spreadsheets and ad-hoc registers — risks, obligations, controls, evidence, and the audit trail behind them. The frameworks library, AskVigil RAG, and regulatory change scanning replace the manual cross-referencing work that usually sits with a single GRC lead.

Is VigilRisk hosted in Australia?

Yes. The platform runs on Azure Container Apps in Australia East, with per-tenant Postgres flexible servers in the same region. Data residency is non-negotiable; we do not move tenant data offshore.

Which frameworks ship pre-loaded?

TCFD (Final Report 2017), ASX Corporate Governance Principles 4th Edition, and the NGER Act + Determination. You can add your own framework PDFs and the AI will generate obligations from them on import.

How does the risk register work in practice?

Risks are scored on a likelihood × impact heatmap with E/S/G pillars, mandatory control linkage, and an immutable hash-chained audit trail. Obligations are tracked with evidence-based assessments and link back to the controls that satisfy them. The workflow follows widely-used industry methodology without redistributing any paywalled standards.

How are AI features priced?

Each plan includes a monthly AI token allowance (2M on Operator, 10M on Operator+). Tokens cover document analysis, AskVigil chat, and obligation generation. Usage shows in-app and is reset monthly. Going over the allowance shows a soft warning rather than hard-blocking.

Can multiple legal entities share one workspace?

Each legal entity should run as its own VigilRisk tenant for clean data residency and audit boundaries. Operator+ adds a consolidated read-only view across related tenants — see the Group feature in /app/admin/group.

How does single sign-on work?

Microsoft Entra (Azure AD) SSO is included on every plan. Each tenant can scope sign-in to one or more email domains; new users are auto-created as Viewer on first sign-in. SAML / OIDC for non-Microsoft IdPs is on the roadmap.

What does cancellation look like?

Cancel at any time from Settings → Billing. Access continues to the end of the current billing period. After 30 days we hard-delete tenant data; you can request a JSON export before then.

Ready to see everything?

Book a 15-minute demo and see how VigilRisk handles your compliance obligations end-to-end.