You are on CAQA GRC
CAQA GRC - Part of CAQA GroupsCall 1800 266 160  |  info@caqa.com.au
The Register Matrix

Platform modules

Every module below is a register with an owner, a review rhythm and an evidence trail. Together they are the one place your organisation's governance actually lives.

Governance

The Governance module holds the instruments that give your organisation its shape: constitutions, charters, terms of reference, delegations of authority and committee structures. Decisions are minuted against the authority they were made under, so every resolution traces back to the power that allowed it.

  • Charters, terms of reference and delegations in one controlled register
  • Decision and resolution records linked to the delegating authority
  • Conflict-of-interest declarations kept alongside the meetings they touch

Risk

The Risk module keeps the enterprise risk register living rather than annual. Risks carry named owners, likelihood and consequence ratings, treatments and review dates — and roll up against the risk appetite the board has actually set.

  • Enterprise and operational risk registers with owner accountability
  • Appetite and tolerance statements the register reports against
  • Treatment plans with progress that is visible, not asserted

  Running a mature ERM program? Step up to CAQA Risk, the dedicated risk platform — it shares this register's discipline with deeper workspaces for risk owners.

Compliance

The Compliance module turns "are we compliant?" into a question with an evidence-backed answer. Requirements from legislation, standards and funding agreements are tracked to a status, an owner and the artefacts that prove it.

  • Compliance status by framework, area and owner
  • Attestations and evidence held against each requirement
  • Findings and corrective actions tracked to closure

  Managing detailed frameworks obligation-by-obligation? Step up to CAQA Compliance, the dedicated compliance platform.

Controls

The Controls module is the library of what actually keeps risk inside appetite. Each control records its design, its operator, the risks and obligations it serves, and a testing schedule — so control effectiveness is measured, not presumed.

  • A single control library mapped to risks and obligations
  • Design and operating-effectiveness testing on a schedule
  • Failed tests raise actions automatically, with owners and dates

Internal audit

The Internal audit module carries the audit cycle from plan to closed finding: scoping, fieldwork notes, findings, recommendations and management responses, all against the registers the rest of the platform already maintains.

  • Audit plans and engagements linked to risks and controls
  • Findings and recommendations with owners and due dates
  • Follow-up that keeps agreed actions honest

  Running a full annual audit program with working papers? Step up to CAQA Audit, the dedicated internal audit platform.

Incidents

The Incidents module captures what went wrong — and what nearly did — while it is still fresh. Incidents are triaged by severity, investigated to root cause and closed with corrective actions that feed back into risks and controls.

  • Simple capture for incidents, near misses and hazards
  • Severity triage, investigation and root-cause records
  • Corrective actions linked back to the controls that should have held

  Handling steady incident volumes with response workflows? Step up to CAQA Incidents, the dedicated incident platform.

Policies

The Policies module keeps one controlled policy library: current versions, owners, review dates and the approval trail behind each document. Staff acknowledgement is recorded, so "everyone has read it" is a report, not a hope.

  • One library of current, approved policy versions
  • Review cycles and approval trails on every document
  • Staff acknowledgement tracked by policy and role

  Need full lifecycle drafting, versioning and attestation campaigns? Step up to CAQA Policies, the dedicated policy platform.

Obligations

The Obligations module is the register of everything your organisation has promised — to regulators, funders, contract partners and its own board. Each obligation carries a source, an owner, a due rhythm and the evidence that it was met.

  • Obligations drawn from legislation, contracts and funding conditions
  • Owners and due dates that surface in worklists, not memories
  • Evidence of discharge held against each obligation

Assurance

The Assurance module maps who checks what — management reviews, compliance monitoring and independent audit — across the three lines. Coverage and gaps become visible on one map instead of being argued from anecdote.

  • An assurance map across management, oversight and independent lines
  • Assurance activities scheduled and recorded against risks and controls
  • Coverage gaps surfaced before the board asks about them

Board reporting

The Board reporting module assembles packs from the live registers — risk movements, compliance status, incident themes, audit progress and KRI trends — so the board reads the same truth management works from, days earlier.

  • Board and committee packs built from live register data
  • Narratives alongside the numbers, with drill-through to evidence
  • A standing record of what each meeting was told, and when

Key risk indicators

The Key risk indicators module watches the metrics that move before risks do. Each KRI carries thresholds and tolerances tied to appetite; breaches alert the risk owner while there is still time to act rather than explain.

  • KRIs linked to the risks and appetite statements they signal
  • Thresholds and tolerances with alerting on breach
  • Trend views that make slow drift as visible as sudden spikes

Regulatory reporting

The Regulatory reporting module keeps regulator returns and lodgements on rails: what is due, to whom, by when, who is preparing it and what was actually submitted. The lodgement record becomes part of the same register as everything else.

  • A calendar of returns and lodgements with named preparers
  • Submission records and acknowledgements retained as evidence
  • Late-risk visibility well before a deadline becomes a breach

Walk the registers with us.

A walkthrough takes your own framework — not a demo dataset — and shows how the modules carry it.

Book a Walkthrough

Newsletter Subscription

To Receive Updates And Offers