
Risk Ledger
Continuous, collective third-party risk management on a shared supplier network
By Risk Ledger · HQ London, United Kingdom · 4.0/5 Value-Position score (estimate)
Positioning guardrails
Best for
- Security and procurement teams that need continuous, evidence-based assurance across hundreds or thousands of suppliers
- Organisations replacing manual, spreadsheet-driven supplier security questionnaires
- Regulated firms in financial services, healthcare and critical infrastructure that must evidence third-party controls
- Buyers who want network effects: reuse suppliers' existing profiles instead of re-assessing from scratch
- Teams that need to see fourth-, fifth- and nth-party dependencies and concentration risk
Ideal size: 5+ person security or GRC team people · Established security, risk or procurement function running a supplier assurance programme
Not for
- Companies seeking a lightweight, self-serve tool with published per-seat pricing
- Teams with no appetite to onboard suppliers onto a shared industry network
- Organisations that need bespoke on-site audit fieldwork rather than standardised assessments
- Very small businesses managing only a handful of vendors
Value metrics scorecard
Time-to-Value
~30 days (estimate)
~30 days to first production value
Total Cost of Ownership
On request
Quote-based enterprise pricing; no public price list. Sales-led, demo-first motion.
Implementation Friction
3/5
Engineering + admin effort required
Value-Position score
out of 5 · model estimate
Full cost breakdown
Mandatory implementation fee
None
Seat tiers
Not published
Add-on costs
- Operational Technology (OT/ICS) assessment add-on domain - pricing not published
Company & support
Who is behind Risk Ledger, and how your team gets help once it is live.
Company
- Founded
- 2018 · 8 yrs in business
- Headquarters
- London, United Kingdom
How you get support
- PhoneNot listed
- EmailPlan not stated
- Live chatPlan not stated
- Support portal / ticketsNot listed
- Community forumNot listed
- Help centre / docsPlan not stated
- Dedicated account managerPlan not stated
- In person / on-siteNot listed
- Hours
- Not recorded
- Response time
- Not stated
Help Centre, FAQs and assessment framework guides are self-serve; live chat is listed for general inquiries. [email protected] and a Customer Success Manager route are used for account and feature requests.
“Not listed” means the vendor’s public pages don’t mention that channel, not that it is unavailable. Ask about it during evaluation.
Market position
Where Risk Ledger sits against its closest alternatives. Pick any two of cost, speed, friction and buyer score, and up to 9 companies to compare.
Quadrant view
Typical annual cost × Time-to-value
The lines cross at the median of the solutions shown, so about half sit on each side of each line.
Companies on the chart 6 / 10
- Risk Ledger
- Sysdig
- Datto
- RegScale
- Hyperproof
- Endor Labs
Add or change companies
Up to 10 companies including Risk Ledger. Listed closest first.
Stack fit signal
Compatibility with standard B2B ecosystems.
No supported MCP path today, so it cannot be driven from an AI client.
AI & MCP readiness
What Risk Ledger ships in AI, and what it asks of your ecosystem.
AI features shipped
Changelog documents an AI-generated Supplier Summary (risk posture, compliance detail, suggested next steps) and Auto Suggest, which helps suppliers complete assessments using an AI model upgraded from Claude Haiku 3.5 to Claude Haiku 4.5.
Your data & models
- Trains on your data
- Not recorded — ask the vendor
- Runs on
- Anthropic
- AI pricing
- Not recorded
In your ecosystem
- AI connection
- Not supported
- Model key
- Not recorded
- AI usage audit
- Not recorded
Compliance attestations
* IAPP AIGP certifies individuals, not products. It means named staff hold the credential — not that the platform does.
Bottom line
Risk Ledger is a London-based third-party risk management platform built as a shared supplier network. Over 19,000 suppliers already hold standardised security profiles, so clients connect and review evidence instead of chasing questionnaires. It adds continuous risk signals, supply-chain mapping for concentration risk, emerging-threat tracking and ISO 27001/Cyber Essentials controls. AI supplier summaries and Auto Suggest speed up reviews. Pricing is quote-based with no public price list; best for security and procurement teams running large regulated supplier estates.
Frequently asked questions
How long does it take to see value?
Risk Ledger runs on a shared network, so if your suppliers are among the 19,000+ already on the platform you can connect and view their security profile immediately rather than waiting for a fresh questionnaire. Suppliers who are not yet on the network are invited to complete one standardised assessment. The vendor publishes no implementation timeline, so a first-value estimate of roughly four weeks is an assumption, not a vendor figure.
Is pricing published?
No. Risk Ledger does not publish a price list or seat tiers; the site directs buyers to book a demo or talk to sales, and support for premium features such as Supplier Summaries is arranged through your Customer Success Manager. Treat any annual cost figure as quote-based until you have a formal proposal.
How does Risk Ledger protect the data we put in it?
The security profile page states that data is encrypted in transit over TLS/SSL (A+ on Qualys SSL Labs) and at rest with AES-256, that multi-factor authentication is mandatory for platform users and staff, and that services run on hardened AWS infrastructure across two availability zones. The vendor also states it undergoes regular third-party penetration testing and maintains ISO 27001 and Cyber Essentials compliance.
What AI does Risk Ledger use, and is our data used to train models?
The changelog documents an AI-generated Supplier Summary of a supplier's risk posture and Auto Suggest, which helps suppliers complete assessments and was upgraded to Claude Haiku 4.5. Risk Ledger does not state publicly whether customer data or content is used to train or improve models, so that question should be put to the vendor directly.
Which industries does Risk Ledger target?
Its communities and case studies point to financial services, insurance, public sector and critical national infrastructure, technology, and healthcare - including work with NHS Test and Trace. Infrastructure and utility customers such as Anglian Water and United Utilities appear in published case studies.
What support is available?
There is a self-serve Help Centre, FAQs and assessment framework guides, a live chat option, and a support email address ([email protected]). Customers also work with a named Customer Success Manager for enablement and feature access. The site does not publish support hours or a response-time SLA.