RISK INSIGHT - AI-Powered Enterprise Risk Management Platform
AI Tool Basics for CA

RISK INSIGHT - AI-Powered Enterprise Risk Management Platform

Author : CA Harshal Vibhakar Anjaria

Watch on Youtube

1. Problem Statement

SEBI LODR mandates structured risk governance for listed entities, yet no affordable implementation tool exists for Indian SMEs, mid-caps, and unlisted promoter-driven groups. Existing practice relies on disconnected Excel sheets and Word memos — manual, time-consuming (3–4 days per quarter), audit-fragile, and devoid of decision-grade analytics. Enterprise GRC(Governance, Risk and Compliance) suites cost between ₹25–80 lakh per annum and need 6–9 months to deploy, creating a structural accessibility gap.


2. Solution Overview

Risk Insight is a single-file HTML application that delivers a complete Enterprise Risk Management platform — risk register, dashboards, heat maps, period-on-period analytics, Board pack, and AI-generated narrative — with zero server, zero installation, and zero subscription. It runs entirely in the user’s browser, stores data privately in localStorage, and is deployable within 60 minutes.


3. Core Features

  1. Pre-loaded risk library: 80+ default risks across 7 categories (Strategic, Financial, Operational, Compliance, Reputational, Cyber & Data, ESG). Facility to add new category and change weight also available.


  1. 36 sector presets: CGD, Oil & Gas, Steel, Aluminium, Cement, Pharma, Banking, NBFC, Insurance, IT, SaaS, Auto, FMCG, Real Estate, Infra/EPC, and 21 more — each with sector-calibrated Likelyhood / Impact scores and tailored risk descriptions.


  1. Real-time dashboard: Composite Risk Index (0–100), 5×5 heat map, control-adequacy view, Top-10 risks, category-vs-appetite chart, governance scorecard, and seven categories of decision-flag alerts.


  1. AI Board narrative: Anthropic Claude AI generates an ready narrative commentary neatly calibrated to company, sector, period, and the actual Critical/High risks in the register.


  1. Governance controls: Optional password-protected period lock, read-only comparative-period snapshot, multi-company isolation, JSON backup/restore, and Google Sheets sync.


  1. One-click exports: Word Board Pack (.docx, in-built OOXML writer), Excel workbook (.xlsx, 4 sheets), print-to-PDF, and structured JSON for reviewer hand-off.


4. Technology Stack

LayerComponents

AI / LLMAnthropic Claude Sonnet 4.5. BYOK architecture — the user supplies their own API key, stored only in browser localStorage and transmitted directly to api.anthropic.com (no intermediate server). Deterministic template-based narrative is used as fallback when no key is configured.
Front-endSingle-file HTML/CSS/JavaScript (~9,400 LOC, vanilla JS, no framework, no build step). Themed via CSS variables with light/dark mode.
VisualisationChart.js 4.4.0 for radial gauge, control-adequacy and distribution charts. Hand-rolled SVG heat map and category-vs-appetite chart.
Document exportSheetJS (xlsx 0.18.5) for the Excel workbook export. In-house OOXML writer (custom ZIP + Word XML packer) for the .docx Board Pack — no docx library dependency.
PersistenceBrowser localStorage with per-company isolation (one key per entity). JSON export/import for backup, device migration, or sharing with a reviewer.
SecurityPeriod-lock password hashed with SHA-256 via Web Crypto API. 100% offline data flow (only the AI narrative call leaves the device, and only when the user clicks Generate).
IntegrationOptional Google Apps Script endpoint for one-click Google Sheets sync. No backend, no database, no vendor lock-in.


5. Methodology

  1. Workflow: Sector preset selection → score Likelihood × Impact × Control → AI processes residual exposure → Dashboard updates live → one-click Board pack.
  2. Scoring framework: Inherent Risk = Likelihood (1–5) × Impact (1–5) → 1–25 scale; bands are Critical ≥ 20, High ≥ 13, Medium ≥ 6, Low < 6. Residual Risk is adjusted for Control Adequacy (1–5). Composite Risk Index (CRI) is the weighted average across the seven categories, normalised to 0–100 using Board-approved weights. User can change the pre-coded L*I scores and control measures based on case to case basis applicable in their company.
  3. Period tracking: Lock-on-snapshot captures the current period as a read-only comparison base; rollover advances FY/Quarter while preserving the snapshot. The tool auto-classifies movement into Escalated, Worsened, Unchanged, and Improving — feeding directly into the Board narrative.
  4. Decision flags: Risks above appetite, critical without owner, near-due target dates, recently-escalated movements, and stale assessments are surfaced as colour-coded alerts so the Audit Committee sees the priority queue at a glance.


6. Differentiation

Risk Insight provides built-in compliance, automated narrative, real-time analytics, minimal cost, and full offline capability—unlike Excel-based methods or costly enterprise GRC tools.


7. Conclusion

Risk Insight converts risk reporting into a decision-support system, eliminating cost barriers and enabling structured governance for Indian corporates.