RiskOS: The AI-Powered Risk Operating Layer
RiskOS connects evidence, governed decisions and board reporting into one operating layer, so risk teams can show what changed and what was actually proven, not just what was recorded.
RiskOS is Acuity Risk Management’s AI-powered risk operating layer, launching November 2026. Most GRC and security work is rich in findings, tickets, controls and reports, but weak at proving the chain from an observation to a genuinely reduced risk. RiskOS is built to close that gap: it turns structured GRC work from STREAM Cloud or any GRC tool you use, supplier assurance evidence and other trusted sources into prioritised decisions, tracked actions and board-ready reporting, with AI that recommends and explains but never moves a risk position without evidence and human approval behind it.
Why RiskOS exists
- AI is automating attacks: as AI-driven attackers find gaps faster than manual review can catch them, defending at the same pace means harnessing AI to orchestrate your cyber defence, not just report on it.
- Policy and reality drift apart: what your policies say should happen and how your critical business systems are actually configured pull apart over time, and closing that gap is central to what RiskOS does.
- Decisions still require manual synthesis: teams spend real time turning raw data into priorities, escalations and board-ready narrative, rather than acting on it.
Where RiskOS fits in Acuity’s product strategy
RiskOS is an additional layer, not a replacement. Acuity’s STREAM Cloud and STREAM Classic remain the guided workspace for GRC work itself: risks, controls, policies, evidence and actions. Vendor Management Hub remains the workspace for supplier assurance. RiskOS sits above both, turning that structured work, plus other trusted sources, into prioritised decisions and reporting.
| STREAM Cloud / STREAM Classic | The guided workspace for GRC work: risks, controls, policies, evidence, actions and audit history. |
| Vendor Management Hub | The workspace for supplier and third-party assurance: questionnaires, evidence and remediation. |
| RiskOS | The operating layer above both: turns their evidence into prioritised decisions, tracked actions and board-ready reporting. |
What RiskOS is designed to do
- Anchors risk to the business-critical services an organisation actually runs, rather than a generic technical inventory.
- Turns evidence (from STREAM Cloud, supplier assurance and other connected sources) into a risk position that only changes with evidence and human approval behind it.
- Keeps what is known, unknown, improving or unverified visibly distinct, rather than blending everything into one score.
- Turns identified gaps into prioritised, owned actions rather than a static findings list.
- Produces a recurring, board-ready view of what changed, what needs a decision, and what has genuinely been proven, not just reported as complete.
- Is designed to work alongside STREAM and other trusted sources rather than lock an organisation into a single closed system.
What it isn’t
RiskOS is not positioned as a replacement for STREAM Cloud, STREAM Classic or Vendor Management Hub: it is intended to consume their evidence, not duplicate their workspaces. It is not designed to be a single opaque score: exposure, confidence and what remains unknown are intended to stay visible and explainable, not blended together. It is not designed to let AI fill evidence gaps with plausible-sounding text: the intent is that it answers from approved evidence or says plainly that it cannot, rather than guessing. And it is not designed to treat a closed ticket or a completed task as proof that risk was actually reduced.
RiskOS has not launched yet, so there is no pricing, onboarding timeline or live product to evaluate today. If your organisation needs an evidence-backed GRC or supplier-assurance workspace now, STREAM Cloud and Vendor Management Hub are live products you can start with; RiskOS is the layer we are building to sit above them.
Who this is for
RiskOS is being built for two audiences who read the same risk position differently.
CISO / Head of Cyber Risk
the operational user: wants a defensible, evidence-backed view of exposure and action, not another dashboard to maintain by hand.
GRC / Risk Leader
wants structured GRC work to translate into prioritised decisions automatically, rather than manual synthesis every reporting cycle.
CFO / CEO
the board-facing reader: wants to know what changed, what needs funding or a decision, and what has genuinely been proven.
Board / Risk Committee / Non-Executive Director
needs a defensible, evidence-backed narrative it can rely on, not a status update with no context behind it.
Third-Party / Supplier Risk Lead
wants supplier assurance evidence connected to the same operating picture, not a separate, disconnected process.
From here to launch
RiskOS has no customers yet: it has not launched. Rather than dress up a placeholder as a case study, here is what happens between now and the November 2026 launch.
Register interest. Tell us a little about your organisation and what you would want a risk operating layer to answer for you.
Early conversation. Where relevant, we will talk through your current GRC and evidence setup ahead of general availability.
Launch access. Registered organisations will be contacted first as access opens around the November 2026 launch.
RiskOS FAQs
Common questions about RiskOS: what it is, who it's for, and when it launches.
Be first to know when RiskOS launches
Register your interest now and we will be in touch as access opens ahead of the November 2026 launch.