Risk Ledger
- Company typePrivate
- Founded2018
- HeadquartersLondon, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
Risk Ledger firmographics
Firmographics- Name
- Risk Ledger
- Legal name
- Risk Ledger Ltd
- Website
- https://riskledger.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
Risk Ledger industry classification
Industry- Product category
- Supply Chain Security Software / Third-Party Risk Management
- NAICS
- Custom Computer Programming Services (541511)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Third-Party/Vendor Risk Management (TPRM/VRM) (HDADAIAE)
- akta.pro secondary industries
- Third-Party & Supply Chain Exposure Monitoring (HDADAHAJ), Third-Party/Vendor Risk Management (TPRM) & Due Diligence (BPAKADAH)
Keywords
Where Risk Ledger is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices2 records
Markets served
Risk Ledger business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Client Platform Access and Assessment Fees: Client organisations (buyers of supply chain security) pay for access to the Risk Ledger platform to assess, monitor, and manage their supplier networks. Fees are based on the number of suppliers onboarded and features accessed. Suppliers maintain free profiles.
- Enterprise and Public Sector Contracts: Direct contracts with large enterprises, government agencies (NHS, police forces, local authorities, central government), and financial institutions for supply chain security services. The company achieved 388% growth in public sector revenue.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Free supplier profile for security assessments |
| Subscription | Annual | Client organisation paid tiers (specific pricing not disclosed) |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels8 records
Risk Ledger product offering
Product offeringCore offering
Risk Ledger sells a network-first supply chain security platform that replaces point-in-time Third-Party Risk Management (TPRM) with continuous, collaborative Active Supply Chain Security (ASCS). Client organisations (buyers) pay annual subscriptions to assess, monitor, and visualise their supplier networks, while suppliers receive free profiles that can be shared across all clients. The platform is built around a 12-dimension Supplier Assessment Framework aligned to ISO 27002, NIST CSF, NCSC CAF, Cyber Essentials, and EU DORA, and includes modules for process improvement, due diligence, remediation, risk visualisation, and reporting with API integrations to BI/ERP systems.
Product overview
Risk Ledger offers a unified network-first supply chain security platform that replaces traditional, point-in-time Third-Party Risk Management (TPRM) with Active Supply Chain Security (ASCS). The core Risk Ledger Platform connects over 16,000 organisations and is complemented by five integrated service modules: Improve Your Process (centralized management and continuous monitoring), Supplier Due Diligence (network-based supplier onboarding), Review and Remediate (automated assessment and remediation workflows), Visualise Risks (nth-party network mapping and concentration risk identification), and Report and Monitor (real-time compliance reporting and API automation). The platform also includes the ASCS Hub for community collaboration across sectors, the Supplier Assessment Framework covering 12 risk dimensions, and the Zero-Friction Partner Programme for channel expansion.
Differentiator
Problem solved
Functional benefit
Products and services
- Risk Ledger Platform A network-first supply chain security platform that transforms Third-Party Risk Management (TPRM) with continuous, collective supply chain defence. It connects over 16,000 organisations, enabling standardised supplier security assessments, nth-party visibility, and real-time threat monitoring for client organisations in public sector, financial services, insurance, CNI, and technology.
- Supplier Due Diligence Reduces time for supplier reviews by connecting client organisations to suppliers already in the Risk Ledger network or engaging new suppliers through bulk invites, automatic chasers, and progress tracking. Built for procurement, security, and risk teams responsible for onboarding third parties.
- Improve Your Process Helps organisations centralise supply chain security management, map security frameworks against regulations, configure rules-based controls, and implement continuous monitoring with automatic six-monthly reassessments. Designed for security and risk teams operationalising a TPRM programme.
- Review and Remediate Automates the process of reviewing and remediating supplier assessments, including identifying non-compliance, requesting remediations, tracking progress, approving resolutions, and documenting the entire process for audits. Built for security and compliance teams managing supplier assurance workflows.
- Visualise Risks Provides network-based visualisation of supply chain risks, including 4th/5th/6th-party risk visibility, supplier network mapping, concentration risk identification, risk heatmaps, and timeline tracking of supplier risk remediation. Designed for risk managers and CISOs needing a living view of supply chain exposure.
- Report and Monitor Provides real-time supply chain risk monitoring with compliance reporting, activity reporting, performance reporting, API automation, and continuous monitoring dashboards with notifications and digest emails. Built for risk, compliance, and BI teams that need data export into Power BI and ERP systems such as Riskonnect.
- Active Supply Chain Security (ASCS) Hub A collaborative community hub within the Risk Ledger platform supporting organisations across Public Sector, Critical National Infrastructure, Financial Services & Insurance, and Technology communities to share intelligence and coordinate supply chain defence.
- Supplier Assessment Framework Standardised assessment framework spanning 12 risk dimensions, aligned to ISO 27002, NIST Cybersecurity Framework, NCSC Cyber Assessment Framework, and Cyber Essentials. Covers cybersecurity, ESG, and financial risks, and is used by organisations to assess and benchmark supplier security posture.
- Zero-Friction Partner Programme A channel partner programme launched in February 2026 designed to help MSPs, resellers, and consultancies modernise supply chain security with a network-first approach, removing channel complexity and rigid tiering through Concierge Co-Selling, Transparent Commercial Model, and Network-Driven Value.
Quantifiable outcome
- Security review times shortened by up to 6 weeks
- +4 more outcomes
Companies that use Risk Ledger
Customer profileNamed customers7 records
Segments5 records
Ideal customer profiles4 records
Risk Ledger technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability3 records
Feature6 records
Risk Ledger partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- Maryland Global Gateway Soft Landing ProgramcoreRisk Ledger announced plans to open its first US office in Montgomery County, Maryland as part of Maryland's Global Gateway Soft Landing program. The programme supports international cybersecurity companies in establishing US presence and leverages Maryland's cybersecurity ecosystem for global growth and North American operations scaling.
- Zero-Friction Partner Programme Partners (MSPs, Resellers, Consultancies)coreRisk Ledger launched its Zero-Friction Partner Programme to help MSPs, resellers, and consultancies modernise supply chain security with a network-first approach. The programme removes channel complexity with concierge co-selling, transparent commercial models, and deal protection. Partners connect clients into the growing ecosystem of organisations sharing standardised security information.
Scale indicators9 records
Recent moves6 records
Expansion highlights6 records
Risk Ledger competitors and assessment
Company assessmentBroad incumbents
- Drata: Compliance and security automation platform with growing TPRM capabilities. Adjacent competitor targeting the same GRC buyer with a wider compliance scope than Risk Ledger's supply-chain focus.
- Vanta: Compliance automation platform with an expanding vendor risk module. Broader scope than Risk Ledger (SOC 2, ISO, HIPAA) but increasingly competing for the same security and risk buyer.
Direct peers
- Prevalent: Third-party risk management platform offering vendor assessments, network intelligence, and continuous monitoring. Direct overlap with Risk Ledger across regulated industries and supplier assessment workflows.
- Bitsight: Security ratings and TPRM platform with strong enterprise and financial services presence. Competes head-to-head with Risk Ledger for the same vendor risk budget, though Bitsight uses external telemetry rather than supplier-collaborated profiles.
- UpGuard: Vendor risk management and attack surface management platform. Overlaps with Risk Ledger on supplier security assessments and continuous monitoring, with comparable self-serve supplier onboarding.
- SecurityScorecard: Global leader in security ratings and third-party risk management. Directly comparable as an enterprise TPRM platform serving similar buyer personas, with ratings-based scoring as an alternative to Risk Ledger's network-first model.
- Whistic: Vendor security assessment network enabling proactive sharing of security documentation between buyers and suppliers. Closely comparable to Risk Ledger's network-first supplier profile sharing model.
- ProcessUnity: TPRM workflow platform focused on vendor onboarding, due diligence, and continuous monitoring. Competes for similar enterprise and financial services buyers, with deeper workflow automation but less network-effect leverage.
- Panorays: Third-party cyber risk management platform combining external scans, questionnaires, and vendor questionnaires. Directly competes for the same TPRM budget, particularly with mid-market and enterprise buyers.
- Black Kite: Third-party cyber risk platform using financial-grade standards (FAIR) and external rating data. Comparable in serving regulated enterprises and supply chain risk use cases overlapping with Risk Ledger.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Risk Ledger social profiles
Digital presenceRisk Ledger compliance and trust
Trust signalCompliance2 records
Risk Ledger financial estimates
Financial estimateRevenue estimate
Valuation estimate
Risk Ledger leadership team
Management profileNumber of profiles
Profiles5 records
Risk Ledger funding detail
Funding detailFunding overview
Funding rounds5 records
Investors8 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Risk Ledger M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Risk Ledger
What does Risk Ledger do?
Risk Ledger sells a network-first supply chain security platform that replaces point-in-time Third-Party Risk Management (TPRM) with continuous, collaborative Active Supply Chain Security (ASCS). Client organisations (buyers) pay annual subscriptions to assess, monitor, and visualise their supplier networks, while suppliers receive free profiles that can be shared across all clients. The platform is built around a 12-dimension Supplier Assessment Framework aligned to ISO 27002, NIST CSF, NCSC CAF, Cyber Essentials, and EU DORA, and includes modules for process improvement, due diligence, remediation, risk visualisation, and reporting with API integrations to BI/ERP systems.
Is Risk Ledger a public or private company?
Risk Ledger is a private company. It is classified as venture growth investor backed and is currently operating.
When was Risk Ledger founded?
Risk Ledger was founded in 2018. It employs 11 to 50 people.
Where is Risk Ledger based?
Risk Ledger is headquartered in London, United Kingdom, in the Europe region.
How does Risk Ledger make money?
Two revenue lines are on record. Client Platform Access and Assessment Fees are the primary driver. The others are enterprise and Public Sector Contracts.
Who are Risk Ledger's main competitors?
Broad incumbents on record are Drata and Vanta. Direct peers are Prevalent, Bitsight, UpGuard, SecurityScorecard, Whistic, ProcessUnity, Panorays and Black Kite.
Does Risk Ledger have an API?
Yes. Risk Ledger offers API automation capabilities enabling users to extract data from the platform for reporting in external systems. The API supports integration with business intelligence tools such as Power BI and ERP systems like Riskonnect. Data can be exported in CSV format for further analysis in external systems.
What industry is Risk Ledger in?
Risk Ledger's product category is Supply Chain Security Software / Third-Party Risk Management. Its primary akta.pro industry code is HDADAIAE, Third-Party/Vendor Risk Management (TPRM/VRM), with a secondary code of HDADAHAJ, Third-Party & Supply Chain Exposure Monitoring. Its NAICS code is 541511 and its SIC code is 7373.