EU AI Act. High-risk obligations apply from 2 August 2026. See what Altisium tracks
Solutions

Built for regulated programs

The platform is the same for everyone. What differs is which registers you need and which templates you start from.

By industry

Where Altisium fits

Financial services

DORA Register of Information, NIS2 supply-chain measures, SS1/21 outsourcing and operational resilience, OCC examiner packs, MAS TRM and APRA CPS 230, all from one supplier record.

DORANIS2SS1/21OCCMAS TRMCPS 230

Healthcare and life sciences

Supplier assessments against HIPAA and ISO 27001 templates, evidence held per requirement, and incident handling with the severity and SLA trail an auditor expects.

HIPAAISO 27001GDPR

Technology and SaaS

Answer your own customers faster with a published Trust Center, while running the same diligence on the vendors underneath your product.

SOC 2CAIQSIG Lite

Public sector and utilities

NIS2 obligations across the supply chain, concentration analysis on critical providers, and a reporting trail that survives a change of personnel.

NIS2NIST CSF
By role

Who uses it day to day

Head of third-party risk

Run the whole program on one record instead of chasing it across a spreadsheet, an inbox and a monitoring tool.

CISO

See concentration and exposure across the portfolio, and hand the board a pack that was not rebuilt by hand.

Compliance and regulatory reporting

Derive the register from live data, fill the gaps inline, and keep the submission history.

Procurement

Intake and onboarding on your own risk rubric, with the contract, the obligations and the renewal date attached to the supplier.

Tell us what you have to report.

We will show you which registers derive from the data you already hold.