Citadel - A clearer approach to risk management

Assessment-driven, evidence-led, and built around how controls actually operate.

View Video

Assessment-Driven Integrated Risk Management

Risk should reflect reality. Citadel provides a clear and reliable view of risk by linking it directly to control performance. Through structured assessments and evidence gathered as part of normal operational activity, risk remains current as conditions and control effectiveness change.

Rather than managing risk as a static register, Citadel provides a living view of risk that evolves as controls operate in practice.

Assessments and audits are used to build a clear picture of how controls are functioning across the organisation. These outcomes inform the view of operational risk, which is then brought together to provide a coherent and up-to-date view of strategic risk — ensuring senior decision-makers see what is actually happening on the ground.

Citadel integrated risk management dashboard showing operational and strategic risk trends
Board-level view: trends and priorities, not snapshots.

How Citadel works

  1. Controls are assessed in the context in which they operate, using structured assessments carried out as part of normal operational activity.
  2. Controls are defined once and linked to all relevant operational risks — a single control may support multiple risks across different areas.
  3. Evidence captured against a control informs the view across all linked risks.
  4. Where a control supports multiple risks, changes in its effectiveness are reflected across those risks.
  5. Operational risk outcomes are aggregated to provide a clear view of strategic risk, with trends and priorities for boards and senior management.

If no material risk exists, it does not appear in the register.

Control Performance
Controls

Assessed with evidence

Operational Risk
Risk

Derived from outcomes

Strategic View
Board View

Trends and priorities


One control can support many risks
A change in control performance updates every linked risk.
Risk stays current
Evidence and assessment outcomes keep the register aligned to reality.
Board-ready insight
Operational outcomes roll up into a coherent strategic picture.

Capabilities

Assess & Assure

A structured and consistent approach to assessment and assurance, giving confidence in how controls are operating in practice.

  • Assessments and audits
  • Integrated risk register
  • Control and evidence management
  • Reporting and analytics

Understand & Visualise

Dashboards, trends and mapping that show how controls support multiple risks, and where change will have the greatest impact.

  • Dashboards and trends
  • Risk and control mapping
  • Interdependencies and aggregation

Respond & Recover

Practical resilience support — plans, training and workflows aligned to operational need.

  • Emergency response planning
  • Learning and training management
  • Notifications and workflows

Built for the enterprise

Entirely configuration driven — configure your own assessment frameworks, scoring, workflows, permissions, reporting, notifications and dashboards without bespoke software development. Secure, open and ready to integrate. See the full capability reference →

Technical architecture

Browser-based, PostgreSQL-backed, configuration-driven. UUID identifiers, UTC timestamps, and air-gapped deployment options.

Import & export

Excel, CSV and JSON import, bulk and API loads, scheduled exports and API data feeds into Power BI.

Workflow engine

Configurable workflows, approvals, escalations, mandatory fields, automation, notifications and enforced state transitions.

Audit trail

Tamper-evident record of user actions, configuration changes and evidence history — fully timestamped and reportable.

Role-based security

Granular access at every level — Enterprise, Organisation, Site, Asset, Assessment and Report — with SSO and MFA.

Security & certifications

Cyber Essentials Plus certified and independently penetration tested, with an immutable audit trail and air-gapped deployment options.

Developer & API

API-first REST/JSON, OpenAPI documentation, Postman collections and worked examples.

A scalable and consistent approach

Making better-informed decisions faster

an enterprise wide picture of the risks facing your organisation

gain confidence in your governance and assurance procedures

real time situational awareness and understanding

enabling better and faster decision making that is evidence based and fully auditable

a scalable and consistent approach to risk

a clear understanding about your business’ risks

See Citadel use cases →

Technology

Working in challenging regulatory and operational environments and the need for rigorous compliance do not have to mean bespoke software development.

We have built a technology stack leveraging industry best practices for cyber security within a generic, modular framework.

This technology stack is the foundation of Citadel, giving organisations a COTS capability with enterprise grade features - without the price tag of bespoke software

  • Data Encryption

    All data is held in secure UK data centers and is encrypted in transit and at rest

  • Citadel can be fully deployed within air-gapped or highly restricted environments, operating without any external internet connectivity.

    Mapping: A static map option is available, removing the need for external mapping services.

    Authentication (2FA/MFA): Authentication can be integrated with existing internal systems or configured to use local methods within the secure environment.

    Alerting: External messaging services (such as SMS) are not required and can be disabled.

    Email: Citadel can operate entirely using an internal email server.

    Document Storage: Supports deployment with an S3-compatible object storage solution such as MinIO, hosted within the environment.

    Database Hosting: Databases can be hosted entirely within the environment, either containerised or on internal infrastructure.

    Configuration: All components are configuration-driven, enabling deployment in secure environments without code changes.

  • Citadel is built on an API structure that allows both incoming and outgoing data to be shared with multiple other sites and applications. This allows Citadel to be used as a central hub for data sharing, and it makes it easy to integrate Citadel with other systems. The API structure of Citadel is designed to be flexible allowing Citadel to be used in a variety of different ways, and it makes it easy to integrate Citadel with other systems. For example the Threat Vector multiplier can take a feed from an external API and automatically rerun an assessment if the threat changes. Citadel can then disseminate notifications to relevant parties or provide feedback to one of the organisation's external APIs to send notifications. The Map function is another example of how Citadel ingests data and blends information into a single view.

  • Customisable hierarchical access control

  • The BSI Kitemark for Secure Digital Transactions rigorously and independently tests websites or apps to make sure they have the security controls in place for the financial and/or personal information they are handling.

    It requires a website or an app to undergo rigorous and independent testing and producers of websites or apps from banking to entertainment can reassure their clients by displaying the BSI Kitemark on their product and in their marketing materials.

Citadel risk management platform interface showing assessments, controls, and risk overview
Cyber Essentials Plus certified Cyber Essentials certified BSI certification

Our Mission

we are on a mission to help improve risk management

At arx, we have worked in high risk and highly regulated environments. We have had the operational responsibility for some of the country’s most sensitive facilities and missions both on the ground and in the air. We know from first hand experience how vital risk management is to delivering success.

Our values

Commitment to our customers

At arx, we believe in team work and putting our customers first. We will work with you to find the best possible solutions that meet your challenges and requirements.

Excellence

We believe in delivery and in doing the important things well. We maintain the highest standards providing our customers with the best possible service.

Integrity

We will always give you an honest assessment of what is possible and quote you a fair price.

Our Story

We have a shared experience of working in some of the most challenging and demanding environments where successful risk management is critical to success. We know how difficult it can be to know and understand the full range of risks to which you might be exposed whilst trying to make the most demanding of operational decisions.

Having the ability to make the right call when weighing up the potential risks and benefits is a key differentiator.

Risk Management can be a resource intensive process. Procedures that require manual interventions and spreadsheets are slow and costly both in terms of the time they take and the financial cost.

Our founding belief and key motivator behind arx Partners is that the right technology will deliver secure, faster and better outcomes.

News and Views


Capturing accurate performance data that gives a true picture is difficult

Most of the companies with which we work will conduct regular risk audits. Whilst companies recognise the need to review their risk posture to assure themselves that the range of measures they have put in place are delivering their intended effect and that the company’s policies and procedures are being followed, their approach can vary significantly. Read More

Our Founders

Richard Thompson, Managing Partner, arx Partners

Richard Thompson

Managing Partner

following a thirty-three year career in government service dealing with some of the most challenging operational, policy and regulatory issues, I fully appreciated the importance of excellent risk management and the power of technology. Having the right technology in place can transform the speed and the quality of decision making.

Andrew Wood, Managing Partner, arx Partners

Andrew Wood

Managing Partner

As an aviator, first as a helicopter pilot and continuing as a B747 Captain I was immersed in a highly regulated and risk-averse environment.
I started developing internet technology in 1998 when the web began to become popular. Utilising both skill sets I have guided the development team to produce the Citadel software.

Some of our users

  • Bbc logo
  • Poolre logo
  • Aberdeen Standard logo
  • Accord Uk Ltd logo
  • Aeg Europe logo
  • Affinity Digital logo
  • Ags Airports Limited logo
  • Amshold Group Ltd logo
  • Anvil Group logo
  • Arcadia Group Limited logo
  • Argent Mining logo
  • Assess Threat logo
  • Assicurazioni Generali logo
  • Axa logo
  • Bank Of England logo
  • Barclays logo
  • Bd Corp logo
  • Bidvest Nooonan logo
  • British Insurance Brokers'association logo
  • Camor logo
  • Canary Wharf Group logo
  • Cbre Ltd logo
  • Charnwood Bc logo
  • Churchill Group Ltd logo
  • City Of London logo
  • Cmg logo
  • Corinthia Hotel logo
  • Covent Garden Market Authority logo
  • Crosby logo
  • Crosfields School logo
  • Db logo
  • Derby County Football Club logo
  • Derwent London logo
  • Dla Piper Uk Llp logo
  • Dneg logo
  • Dorchester Collection logo
  • Dorsett Hotels logo
  • English National Opera logo
  • Enterprise logo
  • Epping Forest District Council logo
  • Eurotunnel logo
  • Fenwick Limited logo
  • G4s logo
  • Glh Hotels logo
  • Grosvenor logo
  • Grosvenor Group logo
  • Harrods logo
  • Harvey Nichols logo
  • Hazard 360 Ltd logo
  • Henderson Park logo
  • Herbert Smith Freehills Llp logo
  • Hines Europe Limited logo
  • Hogan Lovells logo
  • Ibm logo
  • Infinitus Property Investment logo
  • Intu Properties Plc logo
  • Jdc Solutions Ltd logo
  • Jll logo
  • Kiasu Group logo
  • Kings Cross Central Limited Partnership logo
  • Kyndryl logo
  • Landsec logo
  • Liverpool One logo
  • Lockton logo
  • London City Airport Limited logo
  • Lw Theatres Group Limited logo
  • M&g Real Estate logo
  • Marsh Commercial logo
  • Mbda Uk logo
  • Mcarthurglen Group logo
  • Mitsui Fudosan Uk Ltd logo
  • Mod logo
  • Muller International logo
  • Nactso logo
  • Nan Funghelix logo
  • National Ice Centre logo
  • National Museums Liverpool logo
  • Nats logo
  • Newsquest Media Group Ltd logo
  • Next Plc logo
  • Omnyy Llp logo
  • Paddington Square logo
  • Qbe logo
  • Rbwm logo
  • Ripplewood Holdings logo
  • Rx logo
  • Savills logo
  • Sea Containers Hotel Ltd logo
  • Sgc Security Services logo
  • Shrewsbury Town Council logo
  • Sirv logo
  • Somerset House Trust logo
  • Tesselates Innovation logo
  • The Copy Consultancy Ltd logo
  • The Crown Estate logo
  • The Fa logo
  • The Francis Crick Institute logo
  • The Lowry Centre Trust logo
  • The Portman Estate logo
  • Toren Consulting logo
  • Travelodge Hotels Limited logo
  • Ubm Plc logo
  • Vesper Ltd logo
  • Wakefield And Distrct Housing logo
  • Wellcome Trust logo
  • Westminster Abbey logo
  • Willis Towers Watson logo
  • Yougov Plc logo