Integrated Risk Management Assessments & Audits Evidence-led assurance

Citadel: Assessment-Driven Integrated Risk Management

Citadel links control performance to operational and strategic risk, so leaders can make decisions with confidence and teams can focus on the actions that matter most.

No material risk? It doesn’t appear in the register.

Citadel integrated risk management dashboard showing operational and strategic risk trends

Configuration, not custom code

Citadel is entirely configuration driven. Organisations can configure their own assessment frameworks, scoring models, workflows, permissions, reporting, notifications and dashboards without bespoke software development.

Risk that reflects reality

Citadel provides a clear and reliable view of risk by linking it directly to real control performance. Using structured assessments and evidence gathered through operational activity, risk remains current as conditions and control effectiveness change.

This enables a bottom-up view of risk — from controls, through operational risk, to strategic risk — while maintaining a consistent picture across the organisation.

How Citadel works

Controls
Assessed with evidence
Risk
Derived from outcomes
Board view
Trends & priorities
  • One control can support many risks — changes update every linked risk.
  • Risk stays current as assessments and evidence change.
  • Operational outcomes roll up into strategic risk in a consistent way.

Who Citadel is for

Citadel supports the people responsible for assurance, risk decisions, and operational delivery — with a shared view of risk based on control performance.

Board
Decision-ready oversight
Trends, priorities, and concentrations of risk — without relying on point-in-time snapshots.
Risk & Audit
Assurance you can stand behind
Run structured assessments, reuse evidence, and maintain consistent traceability from controls to risk.
Operations
Clear actions and ownership
Understand what needs attention, why it matters, and what good looks like in practice.

Capabilities

Everything you need to assess, assure, and act — with risk informed by real control performance.

Assess & Assure

  • Assessments and audits aligned to your frameworks and standards
  • Control and evidence management with reuse across assurance activity
  • Integrated risk register informed by assessment outcomes
  • Reporting and analytics for consistent governance

Understand & Visualise

  • Dashboards and trends showing direction of travel
  • Risk and control mapping for clarity and planning
  • Interdependencies and aggregation to understand wider impact
  • AI-driven efficiency to accelerate assessment preparation

Respond & Recover

Emergency response planning
Maintain role-based, accessible response and recovery plans.
Learning and training management
Track readiness alongside risk and control performance.
Notifications and workflows
Ensure ownership, follow-up, and timely action.

Scoring you configure, not scoring imposed on you

Scoring in Citadel is fully configurable, so it reflects your operational reality rather than forcing you into one fixed model. Organisations choose the approach that fits each assurance activity, weight individual questions by operational significance, apply Threat Vector criticality multipliers for site and asset importance, and mark answers as non-scorable (N/A) where a question doesn't apply. Models can be refined over time without affecting historical assessments, so you can mature your approach while keeping performance comparable.

Compliance scoringMaturity scoringControl-effectiveness scoring Risk-based scoringWeighted scoring Threat Vector multipliersNon-scorable (N/A)

The full assessment lifecycle

Assessments don't have to be completed in one sitting, and nothing is ever lost.

Save & resume
Start, save and continue later — ideal for long or multi-visit inspections.
Review & approve
Review before submission, with optional approval or QA sign-off.
Reassessment
Repeat inspections with prior answers, comments and evidence shown alongside.
Version history
Reopen and amend with the original and every revision preserved in a full audit history.

Bulk administration & data exchange

Stand up and maintain a large estate without record-by-record entry — via Excel, CSV, JSON and the API, with validation and duplicate detection built in.

User importSite importAsset import Group importQuestion set importBulk updateBulk export

Common use cases

Citadel supports a single assessment-driven framework across many sectors and assurance activities — from routine inspections to strategic, board-level risk oversight. A selection of common use cases is shown below.

By sector

Critical national infrastructure

Protect high-criticality sites and assets with contextual, Threat Vector–weighted scoring, so a minor issue at a Tier 1 site is treated with the significance it deserves.

Defence & military estate

Assure establishments, formations and deployable capabilities across a command structure, with information separation and support for classified and air-gapped deployments.

Aviation & airports

Standardise security inspections, compliance audits and operational readiness checks across terminals, airfields and supporting assets.

Ports, maritime & offshore

Manage assurance for ports, marinas, offshore facilities and vessels within one framework — fixed and mobile assets side by side.

Transport networks

Assess stations, depots, control rooms, vehicles and infrastructure geographically, with map-based reporting across a distributed estate.

Stadiums & major events

Run pre-event security and safety inspections, capture photographic evidence on site, and trigger corrective actions before doors open.

Facilities management

Deliver consistent assurance across a multi-site property portfolio, with local ownership rolling up into regional and enterprise views.

Data centres

Assure physical security, access control and resilience of critical facilities, with a permanent, defensible audit trail per asset.

Corporate & regulated organisations

Support corporate assurance programmes with evidence-led compliance, exception reporting and complete traceability for regulators.

Hotels & hospitality

Standardise safety, security and compliance checks across a hotel portfolio, capturing photographic evidence on site and rolling results up to group level.

Retail & shopping centres

Assess security, fire safety and crowd management across stores and centres, comparing performance between locations to target investment.

Education

Run safeguarding, fire and premises inspections across schools and campuses, keeping a defensible assurance record for governors and inspectors.

Local government & councils

Manage assurance across public buildings, events and services within one framework, with delegated local ownership and enterprise-wide oversight.

Healthcare estates

Assure security, fire and life-safety controls across hospitals and clinical sites, with criticality-weighted scoring that prioritises the highest-risk failures.

Utilities & energy

Protect distributed infrastructure and control rooms, tracking control effectiveness and vulnerabilities across a national or regional network.

By assurance activity

Physical security & guarding

Assess access control, CCTV coverage, perimeter and guarding as reusable controls linked across every site and asset they protect.

Fire & life safety

Run fire safety assessments and life-safety inspections with weighted scoring that flags critical failures immediately.

Supplier & contractor assurance

Assign assessments to external suppliers and specialist teams, keeping their information appropriately separated from the wider estate.

Regulatory audit & accreditation

Evidence compliance for audits, accreditation exercises and regulatory reviews, drilling from any report back to source evidence.

Operational readiness

Validate readiness and training with recurring, event-driven or scheduled inspections across teams and locations.

Martyn's Law & public venue protection

Assess and evidence protective security measures for publicly accessible locations, with clear actions and ownership. Try the Martyn's Law assessment →

Incident-driven investigations

Let incidents automatically generate assessments and investigations, and turn findings into corrective actions in connected systems.

Health, safety & environmental

Standardise HSE checks and facilities inspections, capturing observations and evidence at the point of activity.

Migrating existing checklists

Use AI-assisted question set generation to turn existing procedures, spreadsheets and audit templates into Citadel assessments quickly.

By outcome & scenario

Enterprise assurance

Consistent assessment across sites, teams and suppliers with reusable evidence and clear reporting.

Board & executive reporting

Strategic risk that reflects operational outcomes, with trends that support prioritisation and investment decisions.

Resilience & response

Keep response plans current and accessible, aligned to the risks and dependencies that matter most.

Continuous control monitoring

Move from periodic to continuous assurance, with control effectiveness and risk updating automatically as assessments complete.

Classified & air-gapped deployment

Operate entirely within protected environments — authentication, storage, reporting and analytics — with no dependency on external networks.

Enterprise BI & analytics

Feed assurance data into Microsoft Power BI alongside incident, maintenance, staffing and financial data for data-driven risk management.

By operational challenge

Onboarding new sites & acquisitions

Use AI-assisted import to identify sites, assets, users and structures from existing data, standing up assurance quickly as the estate grows or restructures.

Deferred-maintenance correlation

Combine assurance findings with maintenance and engineering data to reveal where equipment failures align with deferred maintenance before they escalate.

Staffing-change risk detection

Surface correlations between rising vulnerabilities and reduced staffing, contractor changes or increased operational tempo.

Dependency & single-point-of-failure mapping

Model the relationships between sites, assets, people, suppliers and services to understand critical paths and the impact of disruption.

CAPEX & investment prioritisation

Give the board evidence-based trends and risk concentrations to direct investment where it improves resilience most.

Corrective action & escalation

Let negative findings automatically raise actions, mandatory comments, evidence requirements and tiered escalation workflows.

Cross-domain data transfer

Run a submission-only environment that feeds a separate authoritative instance, with fully audited one-way transfer and cleardown across information domains.

Retention, legal hold & evidence

Preserve a complete, defensible assurance history through personnel and structural change, ready for investigations, audits and regulatory review.

Headless / API-first integration

Embed Citadel as an assurance engine behind existing enterprise systems, exchanging records and workflow context through its REST API.

Book a Citadel demo

Tell us a little about your organisation and what you’re looking to achieve. We’ll respond with the next steps.

Email for a demo
support@arxpartners.co.uk