Frequently Asked Questions

Everything you need to know about VeloRisk

Understanding VeloRisk

Who is VeloRisk for?

VeloRisk is built for leaders accountable for risk — to a board, a regulator, an insurer, or a leadership team. Common use cases include: preparing for regulatory examinations, BSA/AML program readiness, fraud program maturity evaluation, investor or acquirer due diligence, board reporting on enterprise or financial crime risk, cyber insurance applications, AI governance documentation, and preparing for growth milestones like Series B, M&A, or an IPO. The people who typically run programs include CISOs, CTOs, CFOs, CROs, COOs, BSA Officers, Chief Compliance Officers, and General Counsel. vCISOs and fractional risk consultants also use VeloRisk to run programs for their clients.

Is VeloRisk a GRC platform, a consulting firm, or a compliance automation tool?

VeloRisk doesn't map cleanly onto any existing category. Here's how it differs from the tools people most often compare it to:

If you're thinking of… What that is Why VeloRisk is different
GRC platform
OneTrust, LogicGate, and others
Workflow and evidence management — tracks policies, controls, tasks, and audit evidence over time GRC platforms manage what you do after a risk assessment. VeloRisk is the platform that runs your program — ongoing analysis, findings, compliance mapping, and board-ready reporting that stays current with your posture. You'd use VeloRisk to feed a GRC platform, not replace it.
Consulting engagement
Big 4, boutique risk firms
A human-led assessment: interviews, workshops, a deliverable after months of work VeloRisk is software. No consultants, no SOW, no timeline measured in quarters. The same quality of analysis — in hours.
Compliance automation
Vanta, Drata, Sprinto
Automates evidence collection for certifications like SOC 2 or ISO 27001 Compliance automation tools collect and track evidence that your controls exist. VeloRisk is the step before that — it identifies what your risks are and what controls you need in the first place. Different jobs in the same workflow.
vCISO platform
Cynomi, Guardz
Enables managed service providers to deliver virtual CISO services to clients — typically includes lightweight risk assessments run on the client's behalf VeloRisk is built for organizations to own and run their own risk program directly — not mediated through a provider. That said, practitioners and MSPs regularly use VeloRisk as part of how they deliver engagements, putting board-ready analysis in the client's hands rather than their own.
Third-party risk rating
BitSight, RiskRecon
Rates vendors and third parties from external signals — without their input VeloRisk assesses your own organization from the inside, based on what your team actually knows about your environment.
TPRM platform
ProcessUnity, Prevalent, Aravo
Manages vendor due diligence workflows — questionnaires, risk tracking, and ongoing monitoring of third-party suppliers TPRM platforms look outward at your vendors. VeloRisk looks inward at your own organization's risk program.
Questionnaire or checklist tool A static survey mapped to a framework, producing a generic output VeloRisk produces tailored analysis across thousands of risk dimensions calibrated to your industry, size, geography, and compliance requirements — not a template filled in with your name.

The closest honest description: VeloRisk is a strategic risk platform — structured analysis, board-ready reporting, and compliance mapping that runs as a living program, not a one-time engagement.

How can VeloRisk be as thorough as a months-long consulting engagement?

Traditional consulting timelines are driven by coordination overhead—scheduling interviews, travel, workshops, and draft reviews—not analytical depth. That's what VeloRisk eliminates. In its place: a structured assessment evaluated across thousands of risk dimensions, producing a detailed Practitioner Report with findings, control gap analysis, prioritized remediation recommendations, and compliance mappings. Every finding traces directly to the specific responses that drove it, so there's no black box—you can see exactly where each conclusion came from.

Does completing a VeloRisk assessment certify my compliance?

No. VeloRisk is not a certification body, and a VeloRisk assessment does not result in a compliance certification, audit opinion, or attestation letter. Formal certifications—SOC 2 Type II, ISO 27001, PCI DSS QSA, FedRAMP—require an accredited auditor or assessor to conduct an independent audit of your controls. VeloRisk helps you understand where your gaps are and what to prioritize before you go through that process. Think of it as the work you do to get ready, not the credential itself.

Does VeloRisk cover every requirement in a given compliance framework?

VeloRisk maps your assessment results to the major frameworks relevant to your assessment type and shows you which gaps are relevant to each one.

Enterprise Risk Program
COSO ERM NIST CSF 2.0 NIST SP 800-53 NIST SP 800-63 ISO 27001:2022 SOC 2 PCI DSS 4.0 GDPR SOX COBIT 2019 ISO 22301:2019 CIS Controls v8 NIST SP 800-171 SEC Cyber Disclosure Rules 2023
Fraud Program
ACFE Fraud Risk Management Guide COSO ERM FATF 40 FFIEC Authentication Guidance FFIEC BSA/AML FTC Red Flags GDPR ISO 27001:2022 NIST CSF 2.0 NIST SP 800-53 NIST SP 800-63 PCI DSS 4.0 SOC 2
AML/CFT Program
ACFE Fraud Risk Management Guide COSO ERM FATF 40 FFIEC Authentication Guidance FFIEC BSA/AML GDPR ISO 27001:2022 NIST CSF 2.0 NIST SP 800-53 NIST SP 800-63 PSD2 Strong Customer Authentication SOC 2
AI Risk Program
NIST AI RMF 1.0 EU AI Act ISO/IEC 42001:2023 MITRE ATLAS OWASP LLM Top 10 ISO/IEC 23894:2023 OECD AI Principles NIST CSF 2.0
CMMC Level 2 Readiness
CMMC 2.0 Level 2 NIST SP 800-171 Rev 2 DFARS 252.204-7012

The coverage is broad and the mappings are substantive, but they are not a substitute for a formal audit scope. A formal certification audit will have its own scope boundaries, evidence requirements, and auditor discretion that VeloRisk doesn't replicate. What VeloRisk gives you is a clear, prioritized picture of where you stand today—so you're not going into an audit blind.

Is the assessment tailored to my industry?

Yes. VeloRisk analyzes your organizational context—industry, company size, geography, and more—to generate risk analysis and recommendations specific to your situation. The compliance frameworks it maps to are also tailored by assessment type; see Does VeloRisk cover every requirement in a given compliance framework? above for the full list.

What You Get

What report PDFs does VeloRisk produce?

Every assessment produces two PDFs: the Executive Report (~25 pages) is designed for board presentations and leadership briefings — a concise view of your risk posture, strategic priorities, and recommended programs. The Practitioner Report is the full technical deliverable: detailed findings across every domain, control gap analysis, evidence-level recommendations, and maturity benchmarking. When you re-run an assessment, both reports include an Assessment Comparison section showing exactly what changed since the prior run — findings opened, closed, or improved — suitable for board reporting, examiner documentation, and audit committee evidence. Sample versions of both are available on the homepage.

What's included in the online platform?

Your annual program includes 12 months of access to a full interactive platform. The platform includes: a findings explorer where you can drill into any finding and see the evidence behind it; a remediations tracker for managing and closing out findings; domain analysis across every assessed area; a compliance posture view showing your current mapping across all applicable frameworks; KPI trends tracked over time across assessments; a changes and delta view showing what shifted between assessments; and a prioritization view showing your highest-priority findings ranked and scored. Enterprise Risk programs also include a Strategic Programs view with 20–30 executive-level initiatives synthesized from your findings. Executive and Practitioner Report PDFs are generated and ready to export for board presentations, auditors, and external stakeholders.

Can I access the full scoring data, including rationales and reasoning?

Yes. The platform gives you access to the full dataset behind your assessment—scoring rationales, analysis reasoning, control-level findings, and compliance mappings. You can drill into any dimension to see exactly how it was evaluated and why. This is included in your 12-month platform access.

Can I see a sample report before purchasing?

Yes. Download sample reports directly: Executive Report (PDF) and Practitioner Report (PDF).

Timeline & Process

What do I need to provide to complete the assessment?

Just your knowledge of your organization. You don't need to upload documents, prepare spreadsheets, or gather files in advance. The assessment is structured as a guided questionnaire—you answer based on what you know about your environment, practices, and current controls. Collecting as little sensitive information as possible is a deliberate design principle: we ask what we need to produce an accurate assessment, nothing more.

How long does the assessment take?

Most organizations complete the assessment in a couple of hours. It's self-paced — you can leave and return anytime, your progress is saved. You can also invite stakeholders to contribute on their own schedule, which can spread the time across your team.

What happens after I purchase?

You get immediate access to the platform. From there, configure your assessment, invite participants, and work through the guided survey at your own pace. Once you're ready, finalize the assessment to trigger the analysis — your findings, recommendations, and compliance mappings are ready in the platform, with PDF exports available to download. Platform access is included for the life of your subscription; your initial program covers 12 months.

Who should participate in the assessment?

It depends on the assessment type. For Enterprise Risk, typical participants come from IT, security, compliance, legal, HR, and operations. For Fraud Program assessments, internal audit, finance, compliance, and operations are the most relevant contributors. For AML/CFT, it's usually the BSA/compliance team, operations, and legal. For AI Risk, the most relevant participants are typically the VP of AI or engineering lead, legal and compliance, and the CISO. There's no limit on participants — involve whoever has relevant domain knowledge without making it a coordination burden.

What if I need help completing the assessment?

The assessment includes guidance and help text throughout. If you run into questions, reach out—before, during, or after. For larger organizations, we also offer implementation support.

Trust & Security

Is my data secure?

We take a minimum-collection approach by design: VeloRisk only collects the information necessary to produce your analysis — nothing more. Data security starts with not having data we don't need. What we do collect is encrypted at rest and in transit, hosted on Google Cloud Platform with SOC 2 controls. We don't share your data with third parties, and you retain full ownership of all assessment data and reports.

What information does VeloRisk collect during the assessment?

Less than you'd expect — by design. All assessment inputs are multiple choice; there are no free-text fields where sensitive information could be entered. We don't ask for your company name, and you never upload documents, share configurations, or provide identifying details about your organization. The assessment collects only your responses to structured, closed-ended questions about your practices, environment, and controls. This is intentional: we ask what's needed to produce an accurate assessment, and nothing more. It also means there's nothing sensitive in the system to protect — or to leak.

Does VeloRisk use AI Agents?

No. VeloRisk uses Candor™ — a controlled, structured analysis engine. There is no autonomous agent: Candor evaluates your responses across thousands of risk dimensions and produces your findings and report. It cannot browse the web, make autonomous decisions, or take any action beyond producing your program output. Every finding traces directly to the specific responses that drove it — no black box.

What is your refund policy?

We offer a 30-day satisfaction guarantee. If you're not satisfied for any reason within 30 days of purchase, you'll receive a full 100% refund — no back-and-forth. See our Refund Policy for the full details.

Ongoing Program

How does the ongoing program work?

VeloRisk isn't a one-time snapshot — your annual program is designed to stay current. After your initial run, re-run whenever your environment changes: a new product launch, a control change, a regulatory shift, or a material event. Each run builds on prior context — findings update in place (new issues surface, resolved ones close out), and an Assessment Comparison Report documents exactly what changed since the last run. KPI trends and posture history accumulate over time in the platform. Unlimited re-runs are included for the duration of your annual program.

How many times can I re-run my assessment?

Unlimited, for the duration of your annual program. There's no per-run charge and no cap on the number of assessments you run within your 12-month subscription period. Run it quarterly, after a material control change, before an exam — whatever cadence fits your program.

What does the Assessment Comparison section show?

When you re-run your assessment, both the Executive Report and Practitioner Report include an Assessment Comparison section. It shows the delta between your current run and the prior one: findings that are new, findings that have been resolved, and findings where your score improved or declined. The Executive version presents a summary suitable for board and audit committee reporting; the Practitioner version includes the full finding-level detail. This section is included automatically on every re-run — no separate setup required.

Can I carry over my previous responses when I re-run?

Yes. When you start a new assessment run, you can pre-populate it from your previous responses and update only what has changed. This makes re-runs faster and ensures your assessment reflects incremental changes rather than requiring a full restart each time. You can also start fresh if you prefer a clean slate.

Does re-running reset my 12-month access period?

No. Your 12-month access period runs from your original purchase date. Re-running doesn't extend or reset it. When you renew your annual subscription, you get another 12 months from the renewal date — including unlimited re-runs for that period.

Can my team push findings to external systems?

Yes. VeloRisk supports webhook delivery of structured findings and remediations to your GRC platform or any webhook-compatible system. Payloads are HMAC-signed so receiving systems can verify authenticity. You can also manually re-push findings on demand — useful for triggering downstream workflows without running a new assessment.

Pricing

How much does VeloRisk cost?

Full pricing is on the homepage. VeloRisk is an annual program — one price covers your entire program for the year, including unlimited re-runs. Pricing is tiered by the number of programs you're running: a single program starts at $7,499/year (Founding Institution) or $12,499/year (standard), with bundle pricing for two through five programs. All prices include tax.

How does renewal work?

Your program renews annually. Renew to continue — your platform access, findings, and program history all carry forward. If you don't renew, platform access expires, but all your PDFs are yours to keep. Founding Institution subscribers renew at their founding rate permanently — it never increases.

What's Founding Institution pricing?

Founding Institution pricing is 40% off standard rates — applied to whichever tier you're on and locked for life. A single-program Founding rate is $7,499/year (vs. $12,499 standard); bundle tiers are discounted at the same rate. That discount applies at every renewal and to every program you add during the founding window. Once the founding cohort closes, this pricing is no longer available to new subscribers. It's not a trial or promotion — it's a permanent rate for organizations that join early.

Can I run more than one program?

Yes. VeloRisk uses bundle pricing for organizations running two or more programs — the per-program cost decreases as you add programs. Bundles are priced by program count, from two up to five programs, with Enterprise pricing available for larger needs. Founding Institution bundle rates are locked for life at the same 40% discount. See the full pricing table on the homepage.

Is there a single assessment option?

We offer a single assessment option for organizations that aren't ready for an annual program. This option isn't listed on our standard pricing — contact us for details.

Do you offer enterprise pricing?

Yes. Enterprise pricing is custom — covering organizations with multi-program needs, multiple organizational units, or complex configuration requirements. Same programs, scoped to your situation. Contact us to discuss.

Do you offer educational or non-profit pricing?

Yes. We offer special pricing for public schools and qualified non-profits. Contact us with details about your organization.

For Risk Practitioners

What programs does VeloRisk offer?

VeloRisk offers five programs, each built for a specific domain and buyer:

  • Enterprise Risk Program — for CISOs, CTOs, and CFOs at mid-market organizations who need a documented enterprise risk posture.
  • Fraud Program — for fraud and risk leaders at fintechs and financial institutions who need a living fraud risk program.
  • AML/CFT Program — for BSA Officers and CCOs at regulated financial institutions who need exam-ready program documentation.
  • AI Risk Program — for CTOs, VPs of AI, and compliance leaders at organizations deploying AI who need governance documentation and compliance framework mapping.
  • CMMC Level 2 Readiness — for DIB contractors who need to know their SPRS score before a C3PAO assessment.

Each program has its own assessment, analysis pipeline, framework mappings, and report outputs. The four Strategic Risk Programs are offered with bundle pricing; CMMC is priced separately.

What's the difference between the AML/CFT Program and the Fraud Program?

These are two separate programs that analyze the same institution through different lenses — and those lenses produce meaningfully different findings and remediation guidance.

The AML/CFT Program uses a regulatory lens. Every finding is evaluated against the question: would a regulator cite this as an MRA or MRIA? The program identifies gaps in CDD/EDD practices, transaction monitoring tuning, SAR quality, beneficial ownership controls, and sanctions/PEP screening — structured against FFIEC BSA/AML, FinCEN guidance, and FATF 40. Remediation guidance follows a compliance maturity model: governance and policy first, then people, technology, process, and data. That sequence reflects how examiners evaluate program maturity.

The Fraud Program uses an adversarial lens. Every finding is evaluated against the question: how would a motivated attacker exploit this? The program identifies exploitable exposures — account takeover, synthetic identity fraud, bust-out schemes, payment fraud, insider risk, and social engineering — along with detection gaps in authentication, velocity controls, behavioral analytics, and device intelligence. Remediation guidance prioritizes defensive depth: technology and detection first, working toward governance.

Both programs run on the same platform and produce the same report formats. The differentiation is in the analytical framing: one asks are we compliant?, the other asks are we defensible? If you're a BSA Officer preparing for a regulatory examination, start with AML/CFT. If your primary concern is fraud loss and attack surface, start with Fraud. Many institutions run both — financial crime compliance and fraud risk are related but distinct disciplines, and the outputs don't overlap.

Will regulators accept VeloRisk output as risk assessment documentation?

Examiners don't specify how a risk assessment must be produced — they require that it exist, that it's current, that it's risk-based, and that it covers the institution's specific risk profile. VeloRisk produces documentation structured to those requirements, mapped to the frameworks examiners actually cite (FFIEC BSA/AML, FATF 40, ACFE, NIST, and others depending on the program). The format is one regulators recognize.

Your institution's responsible officer reviews the output and attests to its accuracy — the same role they'd play with a consultant-produced assessment. What the assessment reveals about your program is up to your program. VeloRisk doesn't obscure gaps; it finds them. Going into an examination with a current, accurate assessment that identifies real issues is a stronger position than going in with a document that doesn't reflect reality.

Can vCISOs or risk consultants use VeloRisk with their clients?

Yes, and several do. VeloRisk is particularly well-suited for vCISOs, fractional CISOs, and risk consultants who manage programs for multiple client organizations. The platform handles assessment intake, framework mapping, and intelligent analysis, which frees you to focus on interpretation and advisory work. Multi-org support lets you manage multiple client organizations from one account. If you're interested in using VeloRisk in your practice, get in touch.

Still have questions?

We're here to help. Get in touch with our team.