The intelligence layer for modern governance

Know what matters.
Prove you're in control.

Metaris connects regulations, obligations, risks, controls and evidence, using AI to surface what needs attention, explain why, and help you act.

Built for modern governance. Designed for continuous assurance.

Command Centre — app.metaris.com

Command Centre

Good morning, Sam. Three matters require your attention today.

Third-party risk moved outside appetite

Action required

Payment processor rating downgraded after a service incident.

2 principal risks · 5 obligations

FCA regulatory update impacts four obligations

Attention

SYSC 8.1 amended outsourcing oversight requirements.

4 obligations · 3 controls

Critical control failed quarterly testing

Action required

Access recertification evidence incomplete for two systems.

1 material control · 2 risks

128

Obligations

42

Material controls

94%

Evidence complete

4

Open deficiencies

The problem

Your governance isn't disconnected.
Your systems are.

Regulations live in one place. Risks in another. Controls in GRC platforms. Evidence in SharePoint. Actions in Jira. Assurance in spreadsheets.

The relationships between them are where governance actually happens, and where traditional systems struggle.

One connected view

From regulation to assurance.

Metaris creates a connected model of your governance environment, making the relationships between requirements, risks, controls and evidence visible and usable.

Understand the requirements that shape your organisation.

Track the regulations and standards that apply to your organisation and understand when they change.

Connects to

  • 42 organisational obligations
  • 8 affected business areas
  • 3 recent regulatory changes

Understand what applies

Know your obligations. Everywhere they land.

Metaris maps regulatory requirements across your organisational structure, helping teams understand which obligations apply directly, which are inherited and where change creates impact.

Regulatory Organisation Coverage

Regulatory organisation coverage

Applicability across the group

OrganisationFCA SYSCPRAGDPRISO 27001
Group
UK Retail Bank
Wealth Management
Operations & Technology
EU Branch
Direct Inherited Not applicable

From data to attention

Don't give people another dashboard.
Tell them what matters.

Metaris continuously interprets changes across your governance environment and surfaces the issues that deserve attention.

Action required

Third-party risk moved outside appetite

Payment processor rating downgraded after a service incident.

Review appetite breach with Risk Committee

Attention

FCA regulatory update impacts four obligations

SYSC 8.1 amended outsourcing oversight requirements.

Reassess outsourcing control design

Action required

Critical control failed quarterly testing

Access recertification evidence incomplete for two systems.

Raise remediation action with control owner

Attention

Evidence missing ahead of audit

Three obligations have no evidence dated in the current period.

Request evidence from accountable owners

Metaris connects the signal to the reason, the impact and the action.

Ask Metaris

Don't search your GRC platform. Ask it.

Investigate your governance environment conversationally. Metaris answers using the regulations, obligations, risks, controls and evidence relevant to your organisation.

Why did third-party risk move outside appetite?
Which obligations are missing evidence?
What changed in FCA SYSC 8.1?
Which material controls haven't been independently assured?
What does the Board need to know this week?

Grounded, not generic.

Metaris responses are connected to underlying governance records and evidence, allowing users to trace an answer back to its source. This is the intended Metaris experience as the platform is being built.

Ask Metaris

Ask Metaris

Third-party risk moved outside appetite on 14 September following a service incident at your payments processor.

  • Risk R-104 Third-party service disruption rated High, above the tolerance set by the Risk Committee.
  • Two material controls depend on this provider; one failed quarterly testing.
  • Five obligations under FCA SYSC 8.1 reference this outsourcing arrangement.
SourcesR-104C-217SYSC 8.1Incident 3391
Attestations

Attestations

Control Owner Attestation — Q3

Completion

72%

  • Operations & TechnologyComplete
  • UK Retail BankIn progress
  • Wealth ManagementAt risk
  • EU BranchNon-responsive

Metaris insight

Two campaigns are at risk of missing the quarter-end deadline. EU Branch has not responded to three reminders and holds four material control attestations.

Governance that moves

Put accountability where it belongs.

Metaris turns governance requirements into structured activity, asking the right people, at the right time, to review, evidence and attest.

  1. Requirement
  2. Owner
  3. Action
  4. Evidence
  5. Attestation
  6. Assurance

Governance becomes a living process, not an annual exercise.

Provision 29

From annual declaration to continuous assurance.

Metaris is being designed to connect principal risks, material controls, evidence, testing, remediation and management attestation, creating a traceable basis for Board assessment.

  1. Principal risks
  2. Material controls
  3. Evidence
  4. Testing
  5. Attestation
  6. Board assessment

Provision 29 readiness

Attention required

87%

Material controls
42
Effective
37
Evidence complete
94%
Open deficiencies
4

Metaris supports management and Board assessment. It does not make the Board declaration.

Work with what you already have

Your GRC estate doesn't need replacing.

Metaris is designed to operate as your governance platform or as an intelligent layer across the systems you already use.

ServiceNow IRM

Designed

Risk and control records

SureCloud

Designed

Existing GRC estate

Microsoft 365

Planned

Evidence in SharePoint

Jira

Planned

Remediation actions

SAP

Planned

Process and financial controls

Other systems

Planned

Extensible connector model

Metaris

Connected governance model

AI · Assurance · Insight

Risks can remain in ServiceNow. Evidence can remain in SharePoint. Actions can remain in Jira. Metaris connects the relationships between them.

Integrations marked designed or planned describe intended capability and are not yet generally available.

Understand the impact of change

When the business changes, know what it triggers.

Regulated Events

Event description

We're outsourcing our UK customer support operation to a third-party provider in India.

12
Potential obligations
4
Material risks impacted
7
Required actions
3
Evidence requirements
2
Potential notifications

FCA outsourcing requirements

Material outsourcing assessment and oversight arrangements may apply under SYSC 8.1.

Data transfer assessment

Transfer of personal data outside the UK requires a documented transfer risk assessment.

Third-party due diligence

Provider assessment, contractual protections and ongoing performance monitoring.

Operational resilience assessment

Important business service mapping and impact tolerance review.

Regulatory notification consideration

Potential notification obligations ahead of the change taking effect.

Metaris is designed to assess significant business events against the organisation's regulatory and governance environment, identifying potential impacts before change becomes compliance risk.

Built for enterprise

Your cloud. Our cloud. Your choice.

Metaris Cloud

Managed multi-tenant SaaS.

Fastest route to Metaris.

Private Cloud

Dedicated customer environment managed by Metaris.

Greater isolation for enterprise requirements.

Customer Cloud

Deploy Metaris within your Azure, AWS or GCP environment.

Designed for organisations requiring greater control over infrastructure, data and approved AI services.

One Metaris platform. Multiple deployment models.

One platform. A connected governance environment.

Regulatory Intelligence

Understand regulatory requirements and change.

Obligations

Know what your organisation is required to do.

Risk

Connect risks to the obligations and controls that matter.

Controls

Understand what you're relying upon and whether it's working.

Evidence

Maintain a traceable basis for compliance and assurance.

Assurance

Test, attest and demonstrate effectiveness.

Third Parties

Understand governance dependencies across your ecosystem.

Regulated Events

Understand what organisational change triggers.

Ask Metaris

Investigate everything conversationally.

Help shape Metaris

We're building Metaris with the organisations that will use it.

We're working with governance, risk and compliance leaders to shape Metaris around real-world regulatory, assurance and control challenges.

If you're exploring Provision 29, struggling with fragmented GRC information, or considering how AI can transform governance, we'd like to hear from you.

No sales pitch required. We're interested in understanding the problems worth solving.