LogicGate Risk Cloud® Services Descriptions

Risk Cloud Use Cases

Standard Use Cases

Enterprise Risk Management, Third-Party Risk Management, IT Security Risk, Control Audit Management, Compliance Management, Incident Management, Issues Management, Policy Management, Regulatory Compliance, Internal Audit Management, Procurement & Contract Management, Business Continuity Management, Data Privacy.

Risk Cloud Platform

Standard Application

A Standard Application is a distinct set of rules and logic built in Risk Cloud supporting a singular use case, as determined by the LogicGate team. Live Applications are those used in a production setting and count towards the contracted Application amount.

Premium Application

A Premium Application includes access to advanced features and capabilities not natively available in Standard Applications. They are priced at a premium to reflect additional value-added features and capabilities such as: 

The following are the currently-available Premium Applications: 

  1. FedRAMP SSP Premium Application
  2. Controls Compliance Application

Power User

Power User functionality includes all Standard User abilities (see below), in addition to the ability to create, modify, and manage Applications. This includes, but is not limited to, jobs, workflows and steps. This user has “Build” permissions in Risk Cloud. This user type was previously denoted as a “Primary User.”

Standard User

Standard Users can view and interact with records, complete tasks, view home screens, view and create reports and dashboards, and view audit history of records. Standard Users cannot create or manage Applications and cannot be assigned the “Build” permission. This user type was previously denoted as a “Secondary User.”

External User

External Users can receive email notifications and perform work using unique, tokenized links. External Users do not have their own login.

 

Additional Product Features

Single Tenancy

Provides database infrastructure that is not shared with other tenants.

Single Tenancy - Healthcare

Single tenant Risk Cloud® environment provisioned for customers who (i) are designated as covered entities (e.g., healthcare providers, health insurance companies, etc.), and (ii) wish to upload and/or store protected health information (“PHI”) within such environment for use with its purchased Application(s). For clarity, purchase of this SKU requires the execution of a Business Associate Agreement (“BAA”).

Risk Cloud Documents

Provides the ability to configure document templates using a template-building tool called Formstack , and enables users to automate document generation in Risk Cloud. Includes access to up to 50 Reports and 2,000 Downloads (per month).

Risk Cloud Quantify ® Standard

Provides access to a risk quantification product designed to calculate potential loss exposure range in monetary terms for a given risk scenario. Risk Cloud Quantify Standard does not include advanced features.

Risk Cloud Quantify® Premium

Provides access to a risk quantification product designed to calculate potential loss exposure range in monetary terms for a given risk scenario. Risk Cloud Quantify Premium includes advanced features.

Public Pages

Public Pages allow you to create publicly available forms that can be submitted by anyone with the unique link.

SCIM User Provisioning

Provides access to SCIM 2.0 supported auto-provisioning that allows integration with identity management systems. Includes support for the following functions: Create, Update, and Deactivate users.

Additional Environment

Provides a customer with access to an additional, separate Risk Cloud environment that may be used in conjunction with other Risk Cloud services purchased by the same customer.

 

Implementation & Professional Services

Quick Start Implementation

Subject to required scoping, LogicGate's Quick Start Implementation Option provides up to 40 hours of hands-on configuration support for an eligible Risk Cloud Application template typically within a 45-day period from the Kickoff Date. Included in the service is:

Standard Implementation

Subject to required scoping, LogicGate's Standard Implementation Option provides up to 90 hours of hands-on configuration support for any of LogicGate's Standard Use Cases, using an official Risk Cloud Application template or a custom build, typically within a 100-day period from the Kickoff Date. Included in the service is:

Enterprise Implementation

Subject to required scoping, LogicGate's Enterprise Implementation package provides up to 200 hours of hands-on configuration support for any of LogicGate's Applications, using an official Risk Cloud Application template or a custom build, typically within a 150-day period from the Kickoff Date. This Service includes:

Enterprise Implementation - Virtual

Subject to required scoping, LogicGate's Enterprise Implementation package provides up to 200 hours of hands-on configuration support for any of LogicGate's Applications, using an official Risk Cloud Application template or a custom build, typically within a 150-day period from the Kickoff Date. This Service includes:

Custom Implementation

Subject to required scoping, LogicGate's Custom Implementation Option provides implementation services for any use case not included in LogicGate's existing implementation packages.

Implementation Scope

Each implementation option listed above can be used to cover the implementation of one Application.

Implementation Services Bundle

Ten (10) hours of access to the Risk Cloud Implementation Team. Such hours shall be used for hands-on configuration support for any of LogicGate's Standard Use Cases, using an official Risk Cloud Application template or a custom build.

Standard Success

Includes access to the LogicGate Help Center; core Risk Cloud training content on LogicGate Learning portal; in-app chat support; and updates related to the latest version of Risk Cloud Standards and Regulations Content provided to you, upon request, via spreadsheet within 120 days of a major release published by the authoritative source.
For updates to the Secure Controls Framework, content and mapping adjustments will be made according to the latest version's Errata.

Premier Success

Premier Success is a recurring service that provides customers with technical support and Power User training in Risk Cloud. Included in the Service: Premier Success Requests (PSR)

Professional Service Bundles

Ten (10) hours of access to the Risk Cloud Consultant Team, in addition to either of the Success packages listed above. Can be used for additional configuration, system administration, content update, or GRC process design and enablement support; and support with applying updates to existing control mappings for Risk Cloud Standards and Regulations Content.

Documents Report Configuration Bundles

Ten (10) hours of access to the Risk Cloud Consultant Team to provide initial setup of report(s) based on Customer-provided template(s) and basic training on how to utilize reports. Customer is responsible for providing template(s) for any report(s) created.

 

Integrations

Ascent Regulators

Each individual Regulator includes obligation, rule, and metadata for a given Ascent regulator integrated into the “Regulatory Compliance Powered by Ascent” Application within the Risk Cloud.

Ascent Banking Bundle - US

The Banking Bundle - US includes retail (consumer) banking/lending, wealth management, and business banking/lending entities, such as:

Items of Note:

The Banking Bundle - US excludes the following:

Full list of specific regulatory offerings included in this Bundle are available upon request.

Ascent Mortgage Lending Compliance Bundle

The Mortgage Lending Compliance Bundle - US includes mortgage brokerage, mortgage origination(insurance) and mortgage servicing:

Full list of specific regulatory offerings included in this Bundle are available upon request.

Ascent Credit Union Compliance Bundle

The Credit Union Compliance Bundle - US includes Retail(consumer) banking and lending and small business banking and lending:

Full list of specific regulatory offerings included in this Bundle are available upon request.

Ascent Money Transmitter Licensing & Compliance Bundle

The Money Transmitter Licensing and Compliance Bundle - US includes MTL licensing and regulation, Virtual currency licensing and regulation and Federal Financial Rights to Privacy Act:

Items of Note:

The Money Transmitter Licensing and Compliance Bundle - US  excludes the following:

Full list of specific regulatory offerings included in this Bundle are available upon request.

Ascent Consumer Lending Compliance Bundle - US

The Consumer Lending Compliance - US includes Personal, auto, private student and small business loans, Secured and Unsecured loans, Small Business Loans and Lines of credit (including personal lines and HELOCs):

The Consumer Lending Compliance - US  excludes the following:

Full list of specific regulatory offerings included in this Bundle are available upon request.

Ascent Broker-Dealer + Investment Advisor Compliance Bundle - US

The Broker-Dealer + Investment Advisor Compliance - US includes State licensing and registration, Digital assets and financial activities regulated by the SEC/CFTC:

The Broker-Dealer + Investment Advisor Compliance - US  excludes the following:

Full list of specific regulatory offerings included in this Bundle are available upon request.

Black Kite Vendor Monitoring

Includes a bucket of vendors monitored by Black Kite bringing over the Cyber Security Rating, Ransomware Index, Breach Index, Compliance Rating, Compliance Completeness, Compliance Confidence, and all FAIR scoring fields directly to the vendor level within the Risk Cloud TPRM application (“Black Kite Buckets”). Black Kite Buckets can be purchased for a quantity of 50, 100, 250, 500 or 1,000.

CUBE Regulatory Content

Includes regulatory information directly from CUBE to monitor changes within tracked regulatory bodies. These can be broken down based upon changes, obligations, and in some cases horizon scanning capabilities if this level of the CUBE platform is purchased. This data is integrated into the Regulatory Compliance application within Risk Cloud.

CUBE Regulatory Services

Custom-scoped services required for the implementation and integration of CUBE Regulatory Content.

Workato

Middleware platform utilized for Risk Cloud Connector integrations. Customer's use of Workato Services is subject to Workato's Terms of Use and Workato's Privacy Policy.

Native Integrations

Provides access to all integrations native to Risk Cloud.

API Access

Access to the RESTful API, allowing you to connect Risk Cloud to third-party tools.

Risk Cloud Connector

Pre-built connector or custom-built connector by LogicGate's Integration Services Team to connect to common SaaS platforms or GRC use cases.

Integration Service Bundles

Ten (10) hours of access to the LogicGate Integration Services Team, in addition to the Risk Cloud Connector above. Will be used to build out the integration to the exact specifications required by the Customer.

Technical Account Management

Technical Account Manager (Silver)

The Technical Account Manager (Silver) is a dedicated LogicGate resource who provides strategic and technical support for up to four (4) Applications in Risk Cloud. These four applications are to be agreed upon between the Customer and LogicGate once per contract Term Year.

Included in the Service for defined in-scope Applications:

Included in the Service for the Risk Cloud Environment:

Additional Service Details:

Technical Account Manager (Gold)

The Technical Account Manager (Gold) is a dedicated LogicGate resource who provides strategic and technical support for up to eight (8) Applications in Risk Cloud. These eight Applications are to be agreed upon between the Customer and LogicGate once per contract term year.

Included in the Service for defined in-scope Applications:

Included in the Service for the Risk Cloud environment:

Additional Service Details:

Technical Account Manager (Platinum)

The Technical Account Manager (Platinum) is a dedicated LogicGate resource who provides strategic and technical support for up to twenty (20) Applications in Risk Cloud. These twenty Applications are to be agreed upon between the Customer and LogicGate once per contract Term Year.

Included in the Service for defined in-scope Applications:

Included in the Service for the Risk Cloud Environment:

 

GRC Maturity Workshop

GRC Maturity Workshops enable LogicGate customers to assess, discuss, and plan their GRC management programs with insights and guidance from a LogicGate workshop facilitator. This engagement requires customer participation

in the following activities:

Following completion of the GRC Maturity Workshop, customers will receive these five deliverables:

  1. Final GRC Maturity Report:
    A comprehensive maturity report outlining a summary of the workshop outcomes, the customer's program maturity level and assessment findings, and solution recommendations based on priority opportunity areas.
  2. Program Roadmap:
    A custom program roadmap that details how customers can operationalize the plan to reach their target GRC maturity, both in and outside of Risk Cloud.
  3. Executive Readout:
    A presentation for the customer's executive team highlighting the current strengths of their program and outlining the support and investments required to enable their roadmap.
  4. GRC Program Value Statement:
    A defined set of core values for the customer's cross-functional GRC team that can be used as a framework for decision-making and prioritization.
  5. Use Case Map:
    A diagram that highlights the customer's GRC program connection points and outlines the path the customer can take to implement additional GRC capabilities as they mature their program over time.

v.2.19 | Last Updated: April2024