The big enterprise risk management systems can do everything, once the implementation project is over. 21RISK does the property-insurance work first — values, COPE, engineering reports and natcat — live in weeks, at a price you can read on the pricing page.
An enterprise RMIS is not wrong. It is built for a risk department with a systems team behind it. A risk manager with 40 sites and a renewal date needs something that works before the project plan is finished.
Scoping, configuration, consultants, go-live. By the time the system is ready, one renewal has already run in Excel — and the next one is close.
A tool built for the risk team is too much for a plant manager who logs in twice a year. So sites answer by email anyway, and someone re-keys it. The chase is back, now with a licence.
Getting numbers out means a report builder, an export request or a services ticket. Your broker still gets a spreadsheet by email, and your analytics team still works from a copy.
What the questions on an RMIS evaluation look like when the answer is a big enterprise tool, and when it is 21RISK.
| The question | In an enterprise RMIS | In 21RISK |
|---|---|---|
| Getting started | An implementation project: scoping, configuration, consultants and a go-live date. | Two Excel imports: your sites and last year’s values. Nilfisk calls it “fairly simple to implement”. |
| Who logs in | The risk team and the people who configured it. Sites get a form by email. | Every site answers in its own browser form. No install, no training course, nothing to send back. |
| Property insurance | One module among many: claims, GRC, policy administration, fleet, workers’ compensation. | Built for property insurance first: values, COPE, engineering reports, natcat from Munich Re. Claims handling is coming soon, and we say so. |
| Compliance and safety | A GRC module, configured as a second project. | Audits, findings and actions on the same sites, in the same tool, from day one. |
| Getting data out | A report builder, an export request or a services ticket. | REST API, direct Postgres access and an MCP server for your AI. Every table exports to Excel. |
| Upgrades | Release upgrades scheduled with the vendor, customisations re-tested each time. | New versions deploy daily. There is nothing to upgrade. |
| Price | Licence, implementation and services, quoted per project. | A published per-user price. Free up to 10 users; sites, audits and actions are never metered. |
Simple for the sites does not mean thin for IT. The controls procurement asks about are already there.
Security, availability, confidentiality, privacy and processing integrity, audited over time. Report and attestation letter available on request.
Learn more → SSO & SCIMSAML and OIDC sign-in, and user provisioning from Microsoft Entra — joiners get access and leavers lose it, without a ticket.
Learn more →Roles and permissions down to single sites and boards. A site sees its own values; a broker sees exactly what you invite them to.
Who changed which value, when, and what it was before. The underwriter’s question about last year has an answer.
REST API for your systems, direct Postgres for Power BI, and an MCP server for Claude, OpenAI or Copilot.
Learn more → EXTENDAudits against fire, ISO and EHS standards, findings tracked to done — no second system to implement.
Learn more →There is no implementation phase. The site list you already have is the project plan.
Bulk import the site list you already have, with its hierarchy and your own columns, from an Excel template — thousands of sites in one upload.
Bulk import users from Excel, or connect SSO and SCIM so your identity provider handles joiners and leavers. Site access decides where each person can enter values.
Pick the sites and the deadline. Sites answer in the browser, you watch the answers land, and your broker reads current values instead of waiting for a file.
| Site | SAP code | Area | Groups | Status |
|---|---|---|---|---|
| Europe | active | |||
| └Aalborg plant | DK-AAL-01 | 18,400 m² | Production · Critical | active |
| └Hamburg DC | DE-HAM-04 | 42,000 m² | Warehouses | active |
| └Lyon plant | FR-LYO-02 | 11,900 m² | Production | active |
| North America | active | |||
| └Toronto plant | CA-TOR-01 | 9,300 m² | Production | active |
| └Detroit warehouse | US-DET-03 | 7,100 m² | Warehouses | inactive |
"Given that we've taken the approach to really market our property risk in order to acquire insurance, we needed another means of collecting the information and presenting the information... There 21RISK has been a huge help"
It is property-insurance software with compliance and safety alongside, built on one site register. If your shortlist needs policy administration, fleet or workers’ compensation today, it is not the tool. Claims handling is coming soon, and we label it that way.
Weeks, not a project. Sites and last year’s values come in as two Excel imports, users as a third or through SCIM. Nilfisk describes 21RISK as “fairly simple to implement”; BHJ says “starting up with 21RISK is not a big investment”.
Sites, insurance values, COPE area values, users and responsibility assignments all import from Excel templates, with a what-if preview for values and COPE. Anything else can be written over the REST API.
A per-user price you can read on the pricing page, free up to 10 users. Sites, audits and actions are never metered. BHJ calls 21RISK “a very, very small part” of its total insurance cost.
SOC 2 Type 2 since 2024, recurring penetration tests, SSO over SAML or OIDC, and SCIM provisioning from Microsoft Entra. The enterprise page lists the documents we hand to procurement.
The data is yours. Every table exports to Excel, your analytics team can read Postgres directly, and the REST API returns everything you put in. BHJ: “the data can be exported, we own the data”.
Bring your site list and last year’s values. We will import them and run the first collection round with you on the call.