Skip to content

Risk Ledger

Risk Ledger is a London-based third-party risk management platform that replaces one-off vendor security questionnaires with a shared network where suppliers maintain a single, continuously updated security profile.

Visit Website ↗ + Add to Compare
65/100Incremental Innovator

Overview

Risk Ledger is a London-based governance, risk, and compliance company that runs a network-model platform for third-party (supply-chain) cyber risk management. The core problem it targets is well known to any procurement or security team: every customer sends its suppliers a bespoke security questionnaire, and every supplier ends up answering dozens of near-identical questionnaires in slightly different formats. Risk Ledger’s model flips that by having each supplier maintain one standardized security profile on the network, which any customer organization on the platform can then review, monitor for changes, and benchmark against peers.

Founded in 2017 by Haydn Brooks and Daniel Saul, the company has built out its network to more than 16,000 organizations, with concentration in critical national infrastructure, financial services, insurance, and government sectors in the UK — industries where third-party and fourth-party risk is both a regulatory requirement (e.g., under the UK’s NIS Regulations and financial-sector operational resilience rules) and a practical attack surface given how many breaches originate through vendor access.

In mid-2026 Risk Ledger raised a £24 million ($32M) Series B led by Axiom Equity, bringing its total raised to roughly £33.8 million, with stated plans to expand into the US market and add AI-driven assessment and monitoring capabilities. That funding trajectory and the platform’s network effects (suppliers only need to fill out one profile to satisfy multiple customers) are a genuine structural advantage over point-in-time questionnaire tools and single-tenant TPRM software.

The company competes against both legacy GRC/TPRM vendors (OneTrust, Prevalent, ProcessUnity) and newer continuous-monitoring rating services (SecurityScorecard, BitSight); its differentiation is the shared-network model rather than either a static questionnaire tool or an outside-in ratings score, though its network effects are strongest within the UK where its base is concentrated.

Innovation Matrix Assessment

Innovation Velocity 6/10

The 2026 Series B round is explicitly earmarked partly for building new AI-driven assessment and monitoring tools, but as of this writing that roadmap is stated intent rather than shipped, independently reviewed capability.

Operational Value 6/10

A network of over 16,000 organizations onboarded, concentrated in UK critical infrastructure, financial services, insurance, and government, demonstrates the platform operates at meaningful scale for a TPRM network model.

Market Momentum 8/10

Risk Ledger raised a £24M ($32M) Series B in 2026 led by Axiom Equity, bringing total funding to roughly £33.8M, a clear and recent capital-raising signal reported by multiple independent outlets (Forbes, SecurityWeek, UKTN).

Category Disruption 6/10

The shared-network model, where a supplier fills out one profile that many customers can review, is a structurally different approach to third-party risk than static point-in-time questionnaires or outside-in security ratings, and creates real network effects as adoption grows.

Real-World Efficacy 6/10

Risk Ledger publishes its network size and sector concentration, which is a reasonable scale indicator, but does not publish independent studies quantifying reduced vendor-onboarding time or breach reduction that CDMG could verify beyond the company's own materials.

Enduring Relevance 7/10

Third-party and supply-chain risk is one of the most consistently cited breach vectors and a growing regulatory focus (UK NIS Regulations, DORA-adjacent financial resilience rules), making a network-based TPRM approach directly relevant to CISOs and procurement/risk teams alike.

Why CISOs Should Care

CISOs and vendor-risk teams drowning in duplicate security questionnaires get a single continuously-updated view of supplier risk instead of re-collecting the same information from every vendor on a different cadence.

What Makes It Different

Risk Ledger's network model means suppliers maintain one profile visible to multiple customers, unlike traditional TPRM tools where each customer-supplier relationship requires its own separate questionnaire cycle.

The Matrix Verdict

65/100 — INCREMENTAL INNOVATOR

A well-funded, UK-anchored TPRM network with genuine structural differentiation and strong recent momentum; its main open question is whether the network-effect advantage transfers as it expands into the US market where it has no existing supplier density.

Editorial Note: Claims vs. Verified Findings

The 16,000+ organization network size and sector-concentration figures are Risk Ledger's own reported numbers; the Series B amount, lead investor (Axiom Equity), and total funding raised are independently corroborated across Forbes, SecurityWeek, UKTN, and Crunchbase coverage of the same round.

Sources