⬡ CONCEPT PROTOTYPE · INDEPENDENT VENTURE · NOT AFFILIATED WITH ANY EMPLOYER ControlPlanIQ LLC · Early-Stage Demo · controlplaniq.com
Portfolio Risk Score
64.2
↑ +3.1 from last quarter
Applications Monitored
35
◈ 8 critical · 14 high
SaaS Annual Spend
$4.7M
↓ $620K redundancy flagged
Open Risk Signals
18
↑ 5 critical unaddressed
Top Risk Applications
Highest composite risk score · Click row for details
ApplicationRisk TierControl ScoreFrameworks
Okta SSO
Identity & Access
● Critical
47
NISTNYDFS
Veeva Vault
Compliance
● High
54
FFIEC
Workday HCM
HR Technology
● High
71
SOC2ISO
Salesforce CRM
Sales & HR Ops
● High
68
NISTSOC2
Portfolio Risk Score
64.2
Moderate–Elevated
0–40 Low
41–70 Mod
71+ High
Framework Coverage
Portfolio average
NIST CSF
67%
ISO 27001
81%
FFIEC
52%
NYDFS
44%
ApplicationCategoryBusiness OwnerRisk TierControl ScoreFrameworksAnnual Cost
Critical
5
Immediate action required
High
7
Review within 30 days
Medium
4
Monitor
Informational
2
No action required
Active Risk Signals
Framework-aligned · Read-only indicator aggregation
Okta SSO — MFA enforcement gap across 3 critical applications. Identity control score below threshold (47/100). NYDFS §500.12 compliance at risk.
Identity · NYDFS §500.12 · NIST PR.AC-7 · Flagged Mar 6, 2026 · Owner: IT Security
Veeva Vault — Annual vendor attestation overdue by 47 days. FFIEC compliance coverage at 52%. Audit committee exposure elevated.
Compliance · FFIEC CAT · Flagged Feb 18, 2026 · Owner: Risk & Compliance
Workday HCM — SOC 2 Type II report expired Jan 31, 2026. Data residency confirmation pending for EU payroll module. GDPR exposure flagged.
Data Governance · SOC 2 · ISO 27001 · Flagged Mar 1, 2026 · Owner: HR Technology
Legacy CRM (×2 apps) — Duplicate CRM functionality with combined $340K spend. No clear business owner. Applications unreviewed for 18+ months.
Cost Optimization · Redundancy · Flagged Mar 3, 2026 · Owner: Unknown
Cloud Storage (×3 apps) — Three overlapping cloud storage vendors with no centralized data classification policy. Potential data residency and exfiltration risk.
Data Classification · NIST DS · Flagged Feb 28, 2026 · Owner: IT Infrastructure
Salesforce CRM — API integration with 4 downstream systems lacks formal data flow documentation. NIST CSF DE.AE-1 gap identified.
Data Governance · NIST CSF · Flagged Feb 24, 2026 · Owner: Sales Operations
Collaboration Suite (×3 apps) — Overlapping functionality across Teams, Slack, and Webex. Combined spend: $210K. Rationalization recommended.
Cost Optimization · Spend Analysis · Mar 8, 2026 · Owner: IT Operations
ServiceNow ITSM — Change management workflow not aligned to current ITIL v4 standard. 3 control gaps identified in incident logging module.
Process · ITIL v4 · ISO 20000 · Flagged Mar 5, 2026 · Owner: IT Governance
NIST CSF 2.0 Update Available — New crosswalk available for 14 applications. Portfolio alignment may improve from 67% → 74% with remapping.
Framework Update · NIST CSF 2.0 · Mar 5, 2026 · Informational
DocuSign eSign — Vendor issued security advisory for enterprise tier. Patch available. No immediate threat — monitoring recommended.
Vendor Advisory · SOC 2 · Mar 7, 2026 · Informational
NIST CSF 2.0
67%
↑ 2.0 crosswalk pending
ISO 27001
81%
↑ Strongest alignment
FFIEC CAT
52%
↓ Requires attention
NYDFS §500
44%
↓ Lowest coverage
NIST CSF 2.0 Domain Coverage
Portfolio average across 35 applications
FFIEC CAT Domain Coverage
Financial sector regulatory alignment
Framework Coverage by Application
✓ Aligned  ◒ Partial  ✕ Gap
ApplicationNIST CSFISO 27001FFIECNYDFSSOC 2
Okta SSO◒ Partial✓ Aligned◒ Partial✕ Gap✓ Aligned
Workday HCM✓ Aligned◒ Partial◒ Partial◒ Partial✕ Expired
Salesforce CRM◒ Partial✓ Aligned✓ Aligned◒ Partial✓ Aligned
Veeva Vault◒ Partial◒ Partial✕ Gap✕ Gap◒ Partial
ServiceNow ITSM✓ Aligned✓ Aligned✓ Aligned◒ Partial✓ Aligned
DocuSign eSign✓ Aligned✓ Aligned✓ Aligned✓ Aligned✓ Aligned
Splunk SIEM✓ Aligned✓ Aligned◒ Partial◒ Partial✓ Aligned
Total SaaS Spend
$4.7M
Annualized · 35 apps
Redundancy Flagged
$620K
↑ 7 applications
Low-Utilization Apps
9
◈ Under 40% active use
Optimization Potential
13%
↓ Est. $611K savings
Spend by Category
Annualized · Utilization-weighted
HR / Workforce
$1.42M
Security
$960K
CRM / Sales
$820K
Collaboration
$610K
Compliance / GRC
$490K
ITSM
$420K
Redundancy Analysis
Overlapping capabilities · Consolidation candidates
$
CRM Overlap — Salesforce + 2 legacy CRM tools. Overlapping contact management and reporting. Consolidation saves est. $340K/yr.
3 applications · Recommended: Consolidate to Salesforce
$
Collaboration Stack — Teams, Slack, and Webex all active with overlapping use cases. Est. $210K/yr consolidation opportunity.
3 applications · Recommended: Single platform evaluation
$
Cloud Storage (×3) — SharePoint, Box, and Dropbox Business running concurrently. No unified data classification policy. Est. $70K/yr savings.
3 applications · Recommended: Policy-driven consolidation
Total Optimization Potential
$620,000 / yr
Across 9 applications in 3 redundancy clusters
Low-Utilization Applications
Under 40% active use · Rationalization candidates
ApplicationCategoryAnnual CostEst. UtilizationLast Active ReviewRecommendation
Legacy CRM ACRM$180K12%18 months agoDecommission
Legacy CRM BCRM$160K18%14 months agoDecommission
Webex MeetingsCollaboration$95K31%6 months agoEvaluate
Dropbox BusinessStorage$42K27%9 months agoEvaluate