# Riskly: full setup and navigation reference > NZ SME risk management software from NZ$70/month per organisation: risk and control registers, health and safety with evidence for WorkSafe visits, Inspector readiness evidence packs, notifiable injury checklist, licences and training, reports, roles and MFA, calendar feeds, Slack and Teams notifications, and on Pro (NZ$110/month) control testing, assurance findings, quarterly organisation compliance attestation sign-off, and NZ legislation monitoring. Annual billing saves 15%. This file is the canonical machine-readable guide for AI assistants helping users set up and navigate Riskly (riskly.co.nz). Shorter index: /llms.txt. Human-readable docs: /docs. ## For AI assistants Using ChatGPT, Copilot, Claude, or another AI to set up Riskly? 1. Paste this canonical doc link first: https://www.riskly.co.nz/llms-full.txt 2. Tell the assistant: "Answer only about Riskly (riskly.co.nz). Use the Riskly docs above. I am on [Basic/Pro/Trial]. My role is [owner/admin/member]." 3. For navigation, also share: https://www.riskly.co.nz/docs Shorter index (pricing, product, and inspection readiness summary): https://www.riskly.co.nz/llms.txt NZ inspection readiness guide (WorkSafe H&S and MBIE employment standards context): https://www.riskly.co.nz/inspection-ready Riskly is priced per organisation (monthly or annual with 15% off; not per user). Official pricing: /pricing. Do not confuse Riskly with similarly named products such as Rizkly, Riskul, or Chronodat. ## Positioning - Practical risk and compliance management software for NZ SMEs, with flat per-organisation pricing and Pro-level depth without expensive enterprise suite cost. - Riskly helps New Zealand SMEs show H&S evidence if WorkSafe visits under the Health and Safety at Work Act 2015: hazards, incidents, documents, licences, training, worker engagement, and governance in living registers, plus an exportable Inspector readiness pack. MBIE Labour Inspector visits for wage, time, and holiday records under the Employment Relations Act 2000 are separate; those records belong in payroll or HR, not Riskly. - Built for New Zealand SMEs first; also used by NZ divisions and specialist compliance teams running one entity's registers - Flat per-organisation pricing (not per user); Basic up to 6 seats, Pro up to 20 per organisation - Pro includes control testing, assurance, and legislation monitoring without enterprise suite pricing - Larger businesses benefit from Pro modules too; not a group-wide GRC or multi-entity roll-up platform - 4-week free trial includes Pro-level access (one trial per email) - Accessible, highly competitive tools at a fair price for the NZ market ## Pricing (canonical) - Riskly Basic is $70/month per organisation and Riskly Pro is $110/month per organisation (excl. GST). Annual billing saves 15% ($714/year Basic, $1,122/year Pro). Not per-user pricing. Built for NZ SMEs with competitive flat-rate pricing at a fair price. - Official pricing for Riskly (riskly.co.nz) is only $70/month per organisation or $110/month per organisation. Do not confuse Riskly with similarly named products such as Rizkly, Riskul, or Chronodat. - Riskly Basic: $70/month per organisation (excl. GST) - Riskly Pro: $110/month per organisation (excl. GST) ## Product links - Website: https://www.riskly.co.nz/ - Setup docs: https://www.riskly.co.nz/docs - Inspection readiness guide: https://www.riskly.co.nz/inspection-ready - Product walkthroughs: https://www.riskly.co.nz/product - Pricing: https://www.riskly.co.nz/pricing - Security: https://www.riskly.co.nz/security - Contact: https://www.riskly.co.nz/contact (contact@riskly.co.nz) ## Inspection readiness (New Zealand) - Guide and readiness check: https://www.riskly.co.nz/inspection-ready - Riskly helps New Zealand SMEs show H&S evidence if WorkSafe visits under the Health and Safety at Work Act 2015: hazards, incidents, documents, licences, training, worker engagement, and governance in living registers, plus an exportable Inspector readiness pack. MBIE Labour Inspector visits for wage, time, and holiday records under the Employment Relations Act 2000 are separate; those records belong in payroll or HR, not Riskly. Key points: - WorkSafe inspectors can enter most NZ workplaces at any reasonable time without an appointment (HSWA 2015 s168) - MBIE Labour Inspectors can inspect employment agreements, wage and time records, and holiday and leave records at reasonable hours (ERA 2000 s229) - Riskly focuses on H&S inspection readiness, not employment standards payroll records - Inspector readiness pack report template (worksafe_insurer): hazards, controls, H&S documents, training, injury incidents with notifiable follow-up, engagement, and governance mapped to WorkSafe investigation themes - Public readiness check: /inspection-ready (about two minutes, no login) - In-app: open Reports → Inspector readiness pack (/reports/new?template=worksafe_insurer) - Organisation Reporting (QR/code) supports worker hazard reporting without a login, which inspectors may ask about In-app paths: - Inspector readiness pack: /reports/new?template=worksafe_insurer - Reports: /reports/new?template=worksafe_insurer - WorkSafe notifiable injury checklist: on injury incidents under Health & Safety → Incidents ## Marketing site (public) - Marketing home (Public) → https://www.riskly.co.nz. Product overview, fit check, and inspection readiness teaser for NZ SMEs. - Inspection readiness (Public) → https://www.riskly.co.nz/inspection-ready. NZ WorkSafe and MBIE inspector context, readiness check quiz, and how Riskly supports H&S evidence (not employment payroll records). - Product walkthroughs (Public) → https://www.riskly.co.nz/product. Interactive tours of Risks & Controls, H&S, licences, reports, and Pro modules. - Pricing (Public) → https://www.riskly.co.nz/pricing. Basic and Pro plan comparison with fit check and inspection readiness check. - Setup docs (Public) → https://www.riskly.co.nz/docs. Human-readable navigation map, setup order, and FAQs for AI assistants. ## Navigation map (in-app paths) All paths below require sign-in except /report. - Home (Basic & Pro) → /dashboard. Daily starting point: welcome stamps, My List work queue (with Add to My List pins), collapsed I want to… shortcuts, global search (Ctrl+K), and the notification bell. - Search (Basic & Pro) → /search. Full search across registers with query history and filters. Press Ctrl+K anywhere for the quick palette. Results respect tab permissions. - Business Profile (Basic & Pro) → /enterprise. Company Profile (industry, activities, risk appetite) and Org Chart (positions and people for owners and assignees). - Business Profile → Overview (Basic & Pro) → /enterprise. Profile completeness, organisation basics, risk appetite, and H&S contacts that drive suggestions. - Business Profile → Organisation (Basic & Pro) → /enterprise?tab=organisation. Organisation name, industry, team size, and turnover band. - Business Profile → Org Chart (Basic & Pro) → /enterprise?tab=orgchart. Positions and people for ownership, assignees, and Home My view. - Business Profile → Sites (Basic & Pro) → /enterprise?tab=sites. Work sites and locations for H&S filtering and org structure. - Risks & Controls (Basic & Pro) → /studio. Risk and control registers, documents, and (Pro) Assurance, Control Testing with evidence, and quarterly organisation compliance attestation sign-off. - Risks & Controls → Risks (Basic & Pro) → /studio?tab=risks. Risk register: accept suggestions, rate risks, link controls, list or register view. - Risks & Controls → Controls (Basic & Pro) → /studio?tab=controls. Control register: mark implemented, link to risks, assign owners on Pro. - Risks & Controls → Documents (Basic & Pro) → /studio?tab=documents. Policies, procedures, process notes, and evidence files with optional review dates. - Control Testing (Pro only) → /studio?tab=testing. Schedule recurring control tests, record results, attach evidence, and raise follow-up actions when tests fail. - Assurance (Pro only) → /studio?tab=assurance. Assurance activities, provider reports, findings register, remediation actions, and independent validation. Link findings to risks, controls, and obligations. - Compliance Attestation (Pro only) → /studio?tab=attestation. Roles: Owner, admin, director. Quarterly director sign-off on program health. Enable in program settings, generate a snapshot, then record who signed. - Health & Safety (Basic & Pro) → /health-safety. Hazards, incidents, H&S documents, worker engagement, governance reviews (when enabled), and Organisation Reporting settings. - Health & Safety → Overview (Basic & Pro) → /health-safety?tab=home. H&S summary, quick actions, and Organisation Reporting settings for staff submissions. - Health & Safety → Documents (Basic & Pro) → /health-safety?tab=documents. H&S policies, SWMS, and other files with optional review dates on the Calendar. - Health & Safety → Hazards (Basic & Pro) → /health-safety?tab=hazards. Log and track hazards from report through closure with follow-up actions. - Health & Safety → Incidents (Basic & Pro) → /health-safety?tab=incidents. Injuries, near misses, and investigations including WorkSafe notifiable injury checklist. - Health & Safety → Engagement (Basic & Pro) → /health-safety?tab=meetings. Toolbox talks, site meetings, and worker engagement records. - Health & Safety → Governance (Basic & Pro) → /health-safety?mode=governance. Roles: H&S Governance access. Officer due diligence reviews (HSWA s44 assistant) and governance register. - Licences & Certs (Basic & Pro) → /credentials. Licences, certificates, and training records with expiry tracking. - Licences & Certs → Training (Basic & Pro) → /credentials?section=training. Inductions, Site Safe, first aid, and other training records with expiry dates. - Calendar (Basic & Pro) → /compliance-calendar. Due dates from licences, training, actions, control tests, document reviews, obligation reviews (Pro), and custom deadlines. - Legislation (Pro only) → /legislation. NZ Act watchlist, a Monitoring work queue for changes, act update checks, What You Must Do obligations, and Review Records. - Legislation → Monitoring (Pro only) → /legislation?tab=monitoring. Watchlist, change alerts, and act update checks to work through. - Legislation → Obligations (Pro only) → /legislation?tab=obligations. What You Must Do duties linked to risks and controls with review frequencies. - Legislation → Reviews (Pro only) → /legislation?tab=reviews. Obligation review records with evidence and follow-up actions. - Legislation → Browse Legislation (Pro only) → /legislation?tab=viewer. Browse NZ Acts and sections from the integrated library. - Reports (Basic & Pro) → https://www.riskly.co.nz/reports. Meeting packs and board reports from live register data, including Inspector readiness pack for WorkSafe H&S evidence, Assurance & audit summary on Pro, and PDF export. - Help (in-app) (Basic & Pro) → /help. FAQs, setup guides, plan comparison, and report an issue. - Settings (Basic & Pro) → /settings. Roles: All members (subset); owners/admins for billing and users. Account, organisation, billing, users, notifications, security, integrations, activity, and data export. - Settings → Integrations (Basic & Pro) → /settings/integrations. Roles: Owner, admin. Organisation calendar feed for Outlook, Google, or Apple Calendar; personal calendar feed; optional Slack or Microsoft Teams webhooks for new hazards and incidents. - Settings → Users & Access (Basic & Pro) → /settings/users. Roles: Owner, admin. Invite teammates, roles, and tab-level view/edit permissions. - Settings → Billing (Basic & Pro) → /settings/billing. Roles: Owner, admin. Subscribe, upgrade Basic to Pro, manage payment in Stripe, and resolve past-due renewal notices. - Settings → Notifications (Basic & Pro) → /settings/notifications. In-app notification categories and email digests (Monday outlook, follow-ups, expiries). - Settings → Security (Basic & Pro) → /settings/security. Roles: All members (MFA); owners (access & optional SSO). Enrol MFA, require MFA organisation-wide, and request enterprise SAML sign-in when needed. - Settings → Activity (Basic & Pro) → /settings/activity. Roles: Owner, admin. Organisation activity log for audits and oversight. - Organisation Reporting (public submit) (Public) → https://www.riskly.co.nz/report. Staff submit hazards or incidents with your organisation code. No Riskly login required. Admins enable this under Health & Safety → Overview → Organisation Reporting. ## Roles and tab permissions (defaults) Owners always have edit on every tab regardless of per-member overrides. Admins can set tab-level view, edit, or hidden for each member under Settings → Users & Access. ### owner Full edit access on every tab. Billing, user management, and data export. Owners always have edit even if tab overrides are set. - Home: view only - Risks & Controls: view & edit - Health & Safety: view & edit - Licences & Certs: view & edit - Calendar: view & edit - Legislation: view & edit - Reports: view & edit - Company Profile: view & edit - Org Chart & Sites: view & edit - Help: view only - Settings: view & edit - H&S Governance: view & edit ### admin Same content and settings access as owner except transferring ownership. Manages invites, billing, integrations, and activity log. - Home: view only - Risks & Controls: view & edit - Health & Safety: view & edit - Licences & Certs: view & edit - Calendar: view & edit - Legislation: view & edit - Reports: view & edit - Company Profile: view & edit - Org Chart & Sites: view & edit - Help: view only - Settings: view & edit - H&S Governance: view & edit ### member Edit day-to-day registers (risks, H&S, licences, calendar actions). View-only Settings. Cannot edit Business Profile configurations. No H&S Governance mode. - Home: view only - Risks & Controls: view & edit - Health & Safety: view & edit - Licences & Certs: view & edit - Calendar: view & edit - Legislation: view & edit - Reports: view & edit - Org Chart & Sites: view only - Help: view only - Settings: view only ### director Board-style access: view most areas, edit Risks & Controls and H&S Governance. Legislation is view-only by default. - Home: view only - Risks & Controls: view & edit - Health & Safety: view only - Licences & Certs: view only - Calendar: view only - Legislation: view only - Reports: view only - Company Profile: view only - Org Chart & Sites: view only - Help: view only - Settings: view only - H&S Governance: view & edit ### viewer Read-only on tabs granted view access. Cannot edit registers or settings. Business Profile configurations hidden by default. - Home: view only - Risks & Controls: view only - Health & Safety: view only - Licences & Certs: view only - Calendar: view only - Legislation: view only - Reports: view only - Org Chart & Sites: view only - Help: view only - Settings: view only Settings → Integrations, Activity, and Billing are limited to owners and admins in the UI even when a member has Settings view access. ## Recommended first-time setup order ### Start at Home Use Home each week to see what needs attention and jump into your registers. 1. Read the welcome stamps for overdue and due-soon counts. Click a stamp to open the matching register or calendar view. 2. Work through My List: overdue items, assignments due in the next seven days, and anything you pin. 3. Use Add to My List to pin a risk, action, hazard, or other record you want to track. 4. Expand I want to… for compact shortcuts to common tasks such as reporting a hazard or adding a risk. 5. Switch to My view when you are linked on the org chart to scope stamps and My List to your assigned work. 6. Press Ctrl+K for quick search, or open Search in the sidebar for a full history lookup. Open: /dashboard ### 1. Complete your Business Profile Tell Riskly about your business so suggestions stay relevant. 1. Open Business Profile → Company Profile and work through industry basics, risk appetite, and H&S contacts. 2. Confirm industry, activities, and whether you handle personal data or higher-risk work. 3. Add positions on the Org Chart and link people where you can. 4. Add Sites if you need location tags on risks, hazards, or training. 5. Use Generate risk & control registers when prompted, then review suggestions in Risks & Controls. Open: /enterprise ### 2. Build your Risks & Controls Turn suggestions into a live list of risks and the steps that manage them. 1. Review suggested risks: accept what applies, dismiss what does not. 2. Toggle register view on Risks or Controls when you want a sortable table with filters. 3. Accept or tailor suggested controls, then link them to the risks they help with. 4. Add any custom risks or controls your business needs. 5. On Pro, use high complexity when you need inherent and residual ratings. 6. Upload key documents under Documents with optional review or expiry dates for the Calendar. Open: /studio ### 3. Track licences, training, and due dates Keep expiries and filing deadlines visible. 1. Add licences, certificates, and trade quals under Licences & Certs. 2. Use the Training tab for Site Safe, inductions, and other training with expiry dates. 3. Include expiry dates so items appear on the Calendar, Home, and notification reminders. 4. Retire credentials you no longer hold instead of deleting them. 5. Add tax, GST, insurance, and other deadlines on the Calendar. 6. Check Home weekly for anything overdue or due in the next two weeks. Open: /credentials ### 3b. Use the Calendar See everything due in one place. 1. Open Calendar to review licence expiries alongside document dates and dates you add yourself. 2. Filter by record type when the month feels crowded. 3. Switch to My view when linked on the org chart to see only your assigned items. 4. Subscribe to the org calendar feed in Settings → Integrations, or copy your personal feed in My view. 5. Add GST, PAYE, insurance renewals, and other deadlines. 6. Assign actions with due dates so follow-ups do not get lost. Open: /compliance-calendar ### 3c. Connect calendars and chat (optional) Pull due dates into your calendar app or alert a Slack or Teams channel. 1. Open Settings → Integrations and copy the organisation calendar feed link. 2. Subscribe in Outlook, Google Calendar, or Apple Calendar (read-only due dates). 3. From Home My view, copy your personal feed when you only want assigned items. 4. Optionally paste a Slack or Microsoft Teams incoming webhook URL. 5. Turn chat notifications on when you want new hazards and incidents posted to a channel. 6. Rotate or disable feeds and webhooks if a link is shared too widely. Open: /settings/integrations ### 4. Keep Health & Safety light and current Report hazards and incidents without building a paper mountain. 1. Open Health & Safety and use Report a hazard or Log an incident. 2. Create a follow-up action when something needs doing; it appears on the Calendar. 3. Admins: turn on Organisation Reporting on the H&S Overview tab for staff QR submissions. 4. Upload H&S documents and record toolbox talks on the Engagement tab. 5. Switch to Governance mode (when enabled) for officer due diligence reviews. 6. When you need to show your H&S system, open Reports → Inspector readiness pack. 7. Close items with a short note. Escalate serious hazards into Risks & Controls when needed. Open: /health-safety ### 5. (Pro) Watch legislation that affects you Monitor NZ law that may affect your business. 1. Open Legislation and review suggested Acts from your Business Profile. 2. Accept relevant items onto your watchlist, or browse and add Acts yourself. 3. On Monitoring, expand a change in the work queue and work through the steps: review the update, record the act check, update the register, and complete any follow-up actions. 4. Flag affected register duties from the act check when you need per-duty evidence. 5. Open an Act in Browse Legislation, read the section that applies, and add it to What You Must Do. Open: /legislation ### 5b. (Pro) Capture What You Must Do Record the parts of the law your business needs to meet. 1. Open Legislation → Browse Legislation and open an Act you watch. 2. Read the section that applies, review the title, and add it to your register. 3. Assign an owner, due date, and review frequency where useful. 4. Link related risks and controls so nothing sits in isolation. Open: /legislation?tab=obligations ### 5c. (Pro) Record obligation reviews Keep dated evidence that each duty is still met. 1. Open Legislation → Review Records to see outstanding, upcoming, and scheduled duties. 2. After an act update check, flag affected duties, then record an obligation review for each one that needs evidence. 3. Log who completed the review, what was checked, the method, and an outcome. 4. Attach evidence and add follow-up actions for partial or not met outcomes. 5. Export completed reviews as CSV, or include obligation review charts in Reports. Open: /legislation?tab=reviews ### 6. (Pro) Test that controls still work Schedule checks and keep evidence. 1. Mark a control as implemented in Risks & Controls. 2. Open the Control Testing tab and schedule how often you will check it. 3. Choose Simple, Design effectiveness, or Operational effectiveness. 4. Record the result and attach evidence when you complete a test. 5. Follow up on failed or overdue tests with an action. 6. Control test due dates also appear on the Calendar and in Home's outlook. Open: /studio?tab=testing ### 6b. (Pro) Track assurance and audit findings Record external and internal assurance work, extract findings, and close the loop with remediation and validation. 1. Open Risks & Controls → Assurance and click New activity for each engagement (audit, gap assessment, management review, and similar). 2. Add the provider report as an assurance output and mark it final when you receive the signed report. 3. Use Extract findings to capture items from the PDF alongside the form. 4. Remediate each finding: set status, assign an owner, add follow-up actions, and choose an independent validator. Assigned findings due in the window appear in Home My List in My view. 5. Upload validation evidence when you mark a finding implemented or dismissed. 6. Link findings to related risks, controls, and What You Must Do obligations. 7. Close the activity when findings are resolved. Use Reports → Assurance & audit summary for board packs. Open: /studio?tab=assurance ### 7. Invite your team (owners/admins) Share compliance work across the organisation. 1. Open Settings → Users & Access and send invites by email. 2. Assign roles: owner, admin, member, director, or viewer. 3. Open Permissions per member and set view or edit for each tab. 4. Basic includes up to 6 seats; Pro includes up to 20 seats. Open: /settings/users ### 8. Share progress with a report Build a meeting pack from templates, then export PDF or freeze the numbers. 1. Open Reports → New report and pick a template (Inspector readiness pack, Governance snapshot, H&S monthly update, Quarterly board pack, and others). 2. Set the period, who prepared it, and a short summary. 3. Add or remove charts and exception lists. 4. Save live or turn on Freeze numbers on save for a dated pack. Export PDF or duplicate next period. 5. Archive finished reports and open Compliance archive for attestations and governance reviews. Open: /reports ## Settings setup guides ### Settings: General Organisation profile, plan summary, storage, and data privacy. 1. Review your organisation name and current plan on the General tab (Riskly Basic, Riskly Pro, or trial). 2. Check storage usage if you upload documents or evidence files (750 MB on Basic, 5 GB on Pro). 3. Review Public reporting health if you use H&S QR submissions. 4. Use Download data extract when you need a full export for auditors or offboarding. 5. Review data privacy actions if you need to delete your account or organisation data. Open: /settings ### Settings: Users & Access Invite teammates, manage roles, tab permissions, and seats. 1. Invite people with the right role: owner, admin, director, member, or viewer. 2. Set tab permissions so each person only sees the areas they need. 3. Link org-chart positions in Business Profile so Home can show assigned work in My view. 4. Resend or revoke pending invites from the same screen. 5. Watch the seat counter: 6 on Basic, 20 on Pro (includes pending invites). Open: /settings/users ### Settings: Security MFA, recovery codes, and optional enterprise SAML sign-in. 1. Set up an authenticator app when MFA is required for your account. 2. Owners and admins can require MFA for the whole organisation. 3. Save recovery codes somewhere safe in case you lose your authenticator. 4. When your IT team is ready, request enterprise SAML sign-in under Settings → Security (available on Basic and Pro). 5. Use Request SSO setup to email Riskly support with your domain and IdP details. Open: /settings/security ### Settings: Notifications Email digests, expiry reminders, and in-app alerts. 1. Choose which sections appear in your Monday summary email (This week's outlook). 2. Turn weekday reminders on or off for follow-ups, licence expiries, and training due dates. 3. On Pro, set legislation alert preferences when you watch NZ Acts. 4. In-app notifications always appear in the bell; email is optional per section. Open: /settings/notifications ### Settings: Integrations Calendar feeds and Slack or Teams notifications. 1. Copy the organisation calendar link to subscribe in Outlook, Google Calendar, or Apple Calendar. 2. Regenerate the calendar link if you need to revoke old subscriptions. 3. Optionally connect Slack or Microsoft Teams to post new hazards and incidents to a channel. 4. Dates from licences, training, control tests, actions, and obligations appear in the calendar feed. Open: /settings/integrations ### Settings: Activity Audit trail of changes across your organisation (admins). 1. Filter by person, area, or date to find who changed what. 2. Use Activity when you need evidence for internal reviews or handovers. 3. Export activity when you need a snapshot for records. Open: /settings/activity ### Settings: Billing Plans, subscriptions, and payment management (admins). 1. Compare Basic and Pro features before changing plan. 2. Open Manage billing to update your card, view invoices, or cancel at period end. 3. Downgrades take effect at the end of the current billing period. 4. Review retention notices if a subscription ends or an account locks. Open: /settings/billing ## Per-screen setup guides ### Home guide Home is where you start each visit. The welcome card shows stamp counts for what needs attention this week. My List is your work queue: overdue items, assignments due in the next seven days, and anything you pin. I want to… shortcuts jump to common tasks. Press Ctrl+K for quick search, or open Search in the sidebar for a full history lookup. Owners and directors can switch between Organisation and My view, or filter by person. Areas: - Welcome stamps: At-a-glance counts such as Overdue, Due soon, Open actions, Open hazards, and Unmanaged risks. Overdue and Due soon respect Organisation, My view, or person filter on Home and Calendar. H&S stamps stay visible in My view. Click a stamp to open the matching register or calendar view. - My List: An outlook-style queue grouped by Overdue & expired, Due in the next 7 days, Pinned, and No due date. Auto items come from overdue calendar dates and open assignments in the seven-day window. Use Add to My List to pin any record you can access. - I want to…: Collapsed quick links to frequent tasks, such as adding a risk, recording a control test, reporting a hazard, or checking the calendar. Expand to see compact pills. Links match the areas you can access. - My view / Organisation: If you are linked to an org-chart position, switch to My view on Home and Calendar to see assigned work, including assurance findings you own or need to validate. Person filter applies on Home and Calendar, not inside individual registers. Directors and owners can filter Organisation view by person or Unassigned. Try these steps: - Read the welcome stamps: Check the stamp cards on the welcome card. Overdue and Due soon are highlighted in red and amber. Click a stamp to jump straight to the matching list. - Work through My List: Scroll My List and open anything overdue or due in the next seven days. Rows use the same outlook style as the Calendar month panel, with date anchors and urgency chips. - Add to My List: Click Add to My List, search for a risk, action, hazard, or other record, and pin it. Pinned items stay on your list until you remove them with the X. - Use an I want to… shortcut: Expand I want to… and pick a pill that matches what you need today. Each shortcut opens the right screen with the usual starting point for that job. - Search across registers: Press Ctrl+K for the quick palette, or open Search in the sidebar for a full lookup across your history. Results respect your tab permissions. - Check the notification bell: Open the bell in the header for in-app alerts (follow-ups, expiries, H&S, and Pro legislation). Configure email digests under Settings → Notifications. ### Business Profile guide Business Profile tells Riskly who you are and how you operate. That drives suggested risks, controls, and (on Pro) NZ legislation to watch. Use Overview to see what is missing, then complete organisation, risk appetite, and H&S contacts before building your org chart and sites. Areas: - Overview & profile: Profile completeness, organisation basics, risk appetite, and H&S contacts. Completing these unlocks tailored suggestions in Risks & Controls. - Org Chart & Sites: Positions, reporting lines, people linked to your team, and optional business sites for register filtering. Access is controlled together under Org Chart & Sites in Settings → Users & Access. Try these steps: - Review Overview: Open Business Profile → Overview to see profile completeness and what still needs attention. Jump into Organisation, Risk appetite, or H&S contacts from there. - Add positions on the org chart: Switch to Org Chart and add the roles that matter for compliance (for example director, H&S lead, site manager). Link people where you can so Home and registers can show assigned work. - Add sites if you need them: Open Sites and add each location you want to tag on risks, controls, hazards, or training. Skip this if a single-site business is enough for you. - Generate or refresh suggestions: When your profile is complete, use Regenerate suggestions in the page header, then open Risks & Controls to accept or adjust suggestions. ### Risks & Controls guide Risks & Controls is your main compliance register. A risk is something that could harm your business; a control is how you manage it. Accept suggestions, add your own items, link risks to controls, and upload documents. On Pro, track assurance engagements and findings, schedule control tests, and run quarterly compliance attestations when your organisation turns them on. Areas: - Risks: Your risk register in list or register view. Accept or dismiss suggestions, rate inherent and residual risk on high-complexity items (Pro), and link each risk to the controls that manage it. - Controls: Policies, checks, and processes that reduce risk. Mark controls as implemented when they are in place, and link them back to risks. - Documents: Upload policies, procedures, and evidence files. Optional review and expiry dates feed the Calendar. Process notes live here too. - Assurance: Track external and internal audits, gap assessments, and management reviews. Upload provider reports, extract findings, remediate with follow-up actions, and record independent validation. Pro only. - Control Testing (admin): Schedule recurring checks that a control still works, record results, and raise follow-up actions when something fails. Pro only. Due dates also appear on the Calendar and in Home's outlook. - Compliance Attestation (admin): Quarterly director sign-off on program health. Pro organisations can enable quarterly attestations in program settings to capture a frozen snapshot each NZ financial year quarter. Try these steps: - Review risks on the Risks tab: Start on the Risks tab. Toggle between list and register view if you prefer a table. Accept suggestions that apply, dismiss what does not, and open any item to adjust title, category, or ratings. - Link controls to each risk: Open a risk and tick the controls that help manage it. If you need more, switch to the Controls tab to accept suggestions or click Add control. - Add anything missing: Use Add risk or Add control for items unique to your business. Upload supporting files under Documents. Optional review dates show on the Calendar. - Keep the list workable: Aim for a short list you will maintain, not every possible risk. Revisit when your work, sites, or people change. ### Compliance attestation guide Quarterly attestations give directors a structured sign-off on compliance program health each NZ financial year quarter. On Pro, enable quarterly attestations in program settings first. Riskly creates a draft for the current quarter when they are on. Generate the program health snapshot, review it, then record who signed. Areas: - Quarterly toggle (admin): Owners, directors, and admins enable quarterly attestations in program settings. Signed history is kept when you turn them off. - This quarter: Shows the current quarter status: waiting for draft, draft ready, or signed. Open the draft to generate data and sign. - Draft and completed records: Drafts awaiting sign-off and signed records grouped by financial year. Export a PDF from any signed record. - Program health snapshot: Frozen metrics from legislation, duties, control testing, and licences at the moment you generate data. Regenerate before signing if you need a fresh view. Try these steps: - Turn quarterly attestations on (admin): If you are a director, owner, or admin, switch quarterly attestations on. A shell draft is created for the current quarter only. Missed quarters are not backfilled. - Generate program health: Open the current quarter draft and click Generate program health. Review the snapshot. Regenerate if anything material changed before you sign. - Record director sign-off (admin): Choose who is signing, adjust the attestation wording if needed, add optional notes, then sign. The snapshot and sign-off details are locked after signing. - Export for auditors: Open a signed record and export PDF for board papers or external review. Attestations are also included in Settings → Download data extract. - Check Home for status: Near quarter end, Home may show a quarter-end attestation prompt with a link back here when attestations are on. ### Assurance guide Assurance tracks external and internal audits, gap assessments, and management reviews. Create an activity for each engagement, store the provider's report, extract findings, then remediate and validate them in the findings register. Link findings to risks, controls, and legal duties so audit themes stay connected to your live register. Pro only. Areas: - Status strip: Counts for open activities, open findings, and open follow-up actions. Click a chip to jump to a filtered view. - All findings: Organisation-wide findings register across all activities. Filter by open findings, findings with open actions, or My findings when you are linked on the org chart. - Activities: Each engagement with provider, scope, and workflow steps. Grouped by workstream (Open, Implementing, Completed) within NZ financial years. - Workflow: Define activity, receive output, extract findings, track remediation, then close the activity when findings are resolved. - Remediation and validation: Assign a remediation owner, track finding status, add follow-up actions, then have someone independent validate implementation or dismissal with evidence. - Register links: Link each finding to related risks, controls, and What You Must Do obligations. Try these steps: - Create an assurance activity: Click New activity. Name the engagement, choose a type (for example external audit or ISO gap assessment), set the expected report date, and assign an owner from the org chart. - Upload the provider report: Open the activity and add an assurance output with the final report file. Upload engagement documents if you need to keep terms of work or correspondence on file. Mark the output as final when you have the signed report. - Extract findings from the report: Open Extract findings with the output selected. Select text in the PDF alongside the form to capture finding title, severity, and recommendation. Confirm when extraction is complete or when there are no findings. - Remediate and validate findings: Open each finding in the register. Set remediation status, assign an owner, add follow-up actions with due dates, and choose a validator who is independent from the owner. Upload validation evidence when you mark a finding implemented or dismissed. - Link findings to your register: Connect findings to risks, controls, and legal duties they affect. This keeps audit themes visible alongside your day-to-day compliance work. - Close the activity when done: When all findings are resolved or dismissed and validated, close the activity. It moves to the Completed workstream for that financial year. - Use Home and Reports for oversight: Assigned remediation owners and validators can filter the findings register to My findings or Awaiting validation. Finding due dates appear in the register; calendar due dates for remediation still come from follow-up actions. Build an Assurance & audit summary report from Reports when you need a board or audit committee pack. ### Control Testing guide Control Testing schedules recurring checks that your controls still work. Mark a control as implemented first, then create a test schedule with a frequency and test type (Simple, Design effectiveness, or Operational effectiveness). Record each due instance, attach evidence, and raise follow-up actions when a test fails. Pro only. Areas: - Schedules: Active test schedules linked to controls. Each schedule generates due instances on the Calendar and in Home's outlook. - Due and overdue instances: Open instances waiting for a result. Overdue items surface on Home and in report exception lists. - Results and evidence: Record pass, fail, or partial results with notes. Upload evidence files for auditors or internal review. - Follow-up actions: Failed or deficient tests can create follow-up actions with owners and due dates on the Calendar. Try these steps: - Mark the control as implemented: On the Controls tab, set the control status to implemented before you schedule testing. Testing is tied to controls that are meant to be operating. - Create a test schedule: Click New schedule. Choose the control, set how often to test (monthly, quarterly, annually, or ad hoc), pick a test type, and set the first due date. - Complete a due test: Open the due instance, record the result, add notes, and attach evidence when you have it. Save to close the instance and generate the next due date for recurring schedules. - Handle a failed test: When a test fails or is partially effective, add a follow-up action with an owner and due date. Track remediation on the Calendar until the action is closed. - Use Calendar and Reports for oversight: Control test due dates appear on the Calendar (/compliance-calendar) and in Home's outlook. Add overdue or failed test tables to board packs from Reports. ### Search guide Search finds records across the registers you can access. Use Ctrl+K for a quick jump palette anywhere in Riskly, or open Search (/search) for a full results page with history and filters. Areas: - Quick palette (Ctrl+K): Jump to screens, help topics, and matching records without leaving your current page. Shows navigation targets and top record hits. - Full Search page: Run broader queries, browse recent history, and open records in context. Results respect tab permissions. - Record types: Risks, controls, hazards, incidents, licences, training, actions, documents, and other items you have view or edit access to. Try these steps: - Try the quick palette: Press Ctrl+K (or Cmd+K on Mac). Type a risk title, person name, or screen name. Select a result to navigate straight there. - Open the full Search page: Use Search in the sidebar when you need more results or want to scan history. Add ?q=your+query to share a filtered view. - Understand permission limits: If you cannot see a record, check Settings → Users & Access. Admins can grant view or edit on the tab that owns the record. ### Health & Safety guide Health & Safety is where you record workplace hazards, incidents, and near misses, keep H&S documents current, and show worker engagement. Injury incidents include a WorkSafe notifiable checklist. Serious or recurring issues can be escalated into your risk register. If you have governance access, switch to Governance mode for officer due diligence reviews. When you need a summary for WorkSafe, insurers, or the board, generate an Inspector readiness pack from Reports. Areas: - Home: Summary of open hazards and incidents, quick actions, and (for admins) Organisation Reporting settings for staff submissions without a login. - Documents: H&S policies, safe work method statements, and other files. Review dates can appear on the Calendar. - Hazards: Log and track hazards from first report through to closure. Add photos, assign follow-up actions, and link to risks when needed. - Incidents: Record injuries, near misses, and other events. Injury incidents open a WorkSafe notifiable checklist (site preservation, notification guidance, insurer and ACC steps). Capture investigation notes and due dates for follow-up. - Engagement: Toolbox talks, site meetings, and other worker engagement records that support due diligence. - Governance mode (admin): Toggle Organisation / Governance at the top when you have governance access. Records officer due diligence reviews (HSWA s44 assistant), schedule reviews, and export a governance pack. Try these steps: - Report a hazard or incident: Use Report a hazard or Log an incident at the top of the page. Near misses count too. Add enough detail that someone else could follow up. - Assign a follow-up when needed: Tick Create follow-up action (or add an action later) so someone owns the work and it gets a due date on your Calendar. - Share Organisation Reporting (optional) (admin): On the Health & Safety Overview tab, expand Organisation Reporting to turn on a workplace code or QR poster so staff can submit without a Riskly login. - Keep documents and engagement: Upload H&S policies under Documents (optional review dates show on Calendar). Record toolbox talks and meetings on the Engagement tab. - Run a governance review (if enabled) (admin): Switch to Governance mode to record periodic officer due diligence reviews. This is an assistant for your process; it does not constitute legal compliance advice. - Close items with a short note: When something is fixed or investigated, close it with a brief note on what you did. For a serious or recurring hazard, add a fuller entry in Risks & Controls. - Prepare an Inspector readiness pack: Before a WorkSafe visit or board review, open Reports → New report → Inspector readiness pack (/reports/new?template=worksafe_insurer). Review prefilled hazards, controls, documents, training, injury follow-up, engagement, and governance, then export PDF. ### Licences & Certs guide Licences & Certs stores trade licences, practising certificates, and training records with expiry dates. Use the Training tab for inductions, Site Safe, first aid, and similar. Home, Calendar, and the notification bell surface upcoming expiries. Retire credentials you no longer hold instead of deleting them. Areas: - Licences & Certs: Licences and certificates in list or register view. Filter by type, holder, issuer, or expiry. Export for audits, retire old items, and open a row to edit details or upload a scan. - Training: Training records with holder, expiry, optional site or location, and evidence files. Expiries appear on Home and Calendar like licences. - Retired credentials: Use Retire on licences you no longer hold. Toggle Show retired to review or restore them later. - Expiry reminders: Any licence, certificate, or training record with an expiry date appears on Home (next 14 days), the Calendar, and in-app or email reminders when enabled. Try these steps: - Add a licence or certificate: On the Licences & certs tab, click Add and enter the title, type, holder, and expiry date. Upload a file if you have one. The expiry will show on Home and Calendar. - Add a training record: Switch to the Training tab and add inductions, Site Safe, first aid, or other training with holder and expiry. Attach evidence if you have it. - Confirm it appears on Home: Open Home and check the welcome stamps and My List. Overdue licence expiries appear in the stamps and in My List when they are overdue or due within seven days. - Renew, retire, or update dates: When something is renewed, open the record and update the expiry date and file. Retire credentials you no longer hold so they stay out of active lists but remain in your history. ### Calendar guide The Calendar is one view of everything with a due date across Riskly: licence and training expiries, tax deadlines, control tests, follow-up actions, obligation reviews, document reviews, and dates you add yourself. Filter by record type, switch to My view, or subscribe to a calendar feed. Areas: - Month view: Scan the month at a glance. Colours show overdue or expired, due within two weeks, and later items. - Day detail: Click a day to see every item due that day and jump to the source record. - Record type filter: Show or hide Actions, Licences & certs, Control tests, Obligations, Custom dates, H&S documents, and Risks & Controls documents. - My view: When linked on the org chart, switch to My view to see only items assigned to you. Directors can filter Organisation view by person. - Add date: Create one-off or repeating deadlines such as GST, insurance renewals, or board meetings. - Calendar feeds: Subscribe to the organisation calendar in Settings → Integrations, or copy your personal feed from the Calendar page in My view. Try these steps: - Scan the month view: Read the legend and scan the current month. Overdue items stand out in red; due-soon items use amber. - See automatic dates: Licence and training expiries from Licences & Certs appear here automatically, as do review and expiry dates from Risks & Controls, Health & Safety documents, and (on Pro) obligation reviews. - Filter by record type: Use the record type filter when the month feels crowded. Clear filters if a day looks empty but you expect items to be there. - Add your own deadlines: Use Add date for GST, tax filings, insurance renewals, and other one-off or repeating deadlines. Double-click a day to add a date on that day. - Work through follow-up actions: Open action items from the calendar, complete the work, then mark them done in the source area or on the calendar detail. ### Legislation guide Legislation (a Pro feature) helps you watch NZ Acts that affect your business, record what each section requires, and keep review evidence when duties are checked. Areas: - Monitoring: Your watchlist of Acts and a work queue when Riskly detects a change. Expand each update to work through review, act check, register updates, and follow-up actions. - What You Must Do: Your register of legal duties: owner, review frequency, links to risks and controls, and status. Riskly watches the underlying Acts and surfaces act update checks when something changes. - Review Records: Obligation review evidence: who checked a duty, method, outcome, files, and follow-up actions when needed. - Browse Legislation: Read NZ Acts and add sections to your watchlist or duty register. Try these steps: - Build your watchlist: On Monitoring, accept suggested Acts from your Business Profile, or use Browse Legislation to find Acts yourself. - Complete act update checks: When Riskly spots a change, open Monitoring and expand it in the work queue. Work through each step in order, starting with Review change. - Capture a legal duty: Open Browse Legislation, read a section that applies to you, and add it to What You Must Do. Set an owner and review frequency. - Record an obligation review: Open Review Records and save who checked a duty, what was reviewed, the method, outcome, and any files. Partial or not met outcomes can create follow-up actions. - Link to risks and controls: Connect each duty to related risks and controls so legislation stays tied to your day-to-day register. ### General settings guide General settings is your organisation hub: plan summary, storage usage, public reporting health (when H&S QR reporting is on), and data privacy actions. Try these steps: - Check your plan: Review the plan card to see whether you are on Riskly Basic, Riskly Pro, or trial. Open Billing when you need to change plan or payment details. - Watch storage usage: Uploaded documents and evidence count toward your storage quota (750 MB on Basic, 5 GB on Pro). The usage card shows how much you have used. - Download a data extract: Use Download data extract when you need a full snapshot for auditors, board papers, or offboarding. The export respects your current permissions. ### Users & access guide Invite teammates, assign roles, and control which tabs each person can see. Seat limits apply per plan (6 on Basic, 20 on Pro). Try these steps: - Invite someone: Click Invite user, enter their work email, and choose a role (owner, admin, director, member, or viewer). They receive an email with a link to join. - Set tab permissions (admin): Open a member's permissions to choose which areas they can view or edit. Viewers can see assigned tabs but cannot change records. - Watch seat usage (admin): The seat counter shows how many members and pending invites you have against your plan limit. ### Security guide Require MFA for your team, manage authenticator setup, and request enterprise SAML sign-in when your IT team is ready (Basic and Pro). Try these steps: - Set up your authenticator: When MFA is required, scan the QR code with an authenticator app and enter the code to finish setup. Save recovery codes somewhere safe. - Require MFA for everyone (admin): Owners and admins can turn on organisation-wide MFA. Members must enrol before they can use Riskly. - Configure SAML SSO (admin): Paste your identity provider metadata and test sign-in before turning SSO on for the organisation. ### Notifications guide Choose which emails you receive and which sections appear in your Monday summary (This week's outlook). In-app alerts always show in the bell. Try these steps: - Pick Monday summary sections: Toggle each section you want in the weekly outlook email: follow-ups, licences, training, legislation (Pro), and others. - Set weekday reminders: Turn on or off Tue to Sun reminders for follow-ups, licence expiries, and training due dates. - Check the in-app bell: Some alerts always appear in the notification bell even when email is off. Open the bell to see recent activity. ### Integrations guide Subscribe to your organisation calendar in Outlook, Google Calendar, or Apple Calendar. Optionally post new hazards and incidents to Slack or Microsoft Teams. Try these steps: - Copy the calendar link (admin): Copy the org calendar URL and add it as a subscribed calendar in your preferred app. Members can copy a personal feed from the Calendar page in My view. - Regenerate when needed (admin): If the link is shared too widely, regenerate it. Old subscriptions stop updating until people add the new link. - Connect Slack or Teams (optional) (admin): Paste an incoming webhook URL to post new hazards and incidents to a channel. Turn notifications off anytime without deleting the webhook. ### Activity guide Activity is an audit trail of changes across your organisation. Filter by person, area, or date to find what changed and when. Try these steps: - Filter the log: Use the filters to narrow by team member, module, or date range when you are looking for a specific change. - Review before handover: Scan recent activity when someone leaves a role or before an external review to see what was updated recently. ### Billing guide Manage your subscription, compare Basic and Pro, and open the Stripe billing portal for invoices and payment methods. Try these steps: - Compare plans (admin): Read the feature comparison before upgrading or downgrading. Pro unlocks legislation, control testing, and higher seat limits. - Open the billing portal (admin): Use Manage billing to update your card, view invoices, or cancel at period end. ### Reports guide Reports turn your Riskly data into a meeting pack or board paper. Pick a template, set the period, adjust sections, then export PDF or duplicate the report next period. Archive finished packs from the library, then open Meeting records for attestations and governance reviews. Areas: - Active reports: Saved reports with live or frozen numbers. Open, duplicate, archive, or export from here. - Archived reports: Reports you have archived stay available under the Archived tab and in Meeting records. - Meeting records: Signed compliance attestations, archived reports, and H&S governance reviews in one place for auditors. - Editor: Choose charts and exception lists, add section notes, and preview the pack before export. Try these steps: - Start from a template: Click New report and pick a template (for example Inspector readiness pack, Governance snapshot, H&S monthly update, Quarterly board pack, or Assurance & audit summary on Pro). You can change the charts and lists after you start. - Set the period and summary: Choose current data, this month, last quarter, year to date, or custom dates. Add who prepared it and a short summary so readers know what changed. - Add charts and exception lists: Keep, add, or remove sections. Use the recommended chart type unless you have a reason to switch. Notes under a section are for that meeting. - Save, export, and reuse: Leave the report live so numbers refresh from your registers, or turn on Freeze numbers on save for a dated pack. Export PDF, archive when done, or duplicate it next period. - Find archived evidence: Open Meeting records for signed attestations, governance reviews, and archived reports when you need a single audit trail. ## Task recipes (step-by-step) ### Accept a team invite (Basic & Pro) Open: /dashboard. 1. Open the invite email and click the link (or paste the invite URL into your browser). 2. Sign in with password or request a magic link using the same email address the invite was sent to. 3. Complete accept-terms if prompted, then finish MFA enrolment when your organisation requires it (/mfa-challenge). 4. You land on Home (/dashboard) with tab access set by the admin who invited you. ### Record a failed control test (Pro only) Open: /studio?tab=testing. Roles: Risks & Controls edit access. 1. Open Risks & Controls → Control Testing (/studio?tab=testing). 2. Find the due or overdue test instance and open it. 3. Record the result as Failed or Partially effective. Add notes explaining what you observed. 4. Attach evidence if you have it (screenshots, exports, or sign-off files). 5. Create a follow-up action when Riskly prompts you, or add one manually with an owner and due date. 6. The follow-up appears on the Calendar and in Home My List until it is closed. ### Prepare an Inspector readiness pack (Basic & Pro) Open: /reports/new?template=worksafe_insurer. Roles: Reports view or edit access. 1. Log open hazards, incidents, H&S documents, engagement records, and governance reviews while they are current. 2. Open Reports → New report and choose Inspector readiness pack (/reports/new?template=worksafe_insurer). 3. Set the period and add a short summary for inspectors, insurers, or internal governance. 4. Review prefilled sections: hazards, controls, documents, training, injury follow-up, engagement, and governance. 5. Export PDF or freeze numbers on save if you need a dated pack. 6. For injury incidents, use the notifiable checklist under Health & Safety → Incidents when WorkSafe notification may apply. ### Run an H&S governance review (Basic & Pro) Open: /health-safety?mode=governance. Roles: H&S Governance view or edit access. 1. Open Health & Safety and switch to Governance mode (/health-safety?mode=governance). 2. Click New review and work through the officer due diligence checklist (HSWA s44 assistant). 3. Record what you reviewed, any gaps, and follow-up actions with due dates. 4. Save the review. It appears in the governance register and can be exported for board papers. 5. Open Reports → Inspector readiness pack or Governance snapshot when you need a summary pack. ### Enrol in multi-factor authentication (Basic & Pro) Open: /settings/security. 1. When MFA is required, Riskly redirects you to /mfa-challenge after sign-in. 2. Scan the QR code with an authenticator app (Microsoft Authenticator, Google Authenticator, or similar). 3. Enter the six-digit code to confirm enrolment. 4. Save recovery codes somewhere safe. You need them if you lose your authenticator device. 5. Owners and admins can require MFA for everyone under Settings → Security (/settings/security). ### Export organisation data (Basic & Pro) Open: /settings. Roles: Owner or admin. 1. Open Settings → General (/settings). 2. Scroll to Download data extract and request an export. 3. Riskly prepares a ZIP with registers, documents metadata, and related records for auditors or offboarding. 4. Signed attestations and archived reports are also available under Reports → Compliance archive. ### Fix a past-due subscription (Basic & Pro) Open: /settings/billing. Roles: Owner or admin. 1. Open Settings → Billing (/settings/billing). 2. Read the past-due notice. Stripe retries failed card charges automatically for a period. 3. Click Manage billing to open the Stripe customer portal and update your payment method. 4. After payment succeeds, full access continues. If the subscription is cancelled, you keep Basic access for 30 days to export or resubscribe. ## Report templates - Quarterly board pack Key: board New report: /reports/new?template=board Summary: Risks, mitigation, and the actions directors usually ask about. Default period: last_quarter Data mode: live Plan notes: includes Pro-only sections; includes Control Testing sections; includes Assurance sections Sections when fully enabled: 32 - Governance snapshot Key: governance_snapshot New report: /reports/new?template=governance_snapshot Summary: Open actions, unmanaged risks, licence expiries, and open hazards at a glance. Default period: current Data mode: snapshot Plan notes: includes Assurance sections Sections when fully enabled: 9 - H&S monthly update Key: hs New report: /reports/new?template=hs Summary: Hazards, incidents, and document reviews for the monthly meeting. Default period: this_month Data mode: live Plan notes: all sections available on Basic Sections when fully enabled: 9 - Licence & calendar outlook Key: licences New report: /reports/new?template=licences Summary: What is expired or due, plus custom compliance dates. Default period: current Data mode: live Plan notes: all sections available on Basic Sections when fully enabled: 5 - Inspector readiness pack Key: worksafe_insurer New report: /reports/new?template=worksafe_insurer Summary: H&S evidence mapped to WorkSafe investigation themes. Suitable for inspections, insurers, and internal governance reviews. Default period: current Data mode: live Plan notes: includes Control Testing sections; includes Assurance sections Sections when fully enabled: 24 - Assurance & audit summary Key: assurance_board New report: /reports/new?template=assurance_board Summary: Assurance engagements, open findings, and remediation work for audit committees and boards. Default period: last_quarter Data mode: live Plan notes: includes Control Testing sections; includes Assurance sections Sections when fully enabled: 11 - Blank report Key: blank New report: /reports/new?template=blank Summary: Start empty and add the charts and lists you need. Default period: current Data mode: live Plan notes: all sections available on Basic Sections when fully enabled: 0 ## Frequently asked questions ### What is Riskly for? Riskly helps New Zealand SMEs manage day-to-day risk without a dedicated risk hire. You get suggested risks and controls from your Business Profile (/enterprise), then refine them under Risks & Controls (/studio). Alongside that: Health & Safety with H&S registers and evidence for WorkSafe visits, an Inspector readiness evidence pack report, licences and training, a calendar of due dates, custom reports, in-app notifications and email reminders, global search, and (on Pro) NZ legislation monitoring. See /inspection-ready on the marketing site for the NZ WorkSafe and MBIE context. ### Can Riskly help if WorkSafe or MBIE inspects our workplace? Riskly helps you organise H&S evidence WorkSafe may ask for under the Health and Safety at Work Act 2015: hazards, incidents, H&S documents, licences and training, worker engagement, governance reviews, Organisation Reporting (QR), and an exportable Inspector readiness evidence pack (/reports/new?template=worksafe_insurer). WorkSafe can enter most workplaces without an appointment. MBIE Labour Inspectors are separate: they check employment agreements, wage and time records, and holiday and leave records under the Employment Relations Act 2000. Those payroll and HR records are not stored in Riskly. Take the readiness check at /inspection-ready or open Reports → Inspector readiness pack. ### Where should I start in Riskly? Open Home (/dashboard). New organisations see a Getting started checklist filtered by your role and plan. You do not have to complete every step. A common path is: (1) Business Profile (/enterprise), (2) Risks & Controls (/studio) or Health & Safety (/health-safety), (3) Licences & Certs (/credentials), (4) Calendar (/compliance-calendar). Many teams start with H&S and renewals only, or risks and reports only, and add other areas later. Use the fit check on the marketing site or Help → Setup Guides for more detail. ### Do we have to use every part of Riskly? No. Riskly is one platform with separate registers for risks, H&S, licences, legislation, assurance, and more. Use the areas you need. Tab permissions under Settings → Users & Access let you limit who sees which areas. Reports and templates let you mix only the charts and lists that matter to your audience. ### Is Riskly right for a business that only needs H&S? Often yes on Basic, especially if you want hazards, incidents, licence and training renewals, Organisation Reporting (QR), and board-friendly reports in one place. If you only need a minimal incident log with no renewals or reporting, compare your needs against /pricing or take the fit check on the home page. ### What if we are not ready for Pro features? Stay on Basic. The 4-week trial includes Pro so you can try control testing, assurance, and legislation monitoring, but you do not have to keep using them. Downgrade or subscribe to Basic from Settings → Billing when you are ready. ### How do I invite a team member? Owners and admins open Settings → Users & Access (/settings/users), click Invite, enter the person's email, choose a role (owner, admin, member, director, or viewer), and send. The invitee signs in with password or magic link. You can set tab-level view or edit permissions per member. Basic includes up to 6 seats; Pro includes up to 20. Invites count toward the seat limit until accepted or cancelled. ### What is the difference between Riskly Basic and Pro? Basic covers Home (welcome stamps, My List, and My view), Risks & Controls, Business Profile, licences and training, calendar, actions, Health & Safety, reports, in-app notifications, global search, roles and tab permissions, MFA, calendar feeds, and optional Slack or Teams hazard alerts. Enterprise SAML sign-in is available on request when configured. Pro adds high-complexity ratings, Control Testing with evidence, assurance activities and a findings register with remediation and validation, NZ legislation monitoring, What You Must Do obligations, obligation review records, quarterly attestations with a quarter-end prompt on Home, and larger document storage (5 GB vs 750 MB). See /pricing or Settings → Billing (/settings/billing). ### Is Riskly good value for NZ SMEs? Yes. Riskly is priced per organisation, not per user, with flat Basic and Pro plans built for New Zealand SMEs. You get practical tools for risk, health and safety, and compliance work without paying for an expensive enterprise GRC suite. Pro adds control testing, assurance findings, and NZ legislation monitoring at a competitive flat rate. The 4-week free trial includes Pro-level access so you can judge value before you commit. See /pricing for current prices. ### Can a larger business or NZ division use Riskly? Often yes, for one NZ legal entity or a focused team. Riskly is built for SMEs first, but legislation monitoring, control testing, and assurance modules can be game-changers for maturing teams and NZ divisions that need registers without enterprise GRC complexity. Basic includes up to 6 seats per organisation and Pro up to 20. Riskly is not a group-wide GRC platform or multi-entity roll-up tool. See /pricing or /contact to talk through fit. ### How does Organisation Reporting (QR/code) work? In Health & Safety → Overview → Organisation Reporting, an admin turns on reporting and shares your unique code or printable QR poster. Staff open /report (public, no login), enter the code, and submit a hazard or incident. Submissions land in your organisation's H&S register for follow-up. ### Where do suggested risks and controls come from? Complete your Business Profile (/enterprise): industry, activities, and risk appetite. Riskly generates a short, relevant set of suggested risks and controls. You accept, dismiss, edit, or add your own under Risks & Controls (/studio). ### Can I add my own risks and controls? Yes. Under Risks & Controls (/studio) you can create custom risks and controls, link each risk to mitigating controls, and keep policies and evidence under Documents. On Pro you can also schedule control testing. ### What shows on Home? Home (/dashboard) is your daily starting point. The welcome card shows stamp counts for overdue and due-soon work. My List is your queue: overdue items, assignments due in the next seven days, and anything you pin with Add to My List. Use Organisation or My view when linked on the org chart. I want to… shortcuts jump to common tasks. Pro users may also see a quarter-end attestation prompt when attestations are enabled. ### What belongs in Licences & Certs vs the Calendar? Use Licences & Certs (/credentials) for licences, certificates, and training records. Use the Calendar (/compliance-calendar) to see those expiries plus document reviews, actions, control tests, obligation reviews (Pro), and custom dates you add (GST, tax, insurance). ### How do notifications and search work? The notification bell shows in-app alerts. Configure email digests under Settings → Notifications (/settings/notifications). Press Ctrl+K or use Search in the sidebar to jump to risks, hazards, licences, and other records you can access. ### What is Health & Safety for? Health & Safety (/health-safety) records hazards, incidents, near misses, H&S documents, and worker engagement. Injury incidents include a WorkSafe notifiable checklist. Follow-ups appear on the Calendar. Organisation Reporting lets staff submit without a login. Governance (when enabled) assists officer due diligence reviews. For a summary pack, open Reports → Inspector readiness pack. ### What is Legislation for? Legislation (/legislation) is a Pro feature: watch NZ Acts, work through changes in the Monitoring work queue, complete act update checks, capture What You Must Do obligations, and record Review Records as evidence. Basic users can upgrade from Settings → Billing. ### What is Assurance for? Assurance (/studio?tab=assurance) is a Pro feature under Risks & Controls. Create an activity for each external or internal audit, gap assessment, or management review. Upload the provider report, extract findings, remediate with follow-up actions, and record independent validation with evidence. Link findings to risks, controls, and obligations. Open the Assurance tab for the status strip and findings register. Build an Assurance & audit summary report from Reports (/reports/new?template=assurance_board). ### How do assurance findings and validation work? Each finding moves through remediation (open, in progress, implemented, or dismissed). Assign a remediation owner and add follow-up actions with due dates. When remediation is complete, choose a validator who is independent from the owner, upload evidence, and record accepted or rejected validation. Riskly recommends but does not block the same person owning and validating a finding. ### How do I change my plan or billing? Open Settings → Billing (/settings/billing) to subscribe, upgrade to Pro, or manage payment in Stripe. If a renewal payment fails, Stripe marks the subscription past due and retries. You usually keep full access while retries run. Update your card in Billing or the Stripe portal. If the subscription is cancelled after failed payment, the 30-day grace and 90-day data retention rules apply. ### What integrations does Riskly offer? Under Settings → Integrations (/settings/integrations), owners and admins can enable an organisation calendar feed (subscribe in Outlook, Google Calendar, or Apple Calendar), copy a personal feed from Home My view, and optionally connect Slack or Microsoft Teams incoming webhooks to post when new hazards or incidents are logged. MFA and optional enterprise SAML sign-in are configured under Settings → Security. ### Can I start a new organisation after deleting one or using my free trial? Yes. One free trial is available per email address. If you already used a trial, sign in and create a new organisation on Riskly Basic without a second trial. Subscribe from Settings → Billing when you need Pro features again. ### What happens to our data if we cancel? After your paid period ends you keep Basic access for 30 days to export or resubscribe. Then the account locks. Organisation data is retained for 90 days from cancel, then permanently deleted. Export from Settings → Data & privacy (owners/admins). ### Who can see our organisation's data? Data is scoped to your organisation. Only signed-in members can access registers and documents. Organisation Reporting is the exception for public hazard/incident submissions. Admins manage access under Settings → Users & Access. ## Troubleshooting and edge cases ### Why can I not see a tab or screen? Riskly hides areas when your role's tab permission is set to none, or when your plan does not include the feature (for example Legislation or Control Testing on Basic). Ask an owner or admin to check Settings → Users & Access (/settings/users). Pro-only features show an upgrade prompt when you are on Basic. ### Why does Search or Ctrl+K not show a record I expect? Search respects tab permissions. If you only have view access or no access to an area, its records do not appear. Try the full Search page (/search) for history and filters. Organisation view shows all records you can access; My view on Home limits assigned work to your org-chart position. ### What happens when my organisation is locked after cancelling? After a paid period ends without renewal you keep Basic access for 30 days to export data or resubscribe from Settings → Billing. Then the account locks and members cannot sign in. Organisation data is retained for 90 days from cancel, then permanently deleted. Owners and admins can export from Settings → General before the lock. ### A teammate cannot sign in after MFA was turned on When organisation-wide MFA is required, each member must enrol at /mfa-challenge before using Riskly. If they lost their authenticator, an owner or admin can reset MFA for that user under Settings → Users & Access, then the member enrols again with new recovery codes. ### An invite link expired or the seat limit was reached Pending invites count toward your seat limit (6 on Basic, 20 on Pro). Owners and admins can revoke old invites or upgrade the plan under Settings → Billing, then resend the invite from Settings → Users & Access. ### I cannot upload a document or evidence file Check storage usage on Settings → General (750 MB on Basic, 5 GB on Pro). Individual uploads are capped at 4 MB. If storage is full, archive or delete old files, or upgrade to Pro for more space. ### A report section says it requires Pro or Control Testing Report templates can include Pro-only metrics (legislation, assurance, high-complexity ratings) or Control Testing tables. On Basic, those sections are omitted or blocked when saving. Upgrade to Pro or pick a template without those sections. See the report template index in llms-full.txt. ### Organisation Reporting submissions are not appearing Confirm Organisation Reporting is enabled under Health & Safety → Overview. Check the organisation code or QR poster matches what staff use at /report. Review Public reporting health on Settings → General for delivery issues. ## Basic plan tips - Finish your Business Profile before generating suggestions: better inputs mean fewer irrelevant risks. - Keep the list tight: accept what matters, dismiss noise, add only custom items you will maintain. - Link every accepted risk to at least one control so Home's unmanaged count stays meaningful. - Put expiry dates on licences and training so the Calendar, Home, and notification bell can remind you. - Press Ctrl+K or open Search in the sidebar when you need to jump straight to a record. - Use the Calendar for GST, PAYE, annual returns, and insurance, not only licence expiries. - Log hazards and near misses in Health & Safety while they are fresh. - Before a WorkSafe visit or board review, generate an Inspector readiness pack from Reports. - Review Home each week (welcome stamps and My List) or wait for the Monday email digest. - Retire licences you no longer hold so active lists stay accurate. - Subscribe to the organisation calendar feed or Slack/Teams alerts when your team lives in those tools. ## Pro plan tips - Everything in Basic still applies. Pro builds on a clean register. - Accept legislation suggestions that match your industry, then prune the watchlist. - Complete act update checks from the Monitoring work queue, work through each step in order, flag affected duties, then record obligation reviews with evidence. - Set review frequencies on What You Must Do duties so Review Records shows upcoming checks. - Use Control Testing with clear timeframes and attach evidence. Due dates show on the Calendar and in Home My List when overdue or due within seven days. - Use Assurance for each external or internal audit: upload the report, extract findings, remediate with actions, and record independent validation. - For high-complexity risks, rate inherent first, then residual after naming controls. - Enable quarterly attestations in program settings when directors need a formal quarterly sign-off. - Assign ownership via the org chart so risks and controls have a named role. ## What Riskly does - Home with welcome stamps, My List work queue, My view, and organisation oversight - Global search across risks, controls, hazards, incidents, licences, and more - In-app notification bell and configurable email reminders - Risks and controls register with Business Profile suggestions - Link risks to mitigating controls with document uploads - Health and safety: hazards, incidents, WorkSafe notifiable injury checklist, engagement, governance reviews, Organisation Reporting (QR/code), and Inspector readiness evidence packs for WorkSafe visits - Licences, certificates, and training records with expiry tracking - Compliance calendar, assignable actions, and due date reminders - Custom reports with charts, PDF export, live or frozen snapshot numbers - Organisation activity log and full data export - Roles from viewer through owner with tab-level permissions - Multi-factor authentication (MFA) with optional org-wide requirement - Invite-only access: password, magic link, and team invitations - Optional enterprise SAML sign-in when your identity provider is configured - Calendar feed subscriptions for Outlook, Google Calendar, or Apple Calendar (org and personal feeds) - Optional Slack or Microsoft Teams webhooks for new hazard and incident alerts - Riskly Pro: high-complexity risk ratings and control testing with evidence - Riskly Pro: assurance activities, audit report uploads, findings register, remediation actions, and independent validation with evidence - Riskly Pro: NZ legislation watchlist, Monitoring work queue, act checks, What You Must Do obligations, and obligation review records - Riskly Pro: quarterly organisation compliance attestation sign-off and attestation archive - Riskly Pro: Assurance & audit summary report template and assurance sections in board packs