Risk Ledger Ltd
United Kingdom · riskledger.com · 50 vendors
Risk Ledger is a third-party risk management platform that enables organisations to identify, measure and mitigate supply chain risks by running a comprehensive, security-led due diligence programme on their third-party vendors.
Resilience scores
- Digital Sovereignty: 2
- Digital Resilience: 9
- Financial Resilience: 5
Technology vendors
- Anthropic, PBC — Technology — United States
- Contentsquare — Technology — France
- Ringkjøbing Landbobank — Financial Services — Denmark
- and 47 more
Insights
Last updated 2026-08-15 · revision 15
50 direct vendors, 351 subvendors
Direct vendors by controlling owner country (sample)
- United States: 35
- United Kingdom: 1
- UK: 2
Subvendors by controlling owner country (sample)
- China: 10
- Cyprus: 1
- Brazil: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Risk Ledger Ltd exhibits a medium-high migration readiness score of 70. The company's modern, cloud-native internal tech stack is a significant advantage, featuring Amazon Web Services (AWS) and Infrastructure-as-Code (IaC). This architecture provides inherent flexibility and reduces technical barriers to migration, allowing for easier replication or movement of infrastructure. The existing ISO 27001 and UK Cyber Essentials certifications demonstrate a mature security posture and established processes, which are beneficial for planning and executing a secure migration. Furthermore, the successful Series A funding round indicates sufficient financial resources to fund potential migration efforts. However, several factors present significant challenges. The regulatory environment is complex, with multiple 'Assessment Required' items for GDPR, UK Data Protection Act 2018, NIS2, SOC2, and ISAE 3000. These regulations, especially those concerning data protection, will necessitate meticulous planning and compliance verification during any migration, potentially increasing complexity and cost. Crucially, stringent data residency requirements, driven by GDPR, UK DPA 2018, and potential sector-specific mandates from critical infrastructure clients, pose a major hurdle. Ensuring data remains within specific jurisdictions or is transferred with appropriate safeguards will add considerable complexity to migration strategies. While the 'Vendor Geographic Diversity' is high (13 countries), the 'Total Vendors: 0' data point is inconsistent and makes a precise assessment of vendor lock-in difficult. However, the use of AWS and IaC generally suggests a lower lock-in risk for core infrastructure, though specific application-level vendor dependencies remain unknown.
Compliance
10 in-scope frameworks identified; showing 3.
GDPR (source) — Partially Compliant
Risk Ledger is a UK-incorporated company (Risk Ledger Ltd) headquartered in London, making UK GDPR and the Data Protection Act 2018 directly and unambiguously applicable. The company acts as both Data Controller (for website visitors, leads, candidates, and lead service users) and Data Processor (for platform users' organisational data). A comprehensive, publicly available Privacy Policy is in place, data subject rights are articulated, and Standard Contractual Clauses (SCCs) are used for international transfers. ISO 27001 and Cyber Essentials certifications demonstrate strong technical and organisational measures. Risk level is rated Medium rather than Low because: (1) the company uses numerous US-based sub-processors (Webflow, Notion, Gong, HubSpot, Segment.io, LogRocket, Mixmax, Docusign) for which SCCs must be maintained and regularly reviewed post-Schrems II; (2) no publicly disclosed ICO registration number or DPO appointment was found; (3) the company is expanding into the US (Maryland), which introduces new cross-border data flow complexity; (4) the platform processes sensitive organisational security posture data for 16,000+ organisations, increasing the stakes of any breach. Enforcement risk is real — the ICO actively enforces UK GDPR against UK-based tech companies.
Evidence: https://riskledger.com/privacy, https://riskledger.com/security-profile, https://riskledger.com/resources/press-release-risk-ledger-expands-united-states, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/, https://www.legislation.gov.uk/ukpga/2018/12/contents/enacted
UK Cyber Security and Resilience Bill — Assessment Required
The UK Cyber Security and Resilience Bill was announced in the King's Speech (July 2024) and is expected to significantly expand the scope of UK NIS Regulations to include managed service providers, digital service providers, and supply chain security providers. Risk Ledger, as a UK-based supply chain security SaaS platform serving critical national infrastructure clients, is directly in scope of the proposed expanded framework. Risk level is Medium because: (1) the Bill is not yet enacted (as of the research date) but is actively progressing; (2) Risk Ledger's business model (supply chain security for CNI clients) places it squarely in the anticipated expanded scope; (3) new incident reporting obligations, security requirements, and regulatory oversight are expected; (4) Risk Ledger's existing ISO 27001 and Cyber Essentials certifications provide a strong foundation for compliance.
Evidence: https://www.gov.uk/government/publications/cyber-security-and-resilience-bill-factsheet, https://riskledger.com/communities/critical-national-infrastructure, https://riskledger.com/security-profile
UK Cyber Essentials — Compliant
Risk Ledger has publicly confirmed Cyber Essentials certification, with the NCSC Cyber Essentials badge displayed on its website. Cyber Essentials is a UK government-backed scheme that helps organisations protect against common cyber threats. Risk level is Low because certification is confirmed, the scheme is well-suited to Risk Ledger's size and profile, and the company's ISO 27001 certification demonstrates controls that exceed Cyber Essentials requirements. Cyber Essentials is also a prerequisite for UK government contracts, which is relevant given Risk Ledger's public sector community.
Evidence: https://riskledger.com/security-profile, https://riskledger.com/, https://www.ncsc.gov.uk/cyberessentials/overview
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 5/10
Risk Ledger Ltd is an early-stage, venture-backed cybersecurity SaaS company with approximately £10M+ in total disclosed funding, including a £6.25M Series A extension in March 2024 led by Mercia Ventures. The company benefits from strong VC backing, a growing sector tailwind driven by regulations such as DORA, NIS2, and the UK Cyber Security & Resilience Bill, and a defensible network effect with 16,000+ connected supplier organisations on its platform. Marquee customers span financial services (Allica Bank, Admiral, Simply Business), critical national infrastructure (Anglian Water, Pennon), and transport (GTR), providing vertical diversification. However, the company remains sub-scale relative to global TPRM competitors like OneTrust, SecurityScorecard, and Prevalent, which have raised hundreds of millions. As a small private company filing abbreviated accounts, detailed P&L visibility is limited, and typical early-stage SaaS cash burn implies ongoing dependence on venture capital. The 2025 US market expansion increases cost base ahead of revenue, adding execution risk. Overall resilience is moderate — well-funded for its stage but reliant on continued VC access and successful international scaling.
Key strengths: £6.25M Series A extension raised March 2024 led by Mercia Ventures, Strong VC backing from Firstminute Capital, Seedcamp, Episode 1, Village Global, CyLon, LORCA, Network effect with 16,000+ connected supplier organisations, Regulatory tailwinds from DORA, NIS2, UK Cyber Security & Resilience Bill, Diversified marquee customers across financial services, CNI, transport, insurance, ISO/IEC 27001 and Cyber Essentials certified
Risk factors: Early-stage cash burn typical of pre-profit SaaS scale-ups, Small absolute scale versus well-funded US TPRM competitors (OneTrust, SecurityScorecard, Prevalent), Crowded competitive TPRM market, US expansion increases cost base ahead of revenue, Potential customer concentration risk given company size, Limited public financial disclosure due to small-company filing status, Dependence on continued access to venture capital
Revenue by geography
- United Kingdom: 100%
- United States: 0%
Revenue by product/service
- Supply Chain Security SaaS Subscriptions: 100%
Workforce by country
- United Kingdom: 70
- United States: 5
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.