Request a demo
Origami risk leadspace gradient background
Insights / Blog

RMIS Configurability Starts with Architecture

September 17, 2026

Risk managers who have been through more than one RMIS evaluation know the pattern. During the polished demo every workflow looks adjustable, every form appears editable, and the sales team answers every configuration question with “yes.” Then the system goes live. From there, any change to an approval chain, a form field, or a report means a support ticket and a three-week wait.

This is a structural problem. “Configurable risk management software” has become a marketing standard applied to platforms with meaningfully different levels of self-sufficiency. Every serious evaluation comes down to what configuration actually requires.

The Hidden Cost of a Rigid System

When a RMIS can’t flex to match how an organization works, the organization adjusts to the system. That compromise is easy to underestimate before go-live and difficult to reverse afterward.

Direct costs appear quickly with IT hours, vendor services engagements, and implementation overruns tied to “customizations” that weren’t in the original scope.

The indirect costs are harder to quantify:

  • Workflows stay manual because changing the system is more trouble than it’s worth.
  • Reports don’t match how the business actually categorizes risk.
  • Approval chains reflect the platform’s logic rather than the organization’s structure.

Over months and years, a system that requires constant workarounds stops serving the program it was built to support.

Switching platforms is expensive and disruptive. Organizations that discover a poor fit late pay twice: once for the original implementation, and again to move to something that actually works. The evaluation is where this risk gets managed.

The Configurability Ceiling: Why Architecture Matters

Configurability and customization are different things. Customization means development work. It requires code changes, vendor involvement, and often breaks during platform upgrades. Organizations that rely on customization trade short-term fit for long-term dependency. Every change requires a services engagement, and the gap between what the system can do and what the organization needs grows over time.

True configurability is self-service and durable. Risk managers and administrators can adjust forms, modify workflows, and build reports without touching code or waiting on a vendor. Changes persist through upgrades because they’re built into the platform’s configuration layer.

What this looks like in practice: When Hurricanes Harvey and Irma hit in 2017, Scott Echerd, Director of Strategic Initiatives for Risk and Safety at Compass Group, created a new audit from scratch. The audit had critical questions designed to capture business closure and property damage data across affected East Texas locations, and they were able to deploy it within minutes. No call to Origami Risk, no development work. Responses started arriving 48 hours later.

Compass Group, which operates across more than 10,000 locations and 240,000 employees, had cited exactly this capability as a factor in selecting the platform: the accessibility and ease of use of administrative settings that allow the team to make changes themselves.

As Brian Van Allsburg, VP Risk Management, observed after the storm, “We’re seeing that a RMIS platform like Origami Risk is not just a claims management platform. There’s so much more that can be done given the flexibility of these tools.”

Architecture determines which of these is possible. Platforms built on general-purpose CRM infrastructure or third-party foundations inherit the data models and configurability limits of that base. A risk management data model built around the actual structures of entities, coverages, incidents, and claims allows a different depth of configuration.

Configurable Workflows in Practice

A genuinely configurable risk management platform can support workflows like these:

  • COI intake automation: extract and validate vendor certificates without manual review
  • FNOL and claim creation: ingest reports and generate routed, structured claims automatically
  • Exposure data collection: schedule collection across business units, validated before renewal
  • Regulatory reporting: generate compliance reports directly from existing system data

Henry Schein, a healthcare products distributor with more than 400 locations worldwide, is a direct example of the third workflow. Their annual exposure data collection had relied entirely on emails and spreadsheets sent to field locations, creating persistent problems. Problems like human error in manual entry, no reliable way to track completion status across hundreds of locations, and significant staff time lost to follow-up.

As George Zaroogian, Director of Risk Management at Henry Schein, put it, “This caused a number of issues. There were human errors, and difficulties in figuring out who had provided complete information. We then had to follow up with everyone at different stages, which made it difficult to track progress.”

The team now launches each annual collection cycle through Origami. Automated emails go to each location with unique secure links, forms are pre-populated with prior year values, and reminder notifications fire automatically for any location that hasn’t submitted. The risk team monitors completion in real time through dashboards.

Zaroogian summarized the outcome, “Switching from a manual values collection process to Origami helped make the process more efficient. It continues to save us a substantial amount of time and shifts accountability to people throughout the organization. We’re seeing meaningful details that ultimately provide a lower total cost of risk.”

For Buncombe County, a local government in North Carolina managing risk across 30 departments and 1,800+ employees, claims intake automation followed a similar pattern. Incidents had arrived by interoffice mail, phone calls, and paper forms. Claims were tracked across multiple spreadsheets. Processing a new workers’ compensation claim took roughly an hour.

After implementing Origami Risk, that same intake dropped to 15-20 minutes. A custom report for the Board of Commissioners that previously took hours every two weeks now takes about five minutes. An electronic integration with the county’s third-party administrator eliminated double entry. Work notes, restrictions, and updates flow through a single system of record.

“Origami Risk was a lifeline for us,” Houston said, reflecting on Hurricane Helene recovery, when the risk team tracked 127 storm-related claims alongside an existing workload of 300+ active claims while normal operations were still disrupted. “I don’t know how we would have managed the insurance and county damage without it.”

King County Metro, one of the largest public transit systems in the U.S., retired 12 legacy systems and 90 paper forms in a single Origami Risk implementation. Incident visibility went from weeks to immediate. “Having all of our safety information in one place — instead of manually entered into multiple systems — is revolutionary. We now have instant visibility into incidents and the ability to follow up with operators,” said Alex Zastrow, Safety Data Analyst at King County Metro.

What the Next Generation of RMIS Evaluators Will Demand

Evaluators who focused on feature lists in past cycles now want to know whether they can actually run their program on the system the way they need to. That gets to architecture, self-sufficiency, and what it costs to change something when the program evolves.

The organizations that will get the most from the next generation of RMIS technology are the ones already running on platforms built for genuine configurability. Origami Risk is purpose-built for risk management, with a platform architecture designed to support the depth of configuration complex programs require, from data models and org hierarchies to workflows, forms, and reporting. Risk teams configure their systems without IT involvement, and changes persist as the platform evolves.

Explore how Origami Risk supports complex risk programs.

Related articles

Insight_Blog_Mgmt of Change in Manufacturing
Blog

Management of Change in Manufacturing: How to Close the Gap Between the Program You Have and the Record That Holds Up

Insight_Blog_Audit ERM
Blog

Why Your Audit Committee Isn’t Satisfied With Your ERM Reporting Anymore

Insight_BLOG_IRM_What Is It
Blog

Integrated Risk Management (IRM) – What Is It, Why Does It Matter, and Where Should You Begin?

Connect with us

Whether you’re exploring solutions or ready to scale, our team is here to help build something great.