
Access control appears in ISO 27001, SOC 2, PCI DSS, Cyber Essentials, NIST CSF and DORA. Evidence it once here and it counts for all of them — with the completion state updating everywhere at the same moment.

Evidence attaches to controls as part of doing the work, and controls map across frameworks. When the audit arrives, preparation is a filter and an export — not four weeks of archaeology across shared drives.
1,109 controls · grouped by framework pack
| Ref | Control | Owner | Evidence | Status |
|---|---|---|---|---|
| A.5.15 | Access control | S. Patel | 4 items | Affirmed |
| A.8.1 | User endpoint devices | J. Okafor | 2 items | Expired |
| A.8.3 | Information access restriction | S. Patel | 3 items | Affirmed |
| A.5.23 | Cloud services security | M. Chen | 5 items | In review |
Planning through to corrective-action closure.

The register of implemented controls with an evidence and assurance case behind each one.

Compliance objectives tracked against owners, target dates and measurable outcomes.

Eight audit types with guided wizards, plus AI-drafted findings for the auditor to review and adjust.

Tracked to the ISO clause with corrective actions, owners, due dates and escalation on slip.

Six root-cause analysis methods, so the analysis fits the incident rather than defaulting to five whys.
Every module shares one system of record, so evidence gathered in one place counts everywhere it is needed.



See the control library and evidence flow end to end.