Compliance & Audit

Evidence once. Satisfy every framework.

Access control appears in ISO 27001, SOC 2, PCI DSS, Cyber Essentials, NIST CSF and DORA. Evidence it once here and it counts for all of them — with the completion state updating everywhere at the same moment.

1,109
Mapped controls
29
Standards covered
8
Audit types
6
Root-cause methods
Shared control architecture

The audit trail is a by-product, not a project.

Evidence attaches to controls as part of doing the work, and controls map across frameworks. When the audit arrives, preparation is a filter and an export — not four weeks of archaeology across shared drives.

  • Controls grouped by framework pack into collapsible tables, each sortable, with filters for company, department, package, status and type.
  • Five evidence types per control — document, audit finding, objective, attestation and external link — each with an assurance status and a one-click affirm.
  • Two creation paths: pick from the framework catalogue, or define a custom control with its own reference.
  • Multi-owner controls with primary, co-owner and board-oversight roles.
  • Eight audit types with guided wizards for scope, schedule, sampling and evidence requirements.
  • Field-level history on every record, so you can show the register exactly as it stood on any past date.
See it live
+≡GR
GGRCxAI

Controls

1,109 controls · grouped by framework pack

AllMineActive
Implemented
942
of 1,109
Evidence affirmed
781
83% of implemented
Expiring soon
24
within 30 days
ISO 27001 Information Security Pack116 controls
RefControlOwnerEvidenceStatus
A.5.15Access controlS. Patel4 itemsAffirmed
A.8.1User endpoint devicesJ. Okafor2 itemsExpired
A.8.3Information access restrictionS. Patel3 itemsAffirmed
A.5.23Cloud services securityM. Chen5 itemsIn review
Framework completion
ISO 27001
92%
SOC 2
78%
DORA
46%
PCI DSS
88%
Open non-conformances
NC-07 — clause 8.1 evidence gapMajor
NC-11 — supplier review overdueMinor
NC-12 — training completion 74%Minor
Inside the module

The five pages

Planning through to corrective-action closure.

Controls

The register of implemented controls with an evidence and assurance case behind each one.

Objectives

Compliance objectives tracked against owners, target dates and measurable outcomes.

Audits

Eight audit types with guided wizards, plus AI-drafted findings for the auditor to review and adjust.

Non-Conformances

Tracked to the ISO clause with corrective actions, owners, due dates and escalation on slip.

Incidents

Six root-cause analysis methods, so the analysis fits the incident rather than defaulting to five whys.

Works with

Every module shares one system of record, so evidence gathered in one place counts everywhere it is needed.

Risk Management

The risks these controls mitigate.

Learn more

29 Standards

Every framework the controls map across.

Learn more

AI Documents

Statements of applicability drafted from your controls.

Learn more

Audit-ready is a state, not a fortnight.

See the control library and evidence flow end to end.