TrustPoint

Compliance

Run every framework from one place.

What it does

Compliance is where the cost of running several overlapping standards actually shows up. Answering the same access-control requirement separately for ISO 27001, NCA ECC and CBO is the single biggest waste in most GRC programmes.

Here you assess a requirement once against a perimeter and attach the evidence once. Where a mapping set exists between two frameworks, the engine suggests the related controls and records each relationship for a person to accept.

Controls sit between the requirements and the risks. Rate a control effective and the residual score on every risk it touches moves. Let its review lapse and that shows up too.

Assessments

Assess a framework against a perimeter, requirement by requirement, with status, score, notes and attached evidence on each one.

Requirement-level granularity is what makes the mapping engine possible. Assess at framework level and there is nothing to propagate.

NCA-ECC-2-1-3 · Implemented · 4/5

Illustrative interface. Not customer data.

Applied controls

The control layer across Policy, Process and Technology, each with an effectiveness rating and a review reminder. Controls link both to requirements and to risks.

This is the join that makes the platform one thing rather than several. One control, rated once, is read by Compliance as coverage and by Risk as mitigation.

Evidence

A managed evidence store: upload, link to any object, issue evidence requests to owners with due dates, work from evidence templates, and reuse one artefact across many requirements.

Reuse is the whole point. The same access-review export satisfies a requirement in four standards, and it is stored once with one owner and one expiry.

Illustrative interface. Not customer data.

Framework roll-up

Per-framework coverage and posture across the whole organization, following the folder scope you have selected.

Answers the question every CISO gets asked without warning: where are we on ISO right now, group-wide.

Maturity

A perimeters by frameworks maturity heatmap using CBO-style maturity levels.

Several Gulf regulators, including the Central Bank of Oman, ask for maturity, not a pass mark. Reporting it natively avoids rebuilding the view by hand every cycle.

Gap roadmap

Every identified gap becomes a work item on a kanban roadmap, with CSV and Excel export.

A gap list is a document. A roadmap has owners and columns, which is what turns an assessment into a programme of work.

Cross-framework mapping

Mapping sets link controls in one framework to controls in another. Each rule records its relationship (equal, subset, superset, intersecting or related) and a strength score, and suggestions are surfaced for a person to review rather than applied silently. The platform currently includes the NCA ECC to ISO/IEC 27001:2022 mapping set.

Silent automatic mapping does not survive an audit. Recording the relationship, and requiring a human to accept the suggestion, is what makes the saving defensible.

NCA ECC 2-2-6 → ISO/IEC 27001:2022 A.5.15 · intersect

Framework transitions

When a standard revises, a guided upgrade carries your assessments forward onto the new version and reports exactly what changed.

A version change normally means reassessing from zero. Carrying the answers forward and showing only the delta is weeks of work you do not repeat.

v1 → v2 · renamed, merged, split, introduced, retired

How a day looks

A compliance officer assesses NCA ECC control 2-2-6, on session management and single sign-on, for the retail banking perimeter, marks it implemented, and attaches the SSO configuration export. The included mapping set suggests two ISO/IEC 27001:2022 controls: A.5.15 Access control, recorded as intersecting, and A.8.5 Secure authentication, recorded as related. The officer accepts the first with a note on what it does not cover and leaves the second for the ISO lead to review. The reason for each decision is on the record.

Roles that live here

  • Compliance Manager
  • Compliance Officer
  • Control Owner
  • Internal Auditor
  • CISO

Drawn from sixteen built-in roles, each scoped along the org tree. Access control

Related frameworks

See Compliance on your frameworks.

A 45-minute working session focused on the frameworks and requirements that matter to your organization.