Compliance
Run every framework from one place.
What it does
Compliance is where the cost of running several overlapping standards actually shows up. Answering the same access-control requirement separately for ISO 27001, NCA ECC and CBO is the single biggest waste in most GRC programmes.
Here you assess a requirement once against a perimeter and attach the evidence once. Where a mapping set exists between two frameworks, the engine suggests the related controls and records each relationship for a person to accept.
Controls sit between the requirements and the risks. Rate a control effective and the residual score on every risk it touches moves. Let its review lapse and that shows up too.
Assessments
Assess a framework against a perimeter, requirement by requirement, with status, score, notes and attached evidence on each one.
Requirement-level granularity is what makes the mapping engine possible. Assess at framework level and there is nothing to propagate.
NCA-ECC-2-1-3 · Implemented · 4/5
Assessment
Attach evidence| REF | Requirement | Maturity | Status |
|---|---|---|---|
| NCA-ECC-2-1-3 | Asset classification | 4/5 | Implemented |
| NCA-ECC-2-2-1 | User access lifecycle | 3/5 | Partially implemented |
| NCA-ECC-2-5-2 | Network traffic filtering | 5/5 | Implemented |
| NCA-ECC-2-9-1 | Scheduled backups | 1/5 | Compliance gap |
Applied controls
The control layer across Policy, Process and Technology, each with an effectiveness rating and a review reminder. Controls link both to requirements and to risks.
This is the join that makes the platform one thing rather than several. One control, rated once, is read by Compliance as coverage and by Risk as mitigation.
Evidence
A managed evidence store: upload, link to any object, issue evidence requests to owners with due dates, work from evidence templates, and reuse one artefact across many requirements.
Reuse is the whole point. The same access-review export satisfies a requirement in four standards, and it is stored once with one owner and one expiry.
Evidence
Request evidence| ID | Artefact | Linked to | Status |
|---|---|---|---|
| EVD-0417 | Quarterly access review export | 6 | Current |
| EVD-0402 | Change approval log | 3 | Current |
| EVD-0388 | Awareness training record | 4 | Awaiting review |
Framework roll-up
Per-framework coverage and posture across the whole organization, following the folder scope you have selected.
Answers the question every CISO gets asked without warning: where are we on ISO right now, group-wide.
Maturity
A perimeters by frameworks maturity heatmap using CBO-style maturity levels.
Several Gulf regulators, including the Central Bank of Oman, ask for maturity, not a pass mark. Reporting it natively avoids rebuilding the view by hand every cycle.
Gap roadmap
Every identified gap becomes a work item on a kanban roadmap, with CSV and Excel export.
A gap list is a document. A roadmap has owners and columns, which is what turns an assessment into a programme of work.
Cross-framework mapping
Mapping sets link controls in one framework to controls in another. Each rule records its relationship (equal, subset, superset, intersecting or related) and a strength score, and suggestions are surfaced for a person to review rather than applied silently. The platform currently includes the NCA ECC to ISO/IEC 27001:2022 mapping set.
Silent automatic mapping does not survive an audit. Recording the relationship, and requiring a human to accept the suggestion, is what makes the saving defensible.
NCA ECC 2-2-6 → ISO/IEC 27001:2022 A.5.15 · intersect
Framework transitions
When a standard revises, a guided upgrade carries your assessments forward onto the new version and reports exactly what changed.
A version change normally means reassessing from zero. Carrying the answers forward and showing only the delta is weeks of work you do not repeat.
v1 → v2 · renamed, merged, split, introduced, retired
How a day looks
A compliance officer assesses NCA ECC control 2-2-6, on session management and single sign-on, for the retail banking perimeter, marks it implemented, and attaches the SSO configuration export. The included mapping set suggests two ISO/IEC 27001:2022 controls: A.5.15 Access control, recorded as intersecting, and A.8.5 Secure authentication, recorded as related. The officer accepts the first with a note on what it does not cover and leaves the second for the ISO lead to review. The reason for each decision is on the record.
Roles that live here
- Compliance Manager
- Compliance Officer
- Control Owner
- Internal Auditor
- CISO
Drawn from sixteen built-in roles, each scoped along the org tree. Access control
Related frameworks
See Compliance on your frameworks.
A 45-minute working session focused on the frameworks and requirements that matter to your organization.