Governance, risk and compliance
Risk, policy, controls, assessments, evidence and the decisions that govern them — one connected model, so every claim traces to a record and a date.


In one sentence
AlignX Governance, Risk and Compliance connects obligations, policies, controls, risks, evidence and decisions on one model, so governance is continuous and audit readiness is a state the organisation is in rather than an exercise it prepares for.
The problem
Each of these is answerable — just not from one place, and not without a fire drill first.
The governance lineage
Seven steps, each one a record that keeps what it was decided on.
Obligation at one end, proven assurance at the other, and every decision in between kept on the record that carries it.
Cause, event and impact stated plainly, scored across five likelihood levels and four impact levels, with velocity, financial exposure and treatment on the same record.

Who it is for
The roles
What they use it for
The impact
Six questions
Evidence is uploaded against the control it supports and hashed at upload, so what an auditor needs is already on the control record with its date and its owner, not reconstructed from folders before the review.
One control library is mapped into every framework, and each control links to the obligations it satisfies and the risks it treats, so the trace from clause to control to evidence is a page, not a spreadsheet.
A risk in AlignX is linked to the applications, initiatives, contracts and suppliers that carry it, because they live in the same model, so exposure reads across the estate rather than in a register on its own.
A committee decision is recorded against the item it concerns, with the authority it was taken under and the papers it was taken on, so the context is on the record the decision changed.
Once. A control is one record mapped to as many framework clauses as it satisfies, so testing it once updates its standing under every framework it is mapped into.
A finding, the actions raised against it, the evidence supplied and the follow-up assessment sit on the same records, so closure is read against what was retested rather than against a tick.
It runs inside your Microsoft environment, on your data, under your controls.