Governance, risk and compliance

Govern with context.
Prove with confidence.

Risk, policy, controls, assessments, evidence and the decisions that govern them — one connected model, so every claim traces to a record and a date.

The risk register: every risk scored twice — inherent and residual — with status, source, category and treatment strategy down the columns
One master control mapped into four frameworks — ISO 27001, NIST SP 800-53, Essential Eight and SOC 2 — each mapping readable from either end

In one sentence

AlignX Governance, Risk and Compliance connects obligations, policies, controls, risks, evidence and decisions on one model, so governance is continuous and audit readiness is a state the organisation is in rather than an exercise it prepares for.

The problem

Not a compliance problem. A connection problem.

Each of these is answerable — just not from one place, and not without a fire drill first.

  • Assurance is reconstructedSix weeks of chasing before every audit, then it goes stale again.
  • The same control, many timesMapped separately into each framework, maintained in none of them.
  • Evidence lives in foldersNobody can prove which file answered which question, or when.
  • Committees decide in documentsMinutes in one place, the decision’s authority in nobody’s.
  • Findings close without closingRemediation is marked done and never actually retested.
  • Risk is disconnected from workThe register has no line to the projects and vendors that carry it.
  • Policy drifts out of dateReview dates pass unnoticed because nothing is watching them.

The governance lineage

From obligation to proven assurance.

Seven steps, each one a record that keeps what it was decided on.

  1. 01ObligationWhat we must do, and who says so.
  2. 02PolicyThe position we take, versioned and owned.
  3. 03ControlWritten once, mapped into every framework.
  4. 04AssessmentTested against the records that matter.
  5. 05EvidenceBound to the answer, hashed at upload.
  6. 06DecisionTaken under a stated authority, on the record.
  7. 07AssuranceFindings remediated, then retested.

Who it is for

Built for the people who own this work.

What they use it for

  • Manage enterprise and operational risk using a consistent framework.
  • Map obligations to policies, controls, evidence and accountable owners.
  • Run policy drafting, consultation, approval, publication and review workflows.
  • Manage committees, agendas, decisions, minutes and actions.
  • Conduct assessments, attestations and control testing.
  • Manage audits, findings, remediation and retesting.
  • Provide continuous compliance and cyber assurance reporting.

The impact

Audit-ready all year, not all quarter.

  • Assurance stops being a projectEvidence accumulates as work happens instead of before an audit.
  • One control, many frameworksAdd a framework and map to what you already have.
  • Answerable authorityWho could decide this, under what delegation, on that date.
  • Risk in contextConnected to the projects, vendors and systems that carry it.
  • Findings that really closeA retest with an assessor, not a status field.
  • Claims that traceEvery number on a slide resolves to a record and a date.

Six questions

Worth asking of whatever you run today.

How much time is spent gathering and validating evidence before each audit?

Evidence is uploaded against the control it supports and hashed at upload, so what an auditor needs is already on the control record with its date and its owner, not reconstructed from folders before the review.

Can every control be traced to the obligations and risks it addresses?

One control library is mapped into every framework, and each control links to the obligations it satisfies and the risks it treats, so the trace from clause to control to evidence is a page, not a spreadsheet.

Are risks connected to the projects, systems and vendors that create the exposure?

A risk in AlignX is linked to the applications, initiatives, contracts and suppliers that carry it, because they live in the same model, so exposure reads across the estate rather than in a register on its own.

How do governance bodies access the context behind the decisions they approve?

A committee decision is recorded against the item it concerns, with the authority it was taken under and the papers it was taken on, so the context is on the record the decision changed.

How many times is the same control maintained across different frameworks?

Once. A control is one record mapped to as many framework clauses as it satisfies, so testing it once updates its standing under every framework it is mapped into.

How do you verify that remediation was effective after a finding was closed?

A finding, the actions raised against it, the evidence supplied and the follow-up assessment sit on the same records, so closure is read against what was retested rather than against a tick.

Prove it without the fire drill.

It runs inside your Microsoft environment, on your data, under your controls.