● One platform for cyber, privacy & AI governance

Run every compliance framework in one place, with clarity.

GRCLens is a multi-tenant GRC platform that turns regulatory and ISO frameworks — from NCA-ECC and PDPL to ISO/IEC 27001 — into a single, trackable program. Assess, evidence, and report across them in one place, capturing evidence once and reusing it everywhere.

Live compliance snapshot

61%
ISO/IEC 2700172%
NCA-ECC64%
PDPL70%
SOC 251%
ISO/IEC 4200138%
7 frameworks, one program
Cyber · Privacy · Service · AI
Multi-tenant & isolated by design
Built for teams worldwide
Domains we secure

Deep expertise across the disciplines that matter

From board-level cyber governance to payment security and critical infrastructure — GRCLens brings every discipline into one lens.

Cyber Governance

Cyber Governance

Board-level oversight, policies and operating models aligned to NCA-ECC, NIST and ISO.

Key Risk Indicators

Key Risk Indicators

Live KPI/KRI dashboards derived from real assessment and evidence data.

AI Management Systems

AI Management Systems

ISO/IEC 42001 AI governance — system registers, impact assessments and controls.

SOC 2 Assurance

SOC 2 Assurance

Trust Services Criteria readiness for service organizations, end to end.

Payment Card Security

Payment Card Security

PCI DSS compliance — SAQ, ROC and AOC workflows built in.

Critical Infrastructure

Critical Infrastructure

Resilience for CNI and OT environments — from ECC to IEC 62443 and AESCSF.

A growing library of frameworks

Cover the standards that matter — side by side

Regulated organizations rarely answer to a single framework. GRCLens maps them to a common control model, so evidence captured for one obligation can satisfy another. Enable only the frameworks each client needs.

AvailableNCA · ECC

NCA Essential Cybersecurity Controls

Saudi Arabia's baseline cybersecurity controls for government entities, critical infrastructure, and their providers.

  • Cyber Governance
  • Cyber Defense
  • Cyber Resilience
  • Third-Party & Cloud
AvailableSDAIA · PDPL

Personal Data Protection Law

The Kingdom's data-privacy law governing how personal data of individuals in KSA is collected, processed, and transferred.

  • Lawful basis & consent
  • Data subject rights
  • Cross-border transfer
  • Breach notification & RoPA
AvailablePTA · CTDISR

PK-CTDISR (Critical Telecom Data & Infrastructure Security)

Pakistan Telecommunication Authority's regulation securing critical telecom data and infrastructure for licensees and operators.

  • Security governance & risk
  • Data & asset protection
  • Network & infrastructure security
  • Incident response & audits
AvailableISO/IEC · 27001

ISO/IEC 27001:2022 (ISMS)

The international standard for an Information Security Management System — clauses 4–10 plus all 93 Annex A controls, with a full Statement of Applicability.

  • ISMS scoping & context
  • Risk assessment & treatment
  • 93 Annex A controls
  • Statement of Applicability
AvailableISO/IEC · 20000-1

ISO/IEC 20000-1:2018 (ITSM)

The service-management standard for planning, delivering, and continually improving IT services — clauses 4–10 with the full SMS process set.

  • Service management system
  • Service levels & reporting
  • Incident, problem & change
  • Continual improvement
AvailableISO/IEC · 42001

ISO/IEC 42001:2023 (AI Management)

The first management-system standard for artificial intelligence — with an AI System Register, Statement of Applicability and AI-specific registers.

  • AI systems inventory
  • AI risk & impact
  • 38 Annex A controls
  • Legal, data & ADM registers
AvailableAICPA · SOC 2

SOC 2 (Trust Services Criteria)

The assurance framework for service organizations, evidencing controls across the five Trust Services Criteria.

  • Security
  • Availability
  • Confidentiality
  • Processing integrity & privacy
AvailableISO/IEC · 9001

ISO 9001:2015 (Quality)

The quality management system standard — process approach, risk-based thinking and continual improvement across clauses 4–10.

  • QMS scope & context
  • Process & risk approach
  • Performance evaluation
  • Continual improvement
AvailableISO/IEC · 14001

ISO 14001:2015 (Environmental)

The environmental management system standard covering environmental aspects, compliance obligations and lifecycle thinking.

  • Environmental aspects
  • Compliance obligations
  • Objectives & targets
  • Emergency preparedness
AvailableISO/IEC · 45001

ISO 45001:2018 (OH&S)

The occupational health and safety management system standard — hazard identification, worker participation and incident management.

  • Hazard identification
  • Worker consultation
  • Incident investigation
  • OH&S performance
AvailablePCI · DSS

PCI DSS v4.0.1

The payment card industry standard for any organization that stores, processes or transmits cardholder data — including the v4.0.1 future-dated requirements now in force.

  • 12 core requirements
  • Scope & segmentation
  • Customised approach
  • QSA-ready evidence
AvailableHHS · HIPAA

HIPAA (Security & Privacy Rules)

The US healthcare regulation protecting electronic protected health information — documented risk analysis plus administrative, physical and technical safeguards.

  • Security Rule safeguards
  • Privacy Rule & PHI
  • Risk analysis & management
  • Breach notification
AvailableNIST · SP 800-53

NIST SP 800-53 Rev. 5

The US federal catalogue of security and privacy controls for information systems, widely adopted as a comprehensive control baseline.

  • 20 control families
  • Baseline tailoring
  • Privacy controls
  • Assessment procedures
AvailablePractice · Risk

Risk Management

An enterprise risk register with scoring, treatment plans and owner accountability — linked directly to the controls that mitigate each risk.

  • Risk register & scoring
  • Treatment & owners
  • Control linkage
  • Board-ready reporting
AvailablePractice · Third Party

Supply Chain / Vendor Assessment

Structured third-party due diligence — tiering, questionnaires and evidence review, so supplier risk is assessed consistently and re-assessed on cadence.

  • Vendor tiering
  • Assessment questionnaires
  • Evidence & findings
  • Periodic re-assessment
AvailableModule · NSPM

Network Security Policy Management (NSPM)

Centralised governance of multi-vendor firewall estates — rule hygiene, change monitoring, risk scoring and compliance posture in one view.

  • Multi-vendor firewall support
  • Rule hygiene & risk scoring
  • Change & drift detection
  • Compliance mapping

Every framework above runs on one shared control model, so evidence captured once can satisfy obligations across several standards at the same time. Frameworks are enabled per tenant, so each client sees only what applies to them. Need a standard that is not listed? Talk to us about adding it to your programme.

Everything you need

A complete compliance workspace

From first assessment to audit-ready reporting — purpose-built for modern GRC teams.

Multi-framework by design

Run NCA-ECC, PDPL and ISO/IEC 27001 together; map controls once and reuse evidence across frameworks.

Real-time dashboards

See compliance scores per framework and domain, updated the moment an assessment changes.

Control-by-control assessment

Every control carries its clause, guidance, and expected deliverables to guide your team.

AI evidence analysis

Uploaded evidence is analysed for relevance and confidence, with a human approve/reject in the loop.

Multi-tenant & role-based

Each organization gets an isolated workspace with admin, assessor, and viewer roles.

Secure by architecture

Schema-per-tenant isolation, encrypted credentials, zero-downtime deploys, and HTTPS everywhere.

7
Frameworks supported
420+
Controls mapped
SOA
& dynamic registers
100%
Cloud-hosted & secure
How it works

Compliance in four steps

Onboard

We provision your isolated tenant workspace, enable your frameworks, and invite your team.

Assess

Work through each framework's controls with built-in guidance and a Statement of Applicability.

Evidence

Attach proof, policies and register entries against each control as you implement.

Report

Track live scores per framework and export an audit-ready compliance package.

Ready to see your compliance posture?

Book a walkthrough and we'll map your obligations across the frameworks you need.

Get in touch →