Run every compliance framework in one place, with clarity.
GRCLens is a multi-tenant GRC platform that turns regulatory and ISO frameworks — from NCA-ECC and PDPL to ISO/IEC 27001 — into a single, trackable program. Assess, evidence, and report across them in one place, capturing evidence once and reusing it everywhere.
Live compliance snapshot
Deep expertise across the disciplines that matter
From board-level cyber governance to payment security and critical infrastructure — GRCLens brings every discipline into one lens.
Cyber Governance
Board-level oversight, policies and operating models aligned to NCA-ECC, NIST and ISO.
Key Risk Indicators
Live KPI/KRI dashboards derived from real assessment and evidence data.
AI Management Systems
ISO/IEC 42001 AI governance — system registers, impact assessments and controls.
SOC 2 Assurance
Trust Services Criteria readiness for service organizations, end to end.
Payment Card Security
PCI DSS compliance — SAQ, ROC and AOC workflows built in.
Critical Infrastructure
Resilience for CNI and OT environments — from ECC to IEC 62443 and AESCSF.
Cover the standards that matter — side by side
Regulated organizations rarely answer to a single framework. GRCLens maps them to a common control model, so evidence captured for one obligation can satisfy another. Enable only the frameworks each client needs.
NCA Essential Cybersecurity Controls
Saudi Arabia's baseline cybersecurity controls for government entities, critical infrastructure, and their providers.
- Cyber Governance
- Cyber Defense
- Cyber Resilience
- Third-Party & Cloud
Personal Data Protection Law
The Kingdom's data-privacy law governing how personal data of individuals in KSA is collected, processed, and transferred.
- Lawful basis & consent
- Data subject rights
- Cross-border transfer
- Breach notification & RoPA
PK-CTDISR (Critical Telecom Data & Infrastructure Security)
Pakistan Telecommunication Authority's regulation securing critical telecom data and infrastructure for licensees and operators.
- Security governance & risk
- Data & asset protection
- Network & infrastructure security
- Incident response & audits
ISO/IEC 27001:2022 (ISMS)
The international standard for an Information Security Management System — clauses 4–10 plus all 93 Annex A controls, with a full Statement of Applicability.
- ISMS scoping & context
- Risk assessment & treatment
- 93 Annex A controls
- Statement of Applicability
ISO/IEC 20000-1:2018 (ITSM)
The service-management standard for planning, delivering, and continually improving IT services — clauses 4–10 with the full SMS process set.
- Service management system
- Service levels & reporting
- Incident, problem & change
- Continual improvement
ISO/IEC 42001:2023 (AI Management)
The first management-system standard for artificial intelligence — with an AI System Register, Statement of Applicability and AI-specific registers.
- AI systems inventory
- AI risk & impact
- 38 Annex A controls
- Legal, data & ADM registers
SOC 2 (Trust Services Criteria)
The assurance framework for service organizations, evidencing controls across the five Trust Services Criteria.
- Security
- Availability
- Confidentiality
- Processing integrity & privacy
ISO 9001:2015 (Quality)
The quality management system standard — process approach, risk-based thinking and continual improvement across clauses 4–10.
- QMS scope & context
- Process & risk approach
- Performance evaluation
- Continual improvement
ISO 14001:2015 (Environmental)
The environmental management system standard covering environmental aspects, compliance obligations and lifecycle thinking.
- Environmental aspects
- Compliance obligations
- Objectives & targets
- Emergency preparedness
ISO 45001:2018 (OH&S)
The occupational health and safety management system standard — hazard identification, worker participation and incident management.
- Hazard identification
- Worker consultation
- Incident investigation
- OH&S performance
PCI DSS v4.0.1
The payment card industry standard for any organization that stores, processes or transmits cardholder data — including the v4.0.1 future-dated requirements now in force.
- 12 core requirements
- Scope & segmentation
- Customised approach
- QSA-ready evidence
HIPAA (Security & Privacy Rules)
The US healthcare regulation protecting electronic protected health information — documented risk analysis plus administrative, physical and technical safeguards.
- Security Rule safeguards
- Privacy Rule & PHI
- Risk analysis & management
- Breach notification
NIST SP 800-53 Rev. 5
The US federal catalogue of security and privacy controls for information systems, widely adopted as a comprehensive control baseline.
- 20 control families
- Baseline tailoring
- Privacy controls
- Assessment procedures
Risk Management
An enterprise risk register with scoring, treatment plans and owner accountability — linked directly to the controls that mitigate each risk.
- Risk register & scoring
- Treatment & owners
- Control linkage
- Board-ready reporting
Supply Chain / Vendor Assessment
Structured third-party due diligence — tiering, questionnaires and evidence review, so supplier risk is assessed consistently and re-assessed on cadence.
- Vendor tiering
- Assessment questionnaires
- Evidence & findings
- Periodic re-assessment
Network Security Policy Management (NSPM)
Centralised governance of multi-vendor firewall estates — rule hygiene, change monitoring, risk scoring and compliance posture in one view.
- Multi-vendor firewall support
- Rule hygiene & risk scoring
- Change & drift detection
- Compliance mapping
Every framework above runs on one shared control model, so evidence captured once can satisfy obligations across several standards at the same time. Frameworks are enabled per tenant, so each client sees only what applies to them. Need a standard that is not listed? Talk to us about adding it to your programme.
A complete compliance workspace
From first assessment to audit-ready reporting — purpose-built for modern GRC teams.
Multi-framework by design
Run NCA-ECC, PDPL and ISO/IEC 27001 together; map controls once and reuse evidence across frameworks.
Real-time dashboards
See compliance scores per framework and domain, updated the moment an assessment changes.
Control-by-control assessment
Every control carries its clause, guidance, and expected deliverables to guide your team.
AI evidence analysis
Uploaded evidence is analysed for relevance and confidence, with a human approve/reject in the loop.
Multi-tenant & role-based
Each organization gets an isolated workspace with admin, assessor, and viewer roles.
Secure by architecture
Schema-per-tenant isolation, encrypted credentials, zero-downtime deploys, and HTTPS everywhere.
Compliance in four steps
Onboard
We provision your isolated tenant workspace, enable your frameworks, and invite your team.
Assess
Work through each framework's controls with built-in guidance and a Statement of Applicability.
Evidence
Attach proof, policies and register entries against each control as you implement.
Report
Track live scores per framework and export an audit-ready compliance package.
Ready to see your compliance posture?
Book a walkthrough and we'll map your obligations across the frameworks you need.
Get in touch →