Run every compliance framework in one place, with clarity.
GRCLens is a multi-tenant GRC platform that turns regulatory and ISO frameworks — from NCA-ECC and PDPL to ISO/IEC 27001 — into a single, trackable program. Assess, evidence, and report across them in one place, capturing evidence once and reusing it everywhere.
Live compliance snapshot
Deep expertise across the disciplines that matter
From board-level cyber governance to payment security and critical infrastructure — GRCLens brings every discipline into one lens.
Cyber Governance
Board-level oversight, policies and operating models aligned to NCA-ECC, NIST and ISO.
Key Risk Indicators
Live KPI/KRI dashboards derived from real assessment and evidence data.
AI Management Systems
ISO/IEC 42001 AI governance — system registers, impact assessments and controls.
SOC 2 Assurance
Trust Services Criteria readiness for service organizations, end to end.
Payment Card Security
PCI DSS compliance — SAQ, ROC and AOC workflows built in.
Critical Infrastructure
Resilience for CNI and OT environments — from ECC to IEC 62443 and AESCSF.
Cover the standards that matter — side by side
Regulated organizations rarely answer to a single framework. GRCLens maps them to a common control model, so evidence captured for one obligation can satisfy another. Enable only the frameworks each client needs.
Protective Security Requirements (NZ)
The New Zealand Government's protective security framework — security governance, personnel, information and physical security, with annual assurance reporting.
- GOVSEC & security leadership
- PERSEC personnel security
- INFOSEC & NZISM alignment
- PHYSEC & annual reporting
Minimum Cyber Security Standards (NZ)
The NCSC's mandatory cyber baseline for mandated agencies — assessed on the CS-CMM maturity model at minimum level CMM2, reported through PSR assurance.
- Business-critical & external systems
- CS-CMM maturity evidence
- Minimum level CMM2 Planned & Tracked
- Reports via PSR assurance
Health Information Security Framework (NZ)
Te Whatu Ora's standard for protecting health information across the NZ health and disability sector, including Māori data governance obligations.
- Plan, identify & protect
- Detect & respond
- Te Tiriti & Māori data governance
- Board-level visibility
Protective Security Policy Framework (AU)
The Australian Government's protective security requirements across governance, information, personnel and physical security — 2025 Annual Release structure.
- Security governance & risk
- Information & technology security
- Personnel & physical security
- Annual maturity reporting
IRAP (Australian ISM Assessments)
Run Australian ISM assessments the IRAP way — scoped engagements, control-by-control evaluation, connector-collected evidence and findings registers.
- Engagement workspaces
- ISM catalogue pinned per revision
- Automated evidence collection
- Findings & assurance loop
AESCSF & SOCI CIRMP
Energy-sector cyber maturity (AESCSF) and SOCI Act risk-management obligations — maturity evidence and the annual board-approved CIRMP report.
- AESCSF maturity assessment
- SOCI CIRMP obligations
- Recognised framework options
- Board-ready reporting
Victorian Protective Data Security Standards
OVIC's data security standards for the Victorian public sector — governance, information, personnel, ICT and physical security with PDSP attestation.
- Five security standards
- Information asset context
- ISM-aligned ICT security
- PDSP & executive attestation
PCI DSS v4.0.1
The payment card industry standard for any organization that stores, processes or transmits cardholder data — including the v4.0.1 future-dated requirements now in force.
- 12 core requirements
- Scope & segmentation
- Customised approach
- QSA-ready evidence
ISA/IEC 62443 (OT / ICS Security)
Industrial control system security — the asset-owner security programme and the seven foundational requirements, with zones, conduits and security levels.
- Security programme (62443-2-1)
- Foundational requirements FR1–FR7
- Zones & conduits
- Security levels SL1–SL4
HIPAA (Security & Privacy Rules)
The US healthcare regulation protecting electronic protected health information — documented risk analysis plus administrative, physical and technical safeguards.
- Security Rule safeguards
- Privacy Rule & PHI
- Risk analysis & management
- Breach notification
GDPR (EU 2016/679)
The EU's data protection regulation — lawful basis, data subject rights, records of processing, transfers and breach readiness, evidenced for accountability.
- Lawful basis & subject rights
- Records of processing (RoPA)
- DPIA & cross-border transfers
- 72-hour breach notification
NIST SP 800-53 Rev. 5
The US federal catalogue of security and privacy controls for information systems, widely adopted as a comprehensive control baseline.
- 20 control families
- Baseline tailoring
- Privacy controls
- Assessment procedures
SOC 2 (Trust Services Criteria)
The assurance framework for service organizations, evidencing controls across the five Trust Services Criteria.
- Security
- Availability
- Confidentiality
- Processing integrity & privacy
ISO/IEC 27001:2022 (ISMS)
The international standard for an Information Security Management System — clauses 4–10 plus all 93 Annex A controls, with a full Statement of Applicability.
- ISMS scoping & context
- Risk assessment & treatment
- 93 Annex A controls
- Statement of Applicability
ISO 9001:2015 (Quality)
The quality management system standard — process approach, risk-based thinking and continual improvement across clauses 4–10.
- QMS scope & context
- Process & risk approach
- Performance evaluation
- Continual improvement
ISO 14001:2015 (Environmental)
The environmental management system standard covering environmental aspects, compliance obligations and lifecycle thinking.
- Environmental aspects
- Compliance obligations
- Objectives & targets
- Emergency preparedness
ISO 45001:2018 (OH&S)
The occupational health and safety management system standard — hazard identification, worker participation and incident management.
- Hazard identification
- Worker consultation
- Incident investigation
- OH&S performance
ISO 22301:2019 (Business Continuity)
The certifiable BCMS standard — business impact analysis, risk assessment, continuity strategies, plans and a validated exercise programme.
- BIA with RTO/MTPD
- Strategies & solutions
- Plans & response structure
- Exercise programme
ISO 22361:2022 (Crisis Management)
Crisis management capability for executive teams — leadership, strategic decision-making, crisis communication and organisational learning.
- CMT structure & activation
- Strategic decision-making
- Crisis communication
- Training, validation & learning
ISO/IEC 20000-1:2018 (ITSM)
The service-management standard for planning, delivering, and continually improving IT services — clauses 4–10 with the full SMS process set.
- Service management system
- Service levels & reporting
- Incident, problem & change
- Continual improvement
ISO/IEC 42001:2023 (AI Management)
The first management-system standard for artificial intelligence — with an AI System Register, Statement of Applicability and AI-specific registers.
- AI systems inventory
- AI risk & impact
- 38 Annex A controls
- Legal, data & ADM registers
NCA Essential Cybersecurity Controls
Saudi Arabia's baseline cybersecurity controls for government entities, critical infrastructure, and their providers.
- Cyber Governance
- Cyber Defense
- Cyber Resilience
- Third-Party & Cloud
Personal Data Protection Law
The Kingdom's data-privacy law governing how personal data of individuals in KSA is collected, processed, and transferred.
- Lawful basis & consent
- Data subject rights
- Cross-border transfer
- Breach notification & RoPA
CST CRF (KSA ICT Sector)
The Communications, Space & Technology Commission's cybersecurity framework for Saudi ICT-sector licensees — 215 controls across six domains.
- Governance & risk
- Asset & logical security
- Physical security
- Third-party security
PK-CTDISR (Critical Telecom Data & Infrastructure Security)
Pakistan Telecommunication Authority's regulation securing critical telecom data and infrastructure for licensees and operators.
- Security governance & risk
- Data & asset protection
- Network & infrastructure security
- Incident response & audits
PISF 2026 (Pakistan Information Security Framework)
Cabinet-approved national baseline for 238 mandatory controls across 13 domains — covering government entities, critical infrastructure operators, and licensed private-sector organisations.
- Governance & risk
- Data protection & privacy
- CIIP & data centre security
- Incident response & supply chain
Risk Management
An enterprise risk register with scoring, treatment plans and owner accountability — linked directly to the controls that mitigate each risk.
- Risk register & scoring
- Treatment & owners
- Control linkage
- Board-ready reporting
Supply Chain / Vendor Assessment
Structured third-party due diligence — tiering, questionnaires and evidence review, so supplier risk is assessed consistently and re-assessed on cadence.
- Vendor tiering
- Assessment questionnaires
- Evidence & findings
- Periodic re-assessment
Network Security Policy Management (NSPM)
Centralised governance of multi-vendor firewall estates — rule hygiene, change monitoring, risk scoring and compliance posture in one view.
- Multi-vendor firewall support
- Rule hygiene & risk scoring
- Change & drift detection
- Compliance mapping
PhishLens (Phishing Simulation)
Awareness testing with realistic campaigns — click analytics, repeat-clicker risk and executive reports that evidence awareness controls.
- Campaign engine & templates
- Click & repeat-clicker analytics
- Executive & ops dashboards
- Evidence for awareness controls
Every framework above runs on one shared control model, so evidence captured once can satisfy obligations across several standards at the same time. Frameworks are enabled per tenant, so each client sees only what applies to them. Need a standard that is not listed? Talk to us about adding it to your programme.
A complete compliance workspace
From first assessment to audit-ready reporting — purpose-built for modern GRC teams.
Multi-framework by design
Run NCA-ECC, PDPL and ISO/IEC 27001 together; map controls once and reuse evidence across frameworks.
Real-time dashboards
See compliance scores per framework and domain, updated the moment an assessment changes.
Control-by-control assessment
Every control carries its clause, guidance, and expected deliverables to guide your team.
AI evidence analysis
Uploaded evidence is analysed for relevance and confidence, with a human approve/reject in the loop.
Multi-tenant & role-based
Each organization gets an isolated workspace with admin, assessor, and viewer roles.
Secure by architecture
Schema-per-tenant isolation, encrypted credentials, zero-downtime deploys, and HTTPS everywhere.
Compliance in four steps
Onboard
We provision your isolated tenant workspace, enable your frameworks, and invite your team.
Assess
Work through each framework's controls with built-in guidance and a Statement of Applicability.
Evidence
Attach proof, policies and register entries against each control as you implement.
Report
Track live scores per framework and export an audit-ready compliance package.
Ready to see your compliance posture?
Book a walkthrough and we'll map your obligations across the frameworks you need.
Get in touch →