● One platform for cyber, privacy & AI governance

Run every compliance framework in one place, with clarity.

GRCLens is a multi-tenant GRC platform that turns regulatory and ISO frameworks — from NCA-ECC and PDPL to ISO/IEC 27001 — into a single, trackable program. Assess, evidence, and report across them in one place, capturing evidence once and reusing it everywhere.

Live compliance snapshot

61%
ISO/IEC 2700172%
NCA-ECC64%
PDPL70%
SOC 251%
ISO/IEC 4200138%
7 frameworks, one program
Cyber · Privacy · Service · AI
Multi-tenant & isolated by design
Built for teams worldwide
Domains we secure

Deep expertise across the disciplines that matter

From board-level cyber governance to payment security and critical infrastructure — GRCLens brings every discipline into one lens.

Cyber Governance

Cyber Governance

Board-level oversight, policies and operating models aligned to NCA-ECC, NIST and ISO.

Key Risk Indicators

Key Risk Indicators

Live KPI/KRI dashboards derived from real assessment and evidence data.

AI Management Systems

AI Management Systems

ISO/IEC 42001 AI governance — system registers, impact assessments and controls.

SOC 2 Assurance

SOC 2 Assurance

Trust Services Criteria readiness for service organizations, end to end.

Payment Card Security

Payment Card Security

PCI DSS compliance — SAQ, ROC and AOC workflows built in.

Critical Infrastructure

Critical Infrastructure

Resilience for CNI and OT environments — from ECC to IEC 62443 and AESCSF.

A growing library of frameworks

Cover the standards that matter — side by side

Regulated organizations rarely answer to a single framework. GRCLens maps them to a common control model, so evidence captured for one obligation can satisfy another. Enable only the frameworks each client needs.

AvailableNZ · PSR

Protective Security Requirements (NZ)

The New Zealand Government's protective security framework — security governance, personnel, information and physical security, with annual assurance reporting.

  • GOVSEC & security leadership
  • PERSEC personnel security
  • INFOSEC & NZISM alignment
  • PHYSEC & annual reporting
AvailableNZ · NCSC MCSS

Minimum Cyber Security Standards (NZ)

The NCSC's mandatory cyber baseline for mandated agencies — assessed on the CS-CMM maturity model at minimum level CMM2, reported through PSR assurance.

  • Business-critical & external systems
  • CS-CMM maturity evidence
  • Minimum level CMM2 Planned & Tracked
  • Reports via PSR assurance
AvailableNZ · HISO 10029

Health Information Security Framework (NZ)

Te Whatu Ora's standard for protecting health information across the NZ health and disability sector, including Māori data governance obligations.

  • Plan, identify & protect
  • Detect & respond
  • Te Tiriti & Māori data governance
  • Board-level visibility
AvailableAU · PSPF

Protective Security Policy Framework (AU)

The Australian Government's protective security requirements across governance, information, personnel and physical security — 2025 Annual Release structure.

  • Security governance & risk
  • Information & technology security
  • Personnel & physical security
  • Annual maturity reporting
AvailableAU · IRAP / ISM

IRAP (Australian ISM Assessments)

Run Australian ISM assessments the IRAP way — scoped engagements, control-by-control evaluation, connector-collected evidence and findings registers.

  • Engagement workspaces
  • ISM catalogue pinned per revision
  • Automated evidence collection
  • Findings & assurance loop
AvailableAU · AESCSF / SOCI

AESCSF & SOCI CIRMP

Energy-sector cyber maturity (AESCSF) and SOCI Act risk-management obligations — maturity evidence and the annual board-approved CIRMP report.

  • AESCSF maturity assessment
  • SOCI CIRMP obligations
  • Recognised framework options
  • Board-ready reporting
AvailableVIC · VPDSS

Victorian Protective Data Security Standards

OVIC's data security standards for the Victorian public sector — governance, information, personnel, ICT and physical security with PDSP attestation.

  • Five security standards
  • Information asset context
  • ISM-aligned ICT security
  • PDSP & executive attestation
AvailablePCI · DSS

PCI DSS v4.0.1

The payment card industry standard for any organization that stores, processes or transmits cardholder data — including the v4.0.1 future-dated requirements now in force.

  • 12 core requirements
  • Scope & segmentation
  • Customised approach
  • QSA-ready evidence
AvailableISA/IEC · 62443

ISA/IEC 62443 (OT / ICS Security)

Industrial control system security — the asset-owner security programme and the seven foundational requirements, with zones, conduits and security levels.

  • Security programme (62443-2-1)
  • Foundational requirements FR1–FR7
  • Zones & conduits
  • Security levels SL1–SL4
AvailableHHS · HIPAA

HIPAA (Security & Privacy Rules)

The US healthcare regulation protecting electronic protected health information — documented risk analysis plus administrative, physical and technical safeguards.

  • Security Rule safeguards
  • Privacy Rule & PHI
  • Risk analysis & management
  • Breach notification
AvailableEU · GDPR

GDPR (EU 2016/679)

The EU's data protection regulation — lawful basis, data subject rights, records of processing, transfers and breach readiness, evidenced for accountability.

  • Lawful basis & subject rights
  • Records of processing (RoPA)
  • DPIA & cross-border transfers
  • 72-hour breach notification
AvailableNIST · SP 800-53

NIST SP 800-53 Rev. 5

The US federal catalogue of security and privacy controls for information systems, widely adopted as a comprehensive control baseline.

  • 20 control families
  • Baseline tailoring
  • Privacy controls
  • Assessment procedures
AvailableAICPA · SOC 2

SOC 2 (Trust Services Criteria)

The assurance framework for service organizations, evidencing controls across the five Trust Services Criteria.

  • Security
  • Availability
  • Confidentiality
  • Processing integrity & privacy
AvailableISO/IEC · 27001

ISO/IEC 27001:2022 (ISMS)

The international standard for an Information Security Management System — clauses 4–10 plus all 93 Annex A controls, with a full Statement of Applicability.

  • ISMS scoping & context
  • Risk assessment & treatment
  • 93 Annex A controls
  • Statement of Applicability
AvailableISO/IEC · 9001

ISO 9001:2015 (Quality)

The quality management system standard — process approach, risk-based thinking and continual improvement across clauses 4–10.

  • QMS scope & context
  • Process & risk approach
  • Performance evaluation
  • Continual improvement
AvailableISO/IEC · 14001

ISO 14001:2015 (Environmental)

The environmental management system standard covering environmental aspects, compliance obligations and lifecycle thinking.

  • Environmental aspects
  • Compliance obligations
  • Objectives & targets
  • Emergency preparedness
AvailableISO/IEC · 45001

ISO 45001:2018 (OH&S)

The occupational health and safety management system standard — hazard identification, worker participation and incident management.

  • Hazard identification
  • Worker consultation
  • Incident investigation
  • OH&S performance
AvailableISO · 22301

ISO 22301:2019 (Business Continuity)

The certifiable BCMS standard — business impact analysis, risk assessment, continuity strategies, plans and a validated exercise programme.

  • BIA with RTO/MTPD
  • Strategies & solutions
  • Plans & response structure
  • Exercise programme
AvailableISO · 22361

ISO 22361:2022 (Crisis Management)

Crisis management capability for executive teams — leadership, strategic decision-making, crisis communication and organisational learning.

  • CMT structure & activation
  • Strategic decision-making
  • Crisis communication
  • Training, validation & learning
AvailableISO/IEC · 20000-1

ISO/IEC 20000-1:2018 (ITSM)

The service-management standard for planning, delivering, and continually improving IT services — clauses 4–10 with the full SMS process set.

  • Service management system
  • Service levels & reporting
  • Incident, problem & change
  • Continual improvement
AvailableISO/IEC · 42001

ISO/IEC 42001:2023 (AI Management)

The first management-system standard for artificial intelligence — with an AI System Register, Statement of Applicability and AI-specific registers.

  • AI systems inventory
  • AI risk & impact
  • 38 Annex A controls
  • Legal, data & ADM registers
AvailableNCA · ECC

NCA Essential Cybersecurity Controls

Saudi Arabia's baseline cybersecurity controls for government entities, critical infrastructure, and their providers.

  • Cyber Governance
  • Cyber Defense
  • Cyber Resilience
  • Third-Party & Cloud
AvailableSDAIA · PDPL

Personal Data Protection Law

The Kingdom's data-privacy law governing how personal data of individuals in KSA is collected, processed, and transferred.

  • Lawful basis & consent
  • Data subject rights
  • Cross-border transfer
  • Breach notification & RoPA
AvailableCST · CRF

CST CRF (KSA ICT Sector)

The Communications, Space & Technology Commission's cybersecurity framework for Saudi ICT-sector licensees — 215 controls across six domains.

  • Governance & risk
  • Asset & logical security
  • Physical security
  • Third-party security
AvailablePTA · CTDISR

PK-CTDISR (Critical Telecom Data & Infrastructure Security)

Pakistan Telecommunication Authority's regulation securing critical telecom data and infrastructure for licensees and operators.

  • Security governance & risk
  • Data & asset protection
  • Network & infrastructure security
  • Incident response & audits
AvailablePKCERT · PISF

PISF 2026 (Pakistan Information Security Framework)

Cabinet-approved national baseline for 238 mandatory controls across 13 domains — covering government entities, critical infrastructure operators, and licensed private-sector organisations.

  • Governance & risk
  • Data protection & privacy
  • CIIP & data centre security
  • Incident response & supply chain
AvailablePractice · Risk

Risk Management

An enterprise risk register with scoring, treatment plans and owner accountability — linked directly to the controls that mitigate each risk.

  • Risk register & scoring
  • Treatment & owners
  • Control linkage
  • Board-ready reporting
AvailablePractice · Third Party

Supply Chain / Vendor Assessment

Structured third-party due diligence — tiering, questionnaires and evidence review, so supplier risk is assessed consistently and re-assessed on cadence.

  • Vendor tiering
  • Assessment questionnaires
  • Evidence & findings
  • Periodic re-assessment
AvailableModule · NSPM

Network Security Policy Management (NSPM)

Centralised governance of multi-vendor firewall estates — rule hygiene, change monitoring, risk scoring and compliance posture in one view.

  • Multi-vendor firewall support
  • Rule hygiene & risk scoring
  • Change & drift detection
  • Compliance mapping
AvailableModule · PhishLens

PhishLens (Phishing Simulation)

Awareness testing with realistic campaigns — click analytics, repeat-clicker risk and executive reports that evidence awareness controls.

  • Campaign engine & templates
  • Click & repeat-clicker analytics
  • Executive & ops dashboards
  • Evidence for awareness controls

Every framework above runs on one shared control model, so evidence captured once can satisfy obligations across several standards at the same time. Frameworks are enabled per tenant, so each client sees only what applies to them. Need a standard that is not listed? Talk to us about adding it to your programme.

Everything you need

A complete compliance workspace

From first assessment to audit-ready reporting — purpose-built for modern GRC teams.

Multi-framework by design

Run NCA-ECC, PDPL and ISO/IEC 27001 together; map controls once and reuse evidence across frameworks.

Real-time dashboards

See compliance scores per framework and domain, updated the moment an assessment changes.

Control-by-control assessment

Every control carries its clause, guidance, and expected deliverables to guide your team.

AI evidence analysis

Uploaded evidence is analysed for relevance and confidence, with a human approve/reject in the loop.

Multi-tenant & role-based

Each organization gets an isolated workspace with admin, assessor, and viewer roles.

Secure by architecture

Schema-per-tenant isolation, encrypted credentials, zero-downtime deploys, and HTTPS everywhere.

7
Frameworks supported
420+
Controls mapped
SOA
& dynamic registers
100%
Cloud-hosted & secure
How it works

Compliance in four steps

Onboard

We provision your isolated tenant workspace, enable your frameworks, and invite your team.

Assess

Work through each framework's controls with built-in guidance and a Statement of Applicability.

Evidence

Attach proof, policies and register entries against each control as you implement.

Report

Track live scores per framework and export an audit-ready compliance package.

Ready to see your compliance posture?

Book a walkthrough and we'll map your obligations across the frameworks you need.

Get in touch →