
Run every compliance framework in one place, with clarity.
GRCLens is a multi-tenant GRC platform that turns regulatory and legislative obligations — from critical infrastructure and industrial control systems, PCI DSS and HIPAA, NCA ECC and PDPL, to ISO 27001 and ISO 42001 — into a single, trackable program. Assess, evidence and report in one place, capturing evidence once and reusing it everywhere.
Then go beyond the checklist. GRCLens reads every control through a risk lens and turns compliance data into business intelligence — dashboards that show leadership where capability stands, where performance is heading and what to act on next. Governance, Performance, Risk and Compliance in one lens: GPRC.
Deep expertise across the disciplines that matter
From board-level cyber governance to payment security and critical infrastructure — GRCLens brings every discipline into one lens.
Cyber Governance
Board-level oversight, policies and operating models aligned to NCA-ECC, NIST and ISO.
Read more →Key Risk Indicators
Live KPI/KRI dashboards derived from real assessment and evidence data.
Read more →AI Management Systems
ISO/IEC 42001 AI governance — system registers, impact assessments and controls.
Read more →SOC 2 Assurance
Trust Services Criteria readiness for service organizations, end to end.
Read more →Payment Card Security
PCI DSS compliance — SAQ, ROC and AOC workflows built in.
Read more →Critical Infrastructure
Resilience for CNI and OT environments — from ECC to IEC 62443 and AESCSF.
Read more →Cover the standards that matter — side by side
Regulated organizations rarely answer to a single framework. GRCLens maps them to a common control model, so evidence captured for one obligation can satisfy another. Enable only the frameworks each client needs.
Protective Security Requirements (NZ)
The New Zealand Government's protective security framework — security governance, personnel, information and physical security, with annual assurance reporting.
- GOVSEC & security leadership
- PERSEC personnel security
- INFOSEC & NZISM alignment
- PHYSEC & annual reporting
Minimum Cyber Security Standards (NZ)
The NCSC's mandatory cyber baseline for mandated agencies — assessed on the CS-CMM maturity model at minimum level CMM2, reported through PSR assurance.
- Business-critical & external systems
- CS-CMM maturity evidence
- Minimum level CMM2 Planned & Tracked
- Reports via PSR assurance
Health Information Security Framework (NZ)
Te Whatu Ora's standard for protecting health information across the NZ health and disability sector, including Māori data governance obligations.
- Plan, identify & protect
- Detect & respond
- Te Tiriti & Māori data governance
- Board-level visibility
Protective Security Policy Framework (AU)
The Australian Government's protective security requirements across governance, information, personnel and physical security — 2025 Annual Release structure.
- Security governance & risk
- Information & technology security
- Personnel & physical security
- Annual maturity reporting
IRAP (Australian ISM Assessments)
Run Australian ISM assessments the IRAP way — scoped engagements, control-by-control evaluation, connector-collected evidence and findings registers.
- Engagement workspaces
- ISM catalogue pinned per revision
- Automated evidence collection
- Findings & assurance loop
AESCSF & SOCI CIRMP
Energy-sector cyber maturity (AESCSF) and SOCI Act risk-management obligations — maturity evidence and the annual board-approved CIRMP report.
- AESCSF maturity assessment
- SOCI CIRMP obligations
- Recognised framework options
- Board-ready reporting
Victorian Protective Data Security Standards
OVIC's data security standards for the Victorian public sector — governance, information, personnel, ICT and physical security with PDSP attestation.
- Five security standards
- Information asset context
- ISM-aligned ICT security
- PDSP & executive attestation
PCI DSS v4.0.1
The payment card industry standard for any organization that stores, processes or transmits cardholder data — including the v4.0.1 future-dated requirements now in force.
- 12 core requirements
- Scope & segmentation
- Customised approach
- QSA-ready evidence
ISA/IEC 62443 (OT / ICS Security)
Industrial control system security — the asset-owner security programme and the seven foundational requirements, with zones, conduits and security levels.
- Security programme (62443-2-1)
- Foundational requirements FR1–FR7
- Zones & conduits
- Security levels SL1–SL4
HIPAA (Security & Privacy Rules)
The US healthcare regulation protecting electronic protected health information — documented risk analysis plus administrative, physical and technical safeguards.
- Security Rule safeguards
- Privacy Rule & PHI
- Risk analysis & management
- Breach notification
GDPR (EU 2016/679)
The EU's data protection regulation — lawful basis, data subject rights, records of processing, transfers and breach readiness, evidenced for accountability.
- Lawful basis & subject rights
- Records of processing (RoPA)
- DPIA & cross-border transfers
- 72-hour breach notification
NIST SP 800-53 Rev. 5
The US federal catalogue of security and privacy controls for information systems, widely adopted as a comprehensive control baseline.
- 20 control families
- Baseline tailoring
- Privacy controls
- Assessment procedures
SOC 2 (Trust Services Criteria)
The assurance framework for service organizations, evidencing controls across the five Trust Services Criteria.
- Security
- Availability
- Confidentiality
- Processing integrity & privacy
ISO/IEC 27001:2022 (ISMS)
The international standard for an Information Security Management System — clauses 4–10 plus all 93 Annex A controls, with a full Statement of Applicability.
- ISMS scoping & context
- Risk assessment & treatment
- 93 Annex A controls
- Statement of Applicability
ISO 9001:2015 (Quality)
The quality management system standard — process approach, risk-based thinking and continual improvement across clauses 4–10.
- QMS scope & context
- Process & risk approach
- Performance evaluation
- Continual improvement
ISO 14001:2015 (Environmental)
The environmental management system standard covering environmental aspects, compliance obligations and lifecycle thinking.
- Environmental aspects
- Compliance obligations
- Objectives & targets
- Emergency preparedness
ISO 45001:2018 (OH&S)
The occupational health and safety management system standard — hazard identification, worker participation and incident management.
- Hazard identification
- Worker consultation
- Incident investigation
- OH&S performance
ISO 22301:2019 (Business Continuity)
The certifiable BCMS standard — business impact analysis, risk assessment, continuity strategies, plans and a validated exercise programme.
- BIA with RTO/MTPD
- Strategies & solutions
- Plans & response structure
- Exercise programme
ISO 22361:2022 (Crisis Management)
Crisis management capability for executive teams — leadership, strategic decision-making, crisis communication and organisational learning.
- CMT structure & activation
- Strategic decision-making
- Crisis communication
- Training, validation & learning
ISO/IEC 20000-1:2018 (ITSM)
The service-management standard for planning, delivering, and continually improving IT services — clauses 4–10 with the full SMS process set.
- Service management system
- Service levels & reporting
- Incident, problem & change
- Continual improvement
ISO/IEC 42001:2023 (AI Management)
The first management-system standard for artificial intelligence — with an AI System Register, Statement of Applicability and AI-specific registers.
- AI systems inventory
- AI risk & impact
- 38 Annex A controls
- Legal, data & ADM registers
NCA Essential Cybersecurity Controls
Saudi Arabia's baseline cybersecurity controls for government entities, critical infrastructure, and their providers.
- Cyber Governance
- Cyber Defense
- Cyber Resilience
- Third-Party & Cloud
Personal Data Protection Law
The Kingdom's data-privacy law governing how personal data of individuals in KSA is collected, processed, and transferred.
- Lawful basis & consent
- Data subject rights
- Cross-border transfer
- Breach notification & RoPA
CST CRF (KSA ICT Sector)
The Communications, Space & Technology Commission's cybersecurity framework for Saudi ICT-sector licensees — 215 controls across six domains.
- Governance & risk
- Asset & logical security
- Physical security
- Third-party security
UAE Information Assurance Standard
The UAE's national information security baseline — six management and nine technical families, prioritised P1 to P4, mandatory for federal entities and critical infrastructure.
- 15 control families (M1–M6, T1–T9)
- P1–P4 priority-tier dashboard
- Risk-based applicability statement
- Arabic & English operation
Dubai Information Security Regulation (ISR v3)
DESC's regulation for Dubai Government entities and their suppliers — strengthened in v3 for cloud and data residency, IoT/OT and supply-chain security.
- 13 security domains
- Cloud & data residency evidence
- IoT / OT security
- Supply-chain requirements
DFSA Cyber Risk Management Rules
The DFSA's cyber rules for every DIFC Authorised Firm, in force since 1 January 2024 — framework, governance, ICT asset protection, resilience testing, response, and the 72-hour notification as a rule of its own.
- 7 sections, 51 rule paragraphs
- 72-hour notification indicator
- Rulebook wording + DFSA Guidance
- Reads beside the FSRA catalogue
ADGM FSRA Cyber Risk Management
The FSRA's cyber rules for every ADGM Authorised Person, binding since 31 January 2026 — with the UAE's strictest incident window: notify the Regulator within 24 hours.
- 7 sections, 43 rule paragraphs
- 24-hour notification readiness
- Third-party ICT risk incl. cloud
- Reads beside the DFSA catalogue
CBUAE Operational Risk, Technology & Cyber
The Central Bank's Operational Risk Management Regulation article by article for every licensed financial institution, plus the SVF and Retail Payment Services technology-risk articles scoped to the licences they bind.
- 15 domains, 220 obligations
- ORM Arts 2–13, 15 for all LFIs
- SVF Art 12 · RPS Art 13 by licence
- Notification readiness indicator
UAE Personal Data Protection Law
Federal Decree-Law 45/2021 article by article — lawful basis, controller and processor duties, breach reporting, DPO, the seven data subject rights, security and cross-border transfer — with Executive-Regulation dependencies flagged.
- 8 article groups, 43 controls
- Article cited on every control
- Pending Regulations marked as such
- Registers shared with ISO 27001 / 42001
Abu Dhabi Healthcare Information & Cyber Security Standard
DoH's mandatory standard for every licensed healthcare entity in Abu Dhabi — 11 domains and 131 controls graded Basic, Transitional and Advanced, generated from the 2024 PDF, with localisation, breach reporting and cloud security as their own indicators.
- 11 domains, 131 controls
- Basic / Transitional / Advanced scoping
- Service Provider rows flagged
- Arabic and English
UAE ICT Health Law
The federal health data law article by article — confidentiality, the Article 13 localisation prohibition and its ten MR 51/2021 exceptions, 25-year retention and Central System access — with the Law, Executive Regulation and Ministerial Resolution coded apart.
- 9 domains, 44 duties
- Three instruments, never confused
- Localisation exceptions with conditions
- Arabic and English
DIFC Data Protection Law
The DIFC's own privacy law consolidated to the 2025 amendments — registration, DPO and Annual Assessment, lawful basis, rights, breach notification, transfers, digital marketing and the Regulation 10 AI-systems rules — 79 obligations across 11 domains.
- 11 domains, 79 controls
- Commissioner-facing duties as one indicator
- Regulation 10 AI systems covered
- Reads beside DFSA and ADGM
ADGM Data Protection Regulations
Abu Dhabi Global Market's privacy law section by section, as amended to September 2025 — registration and fee, DPO, DPIA, lawful basis, rights, 72-hour breach notification, transfers and enforcement readiness — 78 obligations across 10 domains.
- 10 domains, 78 controls
- 72-hour breach clock pinned
- Annual fee and DPO deadlines tracked
- Same six indicators as DIFC
NCSC Baseline Cybersecurity Controls
Bahrain's national cybersecurity baseline — 81 controls across 7 domains, mandatory for critical national infrastructure under Royal Decree 17/2025 and encouraged for every other organisation.
- 7 domains, 81 controls
- Mandatory for CNI entities
- Incident notification to NCSC
- Quarterly VA, annual pentest
CBB Cyber Security Risk Management (OM-5.5)
The Central Bank of Bahrain's binding cyber module for every bank licensee — 171 controls across 17 domains, with the 1-hour/2-hour incident reporting clock as its own indicator.
- 171 controls, 17 domains
- Board and Senior Management duties
- 1-hour call, 2-hour email to CBB
- Conventional and Islamic banks
Bahrain Personal Data Protection Law
Law No. 30 of 2018 with its ten 2022 Ministerial Orders — 82 controls across 12 domains, the Data Protection Guardian regime and the 72-hour breach clock tracked as their own indicators.
- 12 domains, 82 controls
- Data Protection Guardian regime
- 72-hour breach notification
- 83-country transfer whitelist
Non-CNI Private Sector Entities Cybersecurity Controls
NCA's baseline for Saudi private sector entities outside critical national infrastructure — 112 controls across 3 components, scoped to Category A or Category B applicability.
- 112 controls, 3 components
- Category A / Category B scoping
- Mandatory set inside Defense
- Sector picker built in
Cloud Cybersecurity Controls (CCC-2:2024)
NCA's cloud-specific controls for providers and tenants — 175 controls across 4 domains, each population seeing only the text NCA wrote for it.
- 175 controls, 4 domains
- Provider 131 · Tenant 44
- Annex A classification levels
- Supersedes CCC-1:2020
National Information Assurance Standard v2.1
NCSA's current certifiable standard, superseding NIA v2.0 for new applications and re-certification — 356 controls across 26 domains, 166 baseline controls tracked as mandatory.
- 356 controls, 26 domains
- 166 baseline controls
- 2-hour incident notification
- Supersedes NIA v2.0
QCB Cloud Computing Regulation
QCB's binding cloud regulation, in force since 15 April 2024 — 141 controls across 19 domains, with QCB approval before any cloud arrangement and Qatar-only data processing.
- 141 controls, 19 domains
- QCB approval before any arrangement
- Qatar-only PII and financial data
- Exit and termination duties
QCB Data Handling & Protection Regulation
QCB's data protection regulation for its Financial Institutions — 126 controls across 10 domains, DPO governance, 10-year retention and breach notification to QCB, NCSA and the Ministry of Interior.
- 126 controls, 10 domains
- DPO, ROPA and PIA duties
- 10-year retention floor
- Breach to QCB, NCSA and MoI
National Cyber Security Baseline v1.4
NACSA's self-assessment for NCII entities under the Cyber Security Act 2024 — 125 questions across 33 elements and the six NIST CSF 2.0 functions, reported on the four-level Initial-to-Advanced maturity scale.
- 125 questions, 33 elements
- Six NIST CSF 2.0 functions
- Maturity Initial → Advanced, no floor
- Eleven NCII sectors
Risk Management in Technology (RMiT)
Bank Negara Malaysia's technology risk policy, revised effective 28 November 2025 — 173 controls across 14 domains, with the 90-day gap analysis and annual self-assessment tracked as an indicator.
- 173 controls, 14 domains
- 90-day gap analysis clock
- Standard and Guidance kept apart
- English only catalogue
Qatar Central Bank Technology Risk & Cyber Security
QCB's binding regulations for banks and for insurers, held as one framework with two licensee populations — each sees only the text written for it.
- Banks and insurance populations
- 9 domains per population
- 712 controls, QCB's wording
- Group oversight across entities
Qatar Personal Data Privacy Protection Law
Law No. 13 of 2016, the Gulf's first data privacy law — grouped by the duty each article creates, from lawful basis and individual rights to breach notification and cross-border flows.
- 11 duty-based domains, 51 controls
- Article cited on every control
- Breach and request records
- Enforced by NCSA (NCGAA)
Kuwait National Basic Cybersecurity Controls
NCSC Decision 2/2026's mandatory minimum for government, security bodies and critical private-sector operators — 44 controls, due by 5 October 2027.
- Govern to Recover + cloud appendix
- 21 MUST controls tracked as mandatory
- Deadline 5 October 2027
- Arabic-first catalogue
CBK Cyber & Operational Resilience Framework
The Central Bank of Kuwait's resilience-first framework for banks and financial institutions — three baselines and 875 controls generated from CBK's own text.
- Cyber · Operational · Third-party baselines
- 875 controls, 25 domains
- Generated from the CBK document
- TPRM joined to the vendor register
CBO Cyber Security & Resilience Framework
The Central Bank of Oman's framework for banks, finance and leasing companies, exchanges and payment providers — six control domains, compliance due 31 July 2024.
- 6 domains, §3.1–§3.6
- 193 measures with section refs
- Compensating controls on record
- Online financial services evidenced
Oman Personal Data Protection Law
Royal Decree 6/2022 with its Executive Regulation, fully enforceable since 5 February 2026 — lawful processing, sensitive data, rights, breach notification and transfers.
- 9 duty-based domains, 35 controls
- 45-day request and 72-hour breach clocks
- Sensitive and children's data permissions
- Regulated by MTCIT
PK-CTDISR (Critical Telecom Data & Infrastructure Security)
Pakistan Telecommunication Authority's regulation securing critical telecom data and infrastructure for licensees and operators.
- Security governance & risk
- Data & asset protection
- Network & infrastructure security
- Incident response & audits
PISF 2026 (Pakistan Information Security Framework)
Cabinet-approved national baseline for 238 mandatory controls across 13 domains — covering government entities, critical infrastructure operators, and licensed private-sector organisations.
- Governance & risk
- Data protection & privacy
- CIIP & data centre security
- Incident response & supply chain
Network Security Policy Management (NSPM)
See what your firewalls actually permit — multi-vendor rule analysis, path and exposure risk, governed change with rollback, and segmentation evidence taken from the live rulebase.
- Fortinet, Palo Alto, Cisco, Huawei, F5, NSX
- Rule hygiene, path tracing & exposure risk
- Change requests, approval, dry run, rollback
- Unauthorised-change detection
- Remote collectors for unreachable sites
- Segmentation evidence for ECC, ISO 27001, PCI DSS
PhishLens (Phishing Simulation)
Awareness testing with realistic campaigns — click analytics, repeat-clicker risk and executive reports that evidence awareness controls.
- Campaign engine & templates
- Click & repeat-clicker analytics
- Executive & ops dashboards
- Evidence for awareness controls
Every framework above runs on one shared control model, so evidence captured once can satisfy obligations across several standards at the same time. Frameworks are enabled per tenant, so each client sees only what applies to them. Need a standard that is not listed? Talk to us about adding it to your programme.
A complete compliance workspace
From first assessment to audit-ready reporting — purpose-built for modern GRC teams.
Multi-framework by design
Run NCA-ECC, PDPL and ISO/IEC 27001 together; map controls once and reuse evidence across frameworks.
Real-time dashboards
See compliance scores per framework and domain, updated the moment an assessment changes.
Control-by-control assessment
Every control carries its clause, guidance, and expected deliverables to guide your team.
AI evidence analysis
Uploaded evidence is analysed for relevance and confidence, with a human approve/reject in the loop.
Multi-tenant & role-based
Each organization gets an isolated workspace with admin, assessor, and viewer roles.
Secure by architecture
Schema-per-tenant isolation, encrypted credentials, zero-downtime deploys, and HTTPS everywhere.
Compliance in four steps
Onboard
We provision your isolated tenant workspace, enable your frameworks, and invite your team.
Assess
Work through each framework's controls with built-in guidance and a Statement of Applicability.
Evidence
Attach proof, policies and register entries against each control as you implement.
Report
Track live scores per framework and export an audit-ready compliance package.

Ready to see your compliance posture?
Book a walkthrough and we'll map your obligations across the frameworks you need.