Compliance Engine Features / Controls

Controls

All controls for your activated frameworks in one place. AI pre-fills, you confirm and seal — every confirmation is signed and logged in the WORM audit trail.

What is Controls

One control catalog, each framework with its own workbench.

Every activated framework — DORA, NIS2, ISO 27001, EU AI Act, GDPR, SOC 2, CRA — gets its own controls workbench with the full control catalog for that regime: for SOC 2, for example, all Trust Services Criteria CC1 through CC9.

Each control shows an evidence checklist. If an evidence item is missing, you can submit it directly — as a document, text, or an AI-assisted draft. Once a control is ready for confirmation — every evidence item documented and sealed — you confirm the implementation; the confirmation is signed and logged in the WORM audit trail.

An AI recommendation pre-assesses controls using existing data on file — but sealing happens only after your confirmation. The overview across all frameworks shows audit readiness as a percentage, open gaps, and pending AI suggestions at a glance.

Core capabilities

What the controls workbench delivers.

Full control catalog per framework

Every activated regime — including all SOC 2 TSC categories — with its own workbench and its own progress.

Evidence checklist per control

Submit missing evidence items directly at the control, instead of collecting proof separately.

AI pre-fill with mandatory confirmation

AI proposes implementation status based on data on file — sealing happens only after human confirmation.

Signed confirmation in the WORM log

Every status change is logged and cannot be altered or deleted afterward.

Audit readiness at a glance

Percentage coverage, open gaps and running deadlines per framework — centralized in the dashboard.

Workflow

From an open control to a sealed confirmation.

An end-to-end flow instead of scattered email evidence.

Open

A control without sufficient evidence — visible as a gap on the dashboard.

Evidence submitted

A document, text or AI draft attached to the control.

Ready for confirmation

Every evidence item documented and sealed — awaiting human review.

Implemented & sealed

Confirmation signed and logged in the WORM audit trail.

How it works

How Controls works.

Activate a framework

A service books a framework — the full control catalog is created automatically.

Submit evidence

Work through the evidence checklist per control — with an AI suggestion or manually.

Confirm & seal

After review, confirm; the confirmation is signed and logged immutably.

Connected regulations

A core building block for these regimes.

All six frameworks

DORA, NIS2, ISO 27001, EU AI Act, GDPR and SOC 2 — a full control catalog for each.

Regulation in detail →
SOC 2

All nine Trust Services Criteria CC1–CC9 as their own workbench.

Regulation in detail →
ISO/IEC 27001

All Annex A controls as a Statement of Applicability.

Regulation in detail →
Next step

One control catalog instead of six spreadsheets.

We'll show you what the controls workbench looks like for your booked frameworks.