COMPLY
Platform

A compliance operating model for defensible control outcomes.

COMPLY connects requirements, controls, evidence, governance, and audit conclusions in one reusable model.

Platform capabilities

Platform model

Framework & Control Library

Maintain framework versions, framework controls, local control definitions, categories, applicability, and mapping rationale in one structured library.

Includes

  • Framework and version management
  • Unified Control Framework (UCF) alignment capability
  • Control mapping and applicability
  • Control purpose, guidance, status, and recommendations

Outcome

One UCF-aware control structure can support ISO, SOC 2, NIST, PCI DSS, GDPR, DORA, NIS2, and other obligations without duplicate program work.

Platform model

Criteria & Evidence Model

Connect audit criteria, internal compliance artifacts, client evidence, and documentation directly to controls and assessment needs.

Includes

  • Audit criteria associated with controls
  • Internal and client evidence registers
  • Evidence-to-control and evidence-to-criteria linkage

Outcome

Evidence becomes reusable, validated, and traceable enough to support defensible audit conclusions.

Platform model

Client, Engagement & Assessment Model

Organize clients, engagements, assessments, applicable frameworks, assessment assets, and related risk assessment activity.

Includes

  • Client and engagement records
  • Assessment scope and framework alignment
  • Assets attached to assessments

Outcome

Every compliance effort has a defined scope, owner context, framework basis, and assessment record.

Platform model

Asset, Vulnerability, Threat & Risk

Link assets to vulnerabilities, threats, risk evaluations, treatment decisions, owners, review states, and treatment controls.

Includes

  • Asset and vulnerability registers
  • Threat linkage and risk evaluation
  • Treatment plans mapped back to controls

Outcome

Risk treatment decisions connect directly to control operation, evidence needs, and governance review.

Platform model

Legal, Regulatory & Contractual Requirements

Track external obligations by requirement type, jurisdiction, interested party, deadline, owner, source, and compliance state.

Includes

  • Regulatory and contractual obligation register
  • Responsible party and deadline tracking
  • Requirement-to-control linkage

Outcome

External obligations are not stranded in documents; they are mapped to controls, risks, assessments, and evidence.

Platform model

Security Stack & Tooling

Model security stack layers, capabilities, tools, vendors, categories, sources, and justifications that support control operation.

Includes

  • Security stack layer inventory
  • Capability-to-tool mapping
  • Vendor, category, source, and justification records

Outcome

Technology coverage can be evaluated against compliance requirements, risks, and control expectations.

Architecture

An operational database for compliance, audit, risk, and control management.

The COMPLY platform model brings frameworks, controls, audit criteria, evidence, client assessments, assets, vulnerabilities, threats, risk treatment, obligations, and security tooling into one connected system of record.

44

Base tables

114

Table occurrences

85

Relationship links

167

Operational layouts

255

Workflow scripts

98

Value lists

Unified control backbone

Framework obligations flow into local controls with categories, applicability, guidance, and mapping rationale.

Evidence and criteria layer

Audit criteria define what evidence must prove, while artifacts show whether controls are operating effectively.

Risk and treatment loop

Assets, vulnerabilities, threats, evaluations, treatments, and treatment controls keep compliance tied to real risk.

Governance and reporting layer

Reviews, exports, registers, and management reporting create oversight and audit-ready visibility.

Traceability

Requirement -> Framework Control -> Local Control -> Evidence -> Report

Requirement to Audit-Ready Output

01

Requirement

The traceability chain begins with the obligation the organization must satisfy, whether it comes from a law, regulation, contract, customer requirement, internal policy, or security framework. COMPLY captures the requirement as the authoritative source of compliance intent so every downstream control, evidence artifact, and audit conclusion can be tied back to a clear obligation.

02

Framework Control

Framework controls translate requirements into recognized compliance expectations such as ISO 27001, SOC 2, NIST, PCI DSS, GDPR, DORA, or CIS Controls. COMPLY maps these controls through the control library so overlapping obligations can be rationalized, compared, and reused instead of being managed as disconnected audit workstreams.

03

Local Control & Criteria

Local controls define how the organization actually satisfies the mapped framework expectations in its own environment. Criteria, applicability, ownership, implementation guidance, and operating expectations establish what must be true for the control to be considered designed, implemented, operating, and ready for review.

04

Evidence Artifact

Evidence artifacts provide the proof that controls are operating in practice. COMPLY links documents, screenshots, tickets, reports, logs, approvals, reviews, and other evidence directly to the relevant criteria and controls, allowing evidence quality, completeness, reuse, and audit relevance to be evaluated before the audit begins.

05

Audit / Report

Audit-ready outputs consolidate the traceability chain into defensible reporting. Risk registers, Statements of Applicability, audit criteria, control mappings, evidence packages, findings, and management reports show what was assessed, what evidence supports the conclusion, and where remediation or governance action is required.

Governance

Ownership, accountability, review cycles, and oversight.

1

Framework and control library

Frameworks, local controls, categories, mapping rationale, applicability, and guidance.

2

Audit criteria and evidence

Criteria, compliance artifacts, client evidence, and document-to-control relationships.

3

Client engagement governance

Clients, engagements, assessment scope, frameworks, assessment assets, and ownership.

4

Risk treatment oversight

Assets, vulnerabilities, threats, evaluations, treatments, review state, and treatment controls.

5

Management reporting

Risk register, asset register, SoA, audit criteria, mappings, engagement, and artifact reports.

Workflow

Risk-to-control-to-evidence workflow.

Asset

Assessment assets, categories, subcategories, and asset classes establish business context.

Vulnerability

Known weaknesses are linked to assets and used to structure exposure analysis.

Threat

Threat scenarios connect to vulnerabilities so risk is grounded in credible events.

Evaluation

Likelihood, impact, risk level, owner, acceptance, review, and status are recorded.

Treatment

Reduce, accept, avoid, or transfer decisions become accountable treatment records.

Control

Treatment controls link risk decisions back to the control library and evidence model.

Reporting

Audit-ready registers, reports, and workflow outputs.

COMPLY supports practical operating workflows: selection cards, linked records, review states, evidence packaging, reporting, and exports.

Available reporting outputs

Risk RegisterAsset RegisterStatement of ApplicabilityAudit CriteriaEngagementsFramework ControlsControl MappingsComply Artifacts Register

Operational workflows

  • Card-window selection for controls, assets, vulnerabilities, threats, treatments, artifacts, requirements, and audit criteria.
  • Search, sort, navigation, record creation, review, reporting, and export workflows.
  • Picker-driven linking between requirements, controls, evidence, assets, vulnerabilities, threats, risks, and treatments.
  • Register-style reporting for risk, assets, applicability, criteria, engagements, framework controls, mappings, and artifacts.