Twelve disciplines.
One connected graph.
The control is the unit of work.
Every discipline resolves to controls. A single control carries the frameworks it satisfies, the risk it mitigates, the evidence that proves it, and the owner and checker accountable for it, so you implement once and it counts everywhere.
- Status is gated on valid, in-date evidence, not a checkbox
- Maker/checker is enforced per item: the approver can't be the author
- One mapping satisfies ISO, SOC 2, NIST and the local regimes at once
Access provisioning & de-provisioning
Ada Obi
Tunde Akin
And every record is a node in one graph.
That control isn't a row in one app. It's a node connected to the risks it mitigates, the requirements it satisfies, the policy that mandates it, the evidence that proves it, the owner accountable for it, and the findings raised against it. Hover to trace the connections.
Hover a node, every control links to its risks, requirements, policies, evidence, owners and findings.
The full GRC lifecycle, modelled exactly.
Every module maps onto the Three Lines of Defence and doesn't invent its own roles. Built once, the same way, on one connected data model.
Risk & resilience
Identify and treat risk, work incidents, and prove you can recover: enterprise risk through to continuity.
Compliance & policy
Adopt curated frameworks, govern your policies and models, and keep the controls current.
Security & third parties
Operate the technical controls and manage the vendors and assessments around them.
Assurance & collaboration
Independent assurance inside, and a safe workspace for the auditors and vendors who review you.
The rules that hold in every module.
Those twelve entries aren't twelve separate builds. The same enforcement spine runs under all of them.
Evidence-gated status
A requirement can't move to “implemented” without valid, non-expired evidence. The gate blocks; it doesn't warn.
Cadence that runs itself
20+ automated sweeps run hourly: overdue reviews, KRI breaches, evidence expiry, breach clocks, SLAs, recertifications.
An audit trail you don't assemble
Every action lands in an append-only, immutable trail as it happens. When an auditor asks who approved what, and when, the answer is already written.
Three stories you won't get from a checklist, or a US/EU-built tool.
Map a new circular once. Every customer inherits it.
Frameworks, controls and policy templates are curated centrally and versioned by a stable identity. Adopting a framework is a reference, not a fork, so when a new CBN circular lands, we map it one time and every customer sees the new version through their overlay and adopts deliberately. Implement and evidence a control once; it counts across every framework it maps to.
End an audit in days, not a month of emailed ZIP files.
Audit Hub introduces a third kind of principal, the external guest, bound to a single engagement by the platform itself. An auditor or CBN examiner gets their own workspace: a Provided-By-Client list, threaded comments, and a frozen, hash-indexed close-out package. They read a provenance-stamped snapshot of your evidence, never your live data, and every view and download lands in your immutable audit trail. The same security spine powers the vendor self-onboarding portal.
Model governance built to the CBN's automated-AML mandate.
The CBN's 2026 Baseline Standards for Automated AML/CFT/CPF demand a “glass box”: model ownership, independent validation, change control, explainability, demonstrable effectiveness, and the institution is responsible regardless of vendor. Model Governance turns that from a static PDF into a living register, with validation that's independent by construction and a change log that is exactly the trail an examiner asks for. The framework is already in our catalog.
Live AML/KYC evidence, not a quarterly screenshot.
Because financial institutions already run KYC, sanctions screening and transaction monitoring through real-time verification rails, CardinalGRC is uniquely positioned to back AML/KYC controls with continuous, provenance-stamped evidence, the control execution itself, exportable and independently verifiable by an examiner.
This is in active development and deliberately gated on one question we're answering with design partners first: that an examiner will accept a live, signed evidence feed as primary evidence. We'd rather build it right than oversell it.
- Read-only integrations: Google Workspace & GitHub auto-evidence
- Evidence with validity windows; controls revert when evidence goes stale
- Provenance-stamped evidence shared into auditor engagements
Compliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.