Twelve disciplines.
One connected graph.

Not twelve apps stitched together. Risks link to controls, controls to requirements and policies, findings to remediations, sharing one set of owners, one evidence store, and one immutable audit trail.
0
GRC disciplines
0+
curated frameworks
0+
control ⇄ requirement mappings

The control is the unit of work.

Every discipline resolves to controls. A single control carries the frameworks it satisfies, the risk it mitigates, the evidence that proves it, and the owner and checker accountable for it, so you implement once and it counts everywhere.

  • Status is gated on valid, in-date evidence, not a checkbox
  • Maker/checker is enforced per item: the approver can't be the author
  • One mapping satisfies ISO, SOC 2, NIST and the local regimes at once
Control · AC-02Implemented
Control

Access provisioning & de-provisioning

Satisfies · one control, four obligations
ISO 27001 A.5.18SOC 2 CC6.1NIST PR.AACBN Cybersecurity
Owner

Ada Obi

Checker · maker ≠ checker

Tunde Akin

Evidence
Valid to 30 Sep
access-review-Q3.pdfauto-collected
Mitigates · Unauthorised accessNext review · 12 Sep

And every record is a node in one graph.

That control isn't a row in one app. It's a node connected to the risks it mitigates, the requirements it satisfies, the policy that mandates it, the evidence that proves it, the owner accountable for it, and the findings raised against it. Hover to trace the connections.

RequirementPolicyEvidenceFindingOwnerRiskone control

Hover a node, every control links to its risks, requirements, policies, evidence, owners and findings.

The full GRC lifecycle, modelled exactly.

Every module maps onto the Three Lines of Defence and doesn't invent its own roles. Built once, the same way, on one connected data model.

12 built · 1 on the roadmap

The rules that hold in every module.

Those twelve entries aren't twelve separate builds. The same enforcement spine runs under all of them.

Evidence-gated status

A requirement can't move to “implemented” without valid, non-expired evidence. The gate blocks; it doesn't warn.

Cadence that runs itself

20+ automated sweeps run hourly: overdue reviews, KRI breaches, evidence expiry, breach clocks, SLAs, recertifications.

An audit trail you don't assemble

Every action lands in an append-only, immutable trail as it happens. When an auditor asks who approved what, and when, the answer is already written.

Three stories you won't get from a checklist, or a US/EU-built tool.

Mapped once, inherited everywhere

Map a new circular once. Every customer inherits it.

Frameworks, controls and policy templates are curated centrally and versioned by a stable identity. Adopting a framework is a reference, not a fork, so when a new CBN circular lands, we map it one time and every customer sees the new version through their overlay and adopts deliberately. Implement and evidence a control once; it counts across every framework it maps to.

Built · 40+ frameworks, 1,200+ requirements resolved to 132 shared controlsExplore coverage
The flagship

End an audit in days, not a month of emailed ZIP files.

Audit Hub introduces a third kind of principal, the external guest, bound to a single engagement by the platform itself. An auditor or CBN examiner gets their own workspace: a Provided-By-Client list, threaded comments, and a frozen, hash-indexed close-out package. They read a provenance-stamped snapshot of your evidence, never your live data, and every view and download lands in your immutable audit trail. The same security spine powers the vendor self-onboarding portal.

Built · external guests are scoped to a single engagement and see only a provenance projectionExplore Audit Hub
Regulator-mandated, not speculative

Model governance built to the CBN's automated-AML mandate.

The CBN's 2026 Baseline Standards for Automated AML/CFT/CPF demand a “glass box”: model ownership, independent validation, change control, explainability, demonstrable effectiveness, and the institution is responsible regardless of vendor. Model Governance turns that from a static PDF into a living register, with validation that's independent by construction and a change log that is exactly the trail an examiner asks for. The framework is already in our catalog.

Built · aligned to CBN Automated-AML Baseline and ISO/IEC 42001Explore Model Governance

Live AML/KYC evidence, not a quarterly screenshot.

Because financial institutions already run KYC, sanctions screening and transaction monitoring through real-time verification rails, CardinalGRC is uniquely positioned to back AML/KYC controls with continuous, provenance-stamped evidence, the control execution itself, exportable and independently verifiable by an examiner.

This is in active development and deliberately gated on one question we're answering with design partners first: that an examiner will accept a live, signed evidence feed as primary evidence. We'd rather build it right than oversell it.

Available today
  • Read-only integrations: Google Workspace & GitHub auto-evidence
  • Evidence with validity windows; controls revert when evidence goes stale
  • Provenance-stamped evidence shared into auditor engagements

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.