Governance · Risk · Compliance

One system of record for everything your auditor asks.

Controls, risks, policies, evidence, incidents and audit engagements — all in one place, with every required activity owned, dated and tracked through its full lifecycle.

Unified GRC shield logo
Controls
Test, evidence, rate. Track effectiveness over time.
Risks
Inherent and residual scoring, treatments, appetite.
Policies
Lifecycle from draft to retired, with review decay.
Posture
Live dashboards by framework, owner and severity.
Why this exists

Big-firm compliance, without the big-firm bill

Large enterprises spend six figures a year on GRC tooling, consultants and template libraries. The same controls — pre-loaded, connected and guided — now fit in a single application your operations lead can run themselves.

Enterprise stack
  • £80k–£250k tooling p/a
  • External auditors on retainer
  • Dedicated GRC manager
  • 12–18 month rollout
DIY spreadsheets
  • Out of date in weeks
  • No evidence trail
  • Cannot answer client RFPs
  • No regulator-ready output
Unified GRC
  • From £/$ a month per code
  • Self-managed, guided
  • Encrypted templates included
  • Audit-ready in weeks
The pressure is real

Three reasons your customers already expect this from you

SMEs are no longer below the radar — supply chains, insurers and regulators have made cyber and AI governance a precondition to doing business.

Lose the deal at procurement
Enterprise buyers now send 80–200 question security questionnaires before contract. No evidence = no contract. Firms with a posture report close deals 38% faster.
Regulators are not waiting
NIS2 captures medium-sized firms in 18 sectors. GDPR fines reached €2.1bn in 2023. The EU AI Act applies to any firm deploying high-risk AI in the EU market.
Insurance is repricing risk
Cyber insurance premiums rose ~50% YoY. Underwriters now demand evidence of controls. A documented ISO/NIST programme cuts premiums materially.
What you get

One app. All the templates. A plan that runs itself.

The application ships with a library of encrypted Word documents — policies, procedures, registers, DPIAs, AI risk assessments. Each template, project or domain unlocks with its own code, so licensing stays clean.

Complete template library
Policies, SoAs, RoPAs, DPIAs, AI Act conformity assessments, BCP/DR runbooks — all AES-encrypted, all editable in Word once unlocked with your code.
Guided project plan
A pre-built Gantt that sequences controls, owners and evidence so you go from kick-off to audit-ready without a consultant in the room.
Live posture metrics
Coverage by framework, control maturity, overdue evidence, residual risk — exportable to a board pack or client RFP in one click.
Buy Templates by Domain
License the way you operate. Buy one Domain or buy the complete bundle — perfect for multi-entity firms tracking many regulatory demands.
The outcome

Win more revenue. Carry less risk.

+38%
Faster enterprise sales cycles
When buyers receive a complete security pack on day one.
−60%
Time to ISO/NIST readiness
Templates, evidence prompts and a guided plan replace months of drafting.
−15–30%
Cyber insurance premium
Documented controls and tested incident response materially reduce loaded risk.
Frameworks at a glance

Six obligations. One application. Side-by-side with the enterprise stack.

Each framework below is what enterprise buyers ask SMEs to evidence in 2025. Compare what a Big Four programme costs vs. what Unified GRC ships in the box.

NIST SP 800-53
US Federal · global supply chain

NIST SP 800-53 for SMEs — without the federal price tag

The control catalogue your enterprise customers, insurers and US-linked supply chains expect. 20 control families, evidence-led, continuously monitored.

Enterprise route

GRC platform licences (£40k+/yr), specialist consultants to author and map controls, dedicated analyst to maintain evidence.

Unified GRC

Moderate-baseline policy set pre-mapped, evidence cadences scheduled in the plan, maturity scoring exportable to buyers and underwriters.

ISO/IEC 27001:2022
Global certification

ISO 27001 certification, ready to defend at audit

The certification clients ask for by name. ISMS scope, leadership, risk treatment and a Statement of Applicability across all 93 Annex A controls.

Enterprise route

6–12 month implementation programme with a Big Four firm. £80k+ before the certification body sets foot in the door.

Unified GRC

Full ISMS pack — policy, scope, SoA, risk register — editable in Word. Guided internal audit workflow with evidence capture from day one.

GDPR — Regulation (EU) 2016/679
EU · UK · global processors

GDPR compliance that survives a regulator visit

Lawful basis, transparency, Article 30 Record of Processing, Article 35 DPIAs and Article 32 security measures — with a 72-hour breach clock you can prove.

Enterprise route

External DPO retainer, bespoke RoPA build, legal counsel for every DPIA and breach.

Unified GRC

RoPA and DPIA templates pre-populated for common SME processing, breach runbook with the 72h clock built in, Art. 32 cross-mapped to ISO and NIST.

EU AI Act — Regulation (EU) 2024/1689
Anyone selling AI into the EU

EU AI Act readiness before the high-risk deadlines bite

Classify each AI system, document the high-risk ones to Annex IV standard, prove human oversight and post-market monitoring — or lose the EU market.

Enterprise route

Specialist AI legal counsel plus a separate AI governance platform — two new vendors on the buy list.

Unified GRC

AI inventory and risk classifier, Annex IV technical documentation template, post-market monitoring plan wired into the project plan.

NIS2 Directive (EU) 2022/2555
Essential & important entities · 18 sectors

NIS2 alignment with director-level sign-off built in

10 minimum risk-management areas, 24h / 72h / one-month incident reporting tiers and personal accountability for management bodies under Article 20.

Enterprise route

Sector consultancy plus a board advisory engagement to get directors comfortable signing.

Unified GRC

Art. 21 control set mapped onto your existing ISO/NIST work, incident timer and CSIRT notification templates, board-ready governance pack.

WCAG 2.2 AA · EN 301 549
Public sector · European Accessibility Act

WCAG 2.2 AA accessibility, audit-ready and publishable

The European Accessibility Act made WCAG 2.2 AA effectively mandatory for consumer-facing digital products from June 2025. Public-sector tenders already require it.

Enterprise route

External accessibility audit (£10k+ per product) plus a remediation consultancy to write the conformance report.

Unified GRC

Audit checklist mapped to WCAG 2.2 success criteria, ACR / EN 301 549 conformance template ready to publish, remediation tracked in the main plan.