Governance, Risk & ESG (GRC)
A standalone, zero-cost operational risk, carbon accounting, and audit management platform. Available without subscriptions, seat limits, or mandatory paid ERP modules.
Interactive 5×5 Risk Heat Map
Select cells across the 25-cell Likelihood × Impact grid to inspect assessment details, inherent vs. residual scores, and mitigation controls.
Sovereign Cross-Border Data Residency Violation
Hardware-bound RFC 7517 KeyRing HSM with strict tenant-level row isolation and geo-fenced database partitions.
GHG Protocol Scope 1/2/3 Carbon Emissions Breakdown
Standardized carbon accounting methodology with auditable activity data and emission factor tracking.
Scope 1: Direct
Direct greenhouse gas emissions released from owned or controlled operations.
Scope 2: Indirect
Indirect emissions generated from purchased electricity, steam, heating, and cooling consumed by facilities.
Scope 3: Value Chain
All other indirect emissions across the entire upstream supply chain and business activities.
Compliance Controls Mapped to ISO 27001 & SOX 404
Audit-tested internal controls mapped directly to international security standards and Sarbanes-Oxley reporting integrity.
| CONTROL ID | STANDARD | CONTROL OBJECTIVE | TESTING METHOD | STATUS |
|---|---|---|---|---|
| ISO-A.8.2 | ISO 27001:2022 | Privileged access rights enforced by Casbin row-level ABAC security. | Automated quarterly privilege audit | VERIFIED |
| ISO-A.8.24 | ISO 27001:2022 | Use of cryptography: RFC 7517 KeyRing dynamic key rotation for tokens. | 60-min automated JWKS rotation test | VERIFIED |
| SOX-GL-04 | SOX Section 404 | General ledger journal override dual-authorization without bypass permission. | Pre-commit transaction gate validation | TESTED |
| SOX-IT-09 | SOX Section 404 | Segregation of duties (SoD) between purchase order creators and invoice approvers. | Automated policy conflict scan | TESTED |
| SOX-REV-02 | SOX Section 404 | Percentage-of-Completion (POC) milestone signoff for revenue recognition. | Subcontractor retainage ledger audit | TESTED |
CAPA (Corrective & Preventive Action) Audit Remediation Log
Systematic tracking from root-cause analysis (RCA) through corrective actions, preventive controls, and auditor verification.
| CAPA ID | SOURCE | FINDING & ROOT CAUSE | CORRECTIVE & PREVENTIVE ACTION | OWNER | STATUS |
|---|---|---|---|---|---|
| CAPA-2026-088 | Internal Audit | Catch-weight variance between retail terminal & cold storage. RCA: Uncalibrated scale sensor drift. | Automated pre-shift calibration lock enforcing daily certified weight verification before register unlocks. | Warehouse QA | RESOLVED |
| CAPA-2026-092 | SOX Review | Delayed retainage reconciliation on subcontractor billing vouchers. RCA: Manual spreadsheet verification. | Automated retainage escrow withholding schedule linked directly to CSI MasterFormat milestones. | Project Controller | IN PROGRESS |
| CAPA-2026-095 | ISO Surveillance | Terminated contractor account remained in read-only group for 36 hours exceeding 24-hour SLA. | HR offboarding trigger now automatically publishes revocation event to Redis JTI blacklist within 100ms. | Security Lead | VERIFIED |
Designed for Key Governance Roles
Engineered for specific operational mandates across compliance, risk, sustainability, and audit teams.
Compliance Officers
Continuous control monitoring mapped to ISO 27001 and SOX 404, with one-click certified export packages for statutory regulators.
Internal Auditors
Cryptographic verification of audit logs, automated sample generation for journal entries, and tracking of open CAPA remediation tasks.
Risk Managers
Configurable 5×5 risk heat maps with automated recalculation of residual exposure following mitigation control implementations.
ESG Leads
Comprehensive GHG Protocol Scope 1, 2, and 3 accounting with verifiable source ledgers for corporate sustainability mandates.
Enable Free Governance, Risk & ESG Module
Activate the full GRC workspace immediately. No credit card, no expiration date, and no obligation to purchase paid ERP modules.