Not the policy library, not the dashboard, not the workflow. It was the spreadsheet where somebody once wrote down which control covers which system, for which obligation. It was accurate for about a quarter. Then a subsidiary was acquired, a platform was retired, a team was renamed, and nobody could say any more why a given control existed or what it was protecting. Every governance tool sells you the screens around that spreadsheet. None of them fix the spreadsheet.
Take a mid-sized group: a few thousand systems, a few dozen legal entities, and a control framework of a few hundred controls. Mapped by hand, that is hundreds of thousands of decisions, made once, by people who then move on. The moment anything changes the matrix is wrong, and worse, it is wrong silently. Nothing errors. The report still renders. You simply cannot trust it any more, and there is no way to tell from the outside.
The problem is not that people are careless. It is that the question is the wrong shape. Nobody actually knows their control-to-asset map, because it is not a fact anybody holds. It is a consequence of how the organisation runs, and that is a much smaller thing to describe.
The wizard opens on your real estate: the systems it can see, across the legal entities it can see, and the framework controls that apply to them. It then asks one question per control domain, not per control and never per asset.
The question is simply whether that domain is run once for the whole group, or separately, and if separately, split by what: by entity, by platform, by team, by system. Answer that, and the number of control instances is arithmetic. One answer can shape fifty controls at once, and coverage still stays resolved per system underneath.
Where a domain is obviously common to everyone, it is not asked at all. It is taken from the framework's own default and reported to you as taken, not hidden.
This is the part that survives the two-year test. A control is not just a row that covers some systems. It carries the walk that produced it, so the question a new risk officer asks on their first day has an answer that did not depend on anyone still being here.
Walked live from the graph: the regulation, the clause, the framework control, the entity. Not a note somebody typed and never revisited.
Full or partial, resolved per system rather than asserted for the group. Partial is shown as partial instead of rounding up.
Where several obligations demand different frequencies for the same control, the strictest one wins. That is the answer an examiner expects.
What has to be produced to show the control ran, listed per system, so evidence collection is defined at derivation rather than discovered at audit.
Who runs it, who owns it, who attests to it, drawn from real roles in your directory rather than a free-text name field.
Where a system is deliberately outside a shared control, the exception is an edge on the graph, visible and reviewable, not an omission.
Each control implements a framework control and covers named entities. Those are relationships in the graph, so they can be walked in either direction.
Review shows every control before a single row is written, and the count reported afterwards comes from what the engine actually wrote, never from what it intended to.
With AI available, the engine reads your asset and tool graph and suggests an operating model for each domain, with its reasoning attached, so most of the work is confirming rather than deciding. There is also a discovery view that shows who actually touches these systems, drawn from the relationships already in the graph, for the domains where you are not sure.
Switch the AI off and the wizard becomes manual: you answer each domain yourself. What does not change is the deterministic part underneath, the walk from regulation to clause to framework control to entity. AI sharpens the operating model. It never produces the base.
That distinction is the whole architecture in one place. With the model off, this platform still derives your controls and you fill in the operating model. A platform built model-first has nothing to fall back to.
Regulations decomposed to the individual clause, verbatim from source or honestly blank. A control cannot attach to a document.
Many clauses converge into one control. That convergence is what makes testing once and satisfying several standards mechanical rather than aspirational.
This page. The operating model turns one framework control into the instances your organisation actually runs, each covering named systems.
Policy drafted against the regulations you have accepted, implementing named controls, so the document and the control do not drift apart.
The clause-to-control library is being populated framework by framework, and on a call we will tell you exactly which are mapped today rather than implying all of them are. How the library works →
A small cohort of regulated banks, NBFCs and the firms that own them. Early access, real influence, pricing that holds.
We are pre-launch and we will not dress it up. There are no logos on this page because there are none to show. Come and try to break the chain.