Every module, and the agent underneath it.
Six solution pillars on one relational system of record. Each module below carries the AI, agent or computed-guarantee claim that applies to it — so you can see exactly where inference helps and where determinism is required.
Risk Management
A register that records how a score was reached, not just what it is. Inherent and residual held apart, appetite enforced, and treatment whose status derives from the work rather than from someone ticking a box.
Risk RegisterRSK
Identified → assessed → treated → monitored → closed, with categories, entity scope, owners and full relationship mapping to controls, issues, incidents and suppliers.
The AI Risk Composer turns a sentence into a structured risk — category, owner, inherent scores with rationale, candidate controls and a treatment strategy — presented beside the field for you to apply, edit or reject.
Risk Assessments5×5
Dated, attributable assessments with written rationale. Inherent and residual scored separately on a configurable matrix with banding from Low through Critical.
The LLM proposes likelihood and impact grounded in your own control coverage and justifies each. The arithmetic stays deterministic — the model influences inputs, never the number.
Appetite & Tolerance
Appetite held per category and entity, with automatic detection of risks sitting outside stated tolerance and reporting on movement over time.
The Risk Agent flags every appetite breach, quantifies the gap, and ranks the fastest routes back inside tolerance by effort against exposure reduction.
Risk Responses & TreatmentRSP
Accept, mitigate, transfer or avoid. Exactly one approval gate — on the plan — with delivery status derived from the underlying tasks rather than separately maintained.
Drafts the full treatment plan — strategy, sequenced actions, owners, target dates — and creates them as real task records routed to the right owners and queues.
Key Risk IndicatorsKRI
Owner, unit, cadence, direction of good and RAG thresholds, with a time series of dated measurements and automatic work on breach.
Proposes the indicator and a defensible threshold for a given risk, runs a scheduled sweep collecting values from connectors, and writes the interpretation of every breach.
Heat Maps & Portfolio Views
Matrix heat maps, appetite-versus-actual, top-risk views, movement over time and register exports to CSV or print-ready PDF.
Ask the portfolio a question in plain language — "which critical risks have no tested control?" — and get an answer computed from live data with the contributing records cited.
Regulatory Compliance
Multi-standard compliance on a common control framework. Test a control once and report it against every standard that cites it — with a Statement of Applicability that is derived from the register and so can never contradict it.
Control LibraryCTL
Draft → under review → approved → active → retired. Objective, activity, type, automation level, frequency, owner, operator, entity scope and test procedure — mapped many-to-many to risks, policies and clauses.
Drafts a complete control from a risk or straight from selected clauses — objective, activity, frequency, owner and a written test procedure, pre-cited to the standard.
Control Testing & AttestationATC
An attestation designer, campaigns with launch approval, and effectiveness derived from test results. Submitted work does not count toward compliance until independently approved.
Auto-attests controls from connector data with the source artefact attached — then stops at the sign-off gate . The LLM tells the approver whether the evidence actually supports the claim.
Assurance Levels
Every control conclusion graded by how it was reached: high (sampled, re-performed or automated), moderate (evidence review), low (self-attestation) or none. Compliance reports break down accordingly.
Assurance banding and compliance percentages are computed and reproducible — never model-derived. The AI writes the commentary, not the number.
Policy ManagementPOL
Native authoring with structured sections, versioning, effective and review dates, publication approval, and mapping to the controls that enforce each policy.
Gap-checks the policy set against a framework, drafts the next revision of anything overdue, and flags every policy with no enforcing control. It never publishes on its own authority.
Acknowledgement CampaignsACK
Outstanding, acknowledged, exempted and re-issued states. New versions re-issue to the affected population; exemptions require a recorded reason.
Scopes the population from a plain-language description, runs the chase cycle autonomously, and writes a plain-language summary of the policy so acknowledgement is informed rather than reflexive.
Statement of ApplicabilitySoA
Applicability decision, inclusion reason and exclusion justification are held. Everything else is derived at render time from the control citations, so the SoA and the register cannot disagree.
Suggests clause citations with a confidence rating and rationale, drafts exclusion justifications that survive external audit, and warns where a proposed exclusion will be challenged.
Reference StandardsSTD
ISO/IEC 27001, ISO/IEC 20000-1, ISO 31000 and ISO/IEC 42001 out of the box, plus customer-defined frameworks and clause sets held concurrently.
Cross-maps your existing library to a newly adopted standard — already covered, partially covered, genuinely new — turning adoption from a project into a review.
Regulatory ChangeREG
A source register with RSS, API and manual feeds; scheduled ingestion; a triage lifecycle with recorded decisions; and consequential work traceable back to the update that caused it.
Polls sources, triages what arrives, and produces an impact assessment naming your affected records by code — then drafts the amended clause, the revised control and the implementing tasks.
Exceptions & Risk AcceptanceEXC
Carrying a gap on the record with an end date. Expiry and revocation are terminal — renewal is a fresh request — because extending in place is how a temporary exception becomes permanent.
Drafts the case and the approver's brief stating plainly what risk is being accepted and for how long. Detects exception sprawl — repeated renewals pointing at one unfixed root cause.
Training & AwarenessTRN
Course catalogue with validity periods, campaigns generating per-person assignments, automatic expiry and refresher reassignment, linked to the controls the training evidences.
Generates course content and assessment questions from a policy, control or incident — so training derives from your actual obligations and actual failures.
Internal Audit
Risk-based audit from universe to closure. Findings land in the same issue register as everything else — no private audit-only list — and evidence requests are issued and chased without anyone maintaining a spreadsheet.
Audit Universe
Auditable entities with risk-based scoring, last-audited dates and coverage reporting against the annual plan.
Risk-scores the universe from register data — exposure, control weakness, incident history, time since last audit — and proposes the annual plan.
EngagementsAUD
Planned → fieldwork → reporting → remediation → closed, with scope, objectives, in-scope controls and entities, team, budget and timetable.
Drafts the audit plan — scope, objectives, controls selected on risk and the test approach per control — then writes the report narrative from the findings.
Evidence Requests (PBC)
Requests issued from an engagement to named owners and tracked to receipt, with automated chasing and overdue reporting.
Generates and issues the whole request list, chases it automatically, and pre-assesses what comes back — flagging insufficient submissions before an auditor spends time on them.
Findings & IssuesISS
One register for every finding, wherever it came from: control failure, audit, incident, indicator breach or questionnaire. Closure requires verification by someone other than the remediator.
The Remediation Agent triages by severity and exposure, drafts remediation plans as real tasks, proposes root cause, and clusters findings into systemic themes.
Evidence BundlesBDL
The answer to "send me everything supporting this for the period." Chain of custody per artefact, each file hashed, the manifest hashed, gaps stated as first-class entries, and a reproducible content digest.
Assembles the bundle from a natural-language request, writes the cover narrative including what is missing, and pre-reviews it as an auditor would before you send it.
Cyber GRC
Security control assurance driven by live telemetry rather than annual questionnaires. Agents attest what your tooling can prove, and are explicit about what still needs a person.
Continuous Control Monitoring
Connectors declare which controls they can evidence. Control state is refreshed from live signals rather than waiting for a test cycle.
Determines which controls are automatable from currently connected tooling, attests those from live data, routes the rest for manual evidence, and reports the split.
Incident ManagementINC
Containment-first and forwards-only: triage → investigating → contained → eradicated → recovered → closed. Closure gated on root cause, lessons and notifications. Any employee can report from the portal.
Triages within seconds — category, severity, affected systems, notifiability. Identifies which controls failed, drafts the regulatory notification for legal review, and writes the post-incident review.
Regulatory Notification Clocks
A countdown running from detection where an incident is notifiable — 72 hours under GDPR Article 33, and your other applicable regimes — with a visible clock and escalation ladder.
Runs the clock and escalates as the deadline approaches. It drafts the notification; it never sends an external communication on its own authority.
Vulnerability & Posture Evidence
Scan and posture data from Qualys, Tenable, Wiz, Defender and CrowdStrike attached as control evidence with the artefact and the call that produced it recorded.
Extracts structured findings from unstructured artefacts — configuration exports, scan reports, PDFs — and records them against the right control.
Security Awareness
Awareness campaigns tied to the controls and clauses they evidence, with completion, expiry and lapse reporting by campaign, entity and manager.
Targets training from risk and incident data — recommending who needs what based on incidents they were involved in and controls they operate.
BCM & Resilience
Continuity and disaster recovery connected to the services, systems and suppliers they actually protect — so a plan that has gone stale against reality is detectable rather than discovered during an incident.
Continuity & DR PlansBCP
Draft → active → under test → needs update → retired. RTO, RPO, dependencies, recovery steps, invocation criteria and named roles, linked to the entities and suppliers they cover.
Drafts a plan for a service from its dependency graph, criticality and supplier relationships — a starting document rather than a blank template.
Business Impact Analysis
Impact assessment across services and processes, driving plan prioritisation and the recovery objectives that follow from it.
Proposes impact ratings and recovery objectives from dependency and criticality data, with the reasoning recorded for challenge.
Plan Testing
Scheduled tests with recorded results feeding plan status directly, raising issues automatically on failure and reporting time since last successful test.
Generates the test scenario and script appropriate to the plan's criticality, then analyses the result and drafts the plan revision it implies.
Coverage & Staleness
Reporting on critical services with no plan, plans untested within their cycle, and dependency gaps across the estate.
Detects plan staleness against reality — a plan naming systems, people or suppliers that no longer exist in the register — and raises the work to fix it.
Third-Party Risk
Supplier tiers are derived from criticality and data sensitivity — never chosen. Left to a person, everything becomes Tier 1 during onboarding and Tier 3 the moment someone has to do the assessment.
Supplier RegisterVND
Prospect → onboarding → active → under review → offboarding → terminated. Criticality, data processed, services, contract dates, contacts and relationship owner, linked to risks, controls, incidents and issues.
Generates the supplier risk narrative for the relationship owner: what this supplier exposes you to, and what you rely on them for.
Derived Tiering
Tier computed from criticality and data sensitivity, driving assessment depth and reassessment frequency. The record states why it is Tier 1.
The derivation is computed and explainable. The LLM may propose the criticality and data-sensitivity inputs; it never computes the tier.
Questionnaire DesignerASM
Sections, question types, conditional logic, required flags and scoring — built without code. Draft → scheduled → in progress → submitted → reviewed → completed, with review distinct from submission.
Generates a questionnaire from an objective, pre-answers it from what the platform already knows with each source shown, and evaluates free text against the intent of the question.
Certification Tracking
ISO 27001, SOC 2 and other certifications held with expiry monitoring and automatic chasing before they lapse.
Assesses an uploaded SOC 2 Type II or certification report against your control requirements, extracting the exceptions and mapping them to your affected controls.
Reassessment Cycles
Scheduled automatically from the derived tier — annual for Tier 1, biennial for Tier 2 — and chased on the due date without anyone tracking it.
Runs the cycle end to end: identifies what's due, issues the right questionnaire, chases the response and escalates the non-responsive.
Concentration & Fourth Party
Reporting on concentration risk across critical services and recorded fourth-party dependencies behind your suppliers.
Monitors external sources for adverse events affecting critical suppliers and raises them against the supplier record.
Configuration & Control
Everything an administrator changes without raising a ticket with us. Lifecycles, states, transitions, fields, roles, capabilities, notification rules, scoring matrices, taxonomies and every agent's configuration.
Users & Roles
Capability-based roles — administrator, GRC manager, risk manager, auditor, performer, approver and portal end user — with SSO via SAML 2.0 or OIDC and SCIM provisioning.
Every agent run is bound to a security principal, so an agent can never read or act on data the invoking user could not.
GroupsGRP
First-class owners of work with queue-based assignment, claim and release — so ownership survives someone leaving and nothing sits in a departed person's name.
Work an agent raises routes to the correct group queue rather than guessing an individual.
DelegationsDLG
Time-bounded transfer of a person's work and approval authority to a named alternate, activating and expiring automatically at the window boundaries.
An hourly job opens and closes delegation windows, so cover is never dependent on somebody remembering to switch it on.
Organisation Settings
Branding, entity hierarchy, risk matrix dimensions and banding, taxonomies, assurance definitions, retention and data residency — configured, not coded.
Prompt and instruction overrides per agent, versioned and audit-logged, so the fleet speaks in your organisation's language and to your own standards.
Email & Notifications
Your own SMTP relay with a persistent outbox, delivery state, retry and failure visibility. Administrator-editable templates and notification rules by event, audience, channel and cadence.
Composes contextual notifications stating what the recipient must do and why — and suppresses notification fatigue by batching the low-value ones.
Scheduled Jobs
Fifteen recurring jobs — acknowledgement reminders, task and approval SLA, attestation due, policy review, evidence and exception expiry, delegation windows, notification clocks, supplier renewals, indicator sweep, training cycle, board pack and outbox retry — each with enable, cadence, last run, next run and outcome.
The scheduler is also the cadence engine for the fleet, running each agent on its configured schedule and recording every run against it.
Three approaches, one honest comparison
The distinctions that matter when you are evaluating agentic GRC. Apply these tests to us and to everyone else.
| Criterion | Legacy GRCWorkflow and forms | "AI-powered" GRCA chat box bolted on | Vigil8Agents with bounded authority |
|---|---|---|---|
| Can it take an action in the register? | People do all the work | Drafts text you copy in | Agents create and transition records |
| Is every action attributable and reversible? | Audit log of human edits | No record of what the model did | Full run trace, one-click reversal |
| Who signs off an agent’s work? | Not applicable | Often nobody — it is just text | A capability-holding human, always |
| Are compliance figures model-generated? | Computed | Sometimes unclear | Computed and reproducible, never inferred |
| What happens if the model endpoint fails? | Unaffected — there is no model | The AI features stop working | Deterministic fallback behind every feature |
| Is the Statement of Applicability trustworthy? | Maintained by hand, drifts | Maintained by hand, drifts | Derived at render time from citations |
Hold us to the eleven scenarios
We publish the scripted demonstration we want to be measured against — including disabling the model endpoint live, and regenerating an evidence bundle after the panel strips a control’s evidence.