- The European Governance Operating System
Every regulation, law and risk. All managed in one place.
iComply brings together ISO standards, European legislation, risk, audits and evidence on a single, controls-focused platform. Map a control once — and stay compliant across all frameworks, automatically. Designed for those responsible for governance and for the consultants who implement it.
The choice of compliance, legal and security leaders across the EU.
Domains of governance, an architecture
Less duplication of work with shared controls
A library of evidence, reused across all frameworks
Data residency in the EU, audit logs and tenant isolation
Governance Domains
Most tools cover a single standard. iComply manages the entire organisation — security, privacy, AI, ethics, people and third parties — within a single, control-centred model. No silos, no duplicate records, no spreadsheets.
01
SGSI, access reviews, vulnerabilities, incidents and resilience — managed on an ongoing basis.
ISO 27001 · NIS2 · DORA · CIS · SOC 2
Find out more →
02
ROPA, AIPD, data subject requests, consent and retention — with end-to-end auditable evidence.
GDPR · ISO 27701 · ePrivacy
Find out more →
03
AI inventory, risk classification, human oversight, bias and AIDF — AI-native by design.
EU AI Act · ISO 42001 · NIST AI RMF
Find out more →
04
Whistleblowing channels, investigations, anti-corruption, RGPC, conflicts of interest and code of conduct.
RGPC · ISO 37001 · Whistleblowing
Find out more →
05
Pay transparency, health and safety at work, training and compliance with HR policies.
Transparência salarial na UE · ISO 45001 · SHST
Find out more →
06
Supplier risk, due diligence, data protection agreements (DPAs) and ongoing monitoring of the value chain.
TPRM · DORA ICT · Due diligence de fornecedores
Find out more →
07
CSRD/ESRS disclosures, dual materiality, environmental and social KPIs.
CSRD · ESRS · ISO 14001
Find out more →
08
Non-conformities, CAPA, supplier quality and document control.
ISO 9001 · ISO 13485 · ISO 22000
Find out more →
09
Planning and carrying out audits, findings, CAPA and ongoing assurance between audits.
Internal Audit · CAPA · Continuous Assurance
Find out more →
10
Register of obligations, compliance calendar and horizon scanning of European regulation.
Horizon Scanning · Obligations · Alerts
Find out more →
11...
We are continuing to develop further modules for you. If you are looking for something you haven’t found, please contact us.
Others · Under development · Under testing
Contact →
All in the same engine.
Unified Controls Engine
iComply focuses on controls, not checklists. Every law, standard and framework maps to the same operational controls, risks and evidence. Comply with one control and it counts towards all the frameworks that require it — the architecture underpinning the world’s best GRC platforms.
- Mapping between frameworks. An audit covers ISO 27001, NIS2, DORA, SOC 2, the GDPR and the AI Act simultaneously.
- Reuse of evidence. Upload a document once; it meets all the requirements to which it relates, with a version history.
- Ongoing guarantee. Out-of-date evidence, overdue tasks and increasing risk are automatically flagged — without the need for manual follow-ups.
Control
Mandatory multi-factor authentication
- Implemented · evidence attached
- ISO 27001 — A.5.17 Complied
- NIS2 — Art. 21 Cumplied
- DORA — ICT Risk Cumplied
- SOC 2 — CC6.1 Cumplied
AI Native
AI lies at the heart of iComply — it analyses your evidence, monitors your risk and drafts the documentation — enabling your team to operate at a scale that traditional GRC tools can never match.
It drafts policies, summarises audit reports and responds to control issues based on its own data.
It reveals control gaps, out-of-date evidence and increasing risk before an auditor — or a regulator — does.
It analyses documents and automatically maps them to the controls and frameworks with which they comply.
Governance Domains
From management to the implementation team — whether internal or external — iComply provides each role with the insight, controls and evidence it needs.
A comprehensive overview of compliance across the entire organisation — every domain, framework and deadline in one place.
CLOTHING, AIPD, obligations and regulatory changes, all supported by defensible evidence that is ready for audit.
SGSI, risk, incident and ICT resilience records, in line with NIS2 and DORA, on an ongoing basis.
Manage multiple clients and frameworks in a single space, with templates, gap analysis and audit trails.
Pricing
Subscribe to the governance domains you need and add users, entities and AI as you grow.
For a team implementing a framework.
- Base platform & 1 governance domain
- Up to 5 users
- Evidence Library & Standard Reports
For teams that manage compliance across various domains.
- 3 domains of governance included
- Up to 20 users & advanced reports
- AI Co-pilot & audit flows
For groups and organisations operating at scale.
- Unlimited domains & multi-entity groups
- SSO / SCIM, API access & white-label
- Dedicated CSM & premium support
The confidence of those who implement it
From management to the implementation team — whether internal or external — iComply provides each role with the insight, controls and evidence it needs.
★★★★★
★★★★★
★★★★★
FAQ
See how iComply brings together every regulation, law and risk on a single platform — in a 30-minute demonstration tailored to your frameworks.