First steps

Set up your organisation, invite users and launch your first governance domain — from the initial login to the first audit with attached evidence.

This guide takes you from your first login through to gaining a firm grasp of operational governance: organisational structure, users and profiles, domain selection, the controls library and the first evidence uploaded. Allow around an hour for the initial set-up.

Before you begin

Gather these items together — it’ll save you a lot of running back and forth later:

  • Organisational scope. Which legal entities, business units or countries will be managed on the platform.
  • Target Frameworks. The standards and laws you need to comply with first (e.g. ISO 27001, GDPR, NIS2).
  • Those responsible. Who is responsible for each area: security, privacy, legal, HR, IT.
  • Existing documentation. Policies, records and evidence that you already have — these will be reused, not recreated.

Step 1 — Create and configure the organisation

When you log in for the first time, your organisation’s tenant is created. All data is isolated within this tenant, with row-level security — no other organisation has visibility of it.

Organisation details

  • Name and tax registration number — used in reports and exported documents.
  • Sector of activity — determines which frameworks are suitable (e.g. DORA for financial services).
  • Size — number of employees, relevant for regulatory thresholds (NIS2, Pay Transparency, CSRD).
  • Language and time zone — these affect deadlines, notifications and the language of reports.

Organisations and structure

If your group comprises several legal entities, set them up now in Administração → Entidades. Each entity can have its own controls, risks and evidence, and reports can be consolidated or individual. You don’t have to get everything right first time — the structure is editable.

Step 2 — Invite users and assign profiles

In Administração → Utilizadores, invite the team by email. Each invitation has a profile that determines what the person can see and do.

  • Administrador — configuração da organização, utilizadores, faturação e todos os domínios.
  • Domain manager — full control over one or more assigned governance domains.
  • Contributor — carries out tasks and records evidence in the controls for which they are responsible.
  • Auditor / Leitura — acesso de leitura a controlos, evidências e relatórios, sem poder alterar.

For external consultants, use the Auditor or Limited-scope Domain Manager profile, restricted to the scope of the work. Access may be subject to an expiry date.

Authentication

We recommend enabling MFA for all users from the outset. On Enterprise plans, you can configure SSO / SCIM in Administração → Autenticação and provision users from your directory.

Step 3 — Activate the first governance domain

Don’t try to tackle everything at once. Choose one area — usually one with an upcoming regulatory deadline or audit — and do it properly. The others will take a fraction of the effort, because you can reuse the same controls.

  • Do you need to achieve ISO 27001 certification or comply with NIS2/DORA? → Start with Security Governance.
  • Are you facing pressure from the GDPR, ROPA or requests from data subjects? → Start with Privacy Governance.
  • You’re introducing AI into your organisation → start with AI governance.

In Domínios → Ativar, select the domain and the relevant frameworks. The platform automatically generates the corresponding control library.

Step 4 — Review the controls library

The controls are pre-populated based on the chosen frameworks. Your task at this stage is to assign responsible parties and frequencies, not to rewrite the controls.

  1. Go through the list and mark anything that falls outside the scope as ‘Not applicable’, giving a reason (this will be noted for the auditor).
  2. Assign a person responsible for each applicable control.
  3. Set the frequency of reviews (monthly, quarterly, annually) — this is what ensures the guarantee is ongoing rather than a one-off.

Step 5 — Upload the first piece of evidence

Open a check and attach a document you already have — a policy, a log, or a configuration screenshot. As soon as you do this, you’ll see what sets iComply apart: the check dashboard shows all the requirements across all the frameworks that this evidence has just met.

The evidence is versioned. When the document is replaced, the history is retained — this is what ensures audit traceability.

Step 6 — Check the status panel

On the main dashboard, you should now be able to see your real-time compliance status: the percentage of controls in place, missing evidence, overdue tasks and risk by area. This is the view that is presented at management meetings.

What to do next

Now that the first domain is up and running, the next logical step is:

On this page

Need a hand getting started?

Our team will carry out the onboarding process with your organisation and set up your first domain together with you.