Governance Domains

How to enable and configure Security, Privacy, AI and all the other domains — and why the second domain costs a fraction of the first.

A governance domain is an area of responsibility within the organisation — security, privacy, AI, ethics, people, third parties, ESG, quality, audit and regulatory change. They all run on the same controls engine, which means that the domains are not silos: they share controls, risks and evidence with one another.

The model: domains based on a common engine

Each domain has its own library of controls, its own workflows and its own reports. However, the control itself is a single, shared object. When you activate a second domain, the platform recognises the controls you have already implemented and automatically reuses them.

Practical implication: the first area is a project; the second is a mapping exercise. That is why organisations that start with Security are able to add Privacy within weeks rather than months.

Activate a domain

  1. Go to Domínios → Catálogo.
  2. Select the domain and the relevant frameworks (you may select more than one).
  3. Define the scope: which legal entities and units are covered.
  4. Confirm. The control library is generated and the platform flags any controls that already exist in other domains.

Your subscription plan determines how many domains you can have active at the same time — see Pricing.

Security Governance

SGSI and the statement of applicability, risk register, access reviews, vulnerabilities, incidents, assets, and ICT continuity and resilience. This is the area that overlaps most with all the others — which is why it is the most common starting point.

Frameworks: ISO 27001, ISO 27002, NIS2, DORA, CIS Controls, SOC 2, TISAX, ISO 20000. Focus on Security Governance.

Privacy Governance

ROPA (record of processing activities), personal data, data subjects’ requests, consent and legal bases, retention, data breaches, data processors and international transfers.

Frameworks: RGPD, ISO 27701, ePrivacy, ISO 27018. Detalhe em Governance de Privacidade.

AI Governance

Inventory of AI systems, risk classification under the AI Act, human oversight, bias assessment, explainability, AIDF and performance monitoring. Covers both ISO 42001 and the AI Act as a single suite.

Frameworks: EU AI Act, ISO 42001, ISO 23894, NIST AI RMF. Focus on AI governance.

Ethics & Integrity

Whistleblowing channel in accordance with the law, case management and investigations, anti-bribery, conflicts of interest, code of conduct, corruption risk prevention plan and protection against retaliation.

Frameworks: RGPC, Law 93/2021, Whistleblowing Directive, ISO 37001, ISO 37301. Further details in Ethics & Integrity.

Workforce Governance

Pay bands and pay gap analysis, health and safety at work, the compulsory training matrix, HR policies with compliance targets, equality, and AI governance applied to recruitment and career progression.

Frameworks: Pay Transparency Directive, ISO 45001, Labour Code, CSRD. Focus on Workforce Governance.

Third-Party Governance

Supplier inventory and criticality, due diligence and onboarding, security assessments, DPAs and data transfers, ICT supplier registration and concentration risk, ongoing monitoring and audits.

Frameworks: TPRM, DORA ICT, ISO 27036, RGPD Art. 28. Detalhe em Governance de Terceiros.

ESG & Sustainability

CSRD disclosures mapped to ESRS data points, dual materiality, environmental KPIs, social and governance metrics, EU Taxonomy eligibility and assurance-ready evidence.

Frameworks: CSRD, ESRS, ISO 14001, GRI, EU Taxonomy. Focus on ESG & Sustainability.

Quality & Operations

Procedures and SOPs relating to controls, non-conformities, the CAPA cycle, supplier quality, internal quality audits and document control with approvals.

Frameworks: ISO 9001, ISO 13485, ISO 22000, ISO 20000. Specialising in Quality & Operations.

Audit & Assurance

Risk-based audit framework, planning and timetable, execution and working papers, categorised findings, CAPA, ongoing assurance between audits and management review.

Frameworks: applies across all active frameworks. See the Audit & Assurance section for further details.

Regulatory Change

Central register of legal obligations, compliance calendar, horizon scanning of European regulations, mapping of obligations to controls, monitoring of jurisdictions and automatic alerts.

Frameworks: the EU AI Act, NIS2, DORA, CSRD, the GDPR and national legislation. See ‘Regulatory Changes Governance’ for further details.

Which sequence should I follow?

There is no universal order, but there are patterns that work:

  • Organisation subject to certification requirements → Safety, then Audit, then Third Parties.
  • Organisation with significant exposure to personal data → Privacy, then Security, then AI.
  • Organisation to adopt AI → AI, then Privacy (there is significant overlap), then Ethics.
  • Financial institution → Security (DORA), then Third parties (IT suppliers), then Audit.
  • Group with mandatory sustainability reporting → ESG, then People, then Ethics.

Scope and multi-entity

A domain may have a different scope for each entity. A group may, for example, apply Security Governance to all entities but ESG only to the holding company to which it reports. In Domínios → Âmbito, this matrix is defined, and the reports automatically comply with it.

Deactivate a domain

Deactivating a domain does not delete any data. The controls, records and history remain and continue to serve the other domains that reference them — you simply no longer see the flows and reports for that domain. This means you can reactivate it without losing anything.

On this page

Which domain should I start with?

Tell us which frameworks you use and your deadlines — we’ll map out the right approach for your organisation.