Risk Management
A register that sorts itself by what actually matters.
Guide
NVector is a governance, risk and compliance platform. It gives you one place to track the controls you are required to implement, hold the evidence that proves it, manage risk and incidents, and produce the reports a regulator, auditor or board asks for. This page is the short version.
Everything else in the platform follows from this one.
The problem
Most regulated organisations answer to more than one rulebook. Access control appears in ISO 27001, in NIST CSF, in NCA ECC and in SOC 2 — worded differently each time. Done in spreadsheets, that one piece of work gets tracked, evidenced and reported four separate times, and the four copies drift apart.
The idea
NVector inverts it. You maintain one library of plain-language controls. Each control is mapped to the specific clause it satisfies in every framework you have switched on, and the mapping records whether that coverage is full or partial. You work the control, not the rulebook.
The result
Mark a control implemented and every requirement it fully satisfies closes with it, across every framework at once. Switching on a new framework starts partly complete, because the work behind it is already done and already evidenced.
Eleven modules, each one feeding the same picture rather than keeping its own.
A register that sorts itself by what actually matters.
The regulatory clock runs where everyone can see it.
Do the work once, satisfy every framework it touches.
Policies that are current, approved and provably read.
Proof attached to the control it proves, ready before the examiner asks.
Every obligation becomes somebody’s job, with a date on it.
You cannot protect, or evidence, what you have not written down.
Turn examination season into a report, not a project.
Switch a rulebook on and its requirements are already there.
Findings that carry a deadline and an owner, not just a severity.
The board pack builds itself from the data you already keep.
All 8 ship with the product, requirement sets already mapped to the control library. Your own internal standards can sit alongside them.
A realistic shape, not a promise. Yours will move around depending on how much you already have written down.
Week 1
Pick the frameworks you actually report against. Their full requirement sets load with the product — there is no content project — and you get a coverage position on day one, including the parts you have already done.
Week 2
Your existing policies, procedures and evidence go into the vault and get linked to the controls they support. Most teams arrive from spreadsheets; that baseline is the starting point, not something to throw away.
Week 3
Whatever is left open becomes a task against a named person with a deadline. Risks get scored and banded, assets get recorded, and the register stops being a document that is only accurate on the day of the meeting.
Ongoing
Evidence expires, policies come up for review, incidents start a clock, and reports build themselves from live data. The point is that examination season becomes a report rather than a project.
No. The requirement sets and the control library ship with the product, written in plain language. You are choosing which frameworks apply and confirming what you already do — not authoring a control set from a standard document.
That works, and it is the common starting point. The value of the shared library shows up the first time somebody asks you for a second one — a customer wanting SOC 2, or a contract requiring a regional certification. The second framework starts partly complete.
Yes. Internal standards and group policies sit alongside the published frameworks and map to the same control library, so internal obligations are tracked the same way as regulatory ones.
Compliance and risk staff live in it. Control owners across IT and the business get tasks and evidence requests rather than a login they have to learn. Auditors get a read-only view, and executives get the reports.
Cloud deployments are usable the same day, because nothing has to be built first. A realistic answer for a full picture across several frameworks is a few weeks of loading what you already have.
Thirty minutes in the live platform, using the rulebooks you actually report against.