GRC and internal compliance
GRC and internal compliance
Section titled “GRC and internal compliance”RegulaLink is not only for regulating others. For many enterprises and institutions, the goal is to comply: apply internal rules, meet national and regional frameworks, and align with international standards (ISO, sector good practices).
That is the role of GRC (governance, risk and compliance) and obligations, especially in self-regulator posture.
Regulate vs comply
Section titled “Regulate vs comply”| Regulate (authority) | Comply (enterprise / institution) | |
|---|---|---|
| Goal | Oversee external operators | Master your own risk and evidence |
| Examples | Sector agency, national regulator | Bank, MFI, cooperative, holding, large corporate |
| In RegulaLink | Collect, licences, sanctions, inbound reports | GRC, risk registers, audits, obligations, ISO frameworks |
| Typical mode | Regulator | Self-regulator |
Same platform: you can be an authority or an organization that must prove compliance — or both in a group (HQ / subsidiaries).
Layers of rules you must hold
Section titled “Layers of rules you must hold”RegulaLink helps you document, track and prove several layers:
- Internal rules — policies, procedures, risk appetite, internal approvals.
- National framework — laws, supervisors, required registries and filings.
- Regional framework — union / common market / regional supervisor requirements.
- International standards — e.g. ISO 31000 (risk management, included) and ISO/IEC 27001 (information security, paid add-on).
The product does not replace legal advice: it structures day-to-day work (who does what, when, with which evidence).
What GRC covers in RegulaLink (shipping today)
Section titled “What GRC covers in RegulaLink (shipping today)”Frameworks
Section titled “Frameworks”- Framework studio: deploy a pack (steps, process obligations, controls).
- ISO 31000:2018 — risk management cycle. Included when GRC is on / in self-regulator mode.
- ISO/IEC 27001:2022 — ISMS + Annex A controls. Paid add-on.
Other packs (COSO, NIST, etc.) are not shipped packs today.
Risk register
Section titled “Risk register”Inherent / residual risk, barriers, matrix, appetite, treatments (mitigate, transfer, avoid, accept), owners and due dates.
Assessments
Section titled “Assessments”Guided runs along framework steps; outputs locked on submit for an audit trail.
Audits
Section titled “Audits”Planning, audit types, findings, checklists, evidence; links to risks and obligations.
Incidents
Section titled “Incidents”GRC-related incident declaration and workflow instruction (from GRC chrome).
Obligations (“My compliance”)
Section titled “Obligations (“My compliance”)”Deadlines and evidence, often tied to licences or HQ (especially useful for self-regulators without external licences). Calendar on the operator side.
Who sees what
Section titled “Who sees what”| Role | Interface | Examples |
|---|---|---|
| Compliance / risk owner | Admin → GRC | Deploy frameworks, keep the register, run audits and assessments |
| Leadership | GRC cockpit | Overview, “To do” inbox |
| Site / subsidiary / member | Operator → GRC / My compliance | Assigned risks, audits, obligation evidence |
Typical enterprise (B2B) path
Section titled “Typical enterprise (B2B) path”- Choose self-regulator at first-run.
- Let the system seed ISO 31000 and enable GRC / risks / audits.
- Adapt internal policies (thresholds, owners, review cadence).
- Optionally activate ISO 27001 for information security.
- Operate daily: inbox, registers, assessments, audits, obligations.
- Produce evidence for internal control, external auditors or supervisors.
Link to the rest of RegulaLink
Section titled “Link to the rest of RegulaLink”Internal compliance also relies on:
- Collect — know your members, agents, suppliers.
- Authorizations — internal clearances or licences you issue.
- Regulation — internal discipline and findings.
- Intelligence — dashboards to steer.
So RegulaLink covers both “make others comply” and “prove that we comply”.
Known limits
Section titled “Known limits”- Frameworks beyond ISO 31000 / 27001 are not shipped packs today.
- Live federation between a regulator and a self-regulator is not the core current path.
- Some screens may still sound “regulator”; self-regulator mode adapts part of the wording.