Skip to content

GRC and internal compliance

RegulaLink is not only for regulating others. For many enterprises and institutions, the goal is to comply: apply internal rules, meet national and regional frameworks, and align with international standards (ISO, sector good practices).

That is the role of GRC (governance, risk and compliance) and obligations, especially in self-regulator posture.

Regulate (authority)Comply (enterprise / institution)
GoalOversee external operatorsMaster your own risk and evidence
ExamplesSector agency, national regulatorBank, MFI, cooperative, holding, large corporate
In RegulaLinkCollect, licences, sanctions, inbound reportsGRC, risk registers, audits, obligations, ISO frameworks
Typical modeRegulatorSelf-regulator

Same platform: you can be an authority or an organization that must prove compliance — or both in a group (HQ / subsidiaries).

RegulaLink helps you document, track and prove several layers:

  1. Internal rules — policies, procedures, risk appetite, internal approvals.
  2. National framework — laws, supervisors, required registries and filings.
  3. Regional framework — union / common market / regional supervisor requirements.
  4. International standards — e.g. ISO 31000 (risk management, included) and ISO/IEC 27001 (information security, paid add-on).

The product does not replace legal advice: it structures day-to-day work (who does what, when, with which evidence).

Section titled “What GRC covers in RegulaLink (shipping today)”
  • Framework studio: deploy a pack (steps, process obligations, controls).
  • ISO 31000:2018 — risk management cycle. Included when GRC is on / in self-regulator mode.
  • ISO/IEC 27001:2022 — ISMS + Annex A controls. Paid add-on.

Other packs (COSO, NIST, etc.) are not shipped packs today.

Inherent / residual risk, barriers, matrix, appetite, treatments (mitigate, transfer, avoid, accept), owners and due dates.

Guided runs along framework steps; outputs locked on submit for an audit trail.

Planning, audit types, findings, checklists, evidence; links to risks and obligations.

GRC-related incident declaration and workflow instruction (from GRC chrome).

Deadlines and evidence, often tied to licences or HQ (especially useful for self-regulators without external licences). Calendar on the operator side.

RoleInterfaceExamples
Compliance / risk ownerAdmin → GRCDeploy frameworks, keep the register, run audits and assessments
LeadershipGRC cockpitOverview, “To do” inbox
Site / subsidiary / memberOperator → GRC / My complianceAssigned risks, audits, obligation evidence
  1. Choose self-regulator at first-run.
  2. Let the system seed ISO 31000 and enable GRC / risks / audits.
  3. Adapt internal policies (thresholds, owners, review cadence).
  4. Optionally activate ISO 27001 for information security.
  5. Operate daily: inbox, registers, assessments, audits, obligations.
  6. Produce evidence for internal control, external auditors or supervisors.

Internal compliance also relies on:

  • Collect — know your members, agents, suppliers.
  • Authorizations — internal clearances or licences you issue.
  • Regulation — internal discipline and findings.
  • Intelligence — dashboards to steer.

So RegulaLink covers both “make others comply” and “prove that we comply”.

  • Frameworks beyond ISO 31000 / 27001 are not shipped packs today.
  • Live federation between a regulator and a self-regulator is not the core current path.
  • Some screens may still sound “regulator”; self-regulator mode adapts part of the wording.