For startups and SMEs

The integrated GRC platform that knows exactly what applies to you.

Governance, risk and compliance on one platform — powered by our Organisation Context Engine™ (OCE) that scopes your obligations to your real operations and demonstrates the reasoning behind every call. Enterprise-grade capability, on a startup or SME budget.

10 Core modules 46 frameworks One Core One audit log
A compliance and risk leader reviewing an applicability dashboard.
About us

Two decades of GRC. A decade in the GRC standards. One platform.

Over twenty years of hands-on governance, risk and compliance work — and more than ten years contributing to and helping build the ISO 37000-series GRC standards through ISO/TC 309 — led us to build two things the market didn’t have: the Organisation Context Engine™ (OCE) and a single-sourced GRC Spine.

Together they take you from a single regulatory clause to the control that satisfies it, to the framework it maps to — with evidence tracking and maturity rating along the thread. The result simplifies and strengthens an organisation’s GRC capability at once — and gives that organisation back the time and budget to spend on its core activities, instead of on compliance overhead.

Our solution

Same regulatory weight as the enterprise. None of the enterprise resources.

Growing and mid-sized organisations carry the same obligations as the largest firms in their sector — but without the budget, the tooling, or a full in-house GRC team. Three things follow, and we built EnableGRC to answer each one.

01

The capability gap

The same regulatory challenges land on you as on the enterprise — but the systems built to handle them are priced for the enterprise. So teams fall back to spreadsheets, and the GRC expertise needed across every area isn’t in-house, forcing reliance on outside consultants and specialists for each new domain.

02

The clarity gap

Regulatory frameworks are complex and often contradictory — leading to duplicated controls covering one obligation three ways, a pile of reports nobody trusts, and little clarity on whether a control is truly being met. Our Spine and OCE are the answer: one thread from the law to the control to its evidence, scoped to what genuinely applies to you.

03

The integration gap

To meet requirements, organisations stitch together point tools that were never designed to work together — separate logins, separate audit trails, separate versions of the truth. Our truly integrated iGRC platform runs Governance, Risk and Compliance on one Core: one identity, one evidence repository, one audit log.

How the platform answers it.

EnableGRC’s Organisation Context Engine™ (OCE) decides what genuinely binds you, and records why. From there, one connected Spine carries the thread to controls, evidence and frameworks.

OCE — your real context

The Organisation Context Engine™ captures who you actually are: every legal entity, the jurisdictions you operate in, the activities you perform, and your size across four axes — headcount, revenue, asset value and transaction volume — per entity and at group level.

Certainty, not assumption

The OCE decides each obligation by the certainty that it applies. Clear obligations are binding. Genuinely uncertain ones — an undefined size threshold, a law reaching you through a reseller, a threshold met only at group level — route to a documented review with the reasoning attached, rather than being silently included or dropped.

The Spine

From the regulation, to the obligation, to the control, to its evidence, to the framework it satisfies — and a maturity rating along the way. One connected thread. Map a control once; see every obligation it meets. No duplicated controls, no orphaned evidence.

Defensible by design

Every applicability call carries its factors, and every state change is written to a cryptographically chained audit log. When a regulator or auditor asks why a law applies — or doesn’t — the answer is already on file.

Features

Ten Core modules. A growing pack framework. One Core.

Every tenant runs on the same Core — same identity, same evidence repository, same audit log. A pack never implements its own; it uses the Core. That is what makes iGRC an integrated platform rather than a collection of point tools sharing a brand.

Core platform — 10 modules

01ComplianceThe obligations-to-assurance core, fully traceable. Compliance Map · Obligations · Controls · Regulations · Frameworks · Policies · Policy Library · Synergy Map · Assurance Map · Maturity · SME Review · Legal-Duty Triggers.
02Risk ManagementFull ISO 31000 risk lifecycle, register to appetite. Risk Dashboard · KRI Dashboard · Objectives · Scenarios · Loss Events · RCSA Campaigns · Risk Matrix · Risk Categories · Risk Appetite.
03GovernanceRuns the governing framework and its calendar. Governance Dashboard · Governing Bodies · Documents · Calendar · Stakeholders · Configuration.
04Audit & AssuranceInternal audit over the same control universe. Audit Dashboard · Audit Plans · Engagements — findings trace back to obligations.
05Third-Party RiskOnboard, assess and monitor vendors end-to-end. TPRM Dashboard · Third Parties · Assessments · Risk Assessments · Due Diligence · Monitoring · Questionnaires.
06Incident RegisterCapture, triage and resolve incidents — logging, categorisation and status tracking with a full audit trail.
07TrainingIntegrated Learning Management System. Add, assign, track and evidence mandatory training. Courses · Enrolments · Campaigns (by role & business unit) · Attestation.
08Business IntelligenceTurns GRC data into board-ready insight. Executive Dashboard · Report Builder · Scheduled Reports · Board Report · Chart Builder · Surveys.
09My ItemsEach user’s personal home for what’s assigned to them. Dashboard · My Policies (read & attest) · My Training · Notifications.
10AdministrationEnterprise controls and tenant setup. Org Structure · Business Units · Departments · Users · Roles & Permissions (RBAC) · SSO/MFA · Branding · Integrations · AI Settings · Subscription · Data Migration.

Module packs — the domain layer

Nine domain packs, all coming soon — your Core platform is active today, and each pack opens after launch. Every pack runs on the same Core, so a control mapped once counts everywhere, and each ships with preloaded policy templates, risk and control libraries, regulatory mappings and standard reports.

Ethics & ConductComing soonISO 37002 · 37008 · 37009 · 37301

Whistleblowing & Speak-up with triage and internal investigations, plus the shared Conflict-of-Interest register.

Anti-Bribery & CorruptionComing soonISO 37001 · UK Bribery Act · FCPA · Loi Sapin II

Anti-bribery programme with the gifts & hospitality register, risk assessment and intermediary due diligence.

Financial CrimeComing soonFATF · UK MLR 2017 · EU AMLD5/6 · UK Fraud Act

AML programme, KYC / EDD with PEP and sanctions screening, and fraud — sharing one investigations engine.

Third-Party & Supply Chain RiskComing soonISO 31000 · EU DORA · UK Modern Slavery Act · EU CSDDD

Supplier risk and modern-slavery screening, plus the TPRM+ premium — concentration risk, contractual safeguards and 4th-party tracking. Core third-party risk is bundled with Core.

Operational ResilienceComing soonISO 22301 · 22361 · EU DORA Art 11

Crisis management and business continuity: incident response, BIA, recovery strategies, RTO/RPO and dependency mapping.

Security & PrivacyComing soonISO 27001 · 27701 · NIST CSF 2 · NIS2 · GDPR

ISMS controls and data protection: security policies, access reviews, ROPA, DPIAs, breach and cross-border transfer registers.

ESG & SustainabilityComing soonEU CSRD/ESRS · ISSB S1+S2 · ISO 14001/14064

Materiality, GHG inventory (Scope 1/2/3), target tracking and framework disclosures.

Crypto / Digital AssetsComing soonEU MiCA · FATF Travel Rule · EU DLT Pilot

Crypto-asset service provider readiness, crypto AML and market-abuse surveillance.

Sports GRCComing soonBS 25800 · EU/UK GDPR

Grassroots GRC and event-ops: policies, training matrix, safeguarding and volunteer rota.

Packs are sector-agnostic at the Core and schema-aligned to the relevant standard. Available integrated, or standalone on a Core-light shell.

How we compare

One platform against the usual workarounds.

Capability EnableGRC iGRC Spreadsheets Point tools
(Vanta · Drata · Sprinto)
Consultants
(Big-4 / mid-tier)
Governance + Risk + Compliance in one platformCompliance onlyAdvice, not a platform
Applicability scoped to your real operations (the OCE)Manual, per engagement
Defensible audit trail on every decisionPartialIn documents
One control mapped to every obligation it meetsManual
Configurable depth (risk matrix size, pack activation)n/aFixedn/a
Regulatory database + change alertingPartialBespoke
Runs without an outside specialist for each domainPartial✗ (that’s the model)
Priced for a startup or SME£ per area

Point tools are tools, not a function — they automate compliance evidence but leave Governance, Risk and the judgement of what applies to you. EnableGRC does all three, on one Core.

Request a walkthrough

See it on your own context.

A 20-minute walkthrough, scoped to your sector and jurisdictions. No slideware — we run your context through the OCE and show you the applicability call, the reasoning, and the audit trail.

  • Built by a team that has contributed to and helped build the ISO 37000-series GRC standards, through ISO/TC 309, for over ten years.
  • Governance, Risk and Compliance on one integrated platform — not a stitched-together toolset.
  • Truly global — multi-entity, multi-jurisdiction, sector-agnostic.

Why EnableGRC

Enable, don’t block.

A decade in the GRC standardsOur team have contributed to and helped build the ISO 37000-series GRC standards, through ISO/TC 309, for over ten years.
Truly integratedOne Core for Governance, Risk and Compliance — one identity, one audit log.
Truly globalMulti-entity, multi-jurisdiction, sector-agnostic — built for organisations operating anywhere.