Interactive platform tour, sample data

This is the actual GRXForce cockpit

Start with the Dashboard below, then click through Audit Modules and the rest exactly as your team would.

WORKSPACE / MAINExecutive Overview
⚡ Ask GRXForce AI
Evidence Coverage Ratio
51.4%

54 received / 51 missing, 105 controls

Overall Compliance Rate
24.8%

26 compliant / 74 open / 5 N/A

Open Remediation Gaps
08

HIL review and evidence upload

Critical and High Risks
57

30 day remediation SLA enforced

Remediation Progress, ISO Controls
Jan
Feb
Mar
Apr
May
Jun
CompliantIn processOpen
Top Risks
Missing evidence in shared drive95
Cloud MFA and lockout documentation92
Untested disaster recovery plan88
Annual training evidence82

Common Audit Operations

Active Audits
3

1 external, 2 internal

Open Evidence Requests
18

7 due this week

Auditor Approved
126

artifacts this cycle

Audit Pipeline
AuditTypeStageAuditorWindowStatus
ISO 27001:2022 CertificationExternalStage 1 prepCertification bodyNov 2026On track
SOC 2 Type IIExternalObservation windowCPA firmJan to Jun 2026Evidence flowing
Internal ISMS AuditInternalFieldworkInternal auditAug 20262 findings
Vendor Security ReviewInternalPlanningGRC teamSep 2026Scheduled
Evidence Requests, this week
RequestControlOwnerDueAI Verdict
MFA configuration exportA.5.17IT OpsTomorrowConfirmed
Access review Q2 sign offA.5.18HRFriNeeds human review
Backup restore test logA.8.13InfraFriDowngraded, retest
Incident postmortem SEC-1142A.5.26SecOpsMonAwaiting upload

Audit Modules

Run a test now. Run it when it's due. Or let GRXForce build the evidence stack when the auditor asks, all powered by one Audit Engine.

AI prepares the evidence and workpaper. Your auditor retains the final judgement.

Real-Time Audit

Initiate New Control Test

Control IDSelect a control
Control CriticalitySelect a control
⚠ Control RiskSelect a framework, domain and control to see the control risk.
Control Description

Select a framework, domain and control to see the control description.

AI Evidence Agent Dispatch
Select a control to see dispatch sources.
Evidence Requirement List Auto-populated
Select a control to see the evidence requirement list.
Ready
Workpaper History
ControlFrameworkDateAuditorResultWorkpaper
A.5.15 Access controlISO 27001:2022Jul 31, 2026John SmithCompliantView
A.5.18 Access rightsISO 27001:2022Jul 28, 2026John SmithCompliantView
A.8.16 Monitoring activitiesISO 27001:2022Jul 25, 2026John SmithNon-CompliantView

Demonstration data shown.

Pre-Defined Tests

Pre-Defined Tests

Configured once, GRXForce runs each test on its frequency: evidence collected, AI review completed, result or exception identified, workpaper generated and placed in the workpaper repository for auditor review and conclusion.

ControlScopeFrequencyNext RunStatusWorkpaper
Employee TerminationHRIS + Identity ProviderMonthlySep 1ReadyReady for Review → View Workpaper
User Access ReviewFinance ApplicationsQuarterlyOct 1ReadyReady for Review → View Workpaper
Privileged Access ReviewCloud InfrastructureQuarterlyOct 15ReadyReady for Review → View Workpaper
Vulnerability ManagementProduction ServersMonthlySep 5ExceptionReady for Review → View Workpaper
Backup TestingCore SystemsQuarterlyNov 1ReadyReady for Review → View Workpaper
Security AwarenessAll EmployeesQuarterlyDec 1ReadyReady for Review → View Workpaper
Vendor ReviewCritical VendorsAnnualJan 15ReadyReady for Review → View Workpaper
Policy ReviewInformation Security Policy SetAnnualFeb 1ReadyReady for Review → View Workpaper

Schedule → Test → Evidence → Review → Workpaper

Framework Coverage
ISO 27001:2022, Annex A24.8%

26/105 verified compliant

SOC 2 Type II41%

Trust services criteria, security and availability

GDPR Privacy Baseline85%

privacy program baseline

DPDPA 202358%

consent and notice architecture in progress

NIST CSF 2.0, harmonized62%

harmonized alignment via common control framework

Cross Mapping Savings
Evidence reuse across frameworks63%

one artifact satisfies several controls

Controls satisfied by shared policies48
Duplicate requests avoided212

Collect once, satisfy every framework that needs it. Adding a framework maps existing evidence automatically.

Healthy Controls
61

operating with fresh evidence

Degrading
23

evidence older than policy

Failing
21

missing or rejected evidence

Control Register, sample
ControlFamilyOwnerEvidenceHealth
A.5.15 Access controlOrganizationalIT OpsFresh, 3 daysHealthy
A.5.17 AuthenticationOrganizationalIT OpsFresh, 1 dayHealthy
A.6.3 Security awarenessPeopleHRStale, 94 daysDegrading
A.7.4 Physical monitoringPhysicalFacilitiesMissingFailing
A.8.13 BackupTechnologicalInfraRejected, retestFailing
A.8.16 Monitoring activitiesTechnologicalSecOpsFresh, 6 hoursHealthy
Published Policies
24

version controlled

Due for Review
4

within 30 days

Staff Acknowledged
96%

current versions

Policy Library, sample
PolicyVersionOwnerNext reviewStatus
Information Security Policyv5.0CISOMar 2027Published
IT Asset Management Policyv5.0ITFeb 2027Published
Access Control Policyv3.2IT OpsSep 2026Review due
Incident Response Planv4.1SecOpsOct 2026Published
Data Retention Policyv2.0LegalAug 2026In revision
Executive Compliance Report

Board ready summary of posture, gaps and trajectory. Generated monthly.

PDF Auto scheduled

Statement of Applicability

All 93 Annex A controls with applicability, justification and status. Auditor formatted.

XLSX Current

Evidence Workpapers

Every artifact with AI verdict and human sign off trail, exportable per audit.

ZIP 126 approved

Gap Analysis Report

Framework by framework deltas with remediation owners and dates.

PDF 74 open

Risk Register Extract

Residual risk heatmap and treatment decisions for management review.

XLSX Current

Certificate Wallet

Certificates, attestation letters and audit reports in one shareable trust page.

Coming with your first cert

Vendors Tracked
38

12 critical tier

Assessments Due
5

this quarter

Compliance Breaches
0

rolling 12 months

Vendor Risk, sample
VendorTierData accessLast assessmentRisk
Cloud hosting providerCriticalProduction dataMay 2026Low
Payroll processorCriticalEmployee PIIApr 2026Low
Marketing analyticsStandardPseudonymizedJan 2026Medium
Print and logisticsStandardContact dataOverdueAssess now
Open Issues
74

21 critical or high

Due This Sprint
12

SLA enforced

Closed This Month
31

with verified evidence

Issues and Actions, sample
IssueSeverityOwnerDueStatus
Enable MFA on legacy admin portalCriticalIT Ops3 daysIn progress
Upload DR test resultsHighInfra6 daysNot started
Close access review exceptionsHighHR8 daysIn progress
Refresh security training recordsMediumHR14 daysIn progress
Vendor DPA renewal, logisticsMediumLegal21 daysNot started

Sample data shown. Want it live on your controls? Contact us or let us run it for you. Auditor sending you a control list instead? See External Audit Automation.