Governance, Risk & Compliance
Governance, Risk & Compliance is the module through which an organisation runs its entire regulatory and control obligation from a single system of record. It owns the problem every regulated enterprise faces: proving, continuously and on demand, that the right controls exist, that they operate, that risks are understood and treated, and that policies are current and acknowledged. Instead of spreadsheets, shared drives and disconnected point tools, Governance, Risk & Compliance holds every framework, control, assessment, audit, risk and piece of evidence in one connected structure.
It sits at the assurance layer of the Nashua 360 suite, drawing operational signal from the modules where work actually happens and turning that signal into a defensible, audit-ready posture. Where other modules execute the business, this module certifies that the business is executed within its obligations.
What the module does
Governance, Risk & Compliance is a multi-framework engine. It manages any number of regulatory and standards frameworks in parallel, including SOX, ISO 27001, DORA, GDPR and PCI-DSS, each held as a versioned set of requirements so that a control tested today remains traceable to the exact requirement wording it satisfied. At its heart is a reusable control library: a single control is authored once, then mapped across every framework whose requirements it addresses, so evidence gathered for one obligation is credited automatically to all the others it supports.
Around that core the module delivers the full assurance lifecycle. A regulatory calendar tracks filing deadlines, certification renewals and audit schedules. Questionnaire-based assessments drive periodic testing and evidence collection against control objectives. Internal and external audit management captures findings, assigns remediation and follows each item to closure. A risk register records inherent and residual exposure with mitigation planning. Policy management governs the full policy lifecycle with versioning and acknowledgment tracking, and an evidence vault binds documents, screenshots and test results directly to the controls they prove. Compliance dashboards surface readiness scores, gap analysis and trend views across every framework at once.
The domain and the data model
The conceptual model is deliberately simple, which is what lets it scale across many frameworks without duplication. A framework is an external body of obligations, such as a regulation or a standard, expressed as a structured set of requirements that carry versions, so the module always knows which edition of a rule was in force at any moment. A control is an internal safeguard the organisation operates: an access review, a change approval, a reconciliation. The relationship between the two is many to many. One requirement is often satisfied by several controls, and one well-designed control frequently satisfies requirements across multiple frameworks. This mapping is the pivot of the whole domain, because it converts a pile of overlapping regulations into a manageable, deduplicated set of things the organisation actually does.
Everything else attaches to those two ideas. Assessments test whether controls are designed and operating effectively, and the results they produce become evidence. Each piece of evidence is anchored to the specific control it supports and time-stamped, so an assessor can trace any assurance claim back to its source artefact. A risk represents an exposure the organisation carries, scored before and after the controls that treat it, which links the risk register to the same control fabric that compliance testing relies on. Policies sit alongside as the documented intent behind controls, versioned and acknowledged by the people they bind. The result reads as one coherent picture: obligations, the safeguards that meet them, the proof that the safeguards work, and the residual risk that remains.
Principal workflows
Compliance work in the module follows a small number of repeatable cycles. In the assessment cycle, an owner launches a questionnaire against a control set, respondents supply answers and upload supporting artefacts, and each response is reviewed and either accepted or returned for more evidence. Completed assessments update the control's effectiveness state and feed the readiness score for every framework the control is mapped to.
The audit cycle governs both internal reviews and external examinations. An audit is scoped to frameworks and controls, fieldwork records findings with severity and root cause, and every finding generates a remediation item with an owner and a due date that is tracked to closure. The risk cycle runs continuously: risks are identified, scored for inherent exposure, treated with mitigating controls, then rescored for residual exposure, with periodic review keeping the register current. The policy cycle carries a document from draft through review and approval to publication, then distributes it for acknowledgment and records who has attested and who is outstanding. The regulatory calendar sits across all of these, raising obligations ahead of their deadlines so that filings, renewals and scheduled tests are initiated in good time rather than discovered late.
Standards, controls and assurance depth
The module treats each framework with the rigour its own discipline demands. For SOX it models the financial reporting control environment directly: entity-level and process-level controls, control owners and testers kept separate to preserve independence, sampling and test-of-operating-effectiveness results, and deficiency evaluation that grades an exception as a deficiency, a significant deficiency or a material weakness according to its likelihood and magnitude. Because those controls guard financial statement assertions, their status flows into the wider internal-control opinion the organisation must defend.
For information security and operational resilience frameworks the depth is equally specific. ISO 27001 is handled as a managed control set with statement-of-applicability logic. DORA is modelled around ICT risk, resilience testing and third-party dependency, reflecting the operational resilience obligations placed on regulated entities. GDPR and PCI-DSS bring data protection and cardholder-data controls with their own evidentiary expectations. Throughout, the module enforces the controls that make assurance credible: segregation between preparer and reviewer, immutable evidence with a full audit trail of who tested what and when, versioned requirements so historic results are never silently invalidated by a standard changing, and readiness scoring and gap analysis computed from live control state rather than asserted by hand. The effect is a posture that stands up to a regulator or an external auditor because every claim resolves to dated, attributable evidence.
Where it fits in Nashua 360
Governance, Risk & Compliance is an assurance layer over the suite, and it earns that position through direct integration rather than manual re-keying. It connects to Accounting & Control for SOX and internal financial controls, so the reconciliations, approvals and journal controls that operate inside the finance module are the very controls this module tests, and their evidence is drawn from where the work genuinely happened. It integrates with Document Management as the home for policy documents and evidentiary artefacts, giving policy versioning, retention and controlled access without a second document store to govern.
It integrates with Flow Management for every approval the module raises: policy sign-off, remediation acceptance, risk treatment approval and assessment review all run as governed workflows with routing, escalation and a durable record of each decision. Because the suite shares one identity and permission model, control owners, testers, risk owners and approvers are the same people the rest of the platform already knows, and the separation-of-duties rules the module depends on are enforced consistently across every module they touch.
How AI Workers operate inside it
The suite is AI-native, and AI Workers act as first-class participants in the compliance function rather than a bolt-on assistant. A compliance owner can query module data conversationally, asking which controls are failing across DORA and ISO 27001, which remediation items are overdue, or how residual risk has moved this quarter, and receive an answer grounded in live control and evidence state. Workers execute action directly: opening remediation items from a finding, scheduling an assessment, updating a risk score or dispatching a policy for acknowledgment.
They watch continuously for anomaly and exception, flagging a control whose evidence has gone stale, an acknowledgment campaign stalling below threshold, or a filing deadline approaching without preparation begun. They perform document and data extraction, reading an uploaded audit report or vendor attestation and proposing the findings, control mappings and evidence links it implies, which turns unstructured artefacts into structured, testable records. As decision support they surface the residual exposure and control coverage behind a choice before it is made. And an AI Worker participates as an approval or review node in the module's workflows, screening an evidence submission or a proposed risk treatment against policy and passing it on with a recommendation, so that routine assurance keeps moving while genuine judgement reaches the right human at the right moment.
