Platform Features

Every module. One connected system.

ClearGRC is built around the modules your team actually uses, connected through a shared data model so a change in one propagates through all.

Module 01

Risk Management

Maintain a living risk register across the enterprise. Set appetite thresholds, assign owners, track treatment plans to closure, and surface AI-generated risk candidates from your business context.

  • Quantitative and qualitative risk scoring
  • Heat map by likelihood and impact
  • Linked controls and treatment actions
  • AI-assisted probable-risk generation
Module 02

Control Library

Build and manage your organisation's control framework. Map controls across frameworks, assign owners, and track implementation and effectiveness in a single view.

  • Control creation with framework mapping
  • Cross-framework control reuse
  • Implementation status and effectiveness tracking
  • Control owner assignment and review workflows
Module 03

Assessment Management

Run structured assessments across your programme. Four built-in types (Gap, Readiness, Third-Party, and Self-Assessment), with evidence collection and scoring included.

  • Gap assessments against any framework
  • Readiness assessments for certification audit
  • Self-assessments for business units
  • Third-party assessments with questionnaire workflows
Module 04

Audit Management

Plan and execute internal audits with structured workflows. Manage scope, collect evidence, log findings, track management responses, and produce audit-ready reports.

  • Audit planning with scope and timeline
  • Evidence request and collection workflows
  • Finding management with severity classification
  • Audit report generation
Module 05

Policy Management

Author, version, and distribute policies to the right teams. Track acknowledgement, enforce review cycles, and link each policy to the controls and risks it covers.

  • Version-controlled policy authoring
  • Targeted distribution by role or business unit
  • Acknowledgement tracking and automated reminders
  • Linked to controls and risk register
Module 06

Third-Party Risk

Onboard, assess, and continuously monitor every vendor. Tier classification, structured questionnaire workflows, risk scoring, and contract tracking, all in one view.

  • Vendor onboarding and tiering (critical, high, medium, low)
  • Questionnaire dispatch and response tracking
  • Contract and SLA management with renewal alerts
  • Vendor risk report generation
Module 07

Asset Management

Maintain a structured inventory of information assets. Classify by sensitivity, assign owners, and link assets to the risks and controls connected to them.

  • Asset inventory with classification and sensitivity labelling
  • Asset owner assignment
  • Linked risks, controls, and compliance obligations
  • Asset lifecycle tracking
Module 08

Threat Management

Capture and manage threats to your organisation. Link threats to relevant assets and risks for a complete view of your threat landscape.

  • Structured threat capture and classification
  • Threat-to-asset and threat-to-risk linkage
  • Threat owner assignment
  • Integrated view alongside risk register
Module 09

Vulnerability Management

Ingest vulnerability scan data from Nessus and manage remediation workflows alongside your risk register. No separate tool required.

  • Nessus scanner integration for automated ingestion
  • Vulnerability severity classification (Critical–Low)
  • Remediation assignment and due-date tracking
  • Linked to risk register for holistic risk view
Module 10

Process Management

Document and manage the business processes that underpin your compliance programme. Link processes to the risks, controls, and policies they support.

  • Process documentation and owner assignment
  • Linked controls and policy mapping
  • Process risk linkage for full traceability
  • Review cycle management
Module 11

Exception Management

Manage policy and control exceptions through a structured approval workflow. Track duration, risk acceptance, and review dates, with a full audit trail.

  • Structured exception request and approval workflow
  • Risk acceptance documentation
  • Expiry and review date tracking
  • Immutable exception audit log
Module 12

Document Inventory

Centralise programme documentation in a structured, version-controlled repository. Classify documents, assign owners, and link them to the controls and frameworks they support.

  • Structured document library with classification
  • Version control and change history
  • Document owner and review cycle tracking
  • Linked to controls, risks, and frameworks
Module 13

AI Assistance

AI built into the platform's workflow, not bolted on. Generate risk candidates, summarise assessments, and get contextual guidance without leaving the platform.

  • Probable-risk generation from business context
  • Assessment gap summarisation
  • Control and framework explanation in plain language
  • Human review required before any AI output is committed
Platform

Role-Based Access Control

Granular RBAC across every module: control who can view, edit, approve, and export at the object level. Enterprise identity via OIDC and Azure AD B2C.

  • Role-based permissions per module and action
  • Attribute-level data visibility controls
  • OIDC / Azure AD B2C identity integration
  • Full access audit log

See every module in your context.

A 30-minute demo tailored to your frameworks and compliance priorities. No commitment required.