Skip to main content

Compliance Management

Compliance management that keeps up with your obligations

de.iterate is an Australian GRC platform with compliance management and an obligations register built in. Laws change, standards get amended and customers slip new clauses into contracts. de.iterate keeps your obligations in one register, traces each one to the evidence that satisfies it, and provides assurance you’re meeting all your obligations.

Instead of managing policies in one place, risks in another, evidence in folders, and audits through a last-minute scramble, de.iterate connects the whole system. That means better visibility, clearer ownership, stronger assurance and less time lost to manual admin. The current platform spans policies, assurance tasks, registers, evidence, reporting, Trust Centre capabilities, auditor access and support for multiple frameworks.

We help you get your ducks in a row.

deiterate-platform
deiterate-compliance-calender

Sound familiar?

You're working towards ISO 27001, a key customer wants SOC 2, and the board has just asked about the Privacy Act reforms. Somewhere there's a spreadsheet called "control mapping FINAL v3" with 14 tabs and exactly one person who understands it. They're on leave.

Larger organisations have replaced the spreadsheet with a platform, and the problem has moved rather than gone. ISO 27001 belongs to security, SOC 2 to the customer success team that got asked for it, the Privacy Act to legal, and each runs its own evidence requests to the same control owners. The person who runs the firewall has been asked for the same screenshot three times this quarter, by three people who don’t know about each other. The platform knows every obligation. Nobody in it knows which control satisfies all three at once, so each audit starts from scratch.

Auditors have noticed too. "How do you keep across changes to your obligations?" is now a standard audit question, and a good answer has a recent review date on it.

 

How de.iterate handles compliance management

Compliance stays manageable when an obligation is recorded once, every framework that cares about it points at the same control, and the evidence for that control is collected once and reused. de.iterate is built that way. Obligations are mapped as they’re written, controls trace down to their evidence and up to every framework they satisfy, and when a standard changes the update arrives in your system with a record of what moved. The spreadsheet becomes a map everyone can read, and the third screenshot request stops going out.

calculated-control

Map obligations the way they're written

Use de.iterate to record the Act, then the Regulation, and then the guidance. Each obligation has an owner, a regular review cycle and connects directly to your integrated management system through the de.iterate fabric.

see-controls

Follow any obligation all the way to its evidence through fabric

Trace an obligation through the policy that addresses it and the control that puts it into practice, right down to the evidence that proves it. Or start from a control and see every obligation it supports.

board-reporting

Add a framework by filling the gaps

One control can provide evidence for many frameworks, so adding SOC 2 to an ISO 27001 program builds on the work you've already done. Choose from 25+ frameworks, including state, federal and Defence security frameworks, or bring your own.

risk-drift

Stay current when a standard changes

Standards get revised and laws get amended. When a framework in de.iterate is updated, the System Updates feature brings the change into your management system. Each update is recorded, so you can show your auditor how you keep across changes to your obligations.

key-risk-indicator

Let us map your documentation

Upload all your existing policies so that de.iterate can map them to framework controls, showing its reasoning and confidence for each link. It then marks each control as evidenced, partially evidenced or not evidenced.

deiterate-integrations

Connect integrations to dynamically monitor enterprise risks

Integrations connect directly to de.iterate and enable dynamic control monitoring. Find out when a risk is moving out of tolerance in real-time through our suite of integrations. Our public API connects the rest of your systems.

assurance-task-mock-up

Also included

  • Statement of Applicability and all IMS Documentation Set your management system up once and carry consistency through your policies and procedures.
  • Interactive management system guide covering scope, internal and external issues, interested parties, objectives, competency and management review
  • Compliance Calendar for review cycles, due dates and audit scheduling
  • Compliance reporting with important metrics like KRIs with leading and lagging indicators
  • Custom control libraries select from an existing framework or create your own using the platform tools
  • Automated gap assessment engine to see continuously monitor your strengths
  • Free Essential Eight and Privacy Act self-assessments to see where you stand

 

Frequently Asked Questions

Most questions we get about the risk module come down to one worry: will we have to change how we already do compliance to fit the software? The short answer is no. Your matrix, your register and your appetite statements come with you. The longer answers are below.

Do we have to start again for each new framework?

No. de.iterate maps controls across frameworks, so the work you've done for one standard counts towards the others. You only fill the gaps.

What happens when a framework or standard is updated?

de.iterate's System Updates feature brings framework changes into your management system, so a revised standard doesn't mean starting again. Each update is recorded, which gives you an answer when your auditor asks how you keep across changes to your obligations.

Can we add our own framework or a customer's requirements?

Yes. de.iterate lets you build a custom framework or import your own, then map it to your existing controls.

What is an obligations register?

An obligations register lists the legal, regulatory and contractual obligations that apply to your organisation, each with an owner and a review date. Auditors use it to check that you know what applies to you and that you're keeping up with changes.

Which frameworks does de.iterate support?

de.iterate supports more than 25 frameworks natively, including ISO 27001, SOC 2, Essential Eight, NIST, the Privacy Acts, state and federal government frameworks and Defence security frameworks. See our Frameworks page for the full list.

How does de.iterate use AI to map our compliance?

Upload your existing documentation and using our proprietary de.iterate fabric, we link them to framework controls, clauses, related artifacts and assurance items. Always showing rationale and confidence for each link.

Can we manage our Statement of Applicability in de.iterate?

Yes. Your Statement of Applicability, IMS Scope and IMS Manual all live in de.iterate. Set your scope once and it carries through your system.

How do we keep track of review dates and attestations?

de.iterate's Compliance Calendar shows every review cycle, due date and attestation in one view, and sends reminders to the people responsible.

What makes de.iterate different

From setup to scale, every feature is designed to help your team save time, stay focused, and drive meaningful results.

Expert support, not just software

de.iterate combines technology with hands-on support from experienced GRC professionals based in Australia. From onboarding through to certification, our team works with you to build momentum quickly, helping many organisations get audit-ready in less than 12 weeks and providing practical support through external audits and ongoing compliance activities.

Continuous compliance, not annual panic

Great compliance is not built in the two weeks before an audit. de.iterate helps you stay ready year-round with assurance tasks, checklists, live registers, reporting and a compliance calendar that keeps momentum going.

Practical enough to use, powerful enough to scale

From start-ups to enterprise, de.iterate supports multiple frameworks in one system, including ISO 27001, ISO 27701, ISO 9001, ISO 14001, ISO 45001, Privacy Acts, SOC 2, DIP, Essential Eight and more. You can grow your compliance maturity without rebuilding everything from scratch.

Key Features

A smarter way to manage compliance

de.iterate combines policies, training, registers, evidence, reporting and assurance workflows in one integrated management system, helping you reduce complexity, stay audit-ready and turn governance, risk management and compliance into business as usual. Every feature is designed to save time, strengthen accountability and make GRC compliance easier to manage across your organisation.
compliance-management

Enterprise Risk Management

 A risk register with a pulse, with inherent and residual scoring, heatmaps and risk appetite. 

policy-management

Policy Management

 Plain-English policies, clear approvals and proof your staff have read them. 

controls-management

Controls Management

 Scheduled controls testing, with the evidence ready before your auditor asks. 

audit-management

Audit Management

 Audit programs, findings and corrective actions tracked to closure. 

it-cyber-security-consultants

Cyber and IT Risk

 Your whole ISMS, from asset register to Statement of Applicability. 

AI-gov

AI Governance

 ISO 42001, AI impact assessments and an inventory of the AI in your business. 

data-privacy

Privacy and Data Governance

 Find your personal information, see where it goes and keep your privacy policy current.

quality-safety-enviro

Quality, Safety & Environment

 ISO 9001, ISO 14001 and ISO 45001, running alongside everything else you manage. 

risk-drift

Third Party Risk Management

 Keep tabs on the suppliers holding a slice of your risk. 

Multiple compliance frameworks, without extra effort

 

With de.iterate, the complexity of managing multiple frameworks doesn’t translate into increased workload. Our unified platform serves as a central hub for overseeing all your compliance activities, whether you’re working with bespoke frameworks or seeking to meet the criteria of the most sought-after security and privacy standards and certifications.

ISO 27001

Information Security Management Systems

The international standard that sets out the requirements for data protection systems. It’s all about keeping data safe and secure.
ISO 9001

Quality Management Systems

This standard defines the requirements for quality management. It’s all about ensuring your business consistently delivers high-quality products and services.
ISO 45001

Occupational Health and Safety Management Systems

The standard that specifies the requirements for an effective OH&S management system. Create a safer, healthier workplace.
ISO 14001

Environmental Management Systems

The global standard for building EMS. It gives you a structure to identify environmental impacts, manage obligations, strengthen governance.

ISO 42001

Artificial Intelligence Management Systems

This standard specifies the requirements for managing AI systems responsibly and ethically. It helps ensure trustworthy development and use of AI.

SOC 2

System and Organisation Control 2

This specifies how organisations should manage their customer’s data. It is one of the most sought-after security framework for SaaS companies. 

Privacy Acts

Australia, New Zealand, Canada, France, Italy, US and UK

Country-specific legislative frameworks established to protect individuals’ personal information from misuse, interference, unauthorised access, modification, and disclosure.

RRFR

Right Fit for Risk

The Australian Government’s Department of Employment and Workplace Relations uses the External Systems Accreditation Framework and the RFFR approach to assess and accredit third party service providers and systems.

DISP

Defence Industry Security Program

DISP is a critical initiative that ensures businesses in the defence supply chain meet stringent security requirements. DISP compliance is essential for companies that engage in Defence tenders, contracts and projects.

Simple monthly pricing, based on the frameworks you need

de.iterate pricing is structured around the compliance frameworks you choose to access, giving you the flexibility to build a program that fits your organisation’s needs. Every plan includes access to the de.iterate platform and its feature set, from automated and expert-led onboarding, through to migration support, assurance workflows, live registers, compliance reporting and the core documentation needed to run and maintain your management system with confidence.

AUD
GBP
Starter (per month)

$179£100

  • Essential Eight

  • SMB 1001

  • Privacy Acts

  • DISP

  • Cyber Essentials

Business (per month)

$2,100£1,250

  • ISO 27001

  • ISO 27701

  • ISO 42001

  • ISO 9001

  • ISO 45001

  • ISO 14001

  • SOC 2

  • NIST CSF 2.0

  • NIST 800-53

  • NIST 800-172

  • NIST 800-172

  • GDPR

  • Essential Eight

  • SMB 1001

  • Privacy Acts

  • DISP

  • Cyber Essentials

  • DORA

  • NIS2

  • CIS v8

  • EU AI Act

  • TISAX

Enterprise (per month)

$3,500£2,000

  • ISO 27001

  • ISO 27701

  • ISO 42001

  • ISO 9001

  • ISO 45001

  • ISO 14001

  • SOC 2

  • NIST CSF 2.0

  • NIST 800-53

  • NIST 800-171

  • NIST 800-172

  • GDPR

  • Essential Eight

  • SMB 1001

  • Privacy Acts

  • DISP

  • ISM

  • SOCI

  • Right Fit for Risk (RFFR)

  • Cyber Essentials

  • DORA

  • NIS2

  • CIS c8

  • EU AI Act

  • TISAX

Add a framework without adding to the headcount. 

Tell us which frameworks you're juggling, and we'll show you how they fit together in de.iterate.