Skip to main content

Controls Management

See which controls are working, with the evidence to back it up

de.iterate is an Australian GRC platform with controls management and controls testing built in. Writing a control down takes five minutes. Showing it has operated every month for three years takes a system. de.iterate links each control to what it protects, schedules the testing and keeps the evidence together.

Instead of managing policies in one place, risks in another, evidence in folders, and audits through a last-minute scramble, de.iterate connects the whole system. That means better visibility, clearer ownership, stronger assurance and less time lost to manual admin. The current platform spans policies, assurance tasks, registers, evidence, reporting, Trust Centre capabilities, auditor access and support for multiple frameworks.

We help you get your ducks in a row.

deiterate-platform
policy-calendar

Sound familiar?

A control owner finds out they own a control when the auditor asks for evidence. Testing happens in one frantic burst. The screenshot that proves it all is in someone’s inbox, and that someone left in March.

Larger organisations have a controls library, and the problem has scaled with it. Four hundred controls sit in the GRC platform, each with an owner assigned during implementation, and a third of those owners have since moved roles. Testing runs to a calendar, so the same control is tested in March for ISO, in June for SOC 2 and in September by internal audit, with three sets of evidence filed in three places by three teams who don’t compare notes. The control owner answers all three requests with the same screenshot and starts to wonder why anyone needs it.

Either way, the evidence exists and nobody can find it when it counts.

How de.iterate handles control management

A control is only worth having if someone owns it, it gets tested often enough to be trusted, and the evidence lives somewhere other than an inbox. de.iterate builds controls that way. Each control is mapped once across every framework it satisfies, testing is broken into scheduled tasks with named owners, evidence stays attached to the control it proves, and integrations with your security tooling check that what the control says matches what the systems show.

controls-management

See everything a control touches

Link any control to multiple risks, obligations, assets and policies. Start from a control library that's already mapped across frameworks, so one control can count towards ISO 27001, SOC 2 and Essential Eight together.

compliance-management

Turn testing into small, regular tasks

Assurance Tasks break testing into scheduled activities, each with an owner and a due date. Scheduling rules set how often each task falls due, and de.iterate sends the reminders.

see-controls

Test how controls are designed and how they operate

Document each control's design, then assess its design and operating effectiveness with evidence attached. Assurance Checklists turn repeatable reviews into checklists you can send to colleagues or third parties.

prove-read-understood

Catch mismatches before your auditor does

de.iterate enriches your asset register with integration data from your technology vendors like Microsoft Intune, Jamf, CrowdStrike, Microsoft Defender and SentinelOne, and can alert when providers views drift.

key-risk-indicator

Keep evidence with the control, not in an inbox

Attach evidence to the control it proves, with the date and the person who collected it. Every framework that relies on that control draws on the same evidence, so one screenshot answers the ISO auditor, the SOC 2 assessor and internal audit without three separate requests.

connect-policy-obligation

Turn a failed test into a tracked fix

When a test shows a control isn’t working, de.iterate raises a finding, assigns a corrective action and tracks it to closure. Because control effectiveness feeds residual risk, the risks that depend on that control update at the same time, so the register reflects the gap until it’s fixed.

assurance-task-mock-up

Also included

    • Evidence Store: evidence linked to the task, control or requirement it supports
    • Testing history and evidence export for your external auditor
    • Assurance coverage mapped to your enterprise risks, showing which risks are well tested and which are running on hope
    • AI-powered assurance: gap analysis of uploaded documents, with suggested tasks and control mappings and improvements
    • Human approval on every automated suggestion, with its reasoning and confidence recorded

Frequently Asked Questions

Most questions about controls come down to the work involved: how much of it there is, who does it, and whether the auditor can see the result without a week of preparation. The answers below cover the detail, from the control library you start with to where the evidence ends up.

What's the difference between an Assurance Task and an Assurance Checklist?

In de.iterate, an Assurance Task is a scheduled activity with an owner, a due date and evidence attached, such as a quarterly user access review. An Assurance Checklist is a repeatable set of steps or questions, such as a new starter checklist or a supplier questionnaire, that you can send to others to complete.

Can our auditor see our controls testing?

Yes. Your auditor can log in to the de.iterate Auditor Portal to review controls and evidence, or you can export your artifacts for them to review offline.

What's the difference between control design and operating effectiveness?

Design effectiveness asks whether a control would manage the risk if it ran as intended. Operating effectiveness asks whether it actually ran that way over a period of time. Auditors look for evidence of both.

Do we have to build our control library from scratch?

No. de.iterate includes a ready-to-use control library that's already mapped across frameworks. Tailor it to your organisation and add your own controls where you need to.

How does de.iterate remind control owners about testing?

In de.iterate, each Assurance Task has an owner and a due date. Scheduling rules set how often it recurs, and de.iterate sends reminders so nothing is left to the fortnight before the audit.

Can AI help with controls testing?

Yes. de.iterate's AI-powered assurance analyses the documents you upload, identifies gaps and suggests tasks and control mappings. Every suggestion arrives as a draft for a person to approve.

Where is our evidence stored?

In de.iterate's Evidence Store, linked to the task, control or requirement it supports, so you and your auditor can find it straight away.

What makes de.iterate different

From setup to scale, every feature is designed to help your team save time, stay focused, and drive meaningful results.

Expert support, not just software

de.iterate combines technology with hands-on support from experienced GRC professionals based in Australia. From onboarding through to certification, our team works with you to build momentum quickly, helping many organisations get audit-ready in less than 12 weeks and providing practical support through external audits and ongoing compliance activities.

Continuous compliance, not annual panic

Great compliance is not built in the two weeks before an audit. de.iterate helps you stay ready year-round with assurance tasks, checklists, live registers, reporting and a compliance calendar that keeps momentum going.

Practical enough to use, powerful enough to scale

From start-ups to enterprise, de.iterate supports multiple frameworks in one system, including ISO 27001, ISO 27701, ISO 9001, ISO 14001, ISO 45001, Privacy Acts, SOC 2, DIP, Essential Eight and more. You can grow your compliance maturity without rebuilding everything from scratch.

Key Features

A smarter way to manage compliance

de.iterate combines policies, training, registers, evidence, reporting and assurance workflows in one integrated management system, helping you reduce complexity, stay audit-ready and turn governance, risk management and compliance into business as usual. Every feature is designed to save time, strengthen accountability and make GRC compliance easier to manage across your organisation.
compliance-management

Enterprise Risk Management

 A risk register with a pulse, with inherent and residual scoring, heatmaps and risk appetite. 

board-reporting

Compliance Management

 Every obligation traced to the evidence that meets it, across 25+ frameworks.

policy-management

Policy Management

 Plain-English policies, clear approvals and proof your staff have read them. 

audit-management

Audit Management

 Audit programs, findings and corrective actions tracked to closure. 

it-cyber-security-consultants

Cyber and IT Risk

 Your whole ISMS, from asset register to Statement of Applicability. 

AI-gov

AI Governance

 ISO 42001, AI impact assessments and an inventory of the AI in your business. 

data-privacy

Privacy and Data Governance

 Find your personal information, see where it goes and keep your privacy policy current.

quality-safety-enviro

Quality, Safety & Environment

 ISO 9001, ISO 14001 and ISO 45001, running alongside everything else you manage. 

risk-drift

Third Party Risk Management

 Keep tabs on the suppliers holding a slice of your risk. 

Multiple compliance frameworks, without extra effort

 

With de.iterate, the complexity of managing multiple frameworks doesn’t translate into increased workload. Our unified platform serves as a central hub for overseeing all your compliance activities, whether you’re working with bespoke frameworks or seeking to meet the criteria of the most sought-after security and privacy standards and certifications.

ISO 27001

Information Security Management Systems

The international standard that sets out the requirements for data protection systems. It’s all about keeping data safe and secure.
ISO 9001

Quality Management Systems

This standard defines the requirements for quality management. It’s all about ensuring your business consistently delivers high-quality products and services.
ISO 45001

Occupational Health and Safety Management Systems

The standard that specifies the requirements for an effective OH&S management system. Create a safer, healthier workplace.
ISO 14001

Environmental Management Systems

The global standard for building EMS. It gives you a structure to identify environmental impacts, manage obligations, strengthen governance.

ISO 42001

Artificial Intelligence Management Systems

This standard specifies the requirements for managing AI systems responsibly and ethically. It helps ensure trustworthy development and use of AI.

SOC 2

System and Organisation Control 2

This specifies how organisations should manage their customer’s data. It is one of the most sought-after security framework for SaaS companies. 

Privacy Acts

Australia, New Zealand, Canada, France, Italy, US and UK

Country-specific legislative frameworks established to protect individuals’ personal information from misuse, interference, unauthorised access, modification, and disclosure.

RRFR

Right Fit for Risk

The Australian Government’s Department of Employment and Workplace Relations uses the External Systems Accreditation Framework and the RFFR approach to assess and accredit third party service providers and systems.

DISP

Defence Industry Security Program

DISP is a critical initiative that ensures businesses in the defence supply chain meet stringent security requirements. DISP compliance is essential for companies that engage in Defence tenders, contracts and projects.

Simple monthly pricing, based on the frameworks you need

de.iterate pricing is structured around the compliance frameworks you choose to access, giving you the flexibility to build a program that fits your organisation’s needs. Every plan includes access to the de.iterate platform and its feature set, from automated and expert-led onboarding, through to migration support, assurance workflows, live registers, compliance reporting and the core documentation needed to run and maintain your management system with confidence.

AUD
GBP
Starter (per month)

$179£100

  • Essential Eight

  • SMB 1001

  • Privacy Acts

  • DISP

  • Cyber Essentials

Business (per month)

$2,100£1,250

  • ISO 27001

  • ISO 27701

  • ISO 42001

  • ISO 9001

  • ISO 45001

  • ISO 14001

  • SOC 2

  • NIST CSF 2.0

  • NIST 800-53

  • NIST 800-172

  • NIST 800-172

  • GDPR

  • Essential Eight

  • SMB 1001

  • Privacy Acts

  • DISP

  • Cyber Essentials

  • DORA

  • NIS2

  • CIS v8

  • EU AI Act

  • TISAX

Enterprise (per month)

$3,500£2,000

  • ISO 27001

  • ISO 27701

  • ISO 42001

  • ISO 9001

  • ISO 45001

  • ISO 14001

  • SOC 2

  • NIST CSF 2.0

  • NIST 800-53

  • NIST 800-171

  • NIST 800-172

  • GDPR

  • Essential Eight

  • SMB 1001

  • Privacy Acts

  • DISP

  • ISM

  • SOCI

  • Right Fit for Risk (RFFR)

  • Cyber Essentials

  • DORA

  • NIS2

  • CIS c8

  • EU AI Act

  • TISAX

Collect the evidence in March. Relax in September.

See how scheduled controls testing works in a live demo.