Readiness assessments

Know exactly how audit-ready you are.

A maturity score per control against ISO/IEC 42001, SOC 2, GDPR or India's DPDP Act — measured where a machine can measure, attested where it cannot — with a clause-level gap report and a costed plan your board can act on.

India DPDP · GDPR · ISO 27001 · ISO 42001 · SOC 2 · HIPAA · DORA · EU AI Act · NIST AI RMF

0
Mapped controls
0
Packs across 6 jurisdictions
0
Regulations kept current
0%
On-prem data custody

Before an auditor tells you where you stand, GOVERNTIQ already has — scored, evidenced, and costed to close.

Readiness evidence and a remediation plan — not a certification. Certificates are issued by independent accredited auditors. We get you to their door prepared, and keep you there.

The readiness assessment

From “we think we’re compliant” to a number you can defend

A maturity score from 1 to 5 per control, rolled up by objective — measured directly wherever a machine can read the evidence, attested where only documents and judgement can. A control not yet measured is marked not evaluated, never failed; one the evidence contradicts is scored down.

1

Inventory

Register the systems in scope — or let the scanner discover them from an API spec and register them for you.

2

Connect

Give the scanner read-only access to where the data lives: APIs, databases, log platforms, consent stores, file shares. One command per source.

3

Measure

The scanner reads in place and scores every control a machine can verify: what is stored, how old it is, who can read it, what the logs keep, what the consents say.

4

Reconcile

Answers and measurements meet per sub-claim. Telemetry settles what a mechanism did; design, accountability and effectiveness stay with documents and judgement. Claims without corroboration are named.

5

Plan

A maturity score, a clause-level gap report, a critical path and an effort estimate — then a programme that closes the gaps in dated phases.

The unverified claim

What happens when you say a control is in place — and your systems disagree?

A consultant writes down your answer. GOVERNTIQ checks it. If you attest that human oversight is operating and measured evidence on a given system says otherwise, that control is scored down and named by system — months before an auditor would have found it in fieldwork. A system not yet scanned is not failed: the claim stands, labelled unverified. And because oversight is four claims, not one — the mechanism ran, it fits the risk, the right people operate it, the intervention means something — telemetry only ever speaks to the first. The other three are scored separately, from documents and judgement. No questionnaire can do this.

Reconciliation
Attested 4 · measured 3verified
Attested 4 · measured 2scored down
Attested 4 · not evaluatedunverified claim
Not claimed · measured 4understated

Maturity score

1–5 per control, rolled up by objective, with a Statement of Applicability and justified exclusions.

Gap report

Every gap traced to its clause — ISO A.9.2, DPDP Sec. 8(6), SOC 2 CC7 — not generic advice.

Costed plan

Person-days by role, a critical path, and a calendar estimate: “audit-ready in ~22 weeks at 1.5 FTE.”

Where the evidence comes from

It reads the systems that actually hold personal data

Most personal data is not behind a tidy endpoint. It sits in databases, log platforms, consent managers and file shares. GOVERNTIQ connects to each with a read-only credential you issue, reads in place, and brings back kinds and counts — never the content.

APIs

The applications that serve personal data: whether the notice, consent and rights paths behave as declared, and what the records they return actually contain.

Leaves your network: Field names, categories, counts

Databases

Which tables hold personal data and roughly how many records; records kept past their retention period; whether the store is encrypted, who can read it, and whether access is logged.

Leaves your network: Column names, kinds, counts, masks — never a row

Log platforms

How long logs are kept against the period the rules require, whether they can be altered, who can read them, and whether personal data is leaking into them.

Leaves your network: Retention days, flags, kinds and counts — never a message

Consent stores

Whether each consent is specific, timestamped and tied to a notice; whether withdrawals apply; whether consents for minors carry verified parental consent.

Leaves your network: Ratios and counts — never an identifier

File shares & buckets

Exposure, encryption and logging of the store; stale exports and backups; files named like identity or payroll documents; personal data in a bounded sample.

Leaves your network: Counts, ages, flags — never a file
One command per source

Name the source and the framework pack; the scanner reads, scores and reports, and keeps doing so on the schedule you set. The common databases, log platforms, consent managers and storage services are supported — ask us for the current list. Anything a credential cannot see is reported as not evaluated — never guessed, never failed.

What leaves your network, per source →
The programme

From first scan to a signed attestation, in dated phases

Every framework pack ships as a sequenced programme. A phase cannot close until its evidence exists — a completed scan on every system, an adequate document on every required control, a frozen assessment — and the page says exactly what is missing and who it is waiting on.

Discover
1 wk · product-paced
Assess
1 wk · product-paced
Design
2 wks · client-paced
Implement
1.5 wks · client-paced
Review
0.5 wk · product-paced
Week 0DPDP: six weeks · Week 6
PHASE 1

Discover

Systems registered, sources connected, baseline scan, vendor register

PHASE 2

Assess

Questionnaire, evidence, Statement of Applicability, gap report, roadmap

PHASE 3

Design

Governance, policy & SOP pack, notice and consent templates — each reviewed

PHASE 4

Implement

Runbooks executed, training recorded, re-scan proves the change

PHASE 5

Review

Final recompute, frozen assessment, attestation, handover

Half the consulting calendar

Inventory, gap assessment, register, roadmap and report are the platform's work — hours, not weeks. Design and Implement are your team's weeks; the programme shows when it is waiting on them.

Framework time is a gate, not a plan

SOC 2 Type 2's 90-day observation and ISO's internal audit before certification cannot be shortened by tooling, so they are enforced as gates — never a number an agency can trim.

An attestation, not a certificate

The letter is issued in your assessor's name and discloses what was not evaluated, every exclusion and every waiver. Certificates come from accredited bodies; this gets you to their door with the evidence in hand.

Regulatory intelligence, scoped to where you operate

Tell GOVERNTIQ the jurisdictions you serve and the sector you are in, and it recommends the packs that apply. Each pack scans only what its rulebook needs and scores readiness against exactly its controls, on the scale that regulator uses. Every citation is checked against the official text and dated, so nothing you are measured against is out of date.

Global

Standards and frameworks any organisation can adopt

ISO/IEC 42001 + 42005

39 controls

The AI management system standard, Annex A in full, with the 2025 impact-assessment guidance.

ISO/IEC 27001:2022

10 controls

The information-security baseline, as amended in 2024.

SOC 2

11 criteria

Trust Services Criteria with the 2022 points of focus, Type 1 and Type 2.

NIST AI RMF

4 functions

Govern, map, measure and manage, with the generative-AI profile.

European Union

Regulations for organisations serving people in the EU

EU AI Act

16 controls

Provider and deployer duties on the 2026 timeline, including transparency and incident reporting.

GDPR

10 controls

Lawful processing through to breach notification and automated decisions.

DORA

8 controls

ICT resilience, incident reporting and third-party risk for financial entities.

India

The Digital Personal Data Protection Act and its 2025 Rules

India DPDP Act 2023 + Rules 2025

21 controls

Readiness against the Act and the notified Rules on their phased commencement, including Significant Data Fiduciary duties.

India BFSI bundle

60 controls

DPDP together with a certifiable AI management system, for banks and NBFCs.

Saudi Arabia

For private organisations in the Kingdom

Saudi PDPL

22 controls

The amended Law with its Implementing and Transfer Regulations: notice, security, the 72-hour SDAIA clock, transfers outside the Kingdom.

SAMA Cyber Security Framework

20 controls

For SAMA-regulated banks, insurers and finance companies, read on SAMA's own 0-5 maturity scale.

SDAIA AI Ethics Principles

12 controls

The seven principles and their governance for any developer or deployer of AI.

United Arab Emirates

Federal, DIFC and ADGM regimes, plus the financial regulators' AI expectations

UAE Federal PDPL

20 controls

Decree-Law 45/2021 for mainland and non-financial free-zone organisations.

DIFC Data Protection Law

18 controls

Law No. 5 of 2020 as amended in 2025, with Regulation 10 on autonomous systems.

ADGM Data Protection Regulations

16 controls

The 2021 Regulations as amended in 2024 and 2025.

Financial-sector AI guidance

12 controls

The regulators' joint enabling-technologies guidelines and the central bank's responsible-AI expectations.

UAE AI Charter

10 controls

The twelve principles of the 2024 Charter for any developer or deployer of AI.

United States

Sector rules for organisations handling US data

HIPAA Security Rule

10 controls

Safeguards for electronic health information and its handlers, on the rule in force.

Enterprise Governance Packs combine several rulebooks in one programme: India BFSI, EU high-risk AI, SaaS trust, Saudi financial and enterprise, and UAE mainland, DIFC and ADGM financial. SOC 2 ships as both Type 1 and Type 2.

Why GOVERNTIQ

1

Verified, not self-reported

A questionnaire records what you say. GOVERNTIQ reconciles it against what your systems show, control by control, and names the claims nothing corroborates.

2

Evidence from where data lives

APIs, databases, log platforms, consent stores, file shares and buckets — the places personal data actually sits — read directly, read-only, inside your network.

3

Sovereign by design

Measurement runs inside your perimeter. Documents are fingerprinted in your browser and never uploaded. Only findings flow upstream.

4

Costed, not just scored

A sequenced remediation plan with a critical path and an effort estimate in person-days — a number your board can act on, not a colour on a heat map.

How it works

1

Scope it

We agree the frameworks and the systems in scope — the APIs, databases, log platforms, consent stores and shares where personal data actually lives.

2

Connect the scanner

Run one binary inside your perimeter and hand it read-only credentials, one command per source. No Python, no Docker, no inbound ports.

3

Get your score

Maturity per control, clause-level gaps, unverified claims and a costed plan — then a dated programme that closes them and ends in an attestation.

Built for banks, insurers & NBFCs

Engineered for the institutions regulators watch most

Your security team set the perimeter. GOVERNTIQ deploys inside it — under your firewall, your credentials, your control — and proves what it does without ever touching your raw data.

✓

Your data stays put

GOVERNTIQ reads in place. Rows, log messages, file contents, prompts and credentials never leave — only kinds, counts, masked samples and scores do.

✓

Read-only, per source

A read-only database role, a log-platform token, a SAS token, a consent-API credential: each issued by you, scoped to one source, revocable at any time. The scanner never writes.

✓

Outbound-only, no open ports

An HTTPS client that dials out to GOVERNTIQ — never a listener. It drops in behind your firewall with zero inbound rules and works air-gapped.

✓

Encrypted & tamper-evident

TLS in transit, mTLS available; every finding and every review sits on an append-only, hash-chained timeline, so evidence cannot be silently altered.

✓

Auditable before it sends

Dry-run prints the exact payload the scanner would transmit, so your security team can read it before reporting is switched on.

✓

Maps to your audits

Every finding cites the clause of the rulebook in scope — DPDP, GDPR, Saudi PDPL, the DIFC law, SOC 2, ISO 27001 — so the evidence lands where your auditor looks.

Outbound-only · Read-only by default · Redacted findings · Air-gap capable · Revocable keys · Dry-run auditable · TLS/mTLS · Tamper-evident evidence

For governance agencies

Run verified assessments for your whole client portfolio.

If assessments are your business, GOVERNTIQ is the measurement underneath them. Onboard each client, connect the scanner to their APIs, databases, logs, consent records and shares inside their perimeter, and hand over a maturity score their auditor can follow — with the claims already checked against what the systems show.

  • ✓One console, every client organisation you govern
  • ✓Client data stays in the client's network — the scanner reads it in place; you never hold it
  • ✓Licensed per framework pack and per client programme, with volume tiers — never per seat
  • ✓Attestations in your name, handover packs and board-ready reports
Your portfolio
Acme Bank
India DPDP
9 gaps
Al Noor Finance
Saudi PDPL · SAMA CSF
in progress
Northwind SaaS
SOC 2 Type 2
ready

Illustrative view of the agency console. Each organisation is isolated — one client's evidence is never visible to another.

What you actually walk away with

We’re a young company and we don’t have customer logos to show you yet. So here is the deliverable instead — judge it on its own terms, and ask us to run it on your systems.

✓

A maturity score you can defend

Weighted 1–5 across every applicable control, broken down by objective, with the evidence behind each level visible — attested, measured, or both.

✓

A Statement of Applicability

Every control in scope, with any exclusion recorded alongside a written justification — the artefact ISO/IEC 42001 Cl. 6.1.3 expects you to produce.

✓

Unverified-claim findings

The controls you believe are in place that your systems don’t corroborate, named by AI system, ranked by severity.

✓

A costed remediation plan

Person-days split by role, a dependency-ordered critical path, and a calendar estimate with a stated ±25% range.

✓

A readiness attestation in your assessor's name

Issued when the programme closes: scope, method, every control reviewed, what was not evaluated, every exclusion and waiver — and the hash of the frozen scores it describes. An attestation, not a certificate.

✓

A handover pack and a timeline

The letter, the frozen scores, the Statement of Applicability, the evidence register and an append-only timeline of who closed what, when, against which artefact.

Security & trust — your questions, answered

Straight answers for security, risk and compliance teams.

No. The scanner reads your APIs, databases, log platforms, consent stores and file shares in place, inside your network, and classifies what it finds there. Only findings travel: the kinds of personal data and how many, retention and access flags, scores and clause references, masked samples. Database rows, log messages, file contents, consent identifiers, prompts and credentials never leave. Evidence documents are fingerprinted in your browser; the file stays with you.

Need a deeper security review, a DPIA, or a pen-test summary? Get in touch.

Find out how audit-ready you really are.

A readiness programme runs about six weeks end to end — Discover to a signed attestation — against the rulebook you answer to, with the evidence measured in your databases, logs, consent records and shares rather than taken on trust.