GRC software built for small & mid-sized businesses

Compliance software your small business can actually run.

Track ISO 27001, SOC 2, ISO 9001, GDPR, ISO 22301 and Sri Lanka’s PDPA without an enterprise GRC platform, a consultant or a compliance department. Adopt a standard, record your controls against real evidence, and produce audit-ready reports — starting this afternoon.

Start free for 3 months No credit card, no commitment. Set up in minutes.

Maturity

Calculated

from the evidence recorded against each control, never declared

Coverage

Tracked

so a score over half a standard never passes for a whole one

Outcomes

Split three ways

fully, partially and not complied — counted, not averaged away

Free, no account

Free compliance self-assessments

Answer a short questionnaire against a published standard and get an executive summary of where you stand — scored the same way the product would score it. Nothing to install, and no sign-up.

Why SMEs choose Govnex

Enterprise GRC platforms are not built for a fifty-person company

The established GRC suites assume a dedicated risk and compliance function, a rollout project and a budget to match. Most small and mid-sized businesses have none of those, and still have to answer the security questionnaire in front of them. This is the compliance tracking software for that situation.

Traditional enterprise GRC

  • Six-figure implementations and a consultant to configure them
  • Months of onboarding before the first control is tracked
  • Priced and scoped for a dedicated risk and compliance function
  • Modules for everything, most of which an SME will never open

Govnex

  • Sign up and start tracking the same afternoon
  • A guided quick start that has your first cycle open in minutes
  • Built for teams where compliance is one person’s part-time responsibility
  • One job done properly: obligations, evidence, cycles and reports

Everything an SME needs to prove compliance — and nothing it does not

Standards, frozen the day you adopt them

Track obligations against standards such as ISO 27001, SOC 2, GDPR or Sri Lanka’s PDPA with the wording captured at adoption. A revision never silently rewrites what you signed up to, so last year’s audit still means something.

Evidence-based scoring, not self-declaration

Every control is recorded against its evidence — verdict by verdict, with notes and document locations. Your compliance score is calculated from what is actually there, never typed into a box.

Audit-ready reports in one click

An executive report for the board, a compliance report an auditor can follow, and an AI review written from your own recorded evidence. No consultant needed to assemble the pack.

Runs without a compliance team

Assign controls to the people who already do the work, track what is outstanding, and see where you stand. Designed for a business where compliance is somebody’s second job.

Standards and regulations you can track today

Adopt a published standard from the Compliance Library, or write your own controls for contractual and internal obligations and track them in the same cycle.

International

9 standards

ISO 22301

ISO 22301:2019 — Security and resilience — Business continuity management systems — Requirements

Standard · edition 2019

21 controls

ISO 27001

ISO/IEC 27001:2022 — Information security management systems

Standard · edition 2022

103 controls

ISO 37002

ISO 37002:2021 — Whistleblowing management systems — Guidelines

Standard · edition 2021

17 controls

ISO 42001

ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system

Standard · edition 2023

15 controls

ISO 9001

ISO 9001:2015 — Quality management systems — Requirements

Standard · edition 2015

28 controls

ITIL 4

ITIL 4 — Information Technology Infrastructure Library

Framework · edition 4

14 controls

OECD AI Principles

OECD Principles on Artificial Intelligence

Framework · edition 2024

5 controls

PMBOK 7th Ed (PMP)

A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Seventh Edition

Framework · edition 7th Edition

9 controls

SOC 2 (TSC 2017)

AICPA Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy

Standard · edition 2017

20 controls

Australia

5 standards

ASD Essential Eight

ASD Essential Eight Maturity Model

Framework · edition Current

8 controls

Privacy Act & APPs

Privacy Act 1988 (Cth) - Schedule 1: Australian Privacy Principles (APPs)

Legislation · edition Current Consolidated

13 controls

PSPF

Protective Security Policy Framework (PSPF)

Framework · edition Current

16 controls

SOCI Act

Security of Critical Infrastructure Act 2018 (Cth) (including CIRMP Rules)

Legislation · edition Current Consolidated

7 controls

WHS Act 2011

Work Health and Safety Act 2011 (Model WHS Act)

Legislation · edition Current Consolidated

11 controls

European Union

2 standards

EU AI Act

Regulation (EU) 2024/1689 — Artificial Intelligence Act (EU AI Act)

Regulation · edition 2024

15 controls

GDPR

Regulation (EU) 2016/679 — General Data Protection Regulation

Regulation · edition 2016

17 controls

Sri Lanka

2 standards

Sri Lanka ETA

Electronic Transactions Act, No. 19 of 2006 (Consolidated with Act No. 25 of 2017)[cite: 1]

Legislation · edition 2017 Consolidated

9 controls

Sri Lanka PDPA

Personal Data Protection Act, No. 9 of 2022 (Consolidated with Act No. 22 of 2025)

Legislation · edition 2025

18 controls

United States (Internationally adopted)

2 standards

NIST AI RMF 1.0

NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0)

Framework · edition 1.0

12 controls

NIST CSF 2.0

NIST Cybersecurity Framework (CSF) 2.0

Framework · edition 2.0

22 controls

How compliance tracking works here

01

Pick your standard

Choose from the Compliance Library — ISO 27001, SOC 2, ISO 9001, GDPR, ISO 22301, Sri Lanka PDPA — or write controls of your own. Adopting one copies its controls into your register in a single step.

02

Record with evidence

Open an assessment cycle and let your team answer control by control, attaching the documents that prove it. Maturity is computed from the evidence, not asserted.

03

Report and repeat

Close the cycle for a sealed result, hand over the reports, and open the next one. The gaps come out stated plainly enough to act on this quarter.

An AI compliance review, grounded in your own evidence

The executive review reads your recorded controls and evidence and writes the key risks, the strengths and the priorities for the next thirty days — the read-out a consultant would give you, from the same source data. It says on its face that it is AI-generated, so nobody mistakes a draft for a verdict.

Pricing

Plain pricing, priced for an SME

Per organization, in USD. Paying annually takes 10% off and includes free consultation hours.

First 3 months free — on every plan

Start without a credit card and without a commitment. Nothing is charged while you are inside the free period, and there is nothing to cancel if you decide it is not for you.

Start free

Individual

A single seat, just you.

$15/ month

or $162 a year — saving $18

  • 1 seat
  • 1 hour of free consultation with an annual purchase
Start 3 months free

Small business

A team, with structure.

$25/ month

or $270 a year — saving $30

  • 25 seats
  • 3 hours of free consultation with an annual purchase
Start 3 months free

Mid business

Many units, many hands.

$100/ month

or $1,080 a year — saving $120

  • 200 seats
  • 5 hours of free consultation with an annual purchase
Start 3 months free

Frequently asked questions

What is GRC software, and does a small business need it?
GRC stands for governance, risk and compliance. GRC software keeps track of the obligations your business has to meet — from a standard like ISO 27001 or a law like GDPR — along with the evidence that proves you meet them. A small business needs it as soon as somebody starts asking for proof: a customer’s security questionnaire, a regulator, an insurer, or a certification auditor. Below that point a spreadsheet holds; past it, a spreadsheet is where evidence goes to be lost.
How is this different from enterprise GRC platforms?
Enterprise GRC suites are built for organisations with a dedicated risk and compliance function, and they are priced and implemented accordingly — typically a consultant-led rollout measured in months. AI Pazz Govnex does one part of that job for smaller organisations: adopting standards, recording controls against evidence, running assessment cycles and producing reports. You set it up yourself, and you can be tracking your first standard the same day.
Which standards and regulations can I track?
The Compliance Library currently carries ASD Essential Eight, EU AI Act, GDPR, ISO 22301, ISO 27001, ISO 37002, ISO 42001, ISO 9001, ITIL 4, NIST AI RMF 1.0, NIST CSF 2.0, OECD AI Principles, PMBOK 7th Ed (PMP), Privacy Act & APPs, PSPF, SOC 2 (TSC 2017), SOCI Act, Sri Lanka ETA, Sri Lanka PDPA and WHS Act 2011. You can also write your own controls for contractual, internal or sector obligations, and track them in the same cycles alongside a published standard.
How long does it take to get started?
Minutes. Creating a workspace takes one step, and a guided quick start walks you through naming your organisation, adopting a standard and opening your first assessment cycle. There is no implementation project and no configuration consultant.
Is there a free trial?
Yes. Every new organisation starts with a three-month free period — no credit card, no commitment, and nothing to cancel if you stop. You can also take a free public self-assessment against a published standard without creating an account at all, and get an executive summary of where you stand.
How much does AI Pazz Govnex cost?
Individual is $15 a month for 1 seat; Small business is $25 a month for 25 seats; Mid business is $100 a month for 200 seats. Paying annually takes 10% off and includes free consultation hours. Every new organisation starts with a three-month free period — no credit card and no commitment.
How is our compliance data kept separate from other customers?
Each organisation’s data lives in its own partition, and every read asserts the organisation making the request — twice, in the data layer and again at the response boundary. A request for another organisation’s data does not fail politely; it finds nothing.

Start with one standard.

Adopt it, open a cycle, and see where your business actually stands. three months free, no credit card, no commitment, and the quick start has you tracking in minutes.

Create your free workspace