Modules

Compliance, risk, policy, audit and data protection in one workspace

AI Pazz Govnex is a set of GRC modules for small and mid-sized businesses. Use the ones you need; they share your organization, your people and your permissions, so a risk, an audit finding and the issue that fixes it are all in one place.

Modules

Switched on by plan, and shared by one organization, one set of people and one set of permissions — each person holds the role that fits them, module by module.

Every plan

Compliance management software

Compliance Tracker

Track recurring compliance obligations, assign owners and record the evidence, cycle by cycle.

  • Adopt controls from the Compliance Library — ISO 27001, SOC 2, GDPR, Sri Lanka PDPA and more — as your own editable copies
  • Cycles and assessments whose scope is fixed the moment they open
  • Coverage and maturity scoring, withheld below a coverage floor you set
More about Compliance Tracker
Small business and up

Policy management software

Policy Tracker

One place for your policies: publish them, keep every version, and see who has acknowledged the current one.

  • Publish a policy with its owner, effective date and tags
  • Everyone in the module is asked to acknowledge the current version, and asked again when it changes
More about Policy Tracker
Small business and up

Risk management software

Risk Tracking

Risk registers at every level of the organization: score risks, treat them, evidence their closure, and raise the ones the board should see.

  • As many registers as your organization needs, each run by its own administrator
  • Risks at organization, unit or individual level, each with an owner
  • Optional approval before a risk closes — by the register’s administrator or someone you name
More about Risk Tracking
Small business and up

Issue and remediation tracking software

Issue & Remediation

Log what is wrong — gaps, findings, incidents — assign it to whoever has to put it right, and see it closed with evidence and a second pair of eyes.

  • Anyone can open a register and run it: its own severities with target days, categories, custom attributes and visibility
  • A due date from the severity, moved only with a reason that is logged
  • A ladder per register: overdue by so many days, escalate to the administrator, the Module Admins or a named person — worked out live, never stale
More about Issue & Remediation
Small business and up

Regulatory change management software

Regulatory Change

The regulations, standards and frameworks that apply to you — who owns each, whether it is still applicable, and the work to comply with it tracked in its own issue register.

  • Add a regulation from the Compliance Library — its issuer, jurisdiction and editions come with it — or type in one the library does not carry
  • An owner, a status and a rationale for every entry, with the units and jurisdictions it applies to
  • Create an implementation register in Issue & Remediation from the regulation in one click, or link one you already run
More about Regulatory Change
Small business and up

Internal audit management software

Audit Management

Run internal audit programmes: the scopes audited in each, tests with their samples, findings answered by management, issued reports, and every finding handed over to Issue & Remediation for tracking.

  • The year's audits in one plan, approved by an audit lead — anything added afterwards is marked unplanned until the plan is approved again
  • A work programme generated from the controls you track for the standards in scope — with each control's latest recorded verdict and evidence beside the auditor's own conclusion, never written back
  • Findings written as condition, criteria, cause, effect and recommendation, rated on your own scale, with a link to the earlier finding they repeat
More about Audit Management
Small business and up

Data protection compliance software

Data Compliance Tracker

What you hold data about and what you do with it: entities and their records with a business owner and a data owner for each, and Records of Processing Activities with a compliance checklist answered item by item.

  • Entities — Customer, Employee, Supplier — each with a business owner and a data owner
  • A RoPA for each activity: its purpose, its owners, and the records it processes — what they hold read beside it
More about Data Compliance Tracker
Small business and up

Business process catalogue and organization modelling software

Organization

Model the organization: its units, who leads each, and the processes, services and capabilities each one runs — with an owner for every one.

  • Units of every kind — CEO office, division, business unit, department, team, function — nested in whatever order your organization really runs
  • What the organization does, placed under the unit that does it — capabilities holding the processes that deliver them, and the services it provides
  • The organization and every unit seen whole: who leads it, who is in it, what it runs
More about Organization

Consultancy services

Delivered by the AI Pazz team inside the product: asked for from the modules page once you have a workspace, and worked on where you already work.

Administration

Running the organization itself, on every plan.

See it with your own standards

Start free, no credit card. Compare what each plan includes on the pricing page.