Now in Norrsent: Copilot. It drafts. Your team decides.

Platform

A control library you build once and use everywhere

Build a reusable control library aligned to your policies, ISO standards, or regulatory obligations. Apply each control to the risks, mitigations, and obligations it actually governs, with test scheduling and evidence capture wired in.

SEE NORRSENT IN ACTION

How it works

01

Build the library

Create controls once, categorised by type, risk domain, and standard. The same control can apply to multiple risks and business units without anyone copy-pasting it.

02

Map to risks and obligations

Link controls to the risks, obligations, and mitigation plans they govern. The platform shows which risks have control coverage and which carry residual exposure you haven’t handled.

03

Test and evidence

Schedule testing, capture results, store the evidence. Reminders go out automatically so nothing falls off the calendar.

Key capabilities

One library, used in many places

Controls are versioned and linkable. The same control can govern five risks across three business units without you maintaining five copies of it.

From obligation to evidence in one click

An auditor asks how a regulatory obligation is being met. Norrsent traces obligation → policy → control → evidence in a single view, in seconds rather than days.

Effectiveness, not just existence

Set review cadence, effectiveness criteria, and test schedules per control. The platform reminds the owner before the test is due and captures the result the same way every time.

Evidence on the control, not in a folder

Documents, test outputs, sign-offs sit on the control record itself. Evidence is versioned, timestamped, and signed. Nothing lives in a shared drive someone has to find.

Where coverage is thin

Norrsent flags risks without adequate controls and obligations without coverage. Your team gets a prioritised remediation list before an inspection or incident exposes the gap.

An audit trail that matches the work

Every action on a control records who, when, and what. The trail can’t be altered after the fact. Regulators and internal auditors get the evidence they actually need.

Get started

See how Controls works in Norrsent

SEE NORRSENT IN ACTION