All Features
Dashboard
The dashboard is the landing page after signing in. It shows a summary of active audits and key compliance metrics across all workspaces you have access to, giving teams a quick view of overall posture without navigating into individual audits.
Audits
An audit is Governy’s core unit of work - a structured assessment of an organization against a specific compliance framework. Each audit has a dedicated sidebar and the following workspace sections:
| Section | Purpose |
|---|---|
| Overview | Audit metadata, assigned users, and overall progress metrics |
| Assessment | Requirement-by-requirement compliance scoring with filtering by status |
| SoA (ISO 27001) | Statement of Applicability spreadsheet for all 93 Annex A controls |
| Evidences | File and document attachments linked to specific requirements |
| Planning | Remediation milestones, deadlines, and scheduling |
| Tasks | Action items assigned to team members with status tracking |
| Documentation | Audit-level policy documents and reference materials |
| Risk assessment | EBIOS-RM risk register, impact diagram and treatment queue — new in 1.3 |
| Report | Generate a structured compliance report |
| Users | Manage which users have access to this audit |
| Approval Center | Review and approve pending requirements scoped to this audit |
| Settings | Audit configuration, including the link between the risk study and the self-assessment |
Assessment statuses
- Not Assessed - default state, not yet reviewed
- Compliant - control is fully implemented
- Partially Compliant - control is partially implemented
- Non Compliant - control is not implemented
- N/A - not applicable to this organization
Evidence management
Any requirement can have evidence attached directly to it - uploaded files, documents from the library, or external links (a web URL, an intranet path, or a file-share location). Evidence is tracked per requirement with full version history, and is visible in the Evidences tab for a cross-audit overview.
The same document can be linked to several requirements at once - upload or register it once and reference it everywhere it applies, with a single shared version history rather than duplicate copies to keep in step.
Statement of Applicability (SoA)
Exclusive to ISO 27001 audits. The SoA tab presents all 93 Annex A controls in a spreadsheet view. Auditors declare each control as Applicable or Not Applicable and provide a written justification. Export is blocked until every control has a decision. The 11 controls new in the 2022 revision are labeled New 2022.
Risk Analysis
New in 1.3
Every audit includes a Risk assessment section built on the EBIOS-RM method (ANSSI). The register is scoped to the workspace and shared by all of its audits.
Register objects
| Object | Purpose | Rated on |
|---|---|---|
| Asset | What is being protected | — |
| Feared event | What could happen to an asset | Severity G1–G4 |
| Risk source | Who or what could cause it | — |
| Risk scenario | How a source leads to a feared event | Likelihood V1–V4 |
| Requirement link | Which audit requirements treat a scenario; optional contribution (0–100 %) | — |
The risk level (Low, Moderate, High, Critical) is read from the EBIOS-RM 4×4 severity × likelihood matrix. High and Critical scenarios are priority risks.
Views
- Guided setup — step-by-step wizard through Workshop 1 (scope & feared events), Workshops 2–4 (scenarios) and Workshop 5 (treatment); progress is saved as you go.
- Overview — priority risks treated, risk matrix (click a cell to filter), distribution by level, risk exposure verdict, coupling status and score explainer.
- Register — list or table of scenarios with search, level and treatment filters, and a detail panel for editing and linking requirements.
- Impact — flow diagram requirements → scenarios → feared events → assets, with chain tracing, load-bearing controls and an inherent/residual toggle.
- Treatment — queue of scenarios without linked requirements, ordered by inherent risk.
Link with the self-assessment
Configured in the audit Settings; both directions are off by default and apply to every audit of the workspace.
| Direction | Effect when enabled |
|---|---|
| Let risk weight the compliance rate | Each requirement is weighted by the worst risk it treats (linear curve) or by 2 above the priority threshold (priority only curve). Produces a risk-weighted compliance rate, shown separately — the framework’s official score is never weighted. |
| Let assessment results lower risk | Scenarios with linked requirements show a residual level beside the inherent one. Likelihood drops one level when the linked requirements’ average effectiveness reaches 50 %, and never more than one level. Severity is unchanged. |
All derived values — risk levels, residual levels, weights — are computed live and never stored. See Risk Analysis for the full description.
Framework Library
The Frameworks page lists all compliance frameworks available in the platform. Each framework contains a structured requirement tree organized by groups or chapters.
Built-in frameworks:
- ISO 27001:2022 - Two journeys: ISMS Clauses 4-10 and the Statement of Applicability for all 93 Annex A controls.
- GDPR - Single assessment journey covering all General Data Protection Regulation requirements.
- DORA - Single assessment journey for the Digital Operational Resilience Act.
- NIS2 - Single assessment journey for the Network and Information Security Directive 2.
- CyFun - Belgian Centre for Cybersecurity framework, with maturity scoring.
Custom frameworks can be added to the platform with fully configurable journeys and navigation - see Extensibility.
Measures
Measures are reference security controls that can be linked to audit requirements to document how a control is being addressed. They serve as a knowledge base of security practices mapped to framework requirements.
Suggested Measures
The Suggested Measures page surfaces actionable remediation recommendations derived from non-compliant requirements across your audits. Each suggestion is rated by:
- Compliance impact - how much addressing this measure improves overall compliance
- Implementation effort - estimated difficulty of putting the measure in place
Filters let teams focus on specific frameworks or effort levels, making it easy to prioritize quick wins.
Approval Workflows
A requirement is added to the approval queue automatically once it has a self-assessment score and supporting evidence - there is no manual submission step. Approvers can approve or reject the requirement with a comment.
The global Approval Center (accessible from the main sidebar) consolidates all pending requirements across every audit in the platform. Audit-level approval centers scope this view to a single audit.
Administration
User Management
Administrators can create, edit, activate, deactivate, or delete user accounts. New users can be invited via email with a verification step before the account becomes active.
Role-Based Access Control
Permissions are enforced through a role assignment system. Roles can be scoped globally or per-workspace, and users can be organized into groups for bulk permission management.
Workspace Management
Workspaces group related audits together (e.g., all audits for a specific entity or year). Each workspace has its own assigned users, available frameworks, and access settings, managed from the admin panel.
Storage connections
Document storage is configurable from an admin-only Storage settings screen. Each connection points at either an SFTP file server (or a NAS over SFTP) or an S3-compatible object store - AWS S3 or, more typically, an in-company system such as MinIO, Ceph, NetApp StorageGRID or Dell ECS. One connection is the deployment-wide default, and any workspace or audit can override it so its documents are kept in a different location.
- Data residency - by default the platform only accepts storage endpoints that resolve inside your own network; a connection that would store data outside it is rejected unless explicitly allowlisted, and is flagged with an External badge. The policy is
internal_only(default),allowlist, orany. - Encryption at rest - documents can be encrypted by the platform before they reach storage, so the storage host only ever holds ciphertext. Connection credentials are themselves sealed in an encrypted vault.
- Versioning - SFTP/NAS use application-managed version history; an S3 bucket with native object versioning can instead let the store own history (
application/native/auto). - Test - every connection can be validated before it is saved.
See the Security page for the reasoning behind these controls.
Profile & Settings
Every user can update their profile (name, email), change their password with one-time email code verification, and switch the interface language between English and French. Language preference is saved per account.