Skip to content

All Features

Dashboard

The dashboard is the landing page after signing in. It shows a summary of active audits and key compliance metrics across all workspaces you have access to, giving teams a quick view of overall posture without navigating into individual audits.

Audits

An audit is Governy’s core unit of work - a structured assessment of an organization against a specific compliance framework. Each audit has a dedicated sidebar and the following workspace sections:

SectionPurpose
OverviewAudit metadata, assigned users, and overall progress metrics
AssessmentRequirement-by-requirement compliance scoring with filtering by status
SoA (ISO 27001)Statement of Applicability spreadsheet for all 93 Annex A controls
EvidencesFile and document attachments linked to specific requirements
PlanningRemediation milestones, deadlines, and scheduling
TasksAction items assigned to team members with status tracking
DocumentationAudit-level policy documents and reference materials
Risk assessmentEBIOS-RM risk register, impact diagram and treatment queue — new in 1.3
ReportGenerate a structured compliance report
UsersManage which users have access to this audit
Approval CenterReview and approve pending requirements scoped to this audit
SettingsAudit configuration, including the link between the risk study and the self-assessment

Assessment statuses

  • Not Assessed - default state, not yet reviewed
  • Compliant - control is fully implemented
  • Partially Compliant - control is partially implemented
  • Non Compliant - control is not implemented
  • N/A - not applicable to this organization

Evidence management

Any requirement can have evidence attached directly to it - uploaded files, documents from the library, or external links (a web URL, an intranet path, or a file-share location). Evidence is tracked per requirement with full version history, and is visible in the Evidences tab for a cross-audit overview.

The same document can be linked to several requirements at once - upload or register it once and reference it everywhere it applies, with a single shared version history rather than duplicate copies to keep in step.

Statement of Applicability (SoA)

Exclusive to ISO 27001 audits. The SoA tab presents all 93 Annex A controls in a spreadsheet view. Auditors declare each control as Applicable or Not Applicable and provide a written justification. Export is blocked until every control has a decision. The 11 controls new in the 2022 revision are labeled New 2022.

Risk Analysis

New in 1.3

Every audit includes a Risk assessment section built on the EBIOS-RM method (ANSSI). The register is scoped to the workspace and shared by all of its audits.

Register objects

ObjectPurposeRated on
AssetWhat is being protected—
Feared eventWhat could happen to an assetSeverity G1–G4
Risk sourceWho or what could cause it—
Risk scenarioHow a source leads to a feared eventLikelihood V1–V4
Requirement linkWhich audit requirements treat a scenario; optional contribution (0–100 %)—

The risk level (Low, Moderate, High, Critical) is read from the EBIOS-RM 4×4 severity × likelihood matrix. High and Critical scenarios are priority risks.

Views

  • Guided setup — step-by-step wizard through Workshop 1 (scope & feared events), Workshops 2–4 (scenarios) and Workshop 5 (treatment); progress is saved as you go.
  • Overview — priority risks treated, risk matrix (click a cell to filter), distribution by level, risk exposure verdict, coupling status and score explainer.
  • Register — list or table of scenarios with search, level and treatment filters, and a detail panel for editing and linking requirements.
  • Impact — flow diagram requirements → scenarios → feared events → assets, with chain tracing, load-bearing controls and an inherent/residual toggle.
  • Treatment — queue of scenarios without linked requirements, ordered by inherent risk.

Configured in the audit Settings; both directions are off by default and apply to every audit of the workspace.

DirectionEffect when enabled
Let risk weight the compliance rateEach requirement is weighted by the worst risk it treats (linear curve) or by 2 above the priority threshold (priority only curve). Produces a risk-weighted compliance rate, shown separately — the framework’s official score is never weighted.
Let assessment results lower riskScenarios with linked requirements show a residual level beside the inherent one. Likelihood drops one level when the linked requirements’ average effectiveness reaches 50 %, and never more than one level. Severity is unchanged.

All derived values — risk levels, residual levels, weights — are computed live and never stored. See Risk Analysis for the full description.

Framework Library

The Frameworks page lists all compliance frameworks available in the platform. Each framework contains a structured requirement tree organized by groups or chapters.

Built-in frameworks:

  • ISO 27001:2022 - Two journeys: ISMS Clauses 4-10 and the Statement of Applicability for all 93 Annex A controls.
  • GDPR - Single assessment journey covering all General Data Protection Regulation requirements.
  • DORA - Single assessment journey for the Digital Operational Resilience Act.
  • NIS2 - Single assessment journey for the Network and Information Security Directive 2.
  • CyFun - Belgian Centre for Cybersecurity framework, with maturity scoring.

Custom frameworks can be added to the platform with fully configurable journeys and navigation - see Extensibility.

Measures

Measures are reference security controls that can be linked to audit requirements to document how a control is being addressed. They serve as a knowledge base of security practices mapped to framework requirements.

Suggested Measures

The Suggested Measures page surfaces actionable remediation recommendations derived from non-compliant requirements across your audits. Each suggestion is rated by:

  • Compliance impact - how much addressing this measure improves overall compliance
  • Implementation effort - estimated difficulty of putting the measure in place

Filters let teams focus on specific frameworks or effort levels, making it easy to prioritize quick wins.

Approval Workflows

A requirement is added to the approval queue automatically once it has a self-assessment score and supporting evidence - there is no manual submission step. Approvers can approve or reject the requirement with a comment.

The global Approval Center (accessible from the main sidebar) consolidates all pending requirements across every audit in the platform. Audit-level approval centers scope this view to a single audit.

Administration

User Management

Administrators can create, edit, activate, deactivate, or delete user accounts. New users can be invited via email with a verification step before the account becomes active.

Role-Based Access Control

Permissions are enforced through a role assignment system. Roles can be scoped globally or per-workspace, and users can be organized into groups for bulk permission management.

Workspace Management

Workspaces group related audits together (e.g., all audits for a specific entity or year). Each workspace has its own assigned users, available frameworks, and access settings, managed from the admin panel.

Storage connections

Document storage is configurable from an admin-only Storage settings screen. Each connection points at either an SFTP file server (or a NAS over SFTP) or an S3-compatible object store - AWS S3 or, more typically, an in-company system such as MinIO, Ceph, NetApp StorageGRID or Dell ECS. One connection is the deployment-wide default, and any workspace or audit can override it so its documents are kept in a different location.

  • Data residency - by default the platform only accepts storage endpoints that resolve inside your own network; a connection that would store data outside it is rejected unless explicitly allowlisted, and is flagged with an External badge. The policy is internal_only (default), allowlist, or any.
  • Encryption at rest - documents can be encrypted by the platform before they reach storage, so the storage host only ever holds ciphertext. Connection credentials are themselves sealed in an encrypted vault.
  • Versioning - SFTP/NAS use application-managed version history; an S3 bucket with native object versioning can instead let the store own history (application / native / auto).
  • Test - every connection can be validated before it is saved.

See the Security page for the reasoning behind these controls.

Profile & Settings

Every user can update their profile (name, email), change their password with one-time email code verification, and switch the interface language between English and French. Language preference is saved per account.