Global ISO 27001 platforms are built for the company pursuing certification. GRCfy Maestro is built for the internal auditor, lead auditor, or audit firm running the ISMS assessment — SCF-mapped control library, multi-client engagement management, and AI-assisted evidence review.
Readiness platforms help a company get certified. GRCfy Maestro is what the auditor — internal, lead, or third-party — uses to actually assess whether the ISMS holds up, across as many client engagements as your firm runs in parallel.
| Capability | ISO 27001 Readiness Tools | GRCfy Maestro (Auditor Platform) |
|---|---|---|
| Who it's built for | The company seeking certification | The auditor / audit firm conducting the assessment |
| Multi-client engagement management | Single organisation | Unlimited clients, isolated per-tenant DB |
| Findings & risk register | Policy/evidence tracker | 234+ finding templates, severity & remediation tracking |
| Cross-framework control mapping | ISO 27001 only | ISO 27001 + SOC 2 + DPDP + ESG, cross-mapped |
| Client-branded reporting | — | Firm-branded executive summaries & certificates |
Mapped to ISO/IEC 27001:2022 via the Secure Controls Framework and organised by domain rather than the four Annex A themes — with room to bring your own domain-specific controls for regulated sectors.
14 controls — screening, onboarding/offboarding, awareness, and disciplinary process.
11 controls — policies, roles, continuous improvement, and business continuity oversight.
7 controls — risk assessment, treatment, and ongoing review.
6 controls — legal, regulatory, and contractual obligation tracking.
4 controls — inventory, classification, and acceptable use.
3 controls — monitoring, logging, and operational security procedures.
Plus 8 more sections — External Agreements & Published Policies, Security Awareness & Training, Cloud Security, Secure Engineering & Architecture, Third-Party Management, Project & Resource Management, Threat Management, and Change Management.
Adjacent ISO and security frameworks also on board:
Need a framework we don't have pre-built? Bring your own control library — Excel, CSV, or built from scratch, alongside the 21 frameworks already on board.
No — it's the software platform auditors and audit firms use to run internal audits and certification-support engagements. Certification itself is issued by an accredited certification body.
Those are sold to the company pursuing certification, to help them prepare and monitor controls. GRCfy Maestro is sold to the auditor conducting the independent assessment on that company.
Yes — overlapping controls cross-map to SOC 2 Trust Services Criteria and DPDP technical safeguards, so evidence collected once satisfies multiple frameworks in the same engagement.
60 controls across 14 domain sections, mapped to ISO/IEC 27001:2022 via the Secure Controls Framework and organized by control domain rather than the four Annex A themes.
No credit card required · Setup in under 24 hours
We use essential infrastructure (Cloudflare for TLS and DDoS protection — no opt-out, no data retained by us) and optionally Google Fonts, which loads typeface files from Google's servers and sends your IP address to Google. We use no analytics, tracking pixels, or advertising cookies.