Managed GRC for multi-standard, multi-site organisationsv1.4 live

We run your compliance programme.
You keep the decisions.

A named compliance manager carries the documents, the evidence, the internal audits and the risk register, on a schedule, against every standard, regulator and lender you answer to. When the auditor sits down, your team stops searching and starts showing.

Named
compliance manager, not a ticket queue
Your data
in a workspace you own and can export
Independent
we run your programme, we never certify it

We publish no outcome figure we cannot evidence. Reference calls are arranged once a client has agreed to take them.

example-co.compstack.io/readiness
live
Group readiness
87.4/ 100+3.2 wk
5 sites · 4 standards
Q2 audit · 17 days
QMS
ISO 9001:201594%
5 sites
EMS
ISO 14001:201588%
5 sites
OHS
ISO 45001:201882%
4 sites
DR-W
KEBS · KS 46076%
2 sites
Open findings
112 overdue · 3 awaiting verify
Evidence expiring · 30d
26acks · certs · calibrations
What we sell

A management system that is current on any ordinary day.

Most compliance vendors sell you a place to do the work. We do the work. The platform is where it lands, and where you check it whenever you want to.

What you hand over
  • Document reviews, revisions and approval routing
  • Evidence collected against every control cycle
  • The internal audit programme, planned and conducted
  • Findings followed up to verified closure
  • The risk register, maintained on its review dates
  • Preparation for every certification visit
What you keep
  • Every decision. Policy, scope, risk appetite, approvals
  • The certificate and the relationship with your certification body
  • Your data, in a workspace you own and can export in full
  • Your independence. We do not certify you and never will
  • Your people, doing the work they were hired to do
How we are judged

You are buying an outcome.

If the system is not current on the day someone asks, we have not delivered, whatever the software happens to show. That is the standard, and it is the one written into the engagement letter.

When the auditor arrives

They ask for the calibration cert for MD-04.

Same question, two operating models. Below is the audit moment compliance teams know by heart, and what changes when the records are linked.

Beforespreadsheet ops

Three drives, two days, one apology.

  1. 1QA Lead opens the shared drive. The calibration certs folder has 41 PDFs. None of them are named MD-04.
  2. 2She emails the previous maintenance manager, who left in November. No response by lunch.
  3. 3The auditor asks for the linked CAPA. There is one, somewhere. Last accessed in a Word doc by someone who is on leave.
  4. 4Two days later, the cert is found in a sub-folder named "old_finals_v2_USE". The audit team writes an OFI for retrieval delays.
2 days, 4 peopleverdict: OFI
With CompStacklinked records

Search, open, move on.

MD-043 results
  • Calibration cert MD-04 v3
    evidence · valid until Apr 17, 2027
  • QMS-PROC-008 §4.2
    document · monthly calibration program
  • CAPA-2026-0098 (closed)
    finding · MD-04 drift, last cycle

Three linked records on screen in under five seconds. The auditor sees the cert, the policy that owns the cadence, and the CAPA that proved the program works. Audit pack exports as one PDF.

under 1 minute, 1 personverdict: conform
How the work changes

The same work, carried differently.

Nothing in the middle column is a criticism. It is what a competent team does when compliance is the seventh thing on a list of six.

Document review

Someone remembers, or nobody does. Versions drift across drives and inboxes.

Review dates are tracked. We prepare the revision and route it for approval.

Evidence

Gathered in a rush before the auditor arrives, from whoever still has the file.

Filed as the work happens, against the control it proves.

Internal audit

Squeezed in when the calendar allows, often late in the cycle.

Programmed a year ahead and run to that plan.

A finding

Noted, assigned informally, revisited next cycle in much the same words.

Owner, due date, root cause, verification, closed and evidenced.

Risk review

A spreadsheet refreshed before the board paper, rated once and rarely revisited.

Each risk carries a cause, a consequence, the control that reduces it and a review date.

Board reporting

Assembled by hand before each meeting from whatever can be found in time.

A standing monthly report, drawn from the same records the auditor will open.

A certification visit

Six weeks of preparation, most of it reconstruction.

An ordinary week. The pack already exists.

The difference is cadence. The right column is not harder work. It is the same work done on a schedule somebody owns, which is exactly the thing a busy organisation cannot reliably supply.

Standards covered

Quality, safety, security, environmental, food, pharma, privacy, regional. New standards ship as installable modules, cross-mapped at the requirement level.

Browse module store
ISOISO 9001Quality management
ISOISO 14001Environment
ISOISO 45001Occupational H&S
ISOISO 27001Information security
ISOISO 22000Food safety
ISOISO 22301Business continuity
ISOISO 13485Medical devices
KEBSKEBS · KS 460Drinking water
KEBSKEBS · KS 2466Bottled water
SONSON · SONCAPConformity assessment
UNBSUNBSUganda standards
EUGDPREU data protection
SAISA8000Social accountability
FSSCFSSC 22000Food safety scheme
ISOISO 9001Quality management
ISOISO 14001Environment
ISOISO 45001Occupational H&S
ISOISO 27001Information security
ISOISO 22000Food safety
ISOISO 22301Business continuity
ISOISO 13485Medical devices
KEBSKEBS · KS 460Drinking water
KEBSKEBS · KS 2466Bottled water
SONSON · SONCAPConformity assessment
UNBSUNBSUganda standards
EUGDPREU data protection
SAISA8000Social accountability
FSSCFSSC 22000Food safety scheme
What we carry every month

Eight workflows,
and we run all of them.

Eight workflows. They feed each other. Nothing crosses a spreadsheet boundary on the way to the audit folder.

01 · Scoping

Decide what applies. Defend why.

9001 · 7.5.3Control of documented information
Applicable
9001 · 8.3Design and development
Not applicable
9001 · 8.5.5Post-delivery activities
Applicable
14001 · 6.1.2Significant aspects identification
Applicable
45001 · 8.1.4Procurement (contractor mgmt)
Deferred
02 · Document control

Policies that don't fall out of date.

QMS-POL-014 · Supplier evaluation policy
v3.2 · awaiting QM approval · author cannot self-approve
Draft
Review
Approve
Publish
Obsolete
3 ack pendingretain · 7 yrs
03 · Controls

Map what you do to what's required.

CTRL-027 · Calibration programPreventive
owner · QA Lead · monthly · evidence: cert.pdf
linked to
requirement
9001 · 7.1.5
document
QMS-PROC-008
04 · Evidence

Files that show up when the auditor asks.

artifact
type
valid
Mombasa cert · ISO 22000
PDF · 2.4 MB
Mar 12, 2027
Op-09 batch records · 2026-Q1
ZIP · 18.7 MB
·
Calibration cert · MD-04
PDF · 0.8 MB
in 23 days
Forklift operator · J. Otieno
PNG · 0.4 MB
expired
05 · Audits

Run the audit. Get a real report at the end.

AUDIT-2026-Q2-INT
Q2 internal · Mombasa
Standards9001, 14001, 22000
Sites2
Lead auditorQuality Manager
StatusIn progress
clause
checklist item
verdict
7.5.3
Document control records present
Conform
8.5.1
Production change-control evidence
Obs
9.1.3
Trend analysis on customer complaints
NC
10.2
CAPA closure rate vs target (≥ 90%)
OFI
06 · Findings & CAPA

Close the loop with a different person.

Open
5
Action in progress
3
Verifying
2
Closed · 30d
14
verifier ≠ owner · enforced
07 · Risk

Linked to controls. Linked to action.

Risk RGT-094 · Calibration drift · L4 × I3 = 12
likelihood →impact ↑
treatment: mitigate · linked CAPA-0118
08 · Management review

Decisions, on the record.

meeting
Apr 24
attendees
9 · quorum met
inputs
audits · risks · CAPA
  • 10:14Approve scope reduction · KEBS KS 2466Exec
  • 10:21Allocate budget · 4 calibration unitsQM
  • 10:33Defer SA8000 onboarding to Q4Board
  • 10:48Open CAPA on supplier audit overdueQA
immutable record · PDF + CSV exports for audit
What we cover

Every standard you answer to, already loaded.

When ISO 9001 ships its next amendment, your consultant won't email you a 60-page PDF and a Word table of what changed. You get a version diff. You review it. You upgrade.

license model
Per-org · trial · expiry
upgrade safety
Diff · preview · rollback
Browse the module store
iso-9001-2015@2.4.0 → 2.5.0
42 changes
Added
+11
  • 8.2.4 · Customer property · visit logs
  • 9.1.3 · Trend analysis on complaints
  • 10.3 · Continual improvement evidence
Changed
+26
  • 7.5.3 · Now requires retention metadata
  • 8.5.1 · Tightens production change control
  • 9.2 · Internal audit competence rules
3 publishers contributedReviewed · signed · staged
ISO official
ISO 14001:2015
Environmental management
v1.7.2signed · sha256
KEBS
KS 460 · Drinking water
Sampling and lab cross-mapped
v0.9.1signed · sha256
Sector official
Pharma cleanroom pack
EU Annex 1 + GMP templates
v3.1.0signed · sha256
Tools
Internal audit program
Annual plan · 4 audit kits
v2.0.0signed · sha256
Copilot · grounded answer

Calibration cadence for metal detectors on Line 3 is monthly, per QMS-PROC-008 §4.2 and the FSSC 22000 prerequisite program. Next due: Apr 18.

QMS-PROC-008 §4.2FSSC 22000 · PRP-7CAPA-2026-0118Audit Q1-INT · finding 03
Proposal · awaiting human approval
approval gate
Open CAPA-2026-0119 · Calibration drift on MD-04
  • · Owner: J. Otieno (Maintenance)
  • · Linked control: CTRL-027 · linked finding: Q1-INT/03
  • · Verifier: K. Mbeki (different from owner)
  • · Effectiveness review: 2 cycles after closure
every action logged
AI Copilot

AI that an auditor can trust.

Every answer points at a record in your tenant. Anything that writes data waits for a human to click Approve. The transcript lands in your audit log next to the change itself.

  • The auditor role doesn't see what the admin sees. Retrieval respects it.
  • Citations resolve to live records, not URLs that rot.
  • Write actions stage as proposals. A named person approves them.
  • Every prompt, source, and decision is recorded for the next audit.
How the Copilot stays auditable
Two vocabularies, one desk

You speak IMS. Your regulator speaks GRC. We work in both.

Quality leaders talk scope, CAPA, and management review. Risk and security leaders talk controls, attestations, and remediation. Same workflow. Different label.

IMS · quality leader speaks
GRC · compliance & risk leader speaks
Requirement / clause
Control objective
Control / procedure
Control activity
Evidence
Artifact / attestation
Scope applicability
System scope / TSC selection
Internal audit
Readiness assessment
NC · OFI · OBS
Finding / gap
CAPA
Remediation
Management review
Steering / risk committee
ISO 9001 · 14001 · 45001 · 22000 · 13485
SOC 2 · ISO 27001 · GDPR · NIST CSF · HIPAA

One tenant. One audit log. Whichever language your team uses on the morning of the assessment.

How to check we are delivering

Seven tests. Run any of them without warning us.

We would rather be measured than described. Every test below is checkable by you, on any working day, without asking us to prepare anything. If preparing it is required, the system is not running, and running it is the work you were trying to hand over.

On proof

We are early, and we would rather say so than invent a logo wall. Named references are introduced on request once a client agrees to it, and we will tell you plainly which parts of the service they use. Until then, judge the model on the tests, and on the working session.

  1. 01
    The certificate holds

    Visits close with no major nonconformity, and minors are verified closed before the next one.

  2. 02
    Any question is answered from a record

    Name any control. Owner, frequency, last evidence and date, in under a minute, with no notice.

  3. 03
    Findings close and stay closed

    Owner, due date, recorded root cause, verified by someone other than the owner.

  4. 04
    Evidence exists before it is asked for

    The pack for the next visit is assembled continuously, against the control it proves.

  5. 05
    Your board sees it without asking

    One monthly report from live records: what moved, what is late, what needs your decision.

  6. 06
    The month does not change the quality

    The same review runs the same way whoever is on it, because the system will not let a step be skipped.

  7. 07
    The system survives a resignation

    The register, the evidence and the decision history stay current and legible to whoever arrives next.

Built for the audit

The compliance trail is the product.

The same controls that keep your data safe are the ones the certification body asks about during a vendor review. Honest answers, on one page.

Your tenant is yours

Your records never sit next to another customer's records. The same query, run by a different tenant, returns nothing.

Auditor doesn't see admin

Per-role and per-site boundaries on every read. The contractor working at the Mombasa plant can't see the Lagos plant.

No one approves their own work

Authors can't approve their own documents. CAPA verifiers can't be the CAPA owner. The platform refuses, not the policy.

Every change is on the record

Approvals, scope changes, evidence acceptances, AI actions. Append-only log with actor and prior state. Export to CSV.

No public file links

Evidence is reached through time-limited signed URLs. TLS in transit, AES at rest. The cert PDF you shared in November isn't reachable today.

Your data lives where you say

EU, US, or Africa. Pick once, the tenant stays there. Cross-region replication is opt-in.

Read the security overviewSOC 2 in progressISO 27001 alignedGDPR · data residency
A working session, not a slideshow

Bring your real scope. We will run a month of it in front of you.

Bring three policies, a recent audit report, and one CAPA that's been open too long. We index your records into a scoped tenant and run the workflow your team would run on Monday. Forty-five minutes.

Book a working sessionBrowse modules45 min · no slides · bring your scope
what you walk away with
  • A scoped tenant loaded with the standards you actually run.
  • That open CAPA, walked from finding to verification.
  • A two-page brief on which modules to install first.
  • An honest no, if it's not a fit.
average time-to-first-audit-pack · 9 days