
Modular GRC platform for risk, compliance, information security and AI governance
FullyInControl is a Dutch cloud GRC platform that runs governance, risk and compliance, ISMS/PIMS/AIMS, business continuity, QHSE, third-party risk, ESG and internal audit from one system. It links policy, risks, controls, tests, evidence and improvement actions in a single workflow so compliance status against standards like ISO 27001, ISO 27701, ISO 42001, NEN 7510, BIO, NIS2, DORA and the GDPR is visible continuously instead of only at audit time. The platform is built from 35+ modules that can be bought individually or bundled into domain packages, with three editions (SmartStart, Professional, Enterprise) scaling configurability and user counts.
One platform covering GRC, ISMS/PIMS/AIMS, BCM, QHSE, TPRM, ESG, KYC, performance management and internal audit, so the same risks, controls and evidence are reused across domains instead of duplicated in separate tools.
Built-in knowledge bases for ISO 27001, ISO 27701, ISO 42001, NEN 7510, BIO, NIS2, DORA, GDPR, COSO ERM, ISO 31000, COBIT, NIST, CIS, SOC 2 and the EU AI Act, plus the option to load custom internal frameworks and map controls to multiple standards at once.
Register risks, score them with configurable valuation methods, attach control measures and track the tasks that implement and test each measure through to completion.
Maintain a GDPR processing register across processes and systems, run DPIA workflows with decisions and follow-up, and handle data subject requests (access, correction, erasure, portability, objection) and data breach reporting on deadline-driven workflows.
AIMS module for building an AI/algorithm registry, running impact assessments on AI use cases and carrying them through to assurance, aimed at EU AI Act and ISO 42001 obligations.
Run the full ISMS lifecycle — scope, risk assessment, statement of applicability, control measures, periodic tests and evidence — against the ISO 27001 and NEN 7510 libraries, so surveillance audits draw on live data instead of a pre-audit scramble.
Data protection officers maintain the processing register, run DPIAs with documented decisions, log data breaches against statutory reporting deadlines and track data subject requests through to closure in one register.
Build an inventory of AI systems and algorithms, classify and impact-assess each use case, attach controls and assurance evidence, and report on AI governance posture alongside existing security and privacy controls.
Start using FullyInControl today and boost your productivity.
Visit WebsiteOptional AI support that drafts risk assessments, proposes control measures and generates policy drafts to shorten the gap from insight to documented action.
Schedule recurring audits, control tests and questionnaires, capture evidence against each test, and involve colleagues who do not hold a full licence via lightweight 'processor' accounts.
Business intelligence dashboards plus custom Word and Excel report templates (Professional and Enterprise), with KPI, KRI and KCI calculation and saveable custom filters.
Kanban boards, contextual discussion threads, task assignment and responsibility mapping so remediation work happens inside the system rather than in email.
REST API and web services for pushing data in and out of the platform, standard Entra ID single sign-on on all editions, and extended Entra ID authorisation-role synchronisation as a paid add-on.
Configure fields, workflows, user roles, business roles and questionnaires with conditions without custom code — fully open on Enterprise, available as an add-on on Professional, fixed to best practices on SmartStart.
Structured vendor implementation methodology that gets a SmartStart deployment operational within roughly eight weeks on pre-configured best practices.
Municipalities, water boards and housing associations manage BIO baseline compliance, self-assessments and accountability reporting with pre-loaded local frameworks and viewer licences for large staff populations.
Organisations running quality, safety, environment, security, continuity and risk in different spreadsheets or tools merge them into a single integrated management system with shared risks, controls, audits and improvement logs.
Financial institutions and essential-entity organisations map NIS2 and DORA obligations to existing controls, run third-party risk assessments on suppliers and contracts, and evidence board-level oversight through dashboards.

Secure, privacy-first email built in Switzerland