Multi-framework assurance delivery

Four standards. One evidence base. Four separate conclusions.

Compliance Sphere is the delivery record consulting firms run an engagement on. Assessments, evidence, findings, approvals and reports live against one client, and each framework still reaches its own conclusion on its own method.

Evaluation access is issued by invitation. No unscoped self-sign-up.

Programme register

A shared operating record, not a certification shortcut.

A conclusion is a readiness position for a stated boundary and date. It is the consulting firm's assessment, and it does not stand in for a certification body's audit decision.

Catalogues carried in the product
ProgrammeCatalogue
ISO 27001 ISO/IEC 27001:2022 Information security management system 118 requirements
ISO 42001 ISO/IEC 42001:2023 Artificial intelligence management system 65 requirements
CSF NIST CSF 2.0 Cybersecurity maturity assessment 106 outcomes
DPDPA India Digital Personal Data Protection Act 2023 Evidence-backed data protection gap assessment 55 obligations

What governed means here

The record resists being talked into a better answer.

Most of this product is refusals. A conclusion that is not supported cannot be recorded, an approved report cannot be edited afterwards, and the person who proposes a decision is not the person who signs it off.

A conclusion needs evidence attached

Controls and obligations are concluded against linked evidence, not against a dropdown. Coverage is reported separately from sufficiency, so one retained file is never mistaken for a complete evidence set.

Approved records freeze

An approved report is a content-addressed snapshot. Reassessment opens a new record rather than rewriting the old one, so what the client was told in March still reads in March's terms.

Recommending is not deciding

On third-party risk the consultancy records a recommendation and the client's decision authority accepts or declines it. The two are stored separately and export as separate columns.

Maker-checker applies to the recommendation itself.

Catalogues are fixed at a version

Each framework catalogue carries a content hash and validates itself on load. An engagement states which release it was assessed against, and a later release supersedes rather than silently replaces it.

Role separation

One engagement, four bounded views.

Membership is checked on every protected action. A client team sees the workspaces assigned to it and nothing adjacent.

ConsultantRuns fieldwork, links evidence, maintains workpapers and drafts controlled outputs.
ManagerHolds access and approval. Reviews decisions, signs off governed records, sees the firm portfolio.
Client teamAnswers requests, supplies evidence and follows progress on its own engagement only.
External auditorReaches a time-boxed, token-scoped view of approved records without an account on the firm.

A useful evaluation

Try to break the boundary.

An evaluation runs in an isolated workspace. The useful test is not whether a report renders. It is whether you can conclude a control with no evidence behind it, edit a report after approval, approve your own recommendation, or see a client that was never assigned to you.

If any of those succeed, we would rather hear it from you than from an auditor.