Normain
Book a demo
Solutions / Governance, Risk & Compliance

Compliance reviews, grounded in your own sources

Normain reads your standards, policies and client evidence and returns structured, verifiable answers, each one linked to the exact clause it came from. Your team reviews and signs off in a fraction of the time.

Your documents
SOC 2 Type II
ISO 27001 cert
SIG Lite
Question
Any exceptions or deviations noted in this SOC 2 report?
2 minor exceptions, both with management responses.
High confidenceSource p.42
Governance, risk & compliance use cases
Framework gap analysisThird-party and vendor riskPolicy and control framework reviewRisk assessment and risk registerDPIA and data protection riskDORA ICT and third-party risk
How it works
1
Add your knowledge
Standards, policies and the evidence under review. Normain reads and understands each source.
2
Define the questions once
Tell Normain what to extract, how to analyze it and what the output should look like. It handles the framework logic and scoring.
3
Get verified output
Structured answers in seconds, every finding linked to its source, so your team reviews, challenges and signs off with confidence.
Built for GRC teams

Recognize the work you do every day

These are the reviews GRC and compliance teams run by hand today: the same documents, the same questions, the same matrices. Normain does the reading and gives you structured, source-linked answers to check and sign off.

Spreadsheet project

Framework gap analysis

Built forISMS managers · GRC analysts · advisory consultants

Assess your current state against a target framework, control by control, and produce the gap matrix that feeds your Statement of Applicability and remediation roadmap.

Normain
Data sources
ISO/IEC 27001:2022 Annex A
Statement of Applicability
SOC 2 (Trust Services Criteria)
NIST CSF 2.0
Interactive — try it out
Question
Assessment
Explanation & evidence
1
Does A.8.16 Monitoring activities meet its stated purpose?
2
If partially met, what remediation is required and who owns it?
3
A.5.15 Access control — is a documented access policy in place and enforced?
4
A.8.24 Use of cryptography — are key management responsibilities defined?
5
A.5.7 Threat intelligence — is a feed collected and acted on?
Example questions
  • For every control assessed as partially implemented, identify the specific sub-requirement not met and cite the evidence reviewed.
  • Which controls satisfy both ISO 27001:2022 Annex A and the SOC 2 Common Criteria, so we can consolidate to a single control statement?
  • Where a control is applicable but no implementing policy exists, flag it as a documentation gap and propose a remediation owner.
  • Which 2022 Annex A controls are new versus our previous SoA, and are they addressed?
…and any others you write.
Repeat project

Third-party and vendor risk

Built forThird-party risk analysts · DPOs · procurement

Review each vendor's evidence against the same checklist, so onboarding and periodic re-reviews take minutes instead of an afternoon of reading each report.

Normain
Interactive — try it out
Data source
Opinion
Exceptions
Cert
Acme Cloud — SOC 2
Meridian LLP — SOC 2
Northwind — SOC 2
Example questions
  • From the test-of-controls table, list every control with an exception, the auditor's testing method, and management's response.
  • Which subservice organizations are carved out, and do any of them process our regulated data?
  • Extract the Complementary User Entity Controls (CUECs) we must implement, and map each to an internal owner.
  • Does the coverage period leave any gap since the previous report, and is the ISO certificate in scope and valid?
…and any others you write.
Simple project

Policy and control framework review

Built forGRC analysts · policy managers

Ask a set of pointed questions across your policy library at once, to prove coverage, catch contradictions, and find what is overdue for review.

Normain
Data sources
Information Security Policy
Access Control Policy
Incident Response Plan
BCDR plan
Interactive — try it out
Access Control Policy
Instruction
Is phishing-resistant MFA required for privileged access?
Answer
Policy register
Instruction
Which policies are overdue for review?
Answer
Example questions
  • Does our Access Control Policy require phishing-resistant MFA for privileged access, and which clause states it?
  • Which framework requirements have no backing policy clause?
  • Where do two policies conflict, for example on password length or data retention?
  • Which policies are past their stated review date as of today?
…and any others you write.

Testimonials

Trusted by the experts who sign off on the work

Beyond GRC

The examples above are a starting point, not a limit

Point Normain at your own documents and questions. Whatever the review, the work takes one of three shapes, and Normain runs all three.

Read across a stack of documents
Point Normain at a pile of files and ask your questions once. It reads all of them and gives you one combined answer, with every point linked back to its source.
Run the same questions across many items
One row per file, folder, vendor or company. The same questions run across every item, so you can compare and rank a whole set side by side.
Fill in a grid or scorecard
Your questions down one side, your sources along the other. Ideal for questionnaires, scoring grids and readiness assessments.

See it on your own documents

Bring a standard and a client file. In minutes, watch Normain work through them with the reasoning and sources in view, all the way to source-linked answers you can sign off on.