Corporate brochure

Your whole compliance programme, one governed workspace

Sentinel42 unites frameworks, risk, operations, privacy and reporting in a single ISMS platform built around ISO/IEC 27001:2022 — designed by a practising Lead Auditor, and ready for audit from day one.

12
Framework readiness scores
93
Annex A controls governed
46
Ready-to-use templates
94
Legal obligations tracked
1
Evidence base for everything

Twelve frameworks — one workspace

ISO 27001SOC 2ISO 27701ISO 42001NISTCyber EssentialsNHS DSPTEU AI ActISO 9001DORANCSC CAFNIS2

The problems we solve

Compliance pains, and how Sentinel42 resolves them

Every compliance programme fights the same battles. Sentinel42 was designed around them — each capability exists because a real audit, somewhere, went badly without it.

Evidence scattered everywhere

Policies in SharePoint, risks in spreadsheets, screenshots in inboxes — and an audit date approaching with no single source of truth.

One connected evidence base

The Evidence Vault stores every artefact once and links it to the controls, risks, policies, audits, incidents, suppliers and training records it supports.

Multiple frameworks, multiplied effort

Each new standard or regulation seems to demand its own project, its own registers and its own duplicated evidence collection.

Comply once, map many

Twelve framework pages read from the same Annex A controls, risks and nonconformities. You tag existing records rather than re-entering them, and each new framework costs a fraction of the first.

Nobody knows who owns what

Actions drift, reviews lapse and accountability evaporates — until an auditor asks a question no one can answer.

Ownership you can chase

My Tasks gives every user a personal worklist; the Management Action Log shows every owned record across every module, with overdue and due-within-seven-days totals and one-click closure. A DRACI matrix maps 64 deliverables to 17 roles.

Audit week is a fire drill

Readiness is guesswork, evidence is assembled in a panic, and the risk register is reviewed once a year under duress.

Always-on readiness

The dashboard scores readiness for every enabled framework in real time, maintenance checks schedule routine ISMS hygiene, and the audit programme links findings straight into corrective action.

Incidents outrun the paperwork

Statutory clocks — such as the UK GDPR 72-hour window — keep running while teams work out who should tell whom, and what the plan actually says.

Structured response, tracked deadlines

A six-phase incident response plan, a full incident register with regulatory watch flags, and a Regulator Notifications module that scans statutory notification deadlines for you.

Leadership is disconnected

Boards want assurance, not registers — and producing a management pack from raw compliance data takes days.

Executive reporting on demand

The Report Builder assembles management-facing reports from live data, and Management Review drafts your clause 9.3 review directly from the system itself.

The platform at a glance

One workspace, eight connected capability areas

Frameworks

The Statement of Applicability governs all 93 Annex A controls; Clauses 4–10 capture management-system evidence; and twelve framework pages — from Cyber Essentials to NIS2 — score readiness from the same underlying data.

Risk & Compliance

Risk register with inherent and residual scoring, a derived treatment plan, nonconformities and OFIs, audit programme, control testing, legislation tracking, policy management, a 46-document template library and the central Evidence Vault.

Operations

Business impact analysis, incident response and register, regulator notifications, information and physical asset registers with Microsoft Intune sync, supplier due diligence, backup restore testing, environment management and training.

Privacy (GDPR)

The operational privacy toolkit: ROPA, data subject requests, DPIAs, a notices repository, retention schedules and sub-processor tracking — feeding the ISO 27701 readiness score automatically.

Integrations

Connectors bring external evidence in automatically: Microsoft Intune for assets, plus Jira Cloud, Microsoft Defender XDR and GitHub, with further connectors on the roadmap.

Administration

Role-based access with five built-in roles, email invitations, a quarterly access-review workflow aligned to Annex A.5.18, and organisation branding for every exported document.

Executive Reports

The Report Builder assembles management-facing reports from live platform data — readiness, risk, actions and findings — ready for boards and management reviews.

Industry verticals

The architecture extends beyond information security: a complete pharmaceutical distribution (GDP) vertical demonstrates how the same governed-workspace model serves regulated industries of every kind.

Capability detail

What lives inside each area

Frameworks and standards

  • Statement of Applicability — all 93 Annex A controls with justifications, notes and evidence
  • Clauses 4–10 — evidence capture for every management-system sub-clause
  • NIST CSF/800-53 — baseline picker against the full 1,196-control catalogue
  • SOC 2 and ISO 42001 — complete criteria lists with ISO 27001 overlap indicators
  • NIS2 — graded on live operational data against Articles 20, 21 and 23
  • AI register — AI systems, datasets and model cards mapped to ISO 42001

Risk and improvement

  • Risk register — inherent and residual scoring with automatic risk banding
  • Treatment plan — audit-ready evidence for clauses 6.1.3 and 8.3
  • NCs & OFIs — root cause, containment and corrective action through to closure
  • Audit programme — internal and external audits with findings linked to corrective action
  • Control tests — operating-effectiveness testing across four standards
  • IS objectives — clause 6.2 objectives with KPI targets and RAG status

Governance and documents

  • Legislation — 94 tracked legal and regulatory obligations with owners
  • Policies & docs — version control, approval workflow and staff sign-off
  • Template library — 46 policies, procedures and forms across seven frameworks
  • Management review — clause 9.3 reviews drafted from live system data

Operational resilience

  • BIA register — impact analysis aligned to ISO 22301 and Annex A.5.30
  • Incident response plan — maturity assessment across the six-phase SANS model
  • Incident register — severity, handlers, regulatory flags and phased workflow
  • Regulator notifications — statutory deadline tracking with automated scanning
  • Backups & restore — restore-test evidence proving recovery actually works
  • Maintenance checks — scheduled ISMS hygiene from bi-weekly to annual

Assets, suppliers and people

  • Asset registers — information and physical assets, synced from Microsoft Intune
  • Suppliers — due-diligence requests, risk ratings, DPA status and review dates
  • Dev & environments — environment separation with dependency-scan history
  • Training & awareness — course catalogue, completions and phishing simulations
  • DRACI matrix — 64 ISMS deliverables mapped to 17 organisational roles

Privacy operations

  • ROPA register — Article 30 records of processing activities
  • Data subject requests — rights requests tracked through to response
  • Impact assessments — DPIAs for high-risk processing
  • Retention & notices — schedules and notices under version control
  • Sub-processors — the sub-processor list and its changes, in one place

From sign-up to certificate

How it works

1

Assess

Run the built-in gap analysis to establish your baseline and scope your ISMS honestly.

2

Build

Stand up risks, controls and the Statement of Applicability from templates shaped by audit practice.

3

Operate

Collect evidence, run reviews, track actions and log incidents — the routine certification bodies expect to see.

4

Certify

Walk into Stage 1 and Stage 2 with everything indexed and traceable — then extend to your next framework.

Sentinel42 was designed by a practising ISO 27001 and ISO 42001 Lead Auditor with more than sixteen years in the field. Every register, workflow and evidence requirement reflects what certification bodies actually examine — and behind the software sits a consultancy offering fractional CISO support, internal audit and audit-day representation whenever you want it.

See your whole compliance programme in one place

Full platform access for 14 days. No card required. Import your existing ISMS or start from the structured build path.