GOVERNANCE · RISK · COMPLIANCE · AUDIT

One tenant-isolated platform for Governance, Risk, Compliance & Audit

AmanVault brings Governance, Compliance, Risk, Audit and Vendor Risk into one system — each with its own workflow, all sharing the same escalation path, role model, and an audit trail nothing can edit.

Request a demo See what's built ↓
The platform underneath

Every module runs on the same four guarantees

This isn't five separate tools bolted together. Governance, Compliance, Risk, Audit and Vendor Risk are built on one shared foundation — so an escalation raised in Risk lands in the same place as one raised in Compliance, and every action anywhere is provable after the fact.

01 · TENANCY
Every organization's data is isolated at the tenant boundary — no cross-tenant reads, no shared collections.
02 · ROLES
Fine-grained, per-action permissions — not just "admin vs. user." A Risk Owner sees their own risks; a Risk Manager sees all of them.
03 · ESCALATION
Risk, Compliance and Audit all escalate through the same governance decision register — one place to see what's pending approval, from anywhere.
04 · AUDIT TRAIL
Every create, update, approval and rejection is logged immutably. Nothing routes around it.
What's live today

Five modules, each doing one job well

Built and running — not a roadmap. This is what a team logs into today.

GOVERNANCE

Documents, sign-off, and who owns what

Policy and governance documents move through a real lifecycle, get acknowledged by the people who need to read them, and nothing goes overdue silently.

  • Draft → Review → Approved → Expired document lifecycle, versioned
  • Acknowledgement tracking with automatic reminders and a CSV report
  • Exceptions with a required compensating control and expiry date
  • Delegation of Authority — who can approve what, and for how long
COMPLIANCE

Frameworks in, gaps out

Import a framework once and get controls, requirements, and clause coverage together — not a spreadsheet reconciliation exercise.

  • One import path creates the framework's controls and requirements together
  • Requirement-by-requirement assessments with a permanent, append-only history
  • Evidence attached directly to what it's proving
  • Gaps opened automatically from a non-compliant answer, with an action to close them
  • CSV / PDF compliance report, generated on demand
RISK

A risk register people actually keep current

Register a risk, assign a treatment, set a review cadence — and export the trail when someone asks for evidence.

  • Risk register with ownership and a defined treatment plan per risk
  • Treatment actions tracked to closure, not just noted
  • Scheduled review cadence — risks don't just sit unreviewed
  • Audit-ready evidence export
AUDIT

From engagement to closed finding

Run an audit cycle, log findings against it, and close the loop with a corrective action that's verified — not just marked done.

  • Audit cycles / engagements with a defined lead and framework
  • Findings tracked from draft through remediation to closure
  • Corrective actions (CAPA) verified for effectiveness, not just completion
  • A separate, isolated portal for external auditors — no internal access required
VENDOR RISK

Third parties held to the same bar

Vendors get their own issue tracking, corrective actions, and a formal risk acceptance path when a vendor risk has to be accepted rather than fixed.

  • Vendor inventory with issue and corrective-action tracking
  • Completion-vs-effectiveness closure loop, same discipline as internal Audit
  • Formal Risk Acceptance flow — create, approve, renew, or revoke
  • A dashboard view across the whole vendor book
CROSS-MODULE

One view across everything

A single dashboard that pulls from Governance, Compliance, Risk, Audit and Vendor Risk at once — so nobody has to open five tabs to know where the organization stands.

  • Cross-module posture view, not a per-module dashboard repeated five times
  • Framework coverage and open-item counts, live
  • Same escalation register surfaced from every module that feeds it
Underneath every screen

The parts you don't see, and shouldn't have to

Not a marketing checklist — the actual mechanics every module above is built on.

Immutable audit trail

Every write across every module is logged — who, what, when, before and after. It's a record, not a log line that can be quietly deleted.

Per-action RBAC

Dozens of role personas across the five modules — a Risk Owner, a Committee Chair, an External Auditor — each scoped to exactly the actions their role should have, nothing assumed.

Tenant isolation

Every record carries its tenant boundary at the data layer. One organization's data is never a query away from another's.

Shared escalation engine

An exception in Compliance, a high-risk item in Risk, an audit finding — they all escalate through the same governance decision register, not three different ad hoc paths.

Hardened by design

Signed, expiring authentication tokens; every request sanitized against injection before it reaches a handler; dependencies kept current against known vulnerabilities.

Isolated external access

The External Auditor Portal runs on its own authentication path entirely separate from internal accounts — an external party never touches the internal system.

Get in touch

See it running on your own data

The fastest way to understand AmanVault is a walkthrough of a live tenant — Governance, Compliance, Risk, Audit and Vendor Risk, all in one session.

Request a demo