Compliance work gets duplicated when each framework becomes its own spreadsheet. The same access review is rewritten for ISO 27001, SOC 2 and a customer questionnaire, while evidence and conclusions quietly drift apart.
ComplianceCenter starts with a different unit of work: an organisation-owned control. Framework requirements map to that control through versioned coverage rationale and independent review. Programs decide what applies to their scope without cloning the underlying control.
Controls, not copies
A control records its objective, method, cadence, owner, operator, systems, implementation state, and separate design and operating conclusions. One control can cover many requirements, but a draft mapping never counts as coverage. The mapper and reviewer must be different people, so the crosswalk itself is an assurance record.
Applicability remains program-specific. A requirement can be applicable, under review, or not applicable; exclusions require a rationale and stay in the history.
Evidence with provenance
An upload is not proof by itself. Each artifact version preserves its source, reporting period, systems, content hash, classification, collector, expiry and validation decision. Approval must come from someone other than the collector. Links cite an exact version and explain the purpose and scope claimed for it.
Testing adds another independent layer. Plans freeze their population and samples before an immutable result records the procedure, exceptions, conclusion and reviewer. A later retest creates a new result instead of rewriting the old one.
Readiness is derived
The readiness evaluator works requirement by requirement. It looks for applicable scope, reviewed mapping coverage, a monitored and effective control, current approved evidence, and the latest test conclusion. A critical open gap blocks the requirement. An exception helps only when it has exact scope, compensating controls, residual risk, independent approval and a future expiry.
The output is more useful than a self-reported percentage: every pass, warning and blocker includes a deterministic reason and cites the control, artifact, test, gap or exception behind it.
Freeze the answer
Live posture should change as new proof arrives, but last month’s steering report should not. A snapshot freezes the applicable requirements, mapping and evidence versions, control conclusions, tests, gaps, exceptions and score, then hashes the result. Later operational changes cannot alter that record.
How it is built
ComplianceCenter uses the System32 house stack: a Go API with SQLite and a Next.js 16 / React 19 interface. Its deterministic demo includes 8 frameworks, 640 requirements, 210 reusable controls, 1,450 mappings, 1,260 evidence versions, 2,400 test samples, 165 gaps, 72 exceptions, 64 frozen snapshots and 2,000 activity events. Automated tests cover independent review, immutable evidence and results, applicability rationale, gap closure, exception expiry, derived readiness and snapshot stability.
ComplianceCenter is available now in the System32 catalog. Start with a program, follow one requirement through its reviewed mapping and exact evidence, then freeze the resulting posture.