Framework Coverage
Choose your framework. Start drafting in minutes.
Each workspace template packages domain-specific skills, reference material, and validation tools for a complete engagement path.
ISO 27001 ISMS
Full PDCA cycle from scoping through Statement of Applicability, risk assessment, policy generation, internal audit, and management review.
- Clause-aligned artifact generation
- Risk-control-SoA traceability
- Cross-document consistency checks
DORA Compliance
Complete EU Digital Operational Resilience Act (Regulation 2022/2554) compliance program covering all five pillars: ICT risk management, incident classification and reporting, resilience testing (TLPT), third-party risk management with information register, and information sharing.
- RTS/ITS-aligned validation (2024/1774, 2024/1772, 2025/302)
- ITS 2024/2956 information register field checks
- 7-criteria major incident classification
SOC 2 Audit Readiness
From organization profile and system description through risk assessment, gap analysis, control narratives, policy generation, and internal audit.
- AICPA TSC coverage validation
- SCSR pairing and CUEC specificity
- Vague-language detection
NIS2 Directive
Complete EU NIS2 Directive (2022/2555) compliance: entity classification, gap assessment against all Art. 21 measures, governance accountability, policy drafting, supply chain security, business continuity, incident reporting with 24h/72h/1-month timelines, and authority registration.
- Essential vs. important entity classification
- Art. 21 measure maturity rating (0-5)
- Incident reporting timeline validation
CMMI-DEV
Process improvement across all CMMI-DEV practice areas: causal analysis, configuration management, decision analysis, and organizational process definition.
- Practice area coverage scoring
- Maturity level gap analysis
- Process improvement roadmap
ISO 20000 SMS
Full PDCA cycle for IT Service Management: service catalog, SLAs, incident/problem/change/release/configuration management, continuity, capacity, and audit.
- 13 ITSM process area coverage
- Service-SLA-CMDB traceability
- Cross-process integration checks
ISO 17025 Laboratory
Complete accreditation journey for testing and calibration laboratories: scope definition, method validation, measurement uncertainty (GUM), equipment calibration, metrological traceability, PT/ILC, and assessment readiness.
- Per-method scope validation
- GUM uncertainty budget checks
- Equipment-traceability-competence cross-refs
GDPR Compliance
Dual-track program: EU-wide GDPR gap assessment plus Ireland DPC self-assessment alignment. Covers all 14 compliance domains.
- ROPA and DPIA automation
- DPC checklist alignment
- Consent and LIA validation
ISO 42001 AIMS
AI Management System from inventory and impact assessment through risk register, data governance, model development, and Annex A SoA.
- AI-specific risk criteria
- Bias and drift monitoring checks
- Responsible AI policy generation
ISO 45001 OHSMS
Full PDCA cycle for Occupational Health and Safety: organization context, hazard identification, risk assessment with hierarchy of controls, legal register, OH&S policy, emergency preparedness, internal audit, and management review.
- Hierarchy of controls enforcement
- Hazard-legal traceability
- Worker consultation evidence checks
ISO 27701 PIMS
Privacy Information Management System extending ISO 27001 with PII inventory, controller/processor controls, DPIA program, and privacy SoA.
- Annex A/B control coverage
- ROPA data flow mapping
- Privacy risk assessment
NIST SP 800-53
FIPS 199 categorization, baseline selection, family policies, control standards, mapping, gap analysis, and CSF crosswalk.
- Catalog-scale baseline completeness
- Tailoring justification validation
- NIST CSF profile authoring
How it compares
Why GRC teams choose Rakenne over generic AI
Generic chatbots produce plausible-sounding text with no structure guarantees. Rakenne runs your compliance process.
See it in action
Validation catches what reviewers miss
Skills include automated checks that run against the output. When something fails, the agent fixes it — no manual back-and-forth.
The agent validates, then self-corrects
In this ISO 27001 example, the agent runs a clause completeness check, discovers a missing mandatory section, fixes the draft, and re-validates — all within the same conversation.
clause_completeness_check on 14 artifacts…FAIL — 1 issue found:
- Clause 6.1.2: Information security risk assessment — missing mandatory risk acceptance criteria section. Required by Clause 6.1.2(a).
clause_completeness_check again…Beyond the big frameworks
140+ skills across privacy, financial crime, and industry-specific compliance
The GRC skill library goes far beyond the major frameworks. Browse the full catalog or start with a workspace template.
Privacy & Data Protection
- CCPA / CPRA
- Canada PIPEDA
- UK GDPR & ICO DPIA
- EU AI Act (FRIA)
Financial Crime
- AML / BSA Program
- Nordic AML/CFT
- AUSTRAC AML/CTF
- CFPB UDAAP
Industry-Specific
- ISO 14971 (Medical Devices)
- ISO 14001 (Environmental)
- ISO 45001 (OH&S)
- ISO 17025 (Laboratories)
- ITAR / EAR (Export Control)
- AS9100 (Aerospace)
Cross-Framework
- Unified compliance matrix
- ISO 31000 Risk Register
- NIS2 & DORA mapping
- CMMC alignment
Go deeper
Tutorials, use cases, and best practices
Step-by-step guides showing real dialog, tool output, and how skills chain together for each framework.
Framework Tutorials
- ISO 27001 ISMS Workspace Guide 20 min
- SOC 2 Audit Readiness Guide 25 min
- NIST SP 800-53 Compliance Guide 18 min
- GDPR Compliance Program Guide 22 min
- ISO 42001 AIMS Workspace Guide 22 min
- ISO 27701 PIMS Workspace Guide 18 min
- ISO 20000 SMS Workspace Guide 25 min
- ISO 45001 OHSMS Workspace Guide 18 min
- ISO 17025 Laboratory Workspace Guide 25 min
Use Cases
Best Practices
FAQ
Common questions from GRC practitioners
Ready to draft your first compliance document?
Pick a framework, start a workspace, and see validation in action. No sign-up required.