What it does

From regulatory text to work your team can actually finish.

Every regime in the catalogue is broken into controls a practitioner wrote, each with the steps to take and the evidence an auditor will ask for. The platform tracks the work, reads your documents against it and reports the result.

Controls with depth

Every control carries its description, minimum content, suggested owner, review cadence, the articles it evidences and any proportionality relief. Underneath sit the implementation steps and the evidence artefacts an auditor expects.

DORA · Art. 17 · ICT-related incident management process
owner: Head of ICT Risk · cadence: annual · 6 steps · 4 artefacts

Per-control tracking

Status, owner, evidence location, last-reviewed date and notes on each control, with step checklists that roll up into completion. Each field is gated by its own permission, so a contributor can attach evidence without changing a status.

status · owner · evidence · reviewed · notes → five permissions, granted per workspace and per framework

AI readiness gap analysis

Upload policies, registers and plans into the workspace's document library. The AI pass compares them to the controls, grades each one Ready, Partial or Not ready, and writes down the gap and a recommendation.

2,203 controls AI-assessed from 38 documents in one pass · every grade cites the passage it relied on

Cross-framework crosswalk

Related controls are grouped into cross-cutting families, so an obligation assessed once counts everywhere it applies. Incident reporting under DORA, NIS2 and ISO 27001 is one piece of evidence, not three spreadsheets.

family: incident handling → DORA Art. 17–19 · NIS2 Art. 23 · ISO 27001 A.5.24–5.28 · NYDFS 500.17

Reports, export and audit trail

A printable readiness assessment for management or an auditor, a full JSON export of the workspace on demand, and an append-only log of who changed what and when. Your data is never locked in.

readiness-report.pdf · workspace-export.json · activity log: 14,212 entries, none editable

Financial audit BETA and OSS licences BETA

A planning-stage workbench for a bank or an ordinary company: programme checklist mapped to the ISAs, analytical-review ratios and red flags, and AI analysis of uploaded statements. Plus a bill-of-materials licence review that judges each component against your deployment context.

ISA 315 · 320 · 520 · 570 · CycloneDX, SPDX, npm license-checker, CSV · internal / hosted / distributed
Anatomy of a control

Not a checkbox. A record an auditor can read.

This is what one of the 2,368 controls looks like in the workspace. The regulatory reference, the people and dates, the steps, the evidence and the AI grade live together, so the question "can we show this?" has one answer.

  • The clause it evidences, so nobody argues about which article a policy is answering.
  • Steps and artefacts written by practitioners, in five languages, not by the model.
  • A grade that cites its source: the passage the AI relied on, and what it did not find.
  • Edits logged, never overwritten. Every change lands in the append-only trail.
DORA · Regulation (EU) 2022/2554 · Art. 17(1)–(3)

ICT-related incident management process

Partial · AI-assessed 24 Sep 2026
OwnerHead of ICT Risk
Review cadenceAnnual · next 31 Mar 2027
ApplicabilityDirect · universal bank
Also evidencesNIS2 Art. 23 · ISO 27001 A.5.24

Implementation steps 4 / 6

  • Define and document the incident management process, including roles
  • Set early-warning indicators and classification criteria (Art. 18)
  • Establish escalation to senior management and the management body
  • Record all ICT-related incidents and significant cyber threats
  • Define communication plans for clients, counterparties and the public
  • Run a post-incident review after every major ICT-related incident

Evidence artefacts

ICT Incident Management Policy v3.2 · approved 12 Feb 2026
Incident classification matrix (RTS 2024/1772 thresholds)
Incident register, FY2026 extract
Post-incident review template · not found in library
Gap: no evidence of post-incident review or external communication plans. The policy covers detection, classification and internal escalation (§4–§7) but is silent on root-cause analysis after major incidents and on client communication. Recommendation: add a review procedure referencing Art. 17(3)(h) and a communication annex; re-run the pass. Decision-support, not legal advice. Grades are preliminary and control-based.
How the AI readiness pass works

Your own documents, read against every control you carry.

The model reads what you already have. With a full library it produces a readiness picture in minutes; with an empty one it can only tell you the library is empty.

Upload your evidence

Policies, registers, plans, board minutes, test reports. PDF, Word and scans with OCR go into the workspace's document library, per tenant, with versions kept.

The pass compares and grades

Each control is checked against the library by a Claude or ChatGPT model. The result is Ready, Partial or Not ready, with the gap, the passage relied on and a recommendation. Nothing you typed is overwritten.

People decide

Owners review the grade, attach what was missing, and the dashboard, the crosswalk and the readiness report update. The checklist-derived signal stays visible next to the AI one.

Ready

The evidence in the library covers the control as the clause requires.

Partial

Some of the control is evidenced; the gap and a recommendation are recorded.

Not ready

Nothing in the library answers the control, or what is there contradicts it.

Unknown

Not yet assessed, or the documents needed to judge it are not in the library.

Decision-support, not assurance. Resilyo supports preliminary, control-based readiness assessments. It is not a statutory audit, expresses no audit opinion and is not legal advice. Regulatory wording and translations are machine-assisted; verify anything you will rely on against the primary instrument.

See a full control record and the AI pass on one of your own documents.