Compliance

Frameworks, risks and registers — tied to the law.

Run your frameworks from one place. Each one is broken down into what it asks of you — controls, policies, registers, incidents — and every requirement cites the article it comes from.

DORANIS2AI ActGDPR— more are added over time.
Tied to the lawevery requirement cites the article it comes from
Confirmedthe rules propose a classification; a person confirms it
Recorded oncea risk, a control or a supplier counts wherever it applies
Dateddeadlines worked out from the rules that apply

Frameworks

Each framework, broken down into what it asks of you.

DORA

Digital operational resilience

  • ICT risk controls, with their status and applicability.
  • Major ICT incidents classified, with their reporting deadlines.
  • Critical or important functions assessed against the legal criteria.
  • The register of information, exported in the EBA template and checked before you file.
More on DORA
NIS2

Cybersecurity

  • Significant incidents assessed, with the notification timeline.
  • The policies the directive expects in writing.
  • Suppliers flagged as part of your supply chain.
  • Under DORA as well? Your incidents are routed to DORA first.
More on NIS2
AI Act

The AI systems you use

  • An inventory of your AI systems, with their provider and owner.
  • A classification proposed — prohibited, high-risk or not — that you confirm.
  • The deployer duties that follow, system by system.
  • A check for when using a system makes you its provider.
More on the AI Act
GDPR

Personal data

  • Records of processing, with the fields the regulation lists.
  • DPIA screening against the cases where one is required.
  • Data-subject requests and their deadlines — kept as a reference, never the person’s details.
  • Personal-data breaches assessed for notification.
More on GDPR

Risks & controls

Know your risks, and whether your controls hold.

A risk register with inherent and residual ratings on a heat map, treatment decisions and owners — linked to the controls that cover each risk. Controls carry their status, their applicability per framework and their test results.

A risk from the lawHighlight a passage of a regulation and turn it into a risk.
Control testingRecord each test and see where your controls stand.
Suggested mappingsControls matched to the requirements they meet.
Regulator activityRecent enforcement, shown for each risk category.

Policies

Policies that keep up with the law.

Every policy is versioned, with its owner and its review date. See what each framework expects in writing, what changed in the linked law since your last review, and where your policy falls short.

Versions keptGoing back creates a new version; history is never rewritten.
Review datesOverdue and soon-due policies flagged.
Expected in writingWhat the law asks you to have in writing, quoted.
Gap analysisYour policy read against the obligations it should meet.

Incidents

One incident, assessed under every framework that applies.

Record the facts once. RegNext proposes the classification under DORA, NIS2 and GDPR from the rules themselves, a person confirms it, and the reporting deadlines follow.

Classified from the rulesEach criterion shown with its legal text.
DeadlinesDated from the moment that counts.
Owner and assigneesWith severity and status.
LinkedTo the suppliers, risks and tasks involved.

Third parties & registers

Suppliers, functions and assets — recorded once.

Record each supplier once and see which frameworks it falls under — ICT provider, outsourcing, processor, supply chain, AI provider. Map your functions and assets, assess which functions are critical, and export your DORA register of information.

Tagged per frameworkOne supplier, every regime that applies to it.
Critical functionsAssessed against the legal criteria.
Register of informationExported and checked before you file.
Supplier questionnairesGenerated for you to send.

Built in

The rules do the reading. Your team decides.

The law behind every requirement

Each requirement cites its article, and each criterion and test quotes the law.

Proposed, then confirmed

Classifications come from the rules themselves, and a person confirms them.

Your scope

The frameworks shown are the ones your firm has in scope.

Automations

Rules you switch on: when a supplier turns out to be critical or a major incident is confirmed, a task or a risk is created for its owner.

Everything linked

Risks, controls, policies, incidents and suppliers point to one another.

Personal data kept out

Data-subject requests are logged by reference, with no field for the person’s details.

image of brainstorming session for a productivity tools business

Transform compliance.
Accelerate outcomes.

Explore how RegNext supports regulatory intelligence and compliance execution in your industry.