One Platform. Every Assurance Domain.

ExGear Insight has grown from an audit and GRC core into an integrated suite of assurance domains — all sharing one risk universe, one control library, and one evidence base.

New in the Platform

The latest additions to the suite — built on the same shared data model as the audit and GRC core.

Asset Register with classification, criticality, and stock-take controls

Asset Management

A governed register for every managed asset, fed by automated discovery and verified in the field.

  • Asset register with criticality, classification & lifecycle
  • Discovery via agent, network scan, Active Directory & cloud APIs
  • QR-code stock-take with mobile companion app
  • Review cycles & configuration baselines
  • Secure disposal aligned to NIST SP 800-88
QR Stock-Take Mobile App
Vendor Registry with risk scores, tiers, and review cadence

Vendor & Third-Party Risk

Full third-party risk management from onboarding to structured offboarding.

  • Vendor registry with configurable risk tiers
  • Due-diligence campaigns (SIG & CAIQ templates)
  • Fourth-party visibility & concentration-risk analysis
  • Performance scorecards across review periods
  • Offboarding with data-return verification
SIG / CAIQ Concentration Risk
Change Advisory Board with pending approvals, conflict alerts, and blackout windows

Change Management

One lifecycle for every change — regulatory, software, infrastructure, policy, and organisational.

  • Unified Change Advisory Board across all change types
  • Regulatory change scanning with obligation impact
  • Cascade detection — one change triggers its dependents
  • AI-assisted impact analysis & risk prediction
  • Release management aligned to ITIL 4
ITIL 4 AI Impact Analysis
Ethics and Corporate Governance dashboard with cases, disclosures, and culture score

Ethics & Corporate Governance

The conduct layer of your control environment — from code of conduct to board committees.

  • Anonymous whistleblower hotline with encrypted reporting
  • Conflict-of-interest & gifts-and-entertainment registers
  • Board & committee management with minutes and actions
  • Governance-code tracking (incl. King IV template)
  • Case management for ethics investigations
Whistleblower King IV
Executive report package with review, approval, and publish workflow

Executive Reporting & Analytics

Board-grade reporting across every domain, on one indicator registry.

  • Board & executive report packages with approval workflow
  • Configurable dashboards with heat maps and trend widgets
  • Cross-domain KRI/KPI indicator registry
  • Internal & peer benchmarking
  • Scheduled distribution to Email, Teams & SharePoint
Board Packs Benchmarking
Evidence Requests screen with request campaigns and a fulfilment work queue

Document & Evidence Hub

The authoritative home for GRC evidence — from formal request campaigns to court-admissible chain of custody.

  • Central evidence registry with SHA-256 integrity chains
  • Evidence request campaigns with a fulfilment work queue
  • Immutable chain-of-custody and full version history
  • Retention policies with legal hold
  • One record links across audits, risks, controls & policies
SHA-256 Integrity Request Campaigns
Planner Kanban board with GRC-linked tasks across Backlog, To Do, In Progress, Review and Done

Planner

Personal and team work management — Kanban, list, Gantt, and sprint boards, natively linked to your GRC data.

  • Kanban, list, Gantt & sprint views with drag-and-drop
  • Tasks linked to audit findings, controls, risks & vendors
  • Real-time collaboration with comments, @mentions & watchers
  • Subtasks, dependencies, checklists, story points & time tracking
  • Project templates and an embedded ExAI assistant
Kanban & Gantt GRC-Linked

Upscaled Productivity

Productivity modules at roughly 95% completion — rolling out on the same platform foundation. Ask us about early access.

Event & Issue Management

Incident intake and triage, ITIL-style problem management, and corrective action plans — with AI-assisted root-cause analysis using 5-Whys, fishbone, and fault-tree methods.

ITIL AI Root Cause

Business Continuity & DR

Business impact analysis with RTO/RPO targets, versioned recovery plans, exercise management, and dependency mapping — aligned to ISO 22301, NIST SP 800-34, and DORA.

ISO 22301 DORA

Training & Awareness

Role-based training programs, assessment engine with proctoring, learning paths, and QR-verifiable digital certificates — mapped to NIST, ISO 27001, PCI DSS, and HIPAA training requirements.

Assessments Certificates

Legal & Contract Management

Contract lifecycle from draft to termination with per-clause obligation tracking, multi-stage reviews, amendment versioning, and renewal automation.

CLM Obligations

On the Roadmap

Designed and specified — coming to the platform next.

ESG & Sustainability

GRI, SASB, ISSB (IFRS S1/S2), CSRD/ESRS, and TCFD reporting with cross-standard mapping — report once, satisfy many.

Pen Testing & Vulnerability

Ingest findings from Nessus, Qualys, and Burp; AI triage and deduplication; SLA-driven remediation tracking.

SBOM Governance

CycloneDX and SPDX ingestion, component-to-vulnerability matching, and license compliance for your software supply chain.

The Established Core

The audit and GRC foundation everything else builds on.

See the Full Platform in Action

One integrated data model across every module — risks, controls, evidence, and reporting that finally agree with each other.