FREQUENTLY ASKED QUESTIONS
What is Digital Compliance & Governance?
Digital Compliance & Governance is the use of technology, structured processes and governance practices to help organisations manage regulatory requirements, policies, controls, risks, documentation, responsibilities and compliance activities more effectively.
Nexbridge combines these principles with digital systems and platforms such as ISO360 to help organisations establish more structured compliance environments.
What is ISO360?
ISO360 is Nexbridge’s digital compliance management platform. It is designed to help organisations manage frameworks, assessments, controls, risks, evidence, corrective actions, policies, reviews and reporting through a centralised environment.
Is ISO360 only for ISO 27001?
No. ISO360 is being developed around a framework-agnostic architecture.
ISO 27001 is an initial framework implementation, with the platform designed to support additional standards, regulations and governance requirements over time.
Can ISO360 support POPIA?
ISO360 can be structured to support POPIA-related compliance management activities, including requirements, assessments, responsibilities, documentation, actions and evidence.
The specific legal interpretation and application of POPIA should be determined with the organisation’s appropriate legal or privacy professionals.
Can ISO360 support multiple frameworks?
Yes. The platform is designed to allow organisations to manage different frameworks and requirements within a structured compliance environment.
This can help organisations avoid maintaining completely separate systems for every compliance requirement.
Can Nexbridge help us prepare for ISO certification?
Nexbridge can assist organisations with readiness assessments, gap identification, control implementation support, documentation, evidence management, corrective actions and audit preparation.
Nexbridge does not act as the independent certification body. Formal certification is performed by our independent partner.
Can Nexbridge build a custom compliance platform?
Yes.
Where ISO360 does not meet a specific organisational requirement, Nexbridge can design and develop custom compliance and governance solutions around an organisation’s processes, systems and requirements.
Can compliance activities be automated?
Yes. Repeatable activities such as reminders, reviews, approvals, notifications, task assignments, escalations and reporting can be digitally managed or automated where appropriate.
Automation should be implemented with appropriate controls and human oversight.
Can ISO360 manage evidence?
Yes. Evidence management is a core component of the platform approach.
Organisations can maintain structured records of supporting documentation and associate evidence with relevant compliance requirements, controls, assessments or activities.
Can ISO360 manage risks?
Yes. Risk management can be incorporated into the compliance environment, allowing organisations to identify, assess, assign and monitor risks and connect them with appropriate treatment actions.
Can ISO360 help with audit readiness?
Yes.
ISO360 is designed to provide a structured record of compliance activities, controls, evidence, risks, corrective actions and reviews, helping organisations prepare for internal or external assessments.
The platform supports readiness management; it does not replace an independent audit or certification process.
Is Digital Compliance & Governance suitable for regulated organisations?
Yes.
Organisations operating in regulated or highly controlled environments can benefit from structured compliance processes, centralised documentation, controlled access, audit trails, risk management and management reporting.
Nexbridge designs solutions around the organisation’s specific requirements and operating environment.
How do we get started?
Nexbridge begins by understanding your current systems, processes, compliance requirements and objectives.
We can then identify gaps, opportunities for digital improvement and the appropriate technology approach.
Depending on your requirements, this may include a compliance assessment, digital roadmap, ISO360 implementation or a custom compliance and governance solution.