About GRC Lab

Built by Practitioners.
For Practitioners.

GRC Lab was born out of a simple observation: Azerbaijan's financial institutions were managing complex CBAR and ISO compliance requirements using spreadsheets, email threads, and disconnected documents. We built the solution we always wished existed.

405

CBAR Requirements Covered

3

Audit Frameworks

600+

Controls & Implementation Guides

Our Story

From the audit table
to your browser

GRC Lab was founded by information security professionals with deep hands-on experience in Azerbaijan's financial sector. The problem was always the same: institutions were managing complex CBAR and ISO compliance requirements using spreadsheets, email threads, and disconnected documents.

Teams would scramble to map requirements to spreadsheets, recreate implementation guides from memory, and produce compliance reports manually. The process was slow, error-prone, and entirely dependent on the knowledge of one or two individuals.

GRC Lab was created to encode that institutional knowledge into a structured, multi-user platform — so that any compliance team, regardless of experience level, can conduct a rigorous audit with confidence.

Azerbaijan-First Design Built around CBAR's specific cybersecurity regulatory framework — not adapted from a generic Western GRC tool.
Built by Auditors, Not Vendors Every feature, every guide, every risk assessment field reflects real audit experience — not theoretical compliance theory.
Privacy by Design Each user's audit data is fully isolated. No shared data, no third-party analytics, no advertising.
Platform milestones
Problem Identified
Financial institutions across Azerbaijan spending weeks manually preparing for CBAR and ISO audits with no dedicated tooling.
Platform Built
GRC Lab developed from the ground up — 405 CBAR requirements, 93 ISO controls and 106 NIST controls pre-loaded with implementation guides.
Multi-User & Analytics
Full multi-user isolation, live analytics dashboards, and professional PDF / Excel / CSV export added across all three frameworks.
GRC Lab Launched
Azerbaijan's first dedicated information security management platform — live at grclab.net and growing.
Mission & Values

What We Stand For

Six principles that shape every decision we make — from platform features to how we support our users.

Precision

Every CBAR requirement, every ISO control, every NIST subcategory is mapped accurately. No shortcuts, no approximations. Compliance is too important for "close enough."

Transparency

We show you exactly where you stand — compliant, partial, or non-compliant — with no ambiguity. Clear dashboards, clear risk levels, clear export data.

Accessibility

Compliance expertise should not be locked inside one person's head. GRC Lab makes institutional knowledge available to every member of your team, regardless of experience.

Privacy

Your audit data is yours. We do not sell it, share it, or monetise it. Each user's data is isolated by design — not as an afterthought.

Continuous Improvement

Regulatory requirements evolve. So does the platform. We continuously update frameworks, add features, and refine guidance based on real audit cycles and user feedback.

Local Expertise

We are not a global vendor adapting a foreign product for Azerbaijan. We are an Azerbaijani platform, built specifically for Azerbaijani regulations and the institutions that must comply with them.

The Platform

What GRC Lab Delivers

Three complete audit frameworks, live analytics, and professional reporting — all in one platform, all scoped per user.

CBAR
405

CBAR Audit Requirements

Full database-backed audit of all Central Bank of Azerbaijan cybersecurity requirements. Status, risk, evidence, notes and target dates per requirement.

ISO 27001
93

ISO 27001:2022 Controls

All Annex A controls across Organizational, People, Physical and Technological domains. Risk register and step-by-step implementation guide per control.

NIST CSF 2.0
106

NIST CSF 2.0 Controls

All subcategory controls across Govern · Identify · Protect · Detect · Respond · Recover. Full audit workflow with function-level scoring.

Analytics
4

Live Chart Types Per Framework

Compliance Status · Risk Distribution · Category/Function Breakdown · Implementation Progress — updated in real time as you assess controls.

Reports
3

Export Formats

PDF reports (Executive Summary, Detailed, Gaps), multi-sheet Excel workbooks, and flat CSV files — all ready for regulatory submissions or board presentations.

Multi-User
3

Access Roles

Admin · Auditor · Viewer. Each user's audit data is fully isolated — assessments, risk records, module preferences and evidence files are private per account.

Ready to Get Started?

Start Your Compliance Journey

Join financial institutions across Azerbaijan using GRC Lab to manage CBAR, ISO 27001:2022 and NIST CSF 2.0 audits in one platform.