App family

Governance, risk and compliance

The registers a Company Secretary, General Counsel, Chief Risk Officer and Head of Internal Audit carry — as governed data with owners, dates and evidence, instead of spreadsheets that disagree. Nine apps that share the same entities, the same people and the same organisation structure, so a risk, an incident, a control, a policy and an obligation can point at each other.

Who it's for

Written for the people who carry this

The Company Secretary

The entity register is a spreadsheet, and the copy in the board pack disagrees with the one on the laptop. Appointments, shareholdings, resolutions and filings need one statutory record that can prove a decision was properly made.

The General Counsel

Who may approve what, up to which limit, in which part of the group, lives in a PDF nobody is sure is current. Conflicts, gifts, insider lists and whistleblowing cases each need a register that is as careful about who can see it as what it says.

The Chief Risk Officer

Each division keeps its own risk register in its own format and the group view is assembled by hand every quarter. Incidents are logged somewhere else and never link back to the risk that predicted them or the control that failed.

The apps

9 apps, one model underneath

Entity governance

Corporate governance for the legal entities you own: who is appointed to which office, who holds the shares, which boards and committees exist, what they resolved, and what has to be filed with the regulator. Use it to keep the statutory record straight and to prove, later, that a decision was properly made.

Appointments · shareholdings · governance bodies · resolutions and approvals · statutory filings

Delegations of authority

Who is allowed to approve what, up to which limit, for which part of the organisation. It is the delegation of authority as data rather than a PDF, so approval requests can be checked against it automatically instead of relying on someone remembering the schedule.

Authority types · delegations, effective-dated and scoped to the organisation tree

Risk management

The risk register and the controls that manage it: what could go wrong, how likely and how bad it would be, what you are doing about it, and the indicators that warn you when exposure is moving. Use it to make risk a maintained record with owners and dates rather than an annual workshop.

Risk categories · risks · controls · treatments · key risk indicators and readings

Compliance obligations

The regulations you are subject to, the specific obligations they place on you, and the periodic attestations that confirm you are meeting them. Use it to turn 'we comply with X' into a list of named duties with owners and evidence behind each one.

Regulations · obligations · attestation campaigns · attestations

Incident management

The incident register: what went wrong, what nearly went wrong, what was done about it, and what had to be reported to a regulator. Incidents link back to the risks that predicted them and the controls that failed, which is what turns an event log into something that improves the control environment.

Incident categories · incidents · actions · regulatory notifications

Sensitive registers

The registers that have to exist and have to be handled carefully: conflicts of interest, gifts and hospitality, insider lists, and whistleblowing cases. They are grouped together because they share one property — the record itself is sensitive, and who can see it is as important as what it says.

Conflict-of-interest declarations · gift declarations · insider lists · whistleblowing cases

Insurance management

Your insurance programme as data: which policies are in force, what they cover, which entities they name, when they renew, and the claims made against them. Use it so nobody discovers at renewal that a subsidiary was never added, or at claim time that the deductible was higher than assumed.

Insurance policies · claims, born from incidents

Internal audit◦ early access

Internal audit end to end: the annual plan, the engagements it produces, the findings they raise and the agreed actions that close them out. Use it to run a risk-based plan and to show that findings are followed through to independently verified completion rather than simply reported.

Audit plans · engagements · findings · actions

Policy management◦ early access

The policy library: policies, standards, procedures and guidelines, each with an owner, an approval, a review cycle, and links to the obligations and risks it addresses. Use it so people can find the current version of a policy, and so you can show which policy answers which regulatory duty.

Policies · policy exceptions

◦ Early access: in the catalogue now and installed for design partners first; general availability follows as partners put it to work.

How it connects. Contracts (legal and contracts) record who signed under which delegation. Insurance claims can name the asset involved (operations). Recurring obligations — renewals, reviews, attestations — raise tasks on schedule through the platform.

Why one model

One person. Many contexts. One record.

A director is appointed in entity governance, holds a delegation, owns a risk, declares a conflict and attests to an obligation. On Zubl that is one person record, seen through five apps, scoped to whoever is looking. An incident links to the risks that predicted it, the controls that failed and the policy that should have prevented it — because they are records in one system, not rows in five.

Not quite your shape?

Extend these apps, or build the one you need.

Every app here is open to extension on the same licence: a field, a lifecycle state, a link to a record in another family, a rule. Additions sit beside our definition and survive every upgrade.

And if the register your organisation needs is not here, describe it to the AI builder. It arrives governed — same access engine, same audit trail, same reports — because those belong to the platform, not to the app.

Extending and building →

We're working with design partners now.

A small number of organisations shaping the first release, in exchange for early access, direct influence over what ships next, and pricing that reflects the risk of going first.