NewThe AI Consultant plans and drafts your whole ISO 27001 cycle.Read more
Skip to content
New · AI Consultant

Evidence once.Confidence always.

Thirteen frameworks in one workspace — ISO 9001, ISO 27001, SOC 2, PCI DSS and more — with a genuine cross-walk between them, embedded AI, and an AI consultant that plans the work. A human signature on every record.

  • UK / EU data residency
  • Self-host option
  • SSO / SAML

ISO 9001

Quality readiness

Audit-ready0%

35

Clauses

8

Objectives

3

Open CAPAs

Management review auto-assembled its inputs from audits, CAPAs and objectives.

Needs attention

  • Overdue management review1
  • Evidence expiring (30d)2

AI readiness

9.3Management review inputs are complete and evidenced. Ready

A quality engineer reviewing operations on a tablet
One register
Every framework reads the same evidence
Signed off
A named human approver on every record

Built by the teams behind Obligara

  • GeminiSense
  • Innovative
  • Bold
  • Idhammar
  • Manos

Why Obligara

One source of truth for quality, security and trust

Most teams bolt a SOC 2 tool onto a spreadsheet QMS and a separate ISMS. Obligara is one workspace where the frameworks share evidence and reinforce each other.

A quality lead carrying out an on-site inspection

Every framework, one workspace

Run ISO 9001, ISO 27001, SOC 2, Cyber Essentials and sector schemes like NSI on the same process map, the same documents and the same audit trail — instead of separate tools and a folder of spreadsheets.

Colleagues reviewing a report together at a desk

The ISO 27001 → SOC 2 cross-walk

Enable SOC 2 and 71 mappings carry your existing ISO 27001 control evidence onto the Trust Services Criteria. Evidence once, satisfy everywhere — weeks of duplicate work removed.

An AI system, shown as a robotic hand touching a neural network

AI that does the work, not theatre

Gap analysis, readiness verdicts, mapping suggestions and form drafting — all inside your row-level-security boundary. The AI reads and drafts; a person reviews and signs off every save.

Frameworks

Thirteen frameworks, modelled properly

Not checklists bolted onto a generic tool. From ISO 9001, ISO 27001 and SOC 2 to PCI DSS, ISO 42001 and ISO 45001, each framework is instantiated with its real clauses, controls and criteria — and they all share the same evidence.

A quality inspection being carried out on the operations floor
ISO 9001:2015

A living quality system, not a binder.

The QMS module is auto-enabled on every new workspace. 35 clauses and roughly 120 audit questions, quality objectives with per-period measurements, a visual process map, and management reviews that pull live data from the rest of the workspace.

35
clauses modelled
~120
audit questions
Auto
enabled on new orgs
  • Quality objectives & measurements
  • Process map as the spine
  • Management reviews
  • Internal audit wizard
Explore the ISO 9001 module

The workspace

Everything a working compliance programme needs

The modules a real QMS/ISMS uses day to day — all linked back to your processes and one shared audit trail.

Process map

A visual flowchart that links risks, documents and CAPAs to the processes they belong to.

Document control

Versioned documents with an approval workflow and a distribution log. Uploaders can’t self-approve.

CAPAs & non-conformance

Corrective and preventive actions, non-conformances and complaints with root-cause and action plans.

Internal audit wizard

Framework-aware: setup → clauses → walkthrough → findings, with programmes for the multi-year schedule.

Evidence store

Typed uploads with expiry tracking and polymorphic links to the controls and criteria they support.

Competency matrix

Employees × skills × level, so training and competence evidence is structured, not anecdotal.

Management reviews

Reviews that assemble live inputs from every module, with linked actions tracked to closure.

Multi-framework cross-mappings

One control maps to many criteria across every framework — ISO 27001 to SOC 2, PCI DSS, CSA STAR, the EU AI Act and more. Evidence once, satisfy everywhere.

Import your registers

Bring your existing risk, CAPA and complaints registers — CSV or Excel — with AI that maps the columns for you. Switch off the spreadsheets in an afternoon.

Supplier performance

Periodic, dated scorecards per supplier — on-time delivery, quality and support — so vendor reviews are evidenced against ISO 9001 cl. 8.4 and ISO 27001 A.5.22, not remembered.

Public Trust Center

Publish your posture, certifications and policies on a branded page — with gated access and an AI assistant that answers only from what you’ve published.

Embedded AI

AI across the workflow — not a chatbot bolted on the side

Five AI surfaces, all opt-in per workspace, all bound by the same row-level security as the rest of the app. They draft and assess; you stay accountable for what gets saved.

  • Chat assistant

    Answers questions against your live workspace.

    Read-only tools walk your QMS inside the same row-level-security boundary as the rest of the app. It cites record references (CAPA-012, RISK-007) that link straight to the detail page — no vector-search-and-pray.

  • AI gap analysis

    Verdicts each control as ready, partial or gap.

    Per-control verdicts with the cited evidence references behind them, so you can see what is covered and what still needs work before an audit.

  • AI readiness analyser

    Narrative readiness, criterion by criterion.

    Per-criterion narrative verdicts for SOC 2 readiness, persisted as snapshots so you can track how readiness moves over time.

  • AI mapping suggester

    Proposes control → TSC criteria mappings.

    Suggests how each ISO 27001 control maps to SOC 2 Trust Services Criteria — one control at a time, or in bulk across the set.

  • AI form-fill assists

    Drafts the long fields for a human to approve.

    CAPA root-cause, risk treatments, management-review inputs and the SOC 2 system description — drafted from your live data, then edited and signed off by a person.

Why it’s trustworthy

  • Read-only tools, not freeform retrieval

    The assistant calls typed functions that hit the database inside your row-level-security context. It reads what you can read — nothing more.

  • AI cannot mutate your records

    Every assist fills a form for a human to review and save. The audit log only ever records a person’s signature, never the model’s.

  • Shaped output, not loose text

    Structured suggestions run a tool-using research pass and a schema-bound generation pass, so output is always shaped and checkable.

Every AI suggestion is labelled “AI-suggested — you remain accountable for the final answer.” Trust by design, not by disclaimer.
How the AI works

The wedge

The ISO 27001 → SOC 2 cross-walk, in about 60 seconds

Enable SOC 2 on a workspace that already has ISO 27001 and 71 mappings carry your control evidence straight onto the Trust Services Criteria. Watch one control light up the criteria it satisfies.

71
mappings
~3 wks
work removed
1
evidence set
Cross-walk

ISO 27001

SOC 2 — TSC

CC6.1CC6.2CC6.3
Evidence carried across

Access control policy · joiner/leaver records · quarterly access reviews

Who it’s for

Built for the teams walking the framework journey

Mid-market service organisations that have outgrown spreadsheets or hit a customer-driven audit requirement.

A compliance team reviewing their programme together

Head of Quality

ISO 9001-led, growing into ISO 27001

You run a mature QMS and now customers want security assurance too. Add ISO 27001 on the same process map and audit trail you already trust.

ISMS Lead

Head of Information Security at a growth-stage SaaS

You own ISO 27001 and the Statement of Applicability. Instantiate all 93 Annex A controls per workspace and stop maintaining the SoA in a spreadsheet.

CTO / VP Engineering

Series A–C SaaS hitting SOC 2 for US enterprise sales

A big customer needs a SOC 2 report to close. If you already have ISO 27001, the cross-walk gets you most of the way; if not, start with the 40-control starter pack.

Compliance consultancy

ISO lead-implementer / reseller

You implement frameworks for a portfolio of clients. Run them all in one tool, reuse evidence across frameworks, and join the partner programme.

See it on your own frameworks

A 30-minute walkthrough on your QMS, ISMS or SOC 2 scope — no slideware, just the workspace.