Regulatory compliance
Your compliance proven, not merely declared.
KRIogene maps your regulatory obligations to your controls, and each control feeds a timestamped piece of evidence. You no longer tick boxes: you demonstrate control.
Regulatory compliance
KRIogene maps your regulatory obligations to your controls, and each control feeds a timestamped piece of evidence. You no longer tick boxes: you demonstrate control.
The Obligations module
In most organisations, compliance is kept in registers separate from the control framework. When the auditor asks for evidence, it has to be reconstructed — sometimes from scratch.
KRIogene transforms this logic. Each regulatory obligation is linked to one or more controls in an N:M relationship (one control can prove several obligations; one obligation can be proven by several controls).
A single, well-designed control can cover several obligations. You reduce the workload without sacrificing coverage.
Each control execution automatically becomes obligation evidence, timestamped and traced.
On demand, you present the full chain obligation → control → execution evidence, with no manual reconstruction.
Regulatory changes are integrated by our teams and propagated automatically to your framework.
Key Differentiator
Identifying which regulations may apply to your organization is a complex process: it depends on your industry, size, revenue, jurisdiction, activities, and third-party exposure. Most tools leave this analysis entirely to people, increasing the risk of oversight.
KRIogene helps you assess regulatory applicability based on the characteristics you provide about your legal entity.
Criteria considered
Based on these characteristics, the engine helps identify potentially applicable regulations and the expected controls to support compliance.
Frameworks
KRIogene embeds both major cross-cutting frameworks and the standards specific to each sector. They are organised by domain and kept current through the built-in regulatory watch — from risk management to cybersecurity, from finance to sustainability.
Governance, risk & internal control
Information security & cyber resilience
Personal data & privacy
Finance, banking & insurance
Ethics, anti-corruption & sustainability
Quality, environment, health-safety & operations
Non-exhaustive list. New frameworks are added continuously; standards specific to your sector can be integrated on request.
Every sector
KRIogene is not verticalised on a single business. Its applicability logic builds on the European activity nomenclature (NACE, from which the French NAF derives): whatever your activities, the engine maps your obligations to the 21 sections of the framework. The standards cited below are illustrative examples — the system automatically computes your real scope.
CAP, ISO 14001, duty of vigilance, CSRD
Seveso / ICPE, ISO 14001, CSRD, EU taxonomy
ISO 9001, ISO 14001, CE marking, REACH
NIS2, DORA, ISO 50001, EU taxonomy
NIS2, ISO 14001, waste regulations
RE 2020, ISO 45001, Eurocodes, duty of vigilance
GDPR, PCI DSS, consumer law
NIS2, ISO 28000, ADR, GDPR
HACCP, public-venue safety, GDPR
GDPR, NIS2, DORA, AI Act, ISO 27001
DORA, Basel III/IV, Solvency II, AML/CFT, MiFID II
AML/CFT, Sapin II, GDPR, CSRD
GDPR, Sapin II, AI Act, professional secrecy
GDPR, ISO 27001, labour law
RGS, NIS2, SecNumCloud, GDPR
GDPR, digital accessibility (RGAA), public-venue safety
HDS, GDPR, ISO 13485, HAS certification
Public-venue safety, copyright, GDPR
GDPR, dedicated sector standards
Labour law, GDPR
International conventions, GDPR
Sections A to U of the NACE Rev. 2 nomenclature (the European statistical classification of economic activities). KRIogene covers every sector; the obligations actually applicable depend on your size, jurisdiction and exposure, and are determined by the applicability engine.
Frameworks × modules mapping
For each framework covered, KRIogene links the expected workflows to its modules. Here is the mapping, domain by domain.
| Framework | Domain | Workflows concerned | KRIogene modules |
|---|---|---|---|
| Governance, risk & internal control | |||
| ISO 31000 | Risk management | Mapping, register, treatment plans | Risks, Scenarios, Actions |
| COSO ERM | Risk management | ERM framework, risk appetite | Risks, Controls, Campaigns |
| COSO IC | Internal control | Control framework, effectiveness testing | Controls, Campaigns, Audit |
| ISO 37000 | Governance | Roles, accountability, steering | Obligations, Controls, Audit |
| IIA / IFACI | Internal audit | Audit programme, follow-up of recommendations | Audit, Actions |
| ISO 19011 | Management-system audit | Audit plans, evidence, findings | Audit, Controls, Actions |
| Information security & cyber resilience | |||
| ISO/IEC 27001 | Information security | ISMS, Annex A controls, incidents | Risks, Controls, Incidents, Obligations |
| ISO/IEC 27002 | Information security | Implementation and evidence of measures | Controls, Campaigns |
| ISO/IEC 27005 | Information-security risks | Security risk assessment | Risks, Scenarios |
| NIS2 | Cybersecurity | Cyber risk management, notification | Risks, Controls, Incidents, Obligations |
| DORA | Operational resilience | IT risks, testing, third-party management | Risks, Controls, Scenarios, Obligations |
| NIST CSF | Cybersecurity | Identify · Protect · Detect · Respond · Recover | Risks, Controls, Incidents |
| ISO 22301 | Business continuity | BIA, continuity plans, testing | Scenarios, Controls, Actions |
| SecNumCloud | Cloud qualification | ANSSI requirements, evidence collection | Controls, Obligations, Audit |
| PCI DSS | Payment data | Requirements, scans, compliance evidence | Controls, Obligations, Incidents |
| IEC 62443 | Industrial cybersecurity (OT) | Zones & conduits, OT risks | Risks, Controls |
| Personal data & privacy | |||
| GDPR | Data protection | Register, DPIA, rights, retention | Obligations, Controls, Incidents |
| ISO/IEC 27701 | Privacy | Personal-data management system | Obligations, Controls, Audit |
| ISO/IEC 27018 | Data in the cloud | Cloud personal-data protection | Controls, Obligations |
| HDS | Health data | Hosting requirements, evidence | Obligations, Controls, Audit |
| Finance, banking & insurance | |||
| Basel III & IV | Banking | Prudential controls, operational risks | Risks, Controls, Obligations |
| Solvency II | Insurance | ORSA, Pillar 3 reporting | Risks, KRI, Obligations |
| MiFID II | Financial markets | Product compliance, reporting | Obligations, Controls |
| AML/CFT | Anti-money laundering | Due diligence, alerts, reporting | Risks, Controls, Incidents |
| SOX | Financial control | ITGC controls, testing, attestations | Controls, Campaigns, Audit |
| IFRS | Accounting | Financial-reporting controls | Controls, Obligations |
| Ethics, anti-corruption & sustainability | |||
| Sapin II | Anti-corruption | Mapping, controls, alerts | Risks, Controls, Incidents |
| ISO 37001 | Anti-corruption management | Anti-corruption framework, due diligence | Risks, Controls, Audit |
| CSRD / ESRS | Sustainability | Sustainability reporting, indicators | Risks, KRI, Campaigns |
| CS3D | Duty of vigilance | Due diligence across the value chain | Risks, Controls, Actions |
| EU taxonomy | Sustainable activities | Eligibility / alignment, evidence | Obligations, Controls |
| ISO 26000 | Social responsibility | CSR commitments, stakeholders | Obligations, Actions |
| AI Act | AI governance | AI risk classification, compliance | Risks, Obligations, Controls |
| Quality, environment, health-safety & operations | |||
| ISO 9001 | Quality | Processes, non-conformities, corrective actions | Controls, Actions, Incidents |
| ISO 14001 | Environment | Aspects / impacts, regulatory compliance | Risks, Controls, Obligations |
| ISO 45001 | Occupational health & safety | Hazards, incidents, actions | Risks, Incidents, Actions |
| ISO 50001 | Energy | Energy performance, reviews | Controls, KRI, Actions |
| ISO 13485 | Medical devices | Process control, traceability | Controls, Audit, Incidents |
| COBIT | IT governance | IT controls, access management | Controls, Audit |
| ITIL | Digital services | Incident and change management | Incidents, Actions, Controls |
| BPMN 2.0 | Process / BPM | Workflow modelling, versioning | Risks, Controls |
Artificial intelligence
KRIogene's conversational AI gives access to your compliance status without complex navigation.
Example queries
“Which GDPR controls are overdue?”
“Give me the NIS2 coverage status”
“Which obligations apply to our new Italian subsidiary?”
“List the DORA-notifiable incidents from last quarter”
Compliance = Credibility
Proven compliance strengthens your credibility with regulators, partners, clients and investors. It reduces your audit cost, speeds up your tenders and secures your partnerships.
KRIogene turns your compliance from a cost centre into a strategic asset.
A personalised demo on your regulatory context, in 45 minutes.
Book a demo