Skip to content
Sentinel Unity

Compliance

Scored against written descriptors, not opinion

Every question in the library defines what each maturity level means in words. Two assessors reading the same descriptor reach the same number, and an auditor can see why.

  • Six maturity levels, 0 to 5, each with a written definition per question
  • Assessment templates with reusable template questions
  • Evidence files attached to responses and reused across frameworks
  • Delegation, so the person who knows the answer records it

Level 3: Well Defined

A standard process is defined and followed across the organisation.

Every question in the control library carries its own written descriptor at each level.

Scoring

A defined ladder from Not Performed to Continuously Improving

Level 0 is Not Performed; level 5 is Continuously Improving. The intermediate levels, Performed Informally, Planned & Tracked, Well Defined, Quantitatively Controlled: are what make a score defensible.

  • Descriptors authored per question, not per framework
  • The same control assessed once, reported against every framework mapped to it
  • Maturity assessed per framework where standards demand different depth
  • Responses carry comments and attachments for reviewer context

Control

Privileged access is reviewed each quarter by the system owner

PeopleProcessTechnologyDataFacility

PPTDF applicability

One owner · one procedure · one evidence trail

Scope

Assessments that know where they apply

An assessment links to departments, locations, and policies, so scope is explicit and a result can be attributed to the part of the organisation it describes.

  • Department, location, and policy links per assessment
  • Delegation with the delegation itself recorded
  • Comment threads with attachments
  • Evidence held once and referenced by every mapped requirement
  • PaymentsDomain
    • Card acquiringCapability3 risks2 policies
      • Merchant settlementService4 controls2 assets
        • Daily reconciliationProcess1 risk2 controls1 finding

Every level links out to risks, controls, policies, findings, assessments, and assets

Framework alignment

Works with your control frameworks

This module shares the platform control library. Map national frameworks and global standards alongside jurisdiction-specific authorities.

See compliance management in your environment

A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.