Compliance manager reviewing a control register on a laptop
Secure Chain Horizon

Compliance management software that keeps evidence where you can find it.

Horizon holds your risk register, controls, evidence and supplier records in one UK-hosted platform, with owners, review dates and audit trails attached, so nothing is only in one person's inbox or one spreadsheet tab.

Frameworks mapped
2+
Evidence items tracked
1
Access levels
role
Illustrative figures
The challenge

Spreadsheets drift, and nobody notices until an auditor asks.

Most organisations start their compliance work in a spreadsheet, and for a while that's fine. The problem shows up as the programme grows: a risk register held by one person, a controls list held by another, evidence for last year's penetration test sitting in someone's downloads folder, and a supplier list that hasn't been touched since the person who built it left the business. Nobody set out to create this, it just accumulates.

The cost of that drift is usually invisible until it isn't. An ISO 27001 surveillance audit asks for evidence a control is operating, and the file that was supposed to prove it is three versions out of date, or was never uploaded anywhere central at all. A client due diligence questionnaire asks who owns third-party risk, and the honest answer is 'it depends who you ask'. A board asks for the current risk position and gets a summary that's several weeks stale because pulling it together takes half a day.

Version control is a particular pain point. When a policy, a risk assessment or a piece of evidence is updated, does everyone using it know which copy is current? In a shared drive, usually not — older versions get emailed around, referenced in old meeting minutes, and quietly contradict the newer one. That's a genuine audit finding waiting to happen, not just an inconvenience.

Ownership is the other recurring gap. A risk register with no named owner against each entry tends to stop being reviewed. A control mapped to nobody in particular doesn't get maintained when the underlying technology or process changes. Review dates written into a spreadsheet cell don't send a reminder; they just sit there until someone happens to scroll past them, usually too late.

None of this reflects a lack of effort. It reflects tools that were never built for ongoing compliance management — spreadsheets are good at capturing a snapshot, not at tracking accountability and expiry over years, across multiple frameworks, with several people contributing at once.

  • Risk registers and controls held by different people in different files
  • Evidence out of date without anyone noticing until it's requested
  • No single view of who owns what, or when it's due for review
  • Board and client reporting assembled manually each time it's asked for
Our approach

One platform, with owners, dates and evidence attached.

Horizon gives your risk register, controls, evidence library, supplier register and remediation tracking a shared home, with each item held to the same discipline: a named owner, a review or expiry date, and a version history so you can see what changed and when. That structure doesn't remove the need for judgement — it just stops the judgement getting lost.

Controls are mapped to Cyber Essentials and to ISO 27001:2022 Annex A, so where a single control genuinely satisfies both frameworks, you record and evidence it once rather than maintaining two parallel spreadsheets that inevitably fall out of sync with each other over time.

The evidence library is built around expiry, not just storage. Policies, certificates, test reports and supplier assurances each carry a review date, and Horizon surfaces items approaching that date so someone can act before an auditor, insurer or client finds the gap first. Version history means you can also see the previous state of a document, which matters when an auditor asks what changed and why.

Remediation tracking closes the loop between finding an issue and fixing it. Actions raised from a risk assessment, an internal audit or a penetration test sit against the same register, with owners and target dates, so they don't quietly disappear into a separate action log that nobody revisits.

Role-based access means control owners see and update their own area, executives view dashboards and board reports without needing to touch the detail, and our consultants can be given the appropriate access during an engagement without you having to email documents back and forth.

  • Single register for risk, controls, evidence and suppliers
  • Owners and review dates attached to every item, not left implicit
  • Controls mapped once across Cyber Essentials and ISO 27001:2022
  • Version history so you can show what changed, and when
What's included

Everything in the engagement, set out up front.

What's set up when Horizon is introduced as your compliance management platform.

Risk register configuration

Your risks structured with scoring, named owners and review dates, migrated from existing spreadsheets where they exist.

Control library mapping

Controls mapped to Cyber Essentials and ISO 27001:2022 Annex A, so shared controls are recorded once.

Evidence library setup

Policies, certificates and reports uploaded with expiry dates and version history from day one.

Supplier and third-party register

Key suppliers recorded with assurance status and review cycles, replacing an ad-hoc contact list.

Remediation tracking

Open actions from audits, assessments and tests brought into one tracked list with owners and dates.

Dashboard and reporting setup

Executive dashboards and exportable board reports configured to reflect the metrics that matter to your leadership.

Deliverables

What you receive.

  • Configured risk register with scoring and ownership
  • Control mapping across Cyber Essentials and ISO 27001:2022
  • Populated evidence library with expiry reminders active
  • Supplier and third-party register
  • Remediation tracker with open actions assigned
  • Role-based access configured for your team
  • Executive dashboard tailored to your reporting needs
  • Exportable board report template
  • Onboarding session for control owners
Who it suits

Built for organisations that need the work done properly.

Organisations outgrowing spreadsheets

Compliance programmes that have grown past what a shared spreadsheet and a shared drive can reliably hold together.

Businesses holding multiple certifications

Firms maintaining Cyber Essentials alongside ISO 27001 work who want shared controls evidenced once, not twice.

Teams preparing for their next audit

Organisations that want evidence organised and current well before an internal audit or certification renewal date arrives.

Compliance leads reporting to a board

Individuals responsible for pulling together board-level compliance reporting who want that to take minutes, not days.

Outcomes & benefits

What changes once the work is done.

What a compliance lead notices changes once the register is centralised.

One current view, not several old ones

Risk, controls, evidence and suppliers held in one place, with the current version always the one people see.

Fewer surprises at audit time

Evidence expiry reminders mean documents are refreshed ahead of the audit, rather than discovered stale on the day.

Ownership that's actually visible

Every risk and control has a named owner, so accountability doesn't rely on institutional memory.

Board reporting in minutes, not days

Executive dashboards and exportable reports remove the manual pull-together exercise before each meeting.

Shared effort across frameworks

Controls mapped once against Cyber Essentials and ISO 27001:2022 reduce duplicated evidencing work.

A clearer handover between people

Version history and structured ownership make it easier when a role changes hands or a consultant steps in.

Horizon organises the work; it doesn't do the thinking for you.

It's worth being direct about what compliance management software is and isn't. Horizon will not decide your risk appetite, write your control narrative, or tell you whether a supplier's response to a security questionnaire is good enough — those are judgement calls that still need a person with the right knowledge. What it does is make sure that judgement, once made, is recorded, dated, owned and easy to find again next year.

That distinction matters because some platforms are sold as if the software itself provides assurance. It doesn't, and we wouldn't claim it does. Horizon is not a certification body and holding a Horizon account doesn't certify you to anything; it's the working environment that makes it easier to reach and maintain a genuine compliance position, whether that's Cyber Essentials, ISO 27001:2022 or an internal governance framework you've built yourselves.

Our consultants, based in Chesterfield and working with organisations across Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London, use Horizon on client engagements alongside client teams, which is partly why it's built the way it is — around the practical friction points we've seen in gap analyses, internal audits and certification support work over time, not around features that look good in a demo but don't survive contact with a real register.

If you're currently managing compliance through a mix of spreadsheets, shared drives and email, the honest first step is usually a short walkthrough to see how your existing register would look inside Horizon, rather than a wholesale commitment. That lets you judge whether the structure genuinely fits how your organisation works before anything is migrated.

Frequently asked questions

Questions we are asked most often.

What is compliance management software, in practice?

It's a single place to hold your risk register, controls, evidence and supplier records instead of spreading them across spreadsheets, shared drives and email threads. Horizon organises the information and tracks who owns what and when it's due, but the judgement about risk appetite and control design still sits with your team.

Can Horizon manage more than one framework at once?

Yes. Controls in Horizon can map to Cyber Essentials and to ISO 27001:2022 Annex A, so where a control satisfies both, you evidence it once and it's reflected against each framework rather than duplicated. This is most useful for organisations holding Cyber Essentials while working towards ISO 27001.

Does Horizon replace our internal audit or our consultant?

No. Horizon is where the work is organised and evidenced — it doesn't perform an audit, interpret a standard, or make risk decisions for you. Internal auditors and consultants, including our own, use it to see the current state quickly, but the assessment itself is still a human judgement.

How does the evidence library stop documents going stale?

Each piece of evidence — a policy, a penetration test report, an insurance certificate — has an expiry or review date attached. Horizon flags items approaching that date so someone can re-confirm or replace them before an auditor or a client asks for something that's quietly out of date.

Who typically uses Horizon within a client organisation?

Usually a small group: someone accountable for risk and compliance overall, control owners across IT and operations who update their own areas, and executives who view dashboards and board reports without needing to log evidence themselves. Role-based access keeps each group seeing only what's relevant to them.

Is this only useful once we're already certified?

No. Organisations working towards their first Cyber Essentials or ISO 27001 certification often set up their register and controls in Horizon before assessment, so evidence is already organised when a certification body or auditor asks for it, rather than being assembled under time pressure.

Can we export reports for the board or for clients?

Yes. Executive dashboards and board reports can be exported so you can circulate a current compliance position without giving every recipient direct access to the platform. This is commonly used ahead of board meetings or when a client asks for assurance evidence during due diligence.

What happens to our data if we stop using Horizon?

Your risk register, control records, evidence files and version history remain exportable throughout the engagement, so you're not left dependent on the platform to retrieve your own compliance records. We can talk through the specifics of export format as part of onboarding.

Curious how your current register would look in Horizon?

Ask for a walkthrough using an example close to your own setup — no obligation, and no pressure to migrate anything on the call.

Ask for a Horizon walkthrough