Governance, turned into operational intelligence.
Sastrum is the GRC platform for regulated enterprises. Scope your risk universe in minutes, let Lumina draft the controls and policies, and keep a named maker and checker on every decision — across governance, compliance, audit and incidents.
More tools, less visibility.
The problem.
- 01Regulations change faster than teams can read them.
- 02Evidence is stale by the time it is collected.
- 03Policies sit in PDFs, disconnected from the controls they govern.
- 04Nine tools produce nine versions of the truth, and the board still gets a heat-map it cannot act on.
From scope to signed policy
From a blank tenant to an approved policy, in one flow.
One real risk from the Indian banking universe, traced through the platform. The workflow is the product.
Sample organisation- 01
Tell Sastrum who you are.
Seven steps: industry, sector, sub-sector, presence, jurisdictions, frameworks, profile. Lumina prunes the risk universe to what applies: here, 35 risks across six categories for a mid-size bank regulated by RBI, SEBI, CERT-In and MeitY.
Lumina · Risk Universe builderUniverse
- 02
Onboard the risks that matter.
Each catalogue risk carries inherent and residual ratings, its framework drivers and a four-pillar view: governance, technical, people, physical.
Risk CatalogTable view
- 03
Lumina suggests controls; you accept or reject.
For RSK-4012 ransomware, the accepted set included endpoint application whitelisting, secure endpoint storage, an advanced ransomware training programme and a governance framework: one per pillar, each logged.
Lumina · AI Suggest ControlsRSK-4012
- 04
A governance gap becomes a drafted policy.
Policy Studio drafts one policy against a risk and its gap control, with a reasoning summary citing the clauses it relied on. Policy Factory does the same in batches.
Governance · PoliciesPOL-AI-010
Maker, Checker, Head of Department, Strategic Director. Each stage sees the history, the AI rationale and the linked risks, with an SLA clock.
Approval InboxPOL-AI-010
Control tests by pillar, a live event feed, and a regulatory watch that turns a new circular into a triage queue with the affected policies and controls.
Real-time Control Tests · Regulatory WatchLive feed
The same flow, recorded
See it running.
Five moves through the platform, taken from product recordings of the sample organisation. Nothing is re-created: these are the screens as they behave.
Scope & Risk
Risk Universe
The applicability scope is answered step by step — industry, sector, presence, regulators — and the risk catalogue narrows to what applies.Sample organisation Policy
Policy Factory · Batch drafting
Selected risks are de-duplicated by policy archetype, then drafted in parallel. Finished drafts land in Policy Studio for review.Sample organisation Lumina
Lumina · AI Suggest Controls
Lumina proposes a control bundle across all four pillars and shows the reasoning behind it. Each suggestion is accepted or rejected by a person.Sample organisation Controls & Frameworks
Control Mapping · Approval Workflow
The drafted policy is mapped to the controls it governs and to the framework clauses each provision satisfies, then routed through maker, checker, head of department and director.Sample organisation Monitor
Real-time Control Tests
Mapped controls run on a schedule and report back by pillar, each with its own run history, source and current state.Sample organisation
One foundation. Four modules. Lumina across all of them.
Governance is the foundation: frameworks, one control library organised by four pillars, and policies. Compliance, Audit and Incident Management run on top of it. Lumina — Sastrum's AI layer — scopes the risk universe, suggests controls and drafts policies into the same records. Assurance and Risk Appetite are add-on modules.
Explore the platformGovernance
Control Repository
158
Controls
111
Key controls
53
Implemented
Built the way a regulator reads it.
- 01Four-stage approvalsMaker, Checker, Head of Department, Strategic Director, each with history and an SLA clock.
- 02Immutable audit trailEvery recorded change, filterable by module, event, actor and date. AI requests are logged too.
- 03Granular role permissionsNine permission areas; system and custom roles from a permission matrix.
- 04Separation of dutiesConflict rules configured in the browser and enforced on the records they govern.
Risk content mapped to the frameworks your regulator names
- In product
- Content pack
IndiaMapped on catalogue risks
- RBI CSF
- SEBI CSCRF
- CERT-In
- DPDP
- MeitY
- PCI-DSS
- ISO 27001
- NIST CSF
MalaysiaShips as a content pack
- BNM RMiT
- Shariah governance
- PayNet
- PDPA
- Basel II event types
One platform, five conversations.
01 · CISO
Scope the risk universe to your regulators and get a four-pillar control set, not a blank spreadsheet.
SeesRisk CatalogControl Repository
Lumina · Risk Metaverse
Risk Catalog
- 35 risks · six categories
- Inherent and residual ratings
- Framework drivers per risk
Governance
Control Repository
- 158 controls · 111 key
- Four-pillar codes CTL-G/T/P/Y
- Framework count on every control
Configure, don’t code
Your administrators change it. Not your vendor.
Dashboards, report templates, forms, notification templates, taxonomies, review chains (with presets), surveys and separation-of-duties rules are configured in the browser, and every change is logged.
- Controls
- 158
- Key controls
- 111
- Control pillars
- 4
- Permission areas
- 9
- Permissions, admin role
- 625
- Starting risk universe
- 35
Structural figures read from the application, 18 Sep 2026. Not outcomes.
- DashboardsDashboard manager
- Report templatesGeneration on every register
- FormsMulti-step, tabbed
- Notification templatesPer event
- TaxonomiesConfigurable entities
- Review chainsPresets · SLA escalations
- SurveysTemplates and instances
- Separation of dutiesConflict rules
Lumina drafts.
People sign.
Lumina is Sastrum’s AI layer. It scopes your risk universe, proposes controls across governance, technical, people and physical pillars, and drafts policies with the clauses it relied on. Every suggestion is accepted or rejected by a named person and logged. You choose the models: cloud, on-premise, or a hybrid that keeps sensitive tasks inside your perimeter.
See LuminaRansomware attack on branch endpoints. One suggestion per pillar, against the frameworks in scope.
- TEndpoint Application WhitelistingTechnical · CTL-TAccepted
- YSecure Endpoint Storage and HandlingPhysical · CTL-YAccepted
- PAdvanced Ransomware Training ProgrammePeople · CTL-PAccepted
- GRansomware Risk Governance FrameworkGovernance · CTL-GAccepted
The accepted set recorded in the application for RSK-4012. Each decision has its entry in the log.
- Control accepted: Endpoint Application WhitelistingNamed person · RSK-4012Accepted
- Control accepted: Secure Endpoint Storage and HandlingNamed person · RSK-4012Accepted
- Control accepted: Advanced Ransomware Training ProgrammeNamed person · RSK-4012Accepted
- Control accepted: Ransomware Risk Governance FrameworkNamed person · RSK-4012Accepted
Bring your own modelAnthropicOpenAIGoogleOllama / vLLM (on-premise)
Presets: On-prem only · Hybrid · Cloud-first. Per-task routing across policy drafting, control suggestion, control effectiveness, dashboard insights and embeddings. Keys encrypted at rest, masked on screen. Every AI request audited.
Deployed your way.
- 01SaaS with pre-configured defaultsA fast start on Sastrum-managed infrastructure.
- 02SaaS with configurationTailored to your programme and organisation structure.
- 03Single-tenant or on-premiseFull control and data residency, including on-premise AI models.
Proven with a national bank. Built as a product for every regulated sector.
Developed with an anchor bank against 273 tendered requirements, and delivered as a sector-agnostic platform: the same product already carries Indian and Malaysian regulatory content. Tell us your sector and regulators and the demo opens with a universe that is already yours.