Skip to content

Governance

One control library. Every framework mapped to it.

Onboard frameworks, review applicability, and manage one set of controls and policies that every other module reuses.

Framework repository

Onboard a framework, then decide what actually applies.

Applicability review runs by framework or by domain. Every framework record carries its governing body, scope and paradigm, and the review sets which controls are in play before any assessment begins.

4
Frameworks loaded
115
Applicable controls
100%
Applicability set

Read from the application, 18 Sep 2026.

Frameworks we cover

On every framework record

  • Governing body
  • Scope
  • Paradigm

Applicability review

  • By frameworkWalk one framework's controls and mark what applies to you.
  • By domainReview a domain once and settle it across every framework that touches it.

Recorded in the product

Framework Drill-down

Coverage is calculated from the controls that are active. Opening a requirement shows which sub-requirements are covered, partial, or have no control behind them.Sample organisation

Control library

One library, coded four ways.

Every control carries a pillar, so a cyber risk is never answered by technology alone. Filter the library by pillar to see what each one covers and the records held against it.

Library158Controls111Key controls53Implemented
LibraryThe whole library, coded by pillar.
ControlTitleStatusFw
CTL-G-0101Access Control PolicyNot implemented4
CTL-G-0102Information Security Master PolicyImplemented3
CTL-G-0104Incident Response PolicyImplemented1
CTL-G-0105Third-Party Risk Management PolicyPartial2
CTL-G-0110Business Continuity & DR PolicyImplemented2
CTL-GRansomware Risk Governance Framework--
CTL-TEndpoint Application Whitelisting--
CTL-PAdvanced Ransomware Training Programme--
CTL-YSecure Endpoint Storage and Handling--

Entered the library from a control suggestion a person accepted.

Records read from the reviewed tenant. Status and framework counts are shown where they were read; the repository holds 158 controls across the four pillars.

Recorded in the product

Control Mapping · Approval Workflow

The drafted policy is mapped to the controls it governs and to the framework clauses each provision satisfies, then routed through maker, checker, head of department and director.Sample organisation

Policy lifecycle

A policy is a record here, not a document somewhere else.

Policies are created, imported or drafted by Lumina against a control, and they carry their lifecycle states, their rationale and their signatures on the record itself.

  1. Create, import or draftWrite a policy, import one you already hold, or have Lumina draft against a risk and its gap control.
  2. Rationale on the recordAn AI-drafted policy keeps its drafting rationale and the clauses it relied on, stored with the policy rather than beside it.
  3. Four signaturesNothing publishes without people. Each stage sees the history, the rationale and the linked risks.MakerCheckerHead of DepartmentStrategic DirectorPreviewThe Approval Inbox screen is a preview running on sample data.
  4. Published, and still connectedA published policy stays joined to the control it governs and the framework clauses behind it.
Governance · PoliciesPOL-AI-010

Access Control Policy

AI-drafted · rationale on record
10Published10AI-drafted

Clauses relied on

  • RBI CSF §II.3
  • ISO 27001 A.5.15-18
  • CERT-In log retention

Read from the application, 18 Sep 2026.

Recorded in the product

Policy Library

Published policies sit in one library, each with its code, status, version and the date it was last updated.Sample organisation

And the structure the library sits in.

Workflows & Configuration

  • TaxonomiesConfigurable entities, so the vocabulary is yours rather than the vendor's.
  • Separation of dutiesConflict rules configured in the browser and enforced on the records they govern.
  • Organisation hierarchyA multi-level hierarchy with change history behind it.

The foundation

Everything else reads from here.

Governance is not one module among four. It holds the frameworks, the controls and the policies the rest of the platform points at, which is why nothing has to be re-keyed to stay in step.

Start from a library, not a blank spreadsheet.

The demo opens on the frameworks you answer to, with the control library already coded by pillar and the policy records behind it.