About Course
Learning objectives
Explain what GRCLens is, describe its five core modules, position its differentiators, identify the ideal customer, and give a confident pricing/deployment answer.
1. What is GRCLens?
GRCLens is a multi-tenant, cloud-hosted GRC (Governance, Risk & Compliance) platform that turns regulatory and ISO frameworks into a single, trackable program. Instead of spreadsheets, drives and email threads, an organisation runs its entire compliance lifecycle — controls, evidence, risk, audit and reporting — in one place, with live scoring and AI assistance.
One-sentence pitch: “GRCLens replaces spreadsheet-and-email compliance with a single platform that tracks every control, stores and AI-reviews your evidence, and produces audit-ready reports — across all your frameworks, in English or Arabic.”
It spans eight framework families (NCA-ECC, PDPL, ISO/IEC 27001, ISO/IEC 20000-1, ISO/IEC 42001, SOC 2, PK-CTDISR, and a PCI DSS workspace) covering 1,036 catalogue controls, live on Microsoft Azure.
2. The five core modules
- Compliance Management — every control assessed (Implemented / Partially / Not Implemented / Not Applicable) with comments and evidence; live scores per domain and overall.
- Risk Management — ISO 31000-aligned register, heat maps and KRIs.
- Audit Management — evidence collection, audit readiness, control testing, exportable packages.
- Third-Party / Vendor Risk — assess, tier and monitor supplier risk (pairs with EASMLens).
- Incident Management — log, track and report incidents to closure.
3. Key differentiators
- Multi-framework, one control library — assess once, map to many frameworks.
- LensIQ / Baseera AI analyst — reviews each evidence artifact, returns a relevance & confidence assessment, and leaves the accept/reject decision to a human. LensIQ (English) / Baseera بصيرة (Arabic).
- Bilingual English / Arabic — a standout for Gulf/KSA (NCA-ECC, PDPL).
- Live dashboards & scoring, PDF/Word reports, and in-platform sign-off (e.g. PCI DSS CFO→acquirer — no print/sign/scan).
- Enterprise security — schema-per-tenant isolation, mandatory MFA, HTTPS, Azure.
Scoring: (Implemented + 0.5 × Partially Implemented) ÷ assessable controls, excluding Not Applicable.
4. Ideal customer profile
Regulated mid-market to enterprise (finance, government, healthcare, telecom, energy, critical infrastructure), teams juggling multiple frameworks, and especially Gulf/KSA organisations needing NCA-ECC/PDPL with Arabic support.
5. Competitive landscape
- vs 6clicks: Gulf expertise, Baseera AI, cost, faster implementation.
- vs ServiceNow IRM: best-of-breed GRC — lighter, faster ROI, lower cost (8–12 weeks vs 6+ months).
- vs Vanta / Drata: full enterprise GRC (compliance + risk + audit + third-party + incident) vs narrow automation.
6. Pricing & deployment
Cloud-native SaaS on Microsoft Azure, multi-tenant, typical implementation 8–12 weeks. Licensed by solution, scale and support tier with partner margin — always pull live figures from the Partner Pricing Guide before quoting.
7. Assessment
Complete the 10-question Knowledge Check (80% to pass) to finish this module and earn your completion. (Quiz questions are prepared and will be attached in the Tutor quiz builder.)
Course Content
Module 1 — GRCLens Product Fundamentals
Knowledge Check — GRCLens Product Fundamentals

