Home / Platform

One governance chain. Three modules. Every framework that matters.

GovernHQ connects every rule, decision, exception, and piece of evidence into a single live system of record, natively mapped to the frameworks your regulator actually checks.

Connected by design. Traceable by default.

Most tools store governance activity. GovernHQ connects it, so each piece of the chain causes the next, instead of just sitting next to it. Here's how that plays out across the platform.

01

Rule — Policy · Control · Obligation

Every rule starts here: a policy, a control, or a regulatory obligation, entered once with a named owner and a mandatory review date. It links directly to the obligation it serves, so you always know why it exists, not just that it does.

02

Decision — Approved & Traceable

A rule means nothing until someone acts on it. Decisions are captured the moment they're made: who approved it, when, under what authority. Once recorded, a decision can't be edited, only superseded, with the original preserved.

Lives in: Governance Boards

Every committee, from risk to credit to procurement, with submissions arriving pre-attached to the rule they answer to, decisions captured live in the meeting, and a complete board pack ready to export the moment it ends.

Interactive — click a submission, then approve it
Governance Boards
Governance Boards
Review Queue
Decision Records
Board Calendar
Policy
Policy Register
Exemptions
Review Queue
Architecture Review Board · 2 submissions awaiting decision
Payment Service Architecture ReviewAwaiting Decision
Submitted 18 Jun 2026 by R. Okafor · Risk Level: High
Rule
POL-2606031
Obligation
DORA · ICT Risk Management
Submitted by
R. Okafor, Engineering
Summary
Proposes migrating payment settlement to a third-party processor. Requires sign-off from Architecture Review Board under DORA third-party risk obligations.
Vendor Data Processing Agreement — TPRM ReviewAwaiting Decision
Submitted 17 Jun 2026 by S. Patel · Risk Level: Medium
Rule
POL-2605118
Obligation
FCA SYSC · Third-Party Risk
Submitted by
S. Patel, Procurement
Summary
New data processor for customer onboarding documents. Requires Architecture Review Board sign-off under FCA SYSC third-party oversight rules.
03

Exception — Managed Deviation

Sometimes the right call is a deliberate departure from the rule, not a workaround. Every exception has an owner, an expiry date, and a documented reason. When it expires, it's flagged automatically, nothing lingers silently.

Lives in: Policies & Exemptions

Your policy library, version-controlled, with every rule mapped to the frameworks that apply to you from the moment it's created. If it's already in Confluence or SharePoint, GovernHQ governs it there directly, without replacing what you already use.

Interactive — click an exemption, then simulate expiry
Policies & Exemptions
Governance Boards
Review Queue
Decision Records
Policy
Policy Register
Exemptions
Exemptions
3 active exceptions · 1 approaching expiry
All Exemptions
Expiring Soon
Expired
ExemptionRuleOwnerStatus
EXM-2606031Cloud Provider ExceptionA. DasExpires in 6 days
EXM-2605118Vendor Access WindowS. PatelActive · 64 days left
EXM-2604027Legacy Auth MethodR. OkaforActive · 112 days left
04

Evidence — Audit-Ready Proof

The output of the chain: proof that governance happened, generated the moment a decision or exception is recorded. No manual compilation. It's already structured, timestamped, and ready to export.

05

Regulation — DORA · FCA

The framework each rule answers to, mapped from day one, not retrofitted before an audit.

Lives in: Audit & Regulatory Hub

Every piece of evidence the chain produces, surfaced and exportable in hours, with a full timeline view of every decision and exception behind it.

Interactive — select a framework, then export evidence
Audit & Regulatory Hub
Governance Boards
Review Queue
Decision Records
Audit Hub
Regulatory Posture
Evidence Exports
Regulatory Posture
Live — updated continuously, not point-in-time
DORA — ICT Risk Management92%
FCA Operational Resilience78%
APRA CPS 23061%

Five nodes. Three modules. One connected record.

Integrations

The tools stay. The record finally connects.

Five tools your team already uses. One thing they've never shared: a record that proves what happened, on demand. Toggle the diagram to see what changes.

Without GovernHQWith GovernHQ
JiraIssue trackingServiceNowIncident logsConfluencePolicy docsSharePointDocument libraryTeams + OutlookApprovalsGovernHQRulePolicy · Control · ObligationDecisionApproved & traceableExceptionManaged deviationEvidenceAudit-ready proofRegulationDORA · FCA

Five tools. No shared record. Evidence assembled by hand, every time.

Need something custom? Enterprise API available for integrations beyond the list above.

ToolWhat it does todayWhat changes with GovernHQ
JiraTracks issues and ticketsIssues become decisions, linked to the rule they answer to, not just a ticket number
ServiceNowLogs incidents and controlsIncidents map automatically to the regulatory obligation they affect
ConfluenceStores policy documentsConfluence stores policies. GovernHQ governs them, with approval chains added
SharePointHolds your document libraryYour existing library becomes a live, governed register
Teams + OutlookWhere approvals happen informallyApprovals happen in the same place, now captured, timestamped, and traceable

Same tools. Same workflow.

A record that finally holds up.

Built for the regulators you actually answer to.

Every framework below lives inside the platform from day one. Our focus is regulated financial services, and we map further as our founding clients do.

FrameworkWho it's for
DORAEU-regulated financial entities: banks, insurers, investment firms
FCA Operational ResilienceUK financial services firms regulated by the FCA and PRA
APRA CPS 230Australian regulated financial institutions
MAS TRMFinancial institutions operating in Singapore

Working to a framework that isn't here yet? Tell us — founding clients shape what we map next.

Talk to Us