Compliance and RiskOperate phase

Govern the compliance you run.

Continuous compliance. Managed risk.

Across a data centre's operation, as a running system rather than a project before each audit.

ISO 9001ISO 14001ISO 22301ISO 27001ISO 42001ISO 45001ISO 50001NIS2DORA
Kaiinside Compliance and Risk
“Why is this control failing?” — I answer that from the evidence in your own tenant, with the source and the date attached to every claim.

Three questions developers and operators ask

01

Which risks are we carrying today, and which controls cover them?

02

Could we pass an audit tomorrow without weeks of preparation?

03

How do we take on a new standard without starting from scratch?

Standards and frameworks covered today

ISO standards

  • ISO 9001 · Quality management systems
  • ISO 14001 · Environmental management systems
  • ISO 22301 · Business continuity management
  • ISO 27001 · Information security management
  • ISO 42001 · AI management systems
  • ISO 45001 · Occupational health and safety
  • ISO 50001 · Energy management systems

EU and UK law

  • NIS2 · EU Network and Information Security Directive
  • DORA · EU Digital Operational Resilience Act
  • UK NIS — CAF · NIS Regulations 2018, assessed against NCSC Cyber Assessment Framework v4.0, with Cyber Security and Resilience Bill duties
  • EU environmental permitting · EIA, IED and MCPD consent conditions

Industry codes and frameworks

  • EU Code of Conduct for Data Centre Energy Efficiency · Participant and best-practice register
  • SOC 2 · AICPA Trust Services Criteria
  • PCI DSS · Payment card data security
How it runs

In the order you actually work.

Step 01

Plan

Scope your standards and sites, decide what applies, and hold your risk register with risks linked to the controls that treat them.

Step 02

Do

Policies, procedures and evidence in a controlled document vault with role-based access, and controls preloaded for your business.

Step 03

Check

Kai checks what each requirement asks, reads your documents against it, and writes the finding with source citations: met, or a major or minor non-conformity, with a proposed fix.

Step 04

Act

Corrective actions, non-conformity tracking, management review and the board summary. Your team signs off at each step.

Compliance and Risk in the product
Cross-module audit readiness, with open non-conformities counted per framework and internal audits tracked beside them.
What you get

The artefact, not the dashboard.

Nobody buys a dashboard. They buy the thing that goes in front of an auditor, a customer or a board.

  • Evidence bundle, per audit and per clause
  • Management review pack and board summary
  • Training built from your own policies, in your roles and terminology
  • Competence matrix and training record
  • The Compliance Bill of Materials: obligations, controls, owners, documents, data and audit history in one exportable record
Controls and the Statement of Applicability

Evidence mapped once, reused by the next standard.

Every control carries its own justification, owner, implementation state and evidence, and each of those is counted separately, so "we have a control" and "we can prove it" stop being the same claim. Control-to-risk traceability runs both ways: risks point at the controls that treat them, and controls point back at the evidence.

  • Start from a baseline drawn from a real data centre operator’s audited control set
  • Import your existing Statement of Applicability, or auto-map controls from your risk register
  • Carry your ISO 27001 statements onto the UK NIS or NIS2 control set rather than rewriting them
  • An exclusion has to carry a defensible justification — restating "not applicable" is not one
Controls and the Statement of Applicability in the product
The Statement of Applicability, with justified, owned, implemented and evidenced counted as four different things.
Kai presenting findings
Built in

Ask Kai, inside Compliance and Risk.

Kaigrounded in our own corpus
“Why is this control failing?” — answered from the evidence in your own tenant, with the source and the date attached to every claim.
Who it’s for

Three people, three different fears.

The compliance owner

Holds the controls together with spreadsheets and personal memory, and carries the exposure when a finding lands. Wants evidence that survives a challenge.

The operator

Measures audit week in engineer-days spent gathering evidence instead of running the floor. Wants the time back.

The signer

Sees compliance as a cost line and a tender risk. Cares that questionnaires stop losing deals.

Try it on your own data

See where you stand before you talk to us.

What each standard actually requires of a data centre, what auditors ask for, and the instruments each answer rests on. Free, dated, and reviewed by a named lawyer.

Read the standards references
Proof
ISO/IEC 27001:2022Certified · British Assessment Bureau, UKAS-accredited
“A really useful AI compliance tool for data centres.”
John Booth, Data Centre Auditor, Carbon3IT
Kai holding a tick

Kai interprets. People verify.

Kai explains what a regulation means and proposes the fix. Your team decides. The evidence behind every finding carries a source and a date, because a compliance record that reads as machine-generated is worth nothing in an audit.

Kai inviting contact

Start at the gate that is slowing you now.

Clear Decisions runs compliance, carbon and regulatory intelligence as one system. Each module is available on its own, scoped and priced to what you need, from a single site or market to a portfolio.