How it works

From a blank page to audit-ready, without guessing what comes next.

Most compliance projects do not fail on effort. They fail because nobody can see what is left, what counts as evidence, or who decides. Here is how Onwyn removes each of those.

The problem

Why compliance projects stall

Compliance software hands you a checklist and leaves you alone with it. Consultancies write everything for you — on an hourly meter, over many months. Either way the work scatters across tools that were never built for it.

Spreadsheet chaos

Control matrices live in five versions of one workbook. Nobody knows which tab is current, and the gap assessment goes stale the week after it is written.

Evidence ping-pong

Screenshots and policies bounce between shared drives and chat threads. Every request is asked twice, and half the files are the wrong version at fieldwork.

Auditor email threads

Findings, clarifications and sampling requests arrive as email attachments. Status lives in someone's inbox, and the audit trail is the audit problem.

The fix

How Onwyn works

Start in the Compliance Engine

Sign up, pick a framework or a package, and you're live in under a day — free for 30 days, with every requirement explained and tracked. No card, no quote, no call, no waiting. When the 30 days end you keep a free plan showing where your compliance stands; you activate a paid plan yourself when you want to carry on. Pricing.

Escalate when you want help

On any requirement, one click brings in a senior consultant — a review of your work, a guidance call, or done-for-you implementation. For full engagements, AI drafts and your named consultant signs off, all in the same workspace, at a fixed fee.

Certify with your auditor in the loop

When your program is audit-ready, your auditor gets scoped, read-only access to the controls and evidence they need. Fieldwork gets shorter because nothing has to be re-sent or re-explained.

AI + humans

How AI and consultants split the work

AI does the drafting and the bookkeeping; humans do the judgment and carry the accountability. Every AI-produced artifact stays visibly marked as a draft until a named consultant approves it.

01 02 03 AI drafts Marked as draft on creation Consultant approves Named, accountable sign-off Ships to your portal Visible to your whole team

Policies drafted in days, signed by humans

AI drafts your full policy set from your actual context — your stack, your org, your scope — in days, not weeks. Nothing reaches your auditor until your named consultant has reviewed and approved it.

Collect evidence once, reuse it everywhere

The AI crosswalk suggests how each piece of evidence maps across ISO 27001, SOC 2, NIS2 and the rest; your consultant confirms every mapping. Your second framework starts partly done, not from zero.

Nothing goes stale unnoticed

Expiring certificates, outdated screenshots and overdue reviews are flagged automatically — weeks before they would have become audit findings.

EU-routed AI, with a full opt-out

AI processing can be routed through EU-hosted models, your data is never used to train them, and you can disable external AI for your engagement entirely — your consultants then work conventionally in the same portal.