Skip to content
English
  • There are no suggestions because the search field is empty.

iGRC Overview

What is iGRC

Intelligent GRC (iGRC) is the next stage of the 6clicks platform—not a separate product. It connects controls, evidence, tests, tasks and framework requirements in one linked model. This means you can test a control once and apply the result to every framework it supports.
 
iGRC helps your organisation move from structured compliance, where records are managed systematically but remain separate from their supporting evidence, to intelligent assurance. Connected data and AI link evidence with controls, tests and requirements.
 
Hailey, 6clicks’ AI, performs the first review of evidence. It creates validation guides, checks submitted evidence against them and highlights gaps for a person to review. People remain responsible for final judgement and accountability.
 
This article explains what each register does, how the registers connect, where Hailey can help and how you can extend the platform. Each section links to a detailed article about that capability.

 

The four registers

iGRC adds four registers to your Spoke. They are built on the custom registers architecture, so they use the same fields, views, filters and permissions model.
 
Controls contain the compliance requirements your organisation has committed to meet. All other registers link back to controls. A single control can also map to multiple framework provisions, allowing you to assess it once and apply the result wherever it is relevant. See managing and configuring the Controls register and using the Controls register.
 

Tests define how a control is checked, whether manually or automatically, and the scope of the check. Each time a test runs, it creates a test log where the evidence is validated, and the result is recorded. See managing and configuring the Tests register and using the Tests register.

Tasks contain work assigned to a person, including what needs to be done, who is responsible and how often it repeats. iGRC brings all tasks together in one register, regardless of where they were created, so they are not scattered across different modules. See managing and configuring the Tasks register and using the Tasks register.

Files provides one searchable location for every attachment and piece of evidence in your Spoke, with built-in version history and validity tracking. A file becomes evidence when it is linked to a test that has a validation guide. Until then, it remains a record that you can link to other items.  See managing and configuring the Files register.

 

How the registers connect

A control can have one or more tests, each with a defined scope. Every time a test runs—either as a one-off check or as part of a recurring schedule—it creates a test log. The test log records the scope, validation guide and person providing evidence for that run. A manual test is paired with a task, so the person responsible can see exactly what they need to do. An automated test validates evidence directly from an integration, without creating a task.
 
Results flow through iGRC automatically. The test log’s result feeds into the test, the test feeds the control’s compliance status, and the control’s status applies to every framework provision mapped to it. This means you can assess a control once and it applies everywhere the control is relevant.
 

Controls, tests, tasks and files link to each other directly, in any direction. A file can attach straight to a control with no test involved, and the same piece of evidence can satisfy several controls or frameworks at once. For the full walk-through of who does what and when, see the evidence submission and validation workflow.

 

Hailey across iGRC

Hailey supports three key activities in iGRC.

Evidence validation. When you create a test, Hailey uses the test details and its linked control to create a validation guide. Each time you upload evidence, Hailey checks it against the guide and provides a pass, partial or fail assessment, a quality rating, details of any gaps and suggested next steps.
If the test relates to a supported framework, Hailey uses that framework’s assessment guidance when creating the validation guide. You remain responsible for setting the final result; Hailey provides the assessment only. See Hailey evidence validation.
 

Hailey-assisted mappings. Hailey reviews a record’s data and suggests relevant links to other records, such as a control to a test or a piece of evidence to a control, shown as confidence-rated suggestions you accept or reject. Nothing links automatically, and suggestions only appear to users who can edit the register the record belongs to. See Hailey-assisted mappings in Registers.

Semantic search. When you’re working on a risk, Hailey suggests related controls and provisions automatically, and lets you search in plain language instead of guessing keywords, with a confidence level and an explanation for each match. See finding controls and provisions related to a risk.

 

Working with your data

Once your registers contain data, four capabilities help you make the most of it. 

Filtering and search. Build simple or advanced queries on any register, including conditions based on what a record is linked to, such as showing controls where a test failed in the last seven days, and save the views you use often. See filtering and searching using linked data.

Insights. The Controls register has an Insights tab that turns your existing controls, tests and evidence into one view of how your control environment is performing: test coverage, pass rate, framework coverage, and which controls need attention. Every control also has its own Insights tab. See Control register insights.

Hailey import. Bring existing content into a register by uploading a policy document; Hailey reads it and creates the register items for you, the same way “Import control set” already works for the Controls module. See Registers overview.

Requirement-based assessments. Run a requirement-based assessment (RBA) directly against one or more items in a custom register, with the results linked straight back to those items. See creating a requirement-based assessment from a custom register.

 

Extending iGRC

iGRC can connect to systems beyond those with existing 6clicks connectors. The integration recipe building skill is an AI agent skill for Claude Code, Codex or any harness that supports Agent Skills.
Describe the evidence you need and the system where it is stored. The skill then scaffolds a Custom Workflow Builder recipe that retrieves the evidence from that system and posts the result to an existing test.
 
Because the skill uses a description and sample response instead of relying on a fixed connector, it can work with almost any system you can call, including off-the-shelf and in-house systems. This supports continuous assurance by allowing evidence to arrive on a schedule rather than requiring you to collect it each quarter.
 
To complete the recipe in the Custom Workflow Builder, authorise the connections, confirm the field mappings, set a schedule and enable it. See integration recipe building.

 

Permissions

By default, only administrators and advisors can access the iGRC registers. Access is granted separately for each register. For example, giving a role access to the Tests register does not give it access to the Controls, Tasks or Files registers.
 
Hailey-assisted mapping suggestions follow the same permissions. They are only visible to users who can edit the register containing the record.
 
If you are an advisor working across multiple Spokes, you need to configure permissions separately in each Spoke. See granting a role access to iGRC.

 

What’s coming

iGRC continues to add new capabilities. The upcoming items below do not prevent you from using iGRC for day-to-day work. The legacy Controls module will remain available while these capabilities are added to iGRC. 

Closing the gap with the legacy modules:

  • Framework cross-walking in the Controls register, to map controls against a framework and see what’s covered, partly covered, or not covered.
  • Control distribution between hub and spoke, to publish a set of controls from a spoke for other business units to use.
  • Risk Treatment Plan links to the Controls register, so a Risk Treatment Plan can show every control that treats a risk, wherever it’s tracked.

Beyond parity:

  • Notifications with compensating controls, so a control owner is alerted only for genuinely new failures, not issues already acknowledged, suppressed, or covered by a documented compensating control.
  • Policy management as its own register, with clause-level linking to controls, generated policy documents, and attestation tracked through Tasks.
  • An API for automated mapping of tests to controls, extending Hailey’s mapping recommendations to programmatic use.

For a release schedule, check with your Customer Success contact.

 

Related articles