Governance, Risk & Compliance

Envelop

Web-based GRC platform for internal and external audit workflows, risk management, and document control.

About the Project

GRC Envelop is a web-based Governance, Risk, and Compliance platform designed to streamline internal and external audit workflows, risk management, and document control.

Neumeral developed the web application handling core functionality for the Asset Risk Factor (ARF) assessment feature. We built the models that support flexible assessments — letting administrators create customizable forms and assign them to users based on roles — along with the reporting features that turn assessment responses into output auditors can work from.

The Challenge

Risk assessments are not one shape. An asset risk factor questionnaire for one client, framework, or reporting period looks nothing like the next — different sections, different question types, different evidence requirements. Modelling each variant in code means a development cycle every time the compliance team needs a new one.

The assessment engine therefore had to treat the form itself as data: arbitrary structures built by administrators, assigned to the right users by role, filled in with supporting attachments, and moved through published, completed, and closed states — all while keeping responses coherent enough to report on afterwards.

Our Solution
  • Flexible assessment models: Data models that support arbitrary form structures, so administrators build customizable assessments without a code change.
  • Role-based assignment: Assessments are assigned to users by role, so the right people receive the right questionnaires.
  • Assessment lifecycle: Draft, published, completed, and closed states, with duplication to spin up the next period's assessment from an existing one.
  • Response-driven reporting: Reports generated from submitted responses, giving auditors and management output from the assessments themselves.
  • Evidence capture: File attachments collected against individual questions as supporting documentation.

Tech Stack

  • Python Django server
  • Flexible assessment data models
  • Role-based assignment and reporting
  • Custom JavaScript
  • HTML / CSS

Results & Impact

The difference it made.

New Assessments Without Development

Administrators compose and publish new ARF assessment types themselves, so a change in compliance requirements no longer waits on a release.

Assessments That Report Themselves

Reporting is generated from the responses, turning completed questionnaires into audit output instead of a pile of submissions to collate by hand.

One Trail for Audit

Assignment, status, responses, and attached evidence live together in the platform, so internal and external audits draw on the same record.

Have a project like this in mind?

Let's talk about how we can help you go from idea to production-grade system.