The control environment, and everything that disturbs it

Nimmy holds an organisation’s risks, controls, policies and obligations, and carries a regulatory change, an incident or an audit finding through to the evidence that it was dealt with. Built for in-house legal, risk and compliance teams, and for the firms who advise them.

One chain, end to end

Most tools own one link of this and hand off at the edges. The handoffs are where change gets lost.

  1. 01

    Something changes

    A rule is amended, an incident happens, a control test fails, an audit finds something. Nimmy watches the regulators, standards bodies and courts that matter to you and detects the change itself.

  2. 02

    It becomes an obligation, or an issue

    Every stream enters through the same two doors: a requirement the organisation now carries, or something somebody has to fix. Nothing else is a valid outcome, so nothing gets read and then dropped.

  3. 03

    The obligation meets the framework

    Each requirement is mapped, per legal entity, to the policies and controls that cover it and the risk that runs if it is not met. Different entities may meet the same clause differently, and the register says so.

  4. 04

    What nothing covers becomes work

    A gap is not a report; it is an action with an owner and a date, or an acceptance with a reason, a second signature and a review date after which it counts as outstanding again.

  5. 05

    The work leaves evidence

    Every decision, approval and send is an append-only audit event. A board pack or a regulator’s evidence request becomes a saved view rather than a spreadsheet somebody assembled by hand.

What it holds

Risks and controls

Risks scored by people, with the full history and an appetite to hold them to. Controls read as operating, degraded or failed from the signals they produce, not from a field somebody last edited in March.

Policies and obligations

Versioned policies with approval by somebody other than the author, and one obligation register carrying requirements from regulation, contract, licence and your own written rules alike.

Regulatory change

A daily queue from triage through applicability, impact and implementation to closure, with the source document, the redline against the previous version and the extracted obligations beside it.

Assurance, issues and incidents

Reviews by any of the three lines over a named scope, ending in a determination. Findings are issues rather than a second record somebody later converts. Incidents name the issue underneath them.

The whole product →

In-house teams

Banks, insurers, superannuation funds, pharmaceutical, energy and telecommunications groups. One register per entity, one queue per team, and a reporting view a board or a regulator can be handed.

Advisory firms

Law firms, consultancies and boutique regulatory advisers. A workspace per client, walled from every other client, and guidance published under the firm’s own name.

Nimmy is in pilot

A small number of organisations are using it now. If yours would like a place, write to us and say what you carry and which regulators you answer to.

Request access