Skip to main content

Home/Governance & Compliance

Governance built in, not bolted on

DEALWISE is designed around the frameworks institutional investors are measured against, so evidence for audit and the regulator can be produced as a standard report.

Standards & frameworks

Five reference frameworks shaped the platform

Institutional Limited Partners Association

ILPA Principles

Reporting structures, fee and expense transparency and governance expectations align with ILPA guidance, so LP reporting obligations are supported natively.

Project Management Institute

PMI Framework

Deal workstreams, due diligence programmes and implementation follow PMI-aligned planning, scope, schedule and stakeholder disciplines.

Committee of Sponsoring Organizations of the Treadway Commission

COSO Framework

Internal control over the investment process: control environment, risk assessment, control activities, information & communication, and monitoring.

Risk Management Framework

ISO 31000

The risk register, risk scales, categories, appetite thresholds and treatment plans follow the ISO 31000 principles, framework and process model.

Information security, cybersecurity and privacy protection

ISO 27001

Information security management covering access control, encryption, logging, segregation of duties, secure development and supplier assurance.

Control capabilities

What auditors and regulators actually ask for

Immutable audit trail

Who changed what, when, from what value to what value, and under whose authority, covering decisions, approvals, data and document access.

Segregation of duties

Requesters cannot approve their own transactions; approval thresholds and delegate validity are enforced by the system.

Document version control

Every version retained with uploader, timestamp and permissions, so the paper the committee saw can always be reproduced.

Access management

SSO and MFA, password policy, role-based permissions, privileged action logging and periodic access recertification.

Risk register

ISO 31000-aligned categories, scales, appetite thresholds, treatment plans and periodic re-rating with full history.

Retention & legal hold

Retention schedules by document type, with legal hold to suspend disposal during investigation or litigation.

Data protection

Your data, under your control

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Deployment options: vendor-hosted cloud, your own cloud tenancy, or on-premises
  • Data residency selectable by region to satisfy local regulation
  • Role-based data masking for sensitive commercial terms
  • Backup, restore and tested disaster recovery with defined RPO and RTO
  • Security event logs forwarded to your own SIEM
  • Independent penetration testing and vulnerability management
  • Supplier assurance and secure development lifecycle aligned to ISO 27001

Need the security and control pack for your assessment?

We will share the architecture overview, control mapping and data protection documentation ahead of any procurement review.