GRC for SMBs and MSPs
Get audit-ready, and prove it.
Keel helps growing organizations manage risk, meet their obligations, and prove their work through one connected, practical GRC platform.
One control
Continual improvementInternal audit programAccess control policyDocument & records controlLeadership commitment & accountability
- ISO/IEC 27001
- EU AI Act
- SOC 2
- NIST Cybersecurity Framework
- NIST AI Risk Management Framework
- ISO 9001
Computed from Keel’s published crosswalk data, not estimated.
22
crosswalked frameworks
274
crosswalked controls
1,708
control-to-clause mappings
Open data, CC BY 4.0
How it works
One control, every clause it closes
Pick a control. Showing 8 of the 22 live frameworks, ranked by how much of the starter library maps to each.
- ISO/IEC 27001 9.2, A.5.35
- NIST SP 800-53 CA-1, CA-2, CA-2(1), CA-7(1)
- GDPR Not mapped
- NIST Cybersecurity Framework ID.IM-01
- SOC 2 CC4.1
- ISO 9001 9.2.1, 9.2.2
- NIST SP 800-171 3.12.1
- ISO/IEC 42001 9.2
- ISO/IEC 27001 A.5.15
- NIST SP 800-53 AC-1, AC-2, AC-3, AC-6, AC-14
- GDPR Art.32(1)
- NIST Cybersecurity Framework PR.AA-05
- SOC 2 CC6.1, CC6.3
- ISO 9001 Not mapped
- NIST SP 800-171 3.1.1, 3.1.2, 3.1.5
- ISO/IEC 42001 Not mapped
- ISO/IEC 27001 10.2
- NIST SP 800-53 CA-5
- GDPR Not mapped
- NIST Cybersecurity Framework Not mapped
- SOC 2 CC4.2
- ISO 9001 8.7.1, 8.7.2, 10.2.1, 10.2.2
- NIST SP 800-171 3.12.2
- ISO/IEC 42001 10.2
- ISO/IEC 27001 A.5.19, A.5.20, A.5.22
- NIST SP 800-53 SA-1, SA-4, SA-4(1), SA-4(2), SA-4(9), SA-9, SA-9(2), SR-3, SR-6
- GDPR Art.28(1), Art.28(3)
- NIST Cybersecurity Framework GV.SC-01, GV.SC-02, GV.SC-04, GV.SC-05, GV.SC-06, GV.SC-07, GV.SC-10, ID.AM-04
- SOC 2 CC9.2, P6.4, P6.5
- ISO 9001 8.4.1, 8.4.2, 8.4.3
- NIST SP 800-171 Not mapped
- ISO/IEC 42001 Not mapped
- ISO/IEC 27001 A.5.29, A.5.30
- NIST SP 800-53 CP-1, CP-2, CP-2(1), CP-2(3), CP-2(8), CP-3, CP-4, CP-4(1), CP-10, CP-10(2), RA-9
- GDPR Art.32(1)
- NIST Cybersecurity Framework RC.RP-01, GV.OC-04, RS.MA-05, RC.RP-02, RC.RP-04, RC.RP-06
- SOC 2 A1.2, A1.3, CC9.1
- ISO 9001 Not mapped
- NIST SP 800-171 Not mapped
- ISO/IEC 42001 Not mapped
What you get
Every GRC job, on one graph
Compliance & controls
One crosswalked control library: collect evidence once, satisfy many frameworks.
Risk management
Risk register with scoring, treatments and owners, linked to controls.
Policy management
90+ framework-mapped policy templates to approve and export as branded PDFs.
Vendor risk
Third parties tracked by criticality, on review cadences.
People & access reviews
Sync staff from Microsoft Entra, Google Workspace or CSV, then certify access.
Evidence & trust center
Attach evidence once, then publish a branded, public trust center.
Frameworks
All of them, on one control library
22 live today, spanning 9 categories.
- ISO/IEC 27001
- CIS Critical Security Controls
- PCI DSS
- SOC 2
- SOX (Sarbanes-Oxley) Section 404
- NIST Cybersecurity Framework
- NIST SP 800-53
- NIST SP 800-171
- HIPAA
- GDPR
- COPPA
- Google Play Families
- Amazon Appstore Child-Directed Apps
- Apple App Store Kids Category
- PIPEDA
- ISO 9001
- AI Governance Essentials
- ISO/IEC 42001
- NIST AI Risk Management Framework
- EU AI Act
- ESG Essentials
- US Employment Law - Federal Baseline
FAQ
What does it cost?
4 plans, all public: Free $0, Starter $99/mo, Pro $299/mo, Enterprise $1,999/mo. The MSP / Partner plan is quoted per client.
Do I need a consultant?
No. Guided setup, one-click pre-mapped control sets and 90+ policy templates get you moving.
Which frameworks are live?
All 22, spanning 9 categories, every one on the same crosswalked control library.
Can I try it first?
Yes. A 14-day Pro trial on every new workspace, no credit card. The demo needs no signup.
Start free