BCM V2 is a collaborative platform for the integrated management of audit, regulatory compliance, supply chain risk, and vCISO projects.
BCM V2 is a collaborative platform for the integrated management of audit, regulatory compliance, supply chain risk, and vCISO projects. It includes a library of more than 70 management frameworks specific to industry-reference standards — PCI DSS, PCI PIN, ISO 27001, SWIFT, SOC II, NIST2 — strengthening audit, security consulting, and third-party risk control processes.
As a differentiating element, the platform integrates an artificial intelligence assistant embedded directly into the working interface, designed to support the user in interpreting requirements, optimizing evaluations, and generating contextual recommendations, boosting the operational efficiency of auditors, advisors, and compliance managers.
BCM V2 enables organizations to control and optimize their regulatory compliance processes, reducing the time and effort dedicated to audit and third-party risk management.
It provides an agile and adaptable solution that simplifies the management of rules and standards, offering a clear view of compliance effectiveness and ensuring a standardized framework for security and cybersecurity. Ideal for companies of all sizes, BCM V2 accelerates user adaptation and optimizes the resources dedicated to compliance.
BCM V2 facilitates the centralized administration of all certification, audit, supply chain risk management, and vCISO processes — from the creation and secure storage of evidence to the detailed management of activities, third-party security assessments, and reporting. It includes a multilingual environment, customizable templates, and a shared management model that supports activity tracking through assignments, facilitating collaboration between teams. BCM V2 is hosted in the cloud, eliminating the need for physical infrastructure and enabling scalable growth.
A quick tour of how the platform works and what makes it different in the team's day-to-day.
BCM V2 has been designed so that any user can work intuitively from day one, without the need for advanced technical training. It is easy to navigate between the different regulatory frameworks, evaluate controls, and manage evidence — the visual guides the user step by step.
Organize multiple projects within the same environment through independent domains. Create audits, security assessments, and vCISO projects in seconds, choosing from more than 70 regulatory frameworks specific to the main industry standards.
Define precisely what information each participant sees — auditors, compliance managers, vCISOs, and other parties involved — ensuring confidentiality and clarity on every project.
Dynamic table of contents that lets users move quickly through every requirement of the applied framework. Evaluation happens directly on each requirement, with qualitative comments and secure attachment of evidence. Real-time information on maturity level and compliance status.
Create controls linked to the active standard while evaluating requirements, delegate tasks, set deadlines, manage priorities, and enable tracking alerts. All controls, tasks, and evidence are reusable across projects in the same domain, with no duplication.
Real-time information on project progress, accessible from the main view and from the Advanced Analytics module. It underpins the automated generation of reports and the structured presentation of results, reducing the operational load on audit teams and optimizing delivery times.
Robust model with Single Sign-On (SSO), multi-factor authentication (MFA), and credential expiration policies. Team creation with project assignment, notifications, effort control, workload distribution, and per-resource hour tracking.
More than 260 classified resources: frameworks, reference controls, risk matrices, threat intelligence, and metrics — indexable and linkable to projects. Complemented by a library of 265 documents covering legal, regulatory, and audit material.
The cyber supply chain risk management module that evaluates the security posture of critical suppliers through structured questionnaires aligned with recognized frameworks (ISO 27001, SOC 2, PCI DSS 4.0, CIS Controls v8), centralizing responses and evidence on a single platform.
Consolidates supplier responses and evidence on a single platform.
Cross-checks the supplier's declared answers with its external footprint to spot contradictions.
Unlike other solutions that only look at the external footprint, Risk Lens delivers real visibility of third-party risk — not just an outside score.
The platform provides a configurable governance module that allows the administrator to easily set the operational parameters of the environment: interface language, notification rules, access security policies, financial parameter configuration, and other personalization aspects, ensuring the tool aligns with each client's organizational requirements.
It is not a "generic external chat". It is an assistant that supports the project throughout the evaluation, providing suggestions, resolving questions, and creating objects.
Its use is secure: it does not make decisions for you and it has no permissions or access to information beyond what has been configured for the user.