PIT Governance

VENDOR SECURITY QUESTIONNAIRE AUTOMATION

Answer customer security reviews without chasing information.

PIT Governance helps teams complete the vendor questionnaires customers send about data protection, access controls, encryption and security practices.

The PIT Governance control register for QA Bank Ghana, with the navigation down the left and the register filling the screen: every control listed with the framework it came from, its owner and its implementation status across the four states the product records.
One control's assessment result, showing the rules reading and the evidence review beside the final score they combine into, and the remediation task that opened with a date because the control scored below half.

Adopt a framework and the controls arrive with it.

Every control is scored against the evidence attached to it, every risk is carried as money, every policy keeps its approved versions, and a weak control becomes work with an owner and a date.

Adopting a framework brings its controls with it.

The pack's own control list arrives complete, and every control carries the pack version it came from. Each one is matched to its counterpart in other frameworks by what it requires.

Frameworks
The control register immediately after a framework is adopted, every row seeded from the framework pack and stamped with the pack version it came from, under the product's own message confirming that adopting the same pack again added nothing.
02 · ASSESSMENT

Every control is scored, and the score has consequences.

A reading of the rules and a review of the attached evidence combine into one final score, weighted sixty to forty. A control that scores below half opens remediation work with a date on it.

Assessment
An assessment run's overall score above two controls broken down individually, each split into its implementation, evidence and testing readings, with the quality read on the evidence attached and the action the run suggests next.
03 · RISK

A risk is carried as a figure the board can read.

Each risk stores how often it is expected and what it would cost at its lowest, likeliest and highest. The register holds the exposure before controls and the exposure that remains after them.

Risk register
A risk quantified as money: the annualised loss expected before controls beside the loss expected after them, the curve showing how likely a loss is to exceed a given figure for both, and a table reading from the median year out to the one bad year in twenty.
04 · POLICY

Approval writes a version, and the earlier wording stays readable.

A policy moves through draft, review and approval as real states, and a transition out of order is refused. Every acknowledgment records the person and the moment.

Policies
An approved policy at its third version, with all three versions still listed and readable beneath it, and under those the people who acknowledged it, each named with the moment they did.
05 · REMEDIATION

A weak control becomes work that someone owns.

A task an assessment opened runs through four states: open, in progress, completed, verified. A task a framework migration proposed waits for someone to accept it before it becomes live work.

Tasks
The remediation task list under its four status tabs, holding three tasks that reached it by different routes: one opened by an assessment, one raised by a gap analysis, and one proposed by a framework migration and still waiting to be accepted.
Live demonstration

Bring the questionnaire on your desk.

A demonstration runs one of your own controls from adoption through evidence to a scored answer, and PIT Governance keeps that answer ready for whoever asks next.

Book a demo
The PIT Governance risk register, listing each risk with the owner who carries it, the exposure it represents before controls and the exposure that remains after them.