Skip to main content
P
Palka
NEPALI GRC PLATFORMREGULATED INSTITUTIONS

Continuous, evidence-backed compliance for Nepal.

Replace fragmented spreadsheets with a single, verifiable register. Built for Nepali banks and enterprises to automate NRB IT Guidelines and ISO 27001.

ISO 27001:2022 (93 Controls)
NRB IT Directives 2024
SHA-256 Tamper-Check
palka-core // rls: active // cluster: npl-ktm-01
ORGANIZATION POSTURE
Commercial Bank Tier-1
AUDIT READY
ISO 27001:2022
0 / 93
Verified
NRB DIRECTIVES
100%
Attested
INTEGRITY
SHA-256
Tamper-Check
EVIDENCE_LEDGER_STREAM
1control_id: "ISO-2022-A.8.24"
2sha256_digest: "4f738b8120e29b6f..."
3verified_at: "2026-09-21T13:40:00Z"
4status: "VERIFIED_PASS"
THE PALKA NARRATIVE4-PHASE LIFECYCLE

How Palka transforms compliance from panic to precision.

Four sequential phases engineered to take financial institutions from chaotic spreadsheets to continuous audit defensibility.

PHASE 01 OF 04 • ACT I — THE REGULATORY MANDATE

Stop wrestling with 40+ disconnected spreadsheets when regulators knock.

When Nepal Rastra Bank updates cybersecurity guidelines or your ISO/IEC 27001 audit approaches, compliance teams spend weeks locating unversioned files across local drives. Palka ingests your perimeter into a structured registry with zero ambiguity.

Technical Architecture & Impact93 Annex A controls and NRB IT Directives 2024 automatically classified across Organization, People, Physical, and Technology domains.
palka-core // phase: 01 // status: verifiedINSTANT INGESTION
93
Annex A Controls
14 Chapters
NRB Mandates
< 15 Mins
Setup Time
DISCONNECTED CHAOS → CENTRAL REGISTRY
40+ Unversioned Sheets
Palka Structured Ledger
STANDARDS TAXONOMYREGULATORY COMPLIANCE COVERAGE

Built specifically for Nepal's mandated security standards.

Click any framework to inspect its control breakdown and local applicability for Nepali institutions.

ISO/IEC 27001Supported

Information Security Management System

2022 Edition93 controls across 4 themes

Structured mapping against Annex A across Organizational (37), People (8), Physical (14), and Technological (34) controls.

Org (37)Peo (8)Phy (14)Tec (34)
Scope: Global Benchmark● SELECTED
NRB IT GuidelinesSupported

Nepal Rastra Bank IT & Cybersecurity Directives

2024 DirectivesCommercial Banks & PSP/PSOs

Aligned with NRB IT governance guidelines, disaster recovery benchmarks, quarterly reporting, and cloud security mandates.

Scope: Nepal Financial SectorSELECT →
SWIFT CSCFIn development

Customer Security Controls Framework

v2024Mandatory & Advisory Controls

Attestation tracking and segregation-of-duties evidence workflows for SWIFT environment interfaces and local terminals.

Scope: Interbank MessagingSELECT →
ACTIVE FRAMEWORK DETAILSISO/IEC 27001
Information Security Management System (2022 Edition)
Structured mapping against Annex A across Organizational (37), People (8), Physical (14), and Technological (34) controls. Applicable to: Global Benchmark.
View control mappings
PARADIGM SHIFTSYSTEMIC WORKFLOW COMPARISON

Why spreadsheet-driven compliance breaks under inspection.

Managing regulatory requirements through email chains and shared drives creates blind spots, duplicate effort, and audit friction.

CONVENTIONAL WORKFLOW

Legacy Spreadsheets & Folders

HIGH RISK
Scattered in email & static folders
Screenshots and exported spreadsheets stored in ad-hoc shared drives with no cryptographic integrity or chain of custody.
Quarterly panic audits
Compliance teams manually query engineers right before internal or NRB external audits, causing frantic retrospective evidence gathering.
Redundant cross-mapping
Maintaining separate spreadsheets for ISO 27001, NRB IT Directives, and internal risk registers, duplicating work across frameworks.
Untracked spreadsheet edits
No verifiable history of who approved an exception, who uploaded evidence, or when a residual risk score was modified.
THE PALKA ENGINE

Evidence-Linked Ledger

VERIFIED
Cryptographically linked records
Direct artifact attachment with SHA-256 verification, dynamic ownership assignment, and automated expiration warnings.
Continuous posture assessment
Real-time control status dashboard showing pass/review/fail rates with live gap identification and upcoming review reminders.
Unified control registry
One evidence artifact maps across overlapping requirements in NRB guidelines and ISO/IEC 27001:2022 themes simultaneously.
Immutable audit event stream
Structured actor-action-timestamp records logging every control modification, review signoff, and access assignment.
CORE ENGINEENGINEERING CAPABILITIES

Engineered for technical precision and audit defensibility.

Six unified modules that work together to maintain continuous compliance readiness across teams.

01RISK-01

Risk Register & Dynamic Scoring

Structured risk identification with transparent Likelihood × Impact scoring matrices, asset categorization, and mitigation tracking.

  • Configurable risk matrices (1x1 to 5x5)
  • Inherent vs residual risk calculation
  • Direct linkage from risk to mitigating control
02CTRL-02

ISO/IEC 27001:2022 Control Library

Complete implementation of the 2022 edition's 93 Annex A controls structured across all four standardized themes.

  • 37 Organizational controls
  • 8 People controls & 14 Physical controls
  • 34 Technological controls
03EVID-03

Evidence Workflow & Verification

Systematic evidence lifecycle management with assignees, periodic review cadences, and unambiguous signoff states.

  • Artifact integrity verification via SHA-256
  • Assigned review cadences (monthly, quarterly, annual)
  • Explicit signoff and rejection status tracking
04AUDT-04

Granular Audit Trail

Comprehensive event timeline capturing actor IDs, timestamps, affected resources, and exact state transitions for compliance proof.

  • Append-only audit event logging
  • Actor attribution on every state change
  • Filterable by control ID, user, and date window
05REPT-05

Gap Assessment & Regulatory Export

Automated readiness calculations across frameworks to generate exportable gap summaries ready for NRB examiners and external auditors.

  • Real-time framework readiness percentages
  • Exportable Statement of Applicability (SoA)
  • NRB IT guideline gap breakdown
06AUTH-06

Role-Based Access Control

Tenant-isolated workspace structure with distinct roles for Compliance Officers, Evidence Owners, and Read-Only External Auditors.

  • Strict Row-Level Security (RLS) enforcement
  • External auditor read-only guest scopes
  • Multi-department delegation within organizations
EXECUTION FLOWOPERATIONAL LIFECYCLE

From gap assessment to certified compliance.

A structured three-step continuous loop designed to eliminate audit ambiguity.

01
SCOPING & BASELINE

Assess Risk & Framework Scope

Select your applicable frameworks (NRB IT Guidelines, ISO/IEC 27001:2022). Define organizational assets, map threats, and establish your risk appetite baseline.

OUTPUT ARTIFACT:Inherent Risk Heatmap & Statement of Applicability
02
OPERATIONALIZATION

Map & Assign Controls

Distribute the 93 ISO controls and NRB mandates to designated system owners across IT, security, and human resources with clear periodic review intervals.

OUTPUT ARTIFACT:Assigned Control Matrix with Review Cadences
03
VERIFICATION & ATTESTATION

Collect Evidence & Audit

Attach policy files, logs, and configuration snapshots. Reviewers approve or request revisions. Generate verified compliance packages directly for auditors.

OUTPUT ARTIFACT:Exportable Audit Dossier & Live Readiness Metric
INTERFACE TOURINTERACTIVE WORKSPACES

Inspect the system interfaces built for compliance teams.

High-density, distraction-free workspaces tailored for risk owners, IT engineers, and external auditors.

MODULE: RISK_MGMTActive Register

Transparent risk matrix with calculated residual exposure

Every financial IT asset is mapped to threats and vulnerability scores. As controls are verified with evidence, residual risk updates in real time.

INTERACTIVE RISK MATRIX (5×5)SCORE: 16 (CRITICAL)
5
10
15
20
25
4
8
12
16
20
3
6
9
12
15
2
4
6
8
10
1
2
3
4
5
Selected: L4 × I4 = 16 • Maps to ISO 27001 A.8.20
SYSTEM INTEGRITY STATUS
ACTIVE WORKSPACE • RLS ENFORCED • LIVE AUDIT LOGGING
Active Institutional Risk RegistryVIEW: LIVE_REGISTER
ITEM / ASSETMETADATA & OWNERSTATUS
RSK-042: Core Banking API Unauthorized Access
Mitigation: CTRL-5.15 Access Control + MFA
Asset: CBS Gateway | Inherent: 20 (High)MITIGATED (RESIDUAL: 4)
RSK-019: Third-party Payment Switch Outage
Mitigation: CTRL-8.14 Redundancy Failover
Asset: Switch Interconnect | Inherent: 16 (High)PENDING DRILL EVIDENCE
RSK-088: Cloud Storage Misconfiguration
Mitigation: CTRL-8.20 Network Security
Asset: S3 Backup Buckets | Inherent: 12 (Med)MITIGATED (RESIDUAL: 3)
NEPAL CONTEXTREGIONAL DIRECTIVES & SOVEREIGNTY

Purpose-built for Nepal's financial regulatory landscape.

Global GRC tools do not understand Nepal Rastra Bank circulars or localized banking workflows. Palka maps both native directives and global standards into a single engine.

NRB-IT-2024Nepal Rastra Bank

IT Guidelines & Cyber Resilience Directives

Purpose-built controls for 'A', 'B', and 'C' class financial institutions and Payment Service Providers/Operators (PSPs/PSOs).

  • Quarterly compliance reporting matrices aligned with NRB inspection checklists
  • Disaster Recovery (DR) and RPO/RTO verification workflows
  • Information security governance and CISO reporting documentation
  • Cloud adoption assessment and localized data management checks
ISO-NRB-OVERLAPUnified Framework Matrix

Cross-Standard Harmony

Eliminate duplicate evidence gathering. Single controls map simultaneously across ISO 27001:2022 Annex A and NRB requirements.

  • Annex A.5 (Organizational) mapped to NRB Governance Mandates
  • Annex A.8 (Technological) mapped to NRB Switch & Core Banking security
  • Unified Statement of Applicability with multi-standard export
  • Automated gap alerts when regulatory revisions are released
ENGINEERING FOUNDATIONDEFENSE-IN-DEPTH ARCHITECTURE

Trustworthy tenant isolation and cryptographic verification.

How we protect sensitive financial institution audit dossiers, vulnerability logs, and evidence repositories.

Multi-Tenant IsolationRow-Level Security (RLS)

Every tenant's risks, controls, and evidence reside in logically isolated partitions enforced strictly at the database query layer.

Encryption in Transit & RestTLS 1.3 / AES-256

All API transport is enforced with modern TLS 1.3. Uploaded evidence artifacts and metadata are encrypted at rest using AES-256.

Granular Role-Based AccessRBAC & Auditor Scopes

Strict segregation of duties between Compliance Admins, Evidence Uploaders, Reviewers, and Read-Only External Auditor accounts.

Evidence Hash VerificationSHA-256 Checksums

Evidence files generate SHA-256 cryptographic digests upon upload, providing verification against post-upload modification.

example_evidence_ledger_record.json
● RLS_ISOLATED
01{
02  "evidence_id": "EV-2026-0921-088",
03  "tenant_id": "tenant_nrb_bank_04",
04  "control_reference": "ISO-27001-2022-A.8.9",
05  "cross_standard_map": ["NRB-IT-DIR-4.2"],
06  "sha256_digest": "4f738b8120e29b6f84d2a1c0d297",
07  "timestamp": "2026-09-21T13:40:53.000Z",
08  "actor": "auditor_lead@palka.internal",
09  "status": "VERIFIED_PASS"
10}
PLATFORM EVOLUTIONPRODUCT ROADMAP

Transparent milestones from September 2026 onward.

We publish our release roadmap openly so security and compliance teams can plan audit cadences with confidence.

Q3 2026 (September)Shipped

Core Platform & ISO 27001:2022

  • 93 Annex A control library across 4 themes
  • Interactive risk register with dynamic Likelihood × Impact scoring
  • Evidence file manager with SHA-256 checksum stamping
  • Row-level security multi-tenant workspace architecture
Q4 2026In progress

NRB Directives & Auditor Portal

  • Nepal Rastra Bank IT guideline mapping module
  • External auditor read-only guest access scopes with expiring tokens
  • Automated Statement of Applicability (SoA) export
  • Evidence expiration notifications via email & webhooks
Q1 2027Planned

SWIFT CSCF & Automated Integrations

  • SWIFT Customer Security Controls Framework (CSCF) module
  • Readiness assessment reports for interbank messaging nodes
  • Cloud configuration evidence ingest via standard API webhooks
  • Multi-organization group reporting for banking conglomerates
FREQUENT QUESTIONSTECHNICAL & COMPLIANCE FAQ

Answers to common architecture and compliance questions.

Clear details on multi-tenancy, regulatory coverage, and audit access.

Which compliance standards does Palka support out of the box?
Palka supports the complete ISO/IEC 27001:2022 standard (93 controls across Organizational, People, Physical, and Technological themes) and Nepal Rastra Bank (NRB) IT Guidelines. Support for the SWIFT Customer Security Controls Framework (CSCF v2024) is currently in development for release in Q1 2027.
How is data isolated between different client organizations?
Palka uses strict multi-tenant isolation with database Row-Level Security (RLS). Every query is constrained by tenant scope at the database engine level, ensuring zero possibility of cross-tenant data leakage.
Can Palka help our institution prepare for Nepal Rastra Bank IT inspections?
Yes. Palka includes dedicated mapping for NRB IT Directives, allowing financial institutions and PSPs/PSOs to track compliance against DR requirements, IT governance policies, and audit trails in a continuous manner rather than scrambling before annual inspections.
How are uploaded evidence artifacts stored and verified?
Evidence files (policies, screenshots, logs, test reports) are stored with AES-256 encryption at rest. Each file is hashed with SHA-256 on upload, giving compliance officers and external auditors a verifiable checksum to validate integrity.
Can we invite external auditors to review our compliance evidence?
Yes. Palka supports dedicated Read-Only External Auditor accounts. You can grant temporary, scoped access to specific framework modules or evidence repositories for the duration of an audit engagement without exposing internal administrative settings.
How is Palka deployed for enterprise and banking clients?
Palka is delivered as a secure cloud SaaS with dedicated regional availability options. For institutional enterprise requirements or localized data residency mandates, reach out to our team during the demo request.
AUDIT-PROOF GRCTECHNICAL WALKTHROUGH

Schedule a technical walkthrough for your institution.

See how Palka centralizes evidence, automates NRB IT Guidelines, and keeps your institution continuous audit-ready.