Ontech ICTM platform

IT Compliance Management Software

Map your controls to the frameworks you answer to, see where the gaps are, and keep Data Protection Act records in the same system as your IT estate.

How can organisations manage IT compliance?

Organisations manage IT compliance by choosing the frameworks and laws that apply to them, mapping their existing controls to those requirements, finding and fixing the gaps, and keeping records that show the controls operate. Ontech ICTM supports each step with framework control sets, reviewed control mappings, gap analysis, audit-readiness scoring and registers for Zambia's Data Protection Act.

IT compliance is the work of showing that your technology and the way you run it meet the obligations you are bound by: a certification standard such as ISO/IEC 27001, an industry rule such as PCI DSS for card payments, or a law such as Zambia's Data Protection Act No. 3 of 2021. Most organisations answer to more than one of these at the same time, and the requirements overlap.

The hard part is rarely knowing the rules. It is keeping an honest, current picture of which controls exist, who owns them, where they fall short and what is being done about it — without rebuilding that picture in spreadsheets before every audit.

ICTM keeps that picture next to the systems it describes. Compliance checks are mapped to framework controls, gaps are grouped as covered, partial or uncovered, and security findings from connected sources feed the same view. Data-protection registers sit alongside, so privacy and security compliance are managed together rather than in separate tools.

What ICTM does for it compliance management

Framework control sets

Browse pre-loaded control sets for ISO/IEC 27001:2022, NIST CSF 2.0, PCI DSS 4.0, SOC 2, the HIPAA Security Rule, GDPR and CIS Controls v8, and track the status of each control you adopt.

AI-assisted control mapping with human review

ICTM proposes mappings between your compliance checks and framework controls with a confidence score. A person approves, adjusts or rejects each mapping, so the final mapping is always a human decision.

Compliance gap analysis

For each framework, ICTM groups controls as covered, partially covered or uncovered from your approved mappings, then produces a prioritised gap summary. The AI step can run on a locally hosted language model, so prompts and data need not leave your environment.

Security findings from connected sources

Import security findings from AWS Security Hub and GuardDuty, Azure alerts and recommendations, and GitHub Dependabot, code-scanning and secret-scanning alerts, alongside findings from ICTM's own vulnerability scanning.

Audit readiness

An audit-readiness score, checklist and remediation plan per framework, calculated from the records in ICTM, plus an audit package that brings the relevant control mappings together for your auditors.

Compliance roadmap and calendar

Generate a phased compliance roadmap (with a template fallback when the AI service is unavailable) and keep deadlines, reviews and renewals on a compliance calendar you can export to PDF or CSV.

Zambia Data Protection Act self-assessment

A scored questionnaire in ten sections, with weighted questions tied to sections of Act No. 3 of 2021. It gives per-section and overall scores, a severity band and remediation advice, and produces a report.

Data Protection Commissioner registers

Track your controller or processor registration with in-app renewal reminders, and keep records of processing, DPIAs, consent, personal data breaches, deletion requests and cross-border transfers in one place.

ICT inventory from the asset register

Build the ICT inventory for a data-protection self-assessment directly from ICTM's asset register and export it as CSV, instead of maintaining a separate spreadsheet.

Compliance chat grounded in the Act

Ask compliance questions in plain language. Answers about Zambian data protection are grounded in a digest of the Data Protection Act, and fall back to standard guidance if the AI service is unavailable.

ICTM modules: Compliance · Compliance AI · Compliance Roadmap · Compliance Calendar · Compliance Chat · DPA Assessment · Data Protection

Use cases

Preparing for an ISO/IEC 27001 audit

Map existing controls, close the uncovered ones, and hand auditors a package built from current records instead of a last-minute spreadsheet.

Card-payment security

Organisations that store, process or transmit card data can track their position against the PCI DSS 4.0 control set alongside their other obligations.

Data Protection Act readiness

Run the self-assessment, register processing activities, record DPIAs and keep the breach register ready before you need it.

Answering several frameworks at once

Where ISO/IEC 27001, NIST CSF and CIS Controls overlap, one control and its mapping can support several requirements instead of being documented three times.

Board and regulator questions

Give management a current, framework-by-framework view of coverage and open gaps when a regulator or auditor asks where the organisation stands.

Benefits

One compliance picture

Controls, gaps, findings and privacy registers live in one system instead of separate documents owned by different teams.

Less audit rework

Mappings and readiness scores are kept up to date as work happens, so audit preparation starts from existing records.

Human judgement stays in charge

AI suggestions are advisory and every control mapping is reviewed by a person before it counts.

Privacy and security together

Data Protection Act records sit beside the asset register and security findings they depend on.

Data can stay local

AI features can run on a locally hosted model, which matters when compliance data must not leave your environment.

Frequently asked questions

Which compliance frameworks does ICTM include?

ICTM includes control sets for ISO/IEC 27001:2022, NIST CSF 2.0, PCI DSS 4.0, SOC 2, the HIPAA Security Rule, GDPR and CIS Controls v8. Zambia's Data Protection Act is handled differently: through a scored self-assessment and the registers the Act calls for, rather than as a control library.

Will ICTM make my organisation compliant or get us certification?

No software can do that. Certification against a standard such as ISO/IEC 27001 is awarded by an accredited certification body after an audit, and legal compliance depends on how you actually operate. ICTM helps you organise controls, find gaps, track remediation and show your auditors current records.

How does the AI gap analysis work?

ICTM first works out which controls are covered, partially covered or uncovered from your approved control mappings. It then asks a language model to summarise the gaps and suggest priorities. The model can run on your own server, and its output is advice for your team to review, not a verdict.

Can ICTM notify the Data Protection Commissioner of a breach for us?

No. ICTM records the breach, the people affected and the dates on which the Commissioner and data subjects were notified, and alerts your administrators. Under section 49 of the Data Protection Act, the controller must notify the Commissioner within twenty-four hours, so the notification itself remains your responsibility.

Can we attach evidence documents to controls?

ICTM's evidence view is built from your control-mapping records and the findings linked to them, which show how each control is met. It is not a document repository, so keep signed policies and certificates in your document management system and reference them from the mapping.

Does ICTM help with the Cyber Security Act 2025?

Partly. The Cyber Security Act No. 3 of 2025 places duties on controllers of critical information infrastructure, including reporting cyber incidents to the Zambia Cyber Security Agency. ICTM's incident records, vulnerability findings and audit trail help you prepare, but it has no dedicated control set for the Act.

See it compliance management in Ontech ICTM

Book a walkthrough with the Ontech team, or start a free trial and explore the platform yourself.