ISO 19600 Maturity · Compliance management systems (corporate compliance)
Your compliance management, placed on a maturity scale and translated into a costed action plan.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
ISO 19600 Maturity · Compliance management systems (corporate compliance)
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One ISO 19600:2014, superseded by ISO 37301:2021 assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
It is this mechanism (a level, a level above it, and the action linking the two) that turns a finding into a trajectory.
Is the inventory of compliance obligations kept up to date and assigned to identified owners?
- N1
No consolidated inventory. Obligations are known to the teams that apply them, with no shared record.
- N2
An inventory exists as a file, built during a one-off project. It has no designated owner and no update cycle.
- N3
The inventory is structured, each obligation has a named owner and a periodic review is scheduled. A few areas remain incomplete.
- N4
The inventory covers the entire scope, it is fed by a formalised regulatory watch and every change triggers a review of the associated controls.
- N5
The inventory is linked to processes, controls and risks. Revisions are logged and their impact is measured at the management review.
Action to move from L2 to L3
Appoint an owner for each family of obligations, add the inventory review to the quarterly compliance committee agenda and set the date for the first full review before year end.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurementon ISO 19600.
What this framework covers
In 2014, ISO 19600 set out the framework for a compliance management system applicable to any organisation, regardless of size or sector. It requires identifying compliance obligations (laws, regulations, contractual commitments, voluntary codes), assessing the associated risks, defining a policy and responsibilities, putting in place controls, training and a whistleblowing mechanism, and then measuring the performance of the framework. Its architecture follows the common structure of management system standards, which makes it easy to align with ISO 9001, ISO 37001 or ISO 31000.
In practice, this framework is difficult to steer because it is distributed. The map of obligations is rarely owned by a single function: legal tracks regulation, business units track their own commitments, subsidiaries apply local rules. Three questions come up time and again. Who maintains the inventory of obligations, and how often? Do second-line controls cover the processes that are actually exposed, or the ones that are already known to be under control? Do reports escalate to a level capable of deciding, or do they stop with the local manager?
The point of context most often misunderstood concerns the change in the standard’s status. ISO 19600 was a set of guidelines, not certifiable. ISO 37301, published in 2021, replaces it and turns those guidelines into requirements auditable by an accredited body. Many organisations built their framework on the 2014 version and still cite it, without having checked the gap against the 2021 requirements. The EU whistleblowing directive, transposed into national law, has also made binding part of what the standard previously treated as good practice.
A compliance audit ends with a binary finding: the requirement is met or it is not. The maturity assessment asks a different question: what level of control does each component of the framework sit at, and what concrete action moves it to the next level. An organisation may have a signed compliance policy and still sit at level 2 if nobody applies it outside head office. The scale makes that gap visible and gives it a number.
In Datamensio, the framework is ready to use and can be adapted. The AI adjusts the themes, rewords the questions to your sector’s vocabulary and refines the levels according to the CMMI method. It can also build a variant based on your code of conduct, your map of obligations or your existing internal control procedures.
Reference standard: ISO 19600:2014, superseded by ISO 37301:2021
The themes assessed
Context and scope of the framework
Analysis of internal and external issues, identification of interested parties, definition of scope, alignment with other management systems.
Governance and management commitment
Compliance policy, positioning and independence of the compliance function, reporting line, resources allocated, management leading by example.
Inventory of compliance obligations
Mapping of laws, regulations, contractual commitments and voluntary codes, owner per obligation, regulatory watch, update frequency.
Assessment of non-compliance risks
Assessment method, prioritisation by process and entity, distinction between inherent and residual risk, alignment with the enterprise risk map.
Controls and operational procedures
Design of first and second-line controls, integration into business processes, traceability of evidence, management of third parties and the supply chain.
Culture, training and awareness
Code of conduct, training plan by exposed population, measurement of actual understanding, compliance factored into manager appraisals.
Whistleblowing and handling of breaches
Reporting channels, protection of whistleblowers, internal investigation protocol, sanction decisions, traceability and confidentiality of cases.
Performance measurement and reporting
Compliance indicators, dashboard, reporting to the audit committee and the board, quality of the information passed to governance bodies.
Internal audit and management review
Audit programme for the framework, auditor competence, follow-up of recommendations through to closure, periodic review by management.
Continual improvement
Handling of non-conformities, root cause analysis, lessons learned from incidents, updating of the framework and comparison over time.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Is ISO 19600 still in force?
It was superseded in 2021 by ISO 37301. ISO 19600 remains a useful reference because the structure of the framework is identical, but it was only a set of guidelines. The Datamensio framework covers both readings and highlights the points that became requirements in the 2021 version.
Does this assessment deliver certification?
No. Datamensio measures the maturity of the framework and prepares for the audit. ISO 37301 certification is issued by an accredited body, following its own process. The assessment tells you where you stand before starting that process.
What is the difference with a compliance audit?
An audit checks whether requirements are met and ends with a gap or a pass. The assessment places each practice on a progressive scale and points to the action that moves it up a level. The two complement each other: the assessment prepares, the audit validates.
How long does the assessment take?
The short version can be completed in a single session by a compliance lead. The full version, run collaboratively with legal, internal audit and entity contacts, generally takes one to two weeks, most of the time spent gathering evidence.
Can the framework be adapted to our organisation?
Yes. The themes, questions and level wording can all be changed. The AI can reword everything to your sector’s vocabulary, add a theme specific to your local obligations, or build a variant based on your code of conduct and procedures.
How do we compare several subsidiaries?
The same framework is rolled out to each entity, with a score by theme and a shared target. The benchmark compares business units against each other and each against its own past results. A cross-entity roadmap consolidates the action plans of the different entities.
Does this framework overlap with ISO 37001 or ISO 31000?
Yes, without duplicating the work. ISO 37001 deals specifically with bribery, ISO 31000 provides the risk management framework that non-compliance risk falls under. Action plans from several assessments consolidate into a single roadmap.
Where is the data hosted?
In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.





