Every obligation traced to its clause, owner and evidence.

Regulatory obligations management that starts from the alerts your team converts, with the article cited. Each obligation carries an owner, a review date and its evidence, and management reports go out on schedule.

Compliance operations: the product view.
Compliance operations: the product view.

Audit readiness should not be a project.

Most obligation registers are spreadsheets. The link from each obligation back to the regulator’s clause, forward to the owner’s evidence, and through the history of who changed what is rebuilt by hand whenever an auditor asks.

  • Obligations lose the clause they came from.
  • Evidence sits in shared drives, detached from the requirement it proves.
  • Review dates and attestations live in calendars nobody audits.
  • The board report is assembled from exports every quarter.

An obligation from the source

Converting an alert creates the obligation with the article reference, requirement, type, risk, owner, effective date and next review. The originating alert and its excerpt stay one click away.

An obligation from the source
An obligation from the source

Evidence where it belongs

Owners attach files, links, attestations, notes and external records to the obligation, each classified as public, internal, confidential or secret.

Evidence where it belongs
Evidence where it belongs

Reports on a schedule

Management reports are generated as PDFs weekly or monthly and emailed to the people you choose: an executive overview and summary, breakdowns, alert details, and scope and limitations.

Reports on a schedule

What you get

  • Obligations register

    Every obligation with its article, status, risk, topics, jurisdictions, effective date and source type, in one register.

  • Obligation types

    Policy, control, attestation, reporting, disclosure, training and recordkeeping, each with a status of draft, active, superseded or retired.

  • Evidence

    Files, links, attestations, notes and external records, classified by sensitivity and attached to the obligation they prove.

  • Reviews and attestations

    Each obligation carries its next review date. Reviews, attestations and filings appear on the calendar beside regulatory deadlines.

  • History and discussion

    Status changes, owner changes and linked evidence are kept in the obligation’s history, beside the team’s discussion.

  • Tamper-evident audit log

    Changes are written to a tamper-evident, append-only audit log: when, actor, entity, action and reason. Audit Reviewer is a read-only role of its own.

  • Dashboard

    Current workload, watchlist health, and alerts by urgency, topic and market, in one view for the compliance lead.

  • Management reports

    Weekly or monthly PDFs emailed to the people you choose, each with a section on scope and limitations.

Questions

Where do obligations come from?

From alerts your team converts, with the article reference carried over, or created directly in the register. A converted obligation keeps its link to the alert and the source excerpt.

What counts as evidence?

Files, links, attestations, notes and external records, such as a filing reference in another system. Each item carries a classification and stays attached to the obligation it proves.

Is the audit log really tamper-evident?

Yes. Entries are hash-chained and append-only, so a changed or removed entry breaks the chain and can be detected. Each entry records when, the actor, the entity, the action and the reason.

Can reports go to the board directly?

Management reports are PDFs emailed weekly or monthly to the addresses you set. The board pack starts from the same records as the register.

See an obligation traced to its clause.

The demo runs on the regulators you name, from the publication to the evidence.

Book a demo