Every obligation traced to its clause, owner and evidence.
Regulatory obligations management that starts from the alerts your team converts, with the article cited. Each obligation carries an owner, a review date and its evidence, and management reports go out on schedule.
Audit readiness should not be a project.
Most obligation registers are spreadsheets. The link from each obligation back to the regulator’s clause, forward to the owner’s evidence, and through the history of who changed what is rebuilt by hand whenever an auditor asks.
- Obligations lose the clause they came from.
- Evidence sits in shared drives, detached from the requirement it proves.
- Review dates and attestations live in calendars nobody audits.
- The board report is assembled from exports every quarter.
An obligation from the source
Converting an alert creates the obligation with the article reference, requirement, type, risk, owner, effective date and next review. The originating alert and its excerpt stay one click away.
Evidence where it belongs
Owners attach files, links, attestations, notes and external records to the obligation, each classified as public, internal, confidential or secret.
Reports on a schedule
Management reports are generated as PDFs weekly or monthly and emailed to the people you choose: an executive overview and summary, breakdowns, alert details, and scope and limitations.
What you get
Obligations register
Every obligation with its article, status, risk, topics, jurisdictions, effective date and source type, in one register.
Obligation types
Policy, control, attestation, reporting, disclosure, training and recordkeeping, each with a status of draft, active, superseded or retired.
Evidence
Files, links, attestations, notes and external records, classified by sensitivity and attached to the obligation they prove.
Reviews and attestations
Each obligation carries its next review date. Reviews, attestations and filings appear on the calendar beside regulatory deadlines.
History and discussion
Status changes, owner changes and linked evidence are kept in the obligation’s history, beside the team’s discussion.
Tamper-evident audit log
Changes are written to a tamper-evident, append-only audit log: when, actor, entity, action and reason. Audit Reviewer is a read-only role of its own.
Dashboard
Current workload, watchlist health, and alerts by urgency, topic and market, in one view for the compliance lead.
Management reports
Weekly or monthly PDFs emailed to the people you choose, each with a section on scope and limitations.
Questions
Where do obligations come from?
From alerts your team converts, with the article reference carried over, or created directly in the register. A converted obligation keeps its link to the alert and the source excerpt.
What counts as evidence?
Files, links, attestations, notes and external records, such as a filing reference in another system. Each item carries a classification and stays attached to the obligation it proves.
Is the audit log really tamper-evident?
Yes. Entries are hash-chained and append-only, so a changed or removed entry breaks the chain and can be detected. Each entry records when, the actor, the entity, the action and the reason.
Can reports go to the board directly?
Management reports are PDFs emailed weekly or monthly to the addresses you set. The board pack starts from the same records as the register.
Guides
- Regulatory Obligations Register Template: How to Build One That Survives an AuditA free, ungated obligations register template with 28 annotated fields, six populated rows from DORA, and the change-management columns that decide whether the register survives an audit. It is built for a time when regulators collect registers in prescribed formats.
- Free Regulatory Change Tracker Spreadsheet, and When You'll Outgrow ItAn ungated regulatory change tracker in Excel with a 25-field change log, an emerging-regulations tab and worked rows from the EU AI Act, DORA and the FCA Grid. Plus a ten-question scorecard that tells you, with a number, when the spreadsheet stops being the right tool.
- Regulatory Change Impact Assessment Template (With a Worked DORA Example)A six-section regulatory change impact assessment template, published in full with no sign-up wall, then filled in end to end for the DORA subcontracting RTS. It includes the fields most templates omit: instrument lifecycle status, documented out-of-scope reasoning, and evidence and validation for each obligation.
Related

See an obligation traced to its clause.
The demo runs on the regulators you name, from the publication to the evidence.