General Compliance
The compliance office, in one place
Policies, obligations, gap assessments, the compliance calendar, maturity, investigations and the annual sign-off, together with a complete whistleblowing service. The steady work of the compliance office, kept current between audits.

Everything the compliance office runs
Connected areas sharing the same controls, owners and audit trail as the rest of the platform.
Policy management
A policy register with a full lifecycle, version history with change summaries, drafting help and a complete audit trail.
- Register and lifecycle
- Versioned change history
- Complete audit trail
Obligation register
Obligations across 13 pre-configured domains, from anti-bribery and anti-money laundering to sanctions, competition, data protection and cybersecurity, each with an owner, linked controls and a review frequency. Paste in a regulation and have the distinct obligations pulled out for you to review.
- 13 pre-configured domains
- AI-assisted extraction
- Owner and linked controls
Gap assessment
A structured comparison of control coverage against your obligations, so the gaps are named rather than assumed.
- Coverage against obligations
- Named gaps
- Board-ready output
Compliance calendar
Writable events, categories and reusable templates, so the recurring obligations of the year sit on one calendar the whole office can see.
- Writable events
- Categories
- Reusable templates
Compliance maturity
A six-dimension self-assessment aligned to ISO 37301 and the US DOJ criteria, producing a board-ready maturity report.
- ISO 37301 aligned
- US DOJ criteria
- Board-ready report
Investigations
A workdesk with evidence preservation, interview notes, decision records and role-restricted access, for when a matter needs looking into.
- Evidence preservation
- Decision records
- Role-restricted access
Compliance matters
The umbrella record that holds a piece of work together, tying obligations, controls, investigations, third parties and remediation to one thread with one audit trail. High-priority matters mirror into the enterprise risk register.
- One record, one thread
- Mirrors into enterprise risk
- Full audit trail
Controls and testing
A control library you can build from standard templates or your own, with recurring test schedules, evidence against each test, and a pass, partial or fail picture you can show an auditor.
- Control library
- Recurring test schedules
- Evidence per test
Issues and remediation
A closed loop from raising an issue through remediation and validation to closure, so a finding cannot quietly go stale between audits.
- Remediate, validate, close
- Owners and due dates
- Nothing goes stale
A complete whistleblowing service
Aligned with the EU Whistleblower Directive. A branded public portal takes reports anonymously by default, issues a reporter tracking code, and supports encrypted two-way follow-up. Internal case management runs through triage, review and resolution, with SLA-based escalation and strict role-based access.
Anonymous by default
A branded public portal where a reporter can stay anonymous.
Encrypted two-way follow-up
The handler can ask questions without ever learning the reporter's identity.
Tracking code
A reporter code lets a submission be followed up over time.
8 languages
Case management and the reporting portal run in every platform language.

Annual sign-off, with evidential weight
The recurring attestations that keep a compliance programme defensible, run as campaigns rather than chased by email.
Annual policy review and sign-off
Review cycles combined with certification campaigns that target the reviewer population, set the due date, send reminders on their own and track completion, with the policy version history documenting what changed and who approved it.
Annual compliance sign-off
Attestation campaigns targeting individuals, roles, departments or the whole organisation. Conflict-of-interest declarations run annually with step-up authentication before a sign-off is recorded, so each signature carries real evidential weight.
Anti-bribery and corruption
A dedicated register for gifts, hospitality and bribery-risk declarations, with configurable thresholds driving multi-level approvals.
Anti-money laundering and sanctions
Governed as obligation domains with owners, controls, policies, training and investigations, plus a per-country sanctions-exposure indicator, ready to pair with a specialist screening tool for deep list-matching.
Run the whole office from one platform
Policies, obligations, attestations and investigations on one shared record, with a whistleblowing service your people can trust.