Skip to main content

    General Compliance
    The compliance office, in one place

    Policies, obligations, gap assessments, the compliance calendar, maturity, investigations and the annual sign-off, together with a complete whistleblowing service. The steady work of the compliance office, kept current between audits.

    Get Started
    General Compliance hub with the obligation register, compliance calendar and maturity scorecard

    Everything the compliance office runs

    Connected areas sharing the same controls, owners and audit trail as the rest of the platform.

    Policy management

    A policy register with a full lifecycle, version history with change summaries, drafting help and a complete audit trail.

    • Register and lifecycle
    • Versioned change history
    • Complete audit trail

    Obligation register

    Obligations across 13 pre-configured domains, from anti-bribery and anti-money laundering to sanctions, competition, data protection and cybersecurity, each with an owner, linked controls and a review frequency. Paste in a regulation and have the distinct obligations pulled out for you to review.

    • 13 pre-configured domains
    • AI-assisted extraction
    • Owner and linked controls

    Gap assessment

    A structured comparison of control coverage against your obligations, so the gaps are named rather than assumed.

    • Coverage against obligations
    • Named gaps
    • Board-ready output

    Compliance calendar

    Writable events, categories and reusable templates, so the recurring obligations of the year sit on one calendar the whole office can see.

    • Writable events
    • Categories
    • Reusable templates

    Compliance maturity

    A six-dimension self-assessment aligned to ISO 37301 and the US DOJ criteria, producing a board-ready maturity report.

    • ISO 37301 aligned
    • US DOJ criteria
    • Board-ready report

    Investigations

    A workdesk with evidence preservation, interview notes, decision records and role-restricted access, for when a matter needs looking into.

    • Evidence preservation
    • Decision records
    • Role-restricted access

    Compliance matters

    The umbrella record that holds a piece of work together, tying obligations, controls, investigations, third parties and remediation to one thread with one audit trail. High-priority matters mirror into the enterprise risk register.

    • One record, one thread
    • Mirrors into enterprise risk
    • Full audit trail

    Controls and testing

    A control library you can build from standard templates or your own, with recurring test schedules, evidence against each test, and a pass, partial or fail picture you can show an auditor.

    • Control library
    • Recurring test schedules
    • Evidence per test

    Issues and remediation

    A closed loop from raising an issue through remediation and validation to closure, so a finding cannot quietly go stale between audits.

    • Remediate, validate, close
    • Owners and due dates
    • Nothing goes stale

    A complete whistleblowing service

    Aligned with the EU Whistleblower Directive. A branded public portal takes reports anonymously by default, issues a reporter tracking code, and supports encrypted two-way follow-up. Internal case management runs through triage, review and resolution, with SLA-based escalation and strict role-based access.

    • Anonymous by default

      A branded public portal where a reporter can stay anonymous.

    • Encrypted two-way follow-up

      The handler can ask questions without ever learning the reporter's identity.

    • Tracking code

      A reporter code lets a submission be followed up over time.

    • 8 languages

      Case management and the reporting portal run in every platform language.

    Branded anonymous whistleblowing portal with reporter tracking code

    Annual sign-off, with evidential weight

    The recurring attestations that keep a compliance programme defensible, run as campaigns rather than chased by email.

    Annual policy review and sign-off

    Review cycles combined with certification campaigns that target the reviewer population, set the due date, send reminders on their own and track completion, with the policy version history documenting what changed and who approved it.

    Annual compliance sign-off

    Attestation campaigns targeting individuals, roles, departments or the whole organisation. Conflict-of-interest declarations run annually with step-up authentication before a sign-off is recorded, so each signature carries real evidential weight.

    Anti-bribery and corruption

    A dedicated register for gifts, hospitality and bribery-risk declarations, with configurable thresholds driving multi-level approvals.

    Anti-money laundering and sanctions

    Governed as obligation domains with owners, controls, policies, training and investigations, plus a per-country sanctions-exposure indicator, ready to pair with a specialist screening tool for deep list-matching.

    Run the whole office from one platform

    Policies, obligations, attestations and investigations on one shared record, with a whistleblowing service your people can trust.