Feature · Compliance

Compliance monitoring and testing that becomes a finding automatically.

Sample by risk, record results in a sample-by-step matrix, and let governed sign-off promote a failed test into a finding.

SectionCompliance
UpdatedSeptember 2026
Work programs
15
seeded
Checklists
20
monitoring
Prohibitions
13
absence-tested
AU-06 log review · risk-based sample × step
SampleS1S2S3S4
Sample 01PassPassPassPass
Sample 02PassPassExceptionPass
Sample 03PassPassPassPass
Sample 04PassExceptionPassException
3 exceptionsSign-off → Finding F-2026-0035
Illustrative product preview. It does not show tenant data.
01 · Monitoring & testing

Monitoring programs and workpaper

Run monitoring and testing as programs with a real workpaper instead of a spreadsheet you rebuild each quarter (compliance_monitoring).

  • 0120 monitoring checklists and 15 work programs seed the library.
  • 02Each program keeps its own workpaper and history.
02 · Monitoring & testing

Risk-based sampling

Draw the sample by risk, so effort lands where the exposure is instead of evenly across everything.

  • 01Sampling is risk-based and recorded on the workpaper.
03 · Monitoring & testing

Sample-by-step result matrix

Results land in a sample-by-step matrix, with exceptions and their root cause captured in place.

  • 01Every sample × step cell carries its result.
  • 02Exceptions capture root cause where they occur.
04 · Monitoring & testing

Governed sign-off into a Finding

At governed sign-off, a failed test promotes into a Finding that carries the citation, owner, and evidence. Nothing falls through the crack between testing and remediation.

  • 01Sign-off is a governed step instead of a checkbox.
  • 02A failed test becomes a Finding with its citation attached.
05 · Monitoring & testing

Absence testing and questionnaires

Prove a prohibited practice is absent, and gather structured answers with questionnaires (absence_testing, ddq).

  • 01Absence testing runs negative assurance against the 13 prohibitions in the corpus, 9 of them swept automatically today.
  • 02Questionnaires and DDQs collect structured, reviewable answers.
Proof points

Grounded in shipped behaviour.

  • 20 monitoring checklists and 15 work programs seed the program library.
  • A failed test at governed sign-off promotes into a Finding with its citation attached.
  • Absence testing runs negative assurance against the 13 prohibitions in the corpus, 9 of them swept automatically today.

Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.

FAQ

Questions, answered first.

What happens when a test fails?
At governed sign-off it promotes into a Finding that carries the citation, owner, and evidence. Remediation is tracked from there.
What is absence testing?
Absence testing is negative assurance. It proves a prohibited practice is absent. It runs against the 13 prohibitions in the corpus, 9 of them swept automatically today.
How is the sample chosen?
The sample is chosen by risk. Results land in a sample-by-step matrix, with exceptions and root cause captured in place.
Do I have to build every program from scratch?
No. 20 monitoring checklists and 15 work programs ship as starting points.

See monitoring & testing on your library.

Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.