Skip to main content
Compliance management software

Manage obligations, evidence and compliance activity in one system

Consolidate compliance obligations from law, contracts and internal policy into a single register — linked to controls, evidence and corrective actions.

ISO 37301ISO 19011Three lines of defence
Illustration of the product interface
What to know before you choose

Is this module right for your organisation?

What is RiskTech compliance management?

It is the module that holds every compliance obligation in one register. Obligations are extracted from regulations, contracts, internal policy and standards, then linked to the controls in operation and the evidence submitted by business units. The system tracks each obligation through six stages until it reaches compliance.

Who is it for?

Compliance and legal carry the main responsibility. Compliance officers in each unit submit evidence through a dedicated portal. Leadership and the board see consolidated compliance status. Internal audit reuses the same control library once the platform is linked.

What problems does it solve?

Three problems: obligations spread across many spreadsheets so nobody knows the total; no clarity on which obligations lack a matching control; and evidence submitted in one place and assessed in another, so there is no trace of who concluded what, and when.

How is it different from a spreadsheet?

The system separates compliance outcome from workload, distinguishes five result levels rather than pass or fail, prevents whoever submitted evidence from assessing it, and keeps a log of who, when and why for every change.

How is it rolled out?

The module runs on its own; the other two are not required. Initial data covers the applicable regulations, the existing control list and the org structure. When the organisation is ready, switch on linking to share the risk register and control library with the other two modules.

The business problem

When obligations are scattered, mistakes slip through

01

Nobody knows the total number of obligations

Obligations sit in spreadsheets across many departments. When the regulator asks, it takes days to pull together.

02

Obligations are not linked to controls

The organisation has control processes and legal obligations, but nobody can reconcile which obligation is missing a control.

03

Evidence cannot be traced

Attachments live in email. It is unclear who submitted, who assessed, and on what grounds the conclusion was reached.

04

Regulatory change goes unreviewed

A new regulation is issued, but there is no mechanism to identify which obligations are affected and which controls must change.

Photo of a compliance officer reviewing files — landscape
Compliance obligations
From the source regulation through to assessed evidence.
End-to-end process

Track obligations from requirement through to remediation

Input
Regulations, contracts, internal policy
Activity
Extract obligations · link controls · collect evidence
Control and approval
The assessor concludes, separate from the submitter
Output
Compliance status, gaps, period reports
Compliance check processfour steps, following ISO 190114 steps
  1. 1Plan
    Annual programme, objectives, scope, criteria and team assignment.
  2. 2Perform
    Collect evidence against the programme, record findings and severity.
  3. 3Report
    Discuss with the unit, confirm findings, draft and issue the report.
  4. 4Monitor remediation
    Track actions to closure and update compliance risk.
Product screens

See compliance activity managed in practice

Two representative screens illustrating the product interface. The figures shown are sample data.

Compliance overview

Screen 1

Two separate groups of measures: the compliance outcome of obligations in force, and the workload still to be done.

Obligation lifecycle and check campaigns

Screen 2

Each obligation passes through six stages; compliance check campaigns run alongside them in the four steps of ISO 19011.

Feature groups

Every role knows what needs doing

Consolidated obligation register

Compliance function
  • Extract obligations from four sources: law, contracts, internal policy, standards
  • Link obligations to controls so uncovered obligations surface by themselves
  • A reassessment cycle set per obligation

Evidence and assessment

Unit compliance officers
  • Units submit evidence through a dedicated portal with deadlines
  • Five result levels rather than pass or fail
  • Submitter and assessor are different people, enforced from assignment onward

Regulatory change

Legal
  • Compare regulation versions
  • Impact analysis against every obligation being tracked
  • Rank impact as high, medium or low

Findings and remediation

Compliance function
  • Findings carry severity, an owner and a deadline
  • Exceptions carry a validity period and an approver
  • Tracked through to closure

Concerns and training

HR, compliance
  • A channel for raising concerns plus an investigation process
  • Awareness training campaigns per period
  • Completion rates tracked by unit

AI assistant with citations

All roles
  • Points out obligations with no control and suggests existing ones
  • Every suggestion carries source citations
  • Approval is required; with AI off the system still runs in full
Who it fits

Who is it for and what do you need to prepare?

Portrait photo of a compliance officer
Who it fitsWhen to use itData to prepare
Enterprises with many sector obligations: finance, banking, insurance, healthcare, educationAhead of a review period or a sector inspectionThe list of applicable regulations
Groups with several member companies and legal entitiesWhen consolidating compliance after a merger or branch expansionOrg structure and compliance owners
Organisations building a compliance management system to ISO 37301When moving from spreadsheets to a systemThe existing control list
Reference standards

Which standards is it built around?

RiskTech supports organisations operating to the standards below. This is not a certification claim for the software or for the organisations using it.

ISO 37301
Compliance management systems
ISO 19011
Guidelines for auditing management systems
Three lines of defence
Responsibility model
Application scenario

Illustrative application scenario

This scenario explains how the product is used; it is not the result of a rollout at a specific client. Once we have a real client scenario with written consent to publish, this section will be updated.

Frequently asked questions

Compliance management

See how RiskTech supports your compliance needs

A 30-minute demo following the role you hold. No data preparation needed beforehand. We respond within one business day.

ceo-office@risktech.asia