Registers
Policies, controls and findings, all linked.
Policy library, control library, and findings and actions. Mandatory fields, configurable approvals, requirement links and full history on every row.
What it replaces
Separate spreadsheets for policies, controls and issues, each in its own format, none linked to the obligations they exist to meet.
How it works
Step 1
Record
Each register has mandatory fields that cannot be left blank. Your admin can add custom fields without code.
Step 2
Approve
Configure the approval workflow per register. Set ordered steps, roles or named approvers, four-eyes where you need it, and e-signature. A rejected record returns to draft with the comment.
Step 3
Link and export
Every row links to the requirements and policies it serves, and unlinked rows are flagged on the dashboard. Export to PDF with the approval chain and a hash footer, or to CSV.
Why it exists
An inspector does not only ask whether you have a policy. They ask who approved it, which obligations it covers, which controls put it into effect, and what you did about the last exception. Registers that are linked to each other answer those questions directly.
Registers available in the monitoring core
- Policy library. Owner, version, approval, effective date, review frequency and the document itself. A coverage view shows applicable requirements with no mapped policy. Policies can require read-and-attest from named roles, tracked per person with a timestamp. Every prior version is kept.
- Control library. Control ID, description, owner, type (preventive, detective or corrective), frequency, whether it is automated, and the requirements and policies it serves. Controls without a monitoring test are flagged.
- Findings and actions. One tracker for every source: monitoring tests, internal audit, external audit, regulator inspections, operational risk events and self-identified issues. Each finding has a severity, owner and due date. Closing it needs evidence and reviewer approval.
On the roadmap
Every register is built on the same framework, so later registers behave the same way. Planned next are financial crime, regulatory engagement and risk registers, such as SAR/STR, sanctions and TFS, the business-wide risk assessment, the risk register and risk appetite. Conduct, governance and virtual asset registers follow. These are not available today. TODO(Miles): confirm how much of the roadmap to show publicly