The compliance record

One page that says how ready you are — every clause of your standard, one verdict per clause, and a readiness number that reconciles against the rows below it.

The compliance record is the page you point an auditor at: every clause of the standard you are working toward, each with one verdict, and a readiness percentage at the top that is the sum of what you see below it — nothing more, nothing less.

One verdict per clause

Each clause row reads as exactly one state, folded from everything attached to it — its documents, their audit results, and its controls:

VerdictMeaning
ConformingThe clause's document audit passed, or every control on it is met
In progressDocumented, but not yet passing an audit
GapAn open non-conformity — in the document audit or on any control
Needs evidenceAn audit asked for evidence that isn't attached yet
Not assessedIn scope, but no evidence of any kind yet
ExcludedTaken out of scope in your Statement of Applicability, with a reason

The worst state wins. A clause with a live gap never reads Conforming, even if an earlier audit passed — the record tells you where you stand today, not where you stood at your best.

A clause no team owns yet shows as Unassigned (a hollow dot) — it is outside your scope until someone takes it on.

How the readiness number is worked out

Conforming clauses count in full, in-progress clauses count half, over everything in scope. A document merely existing is progress, not compliance — which is why an unaudited policy can only ever carry a clause halfway.

The count line under the headline — so many conforming, so many in progress, so many gaps — is clickable: each count filters the list to exactly the clauses behind it. Those counts are the percentage's own terms, so the number always reconciles against the rows you can see; they are the same verdicts, counted once.

What a row shows

Each row carries the clause code and name, what's attached (documents first, then controls), the team that owns it, and the verdict. Open a row to see the detail panel: the verdict, the owning teams, the attached documents and controls, and the doors to assign, attach, or exclude.

Scope and exclusions

Not every clause applies to every organisation. Excluding a clause asks for a reason, drops it from the readiness denominator, and shows it struck through with the reason kept — the record of what is in scope, what is out, and why is your Statement of Applicability, kept live on this page.

Attaching documents

Attaching is how a clause earns its first credit: link the policy, procedure, form, record or uploaded file that satisfies it, and the clause moves from Not assessed to In progress — half credit toward readiness.

There are three doors to the same picker:

  • On the row — a clause with nothing attached shows + Attach… when you point at it.
  • In the clause panelLink document under the Documents list.
  • In bulk — select several clauses and choose Attach document… from the action bar: one document's scope gains every selected clause in a single step, the way one manual legitimately covers a whole chapter of your standard.

The picker searches your whole Governance library, with each document's code, status, and how many clauses it already covers. A Suggested section leads with documents likely to satisfy the clause you're on — and says why in plain words (it covers a neighbouring clause, or its name matches the clause's subject). Suggestions never attach themselves.

If the document doesn't exist yet, you don't leave the picker: Upload a file brings a PDF or Word file in as a governed record first and then attaches it, and Write a new document creates a draft with the clause already attached and opens it in the editor.

Attaching declares the document's audit scope — the same link the document's own scope picker edits — so the record and the document can never disagree about what covers what. Every attach and detach is a line in the activity ledger, with who did it.

The activity ledger

The Activity tab is the record's memory, and it holds two kinds of line. Audit runs — what the audits found — carry status dots. Scope changes — what people did — carry a neutral dot: controls removed or restored, clauses excluded or returned to scope, standards added or removed, each with who did it and when. That second kind exists because a compliance record must be able to answer an auditor's first question — who changed this, and when? — about itself.

The ledger is append-only: nothing in the product can rewrite or delete a line.

When controls are removed, the removal line carries its own Restore — one click brings back exactly the controls that line recorded, statuses and audit history intact, and writes the restore as its own line. Removed controls are never destroyed; they are retired, and the ledger is the door back.