The compliance record
One page that says how ready you are — every clause of your standard, one verdict per clause, and a readiness number that reconciles against the rows below it.
The compliance record is the page you point an auditor at: every clause of the standard you are working toward, each with one verdict, and a readiness percentage at the top that is the sum of what you see below it — nothing more, nothing less.
One verdict per clause
Each clause row reads as exactly one state, folded from everything attached to it — its documents, their audit results, and its controls:
| Verdict | Meaning |
|---|---|
| Conforming | The clause's document audit passed, or every control on it is met |
| In progress | Documented, but not yet passing an audit |
| Gap | An open non-conformity — in the document audit or on any control |
| Needs evidence | An audit asked for evidence that isn't attached yet |
| Not assessed | In scope, but no evidence of any kind yet |
| Excluded | Taken out of scope in your Statement of Applicability, with a reason |
The worst state wins. A clause with a live gap never reads Conforming, even if an earlier audit passed — the record tells you where you stand today, not where you stood at your best.
A clause no team owns yet shows as Unassigned (a hollow dot) — it is outside your scope until someone takes it on.
How the readiness number is worked out
Conforming clauses count in full, in-progress clauses count half, over everything in scope. A document merely existing is progress, not compliance — which is why an unaudited policy can only ever carry a clause halfway.
The count line under the headline — so many conforming, so many in progress, so many gaps — is clickable: each count filters the list to exactly the clauses behind it. Those counts are the percentage's own terms, so the number always reconciles against the rows you can see; they are the same verdicts, counted once.
What a row shows
Each row carries the clause code and name, what's attached (documents first, then controls), the team that owns it, and the verdict. Open a row to see the detail panel: the verdict, the owning teams, the attached documents and controls, and the doors to assign, attach, or exclude.
Scope and exclusions
Not every clause applies to every organisation. Excluding a clause asks for a reason, drops it from the readiness denominator, and shows it struck through with the reason kept — the record of what is in scope, what is out, and why is your Statement of Applicability, kept live on this page.
Attaching documents
Attaching is how a clause earns its first credit: link the policy, procedure, form, record or uploaded file that satisfies it, and the clause moves from Not assessed to In progress — half credit toward readiness.
There are three doors to the same picker:
- On the row — a clause with nothing attached shows + Attach… when you point at it.
- In the clause panel — Link document under the Documents list.
- In bulk — select several clauses and choose Attach document… from the action bar: one document's scope gains every selected clause in a single step, the way one manual legitimately covers a whole chapter of your standard.
The picker searches your whole Governance library, with each document's code, status, and how many clauses it already covers. A Suggested section leads with documents likely to satisfy the clause you're on — and says why in plain words (it covers a neighbouring clause, or its name matches the clause's subject). Suggestions never attach themselves.
If the document doesn't exist yet, you don't leave the picker: Upload a file brings a PDF or Word file in as a governed record first and then attaches it, and Write a new document creates a draft with the clause already attached and opens it in the editor.
Attaching declares the document's audit scope — the same link the document's own scope picker edits — so the record and the document can never disagree about what covers what. Every attach and detach is a line in the activity ledger, with who did it.
The activity ledger
The Activity tab is the record's memory, and it holds two kinds of line. Audit runs — what the audits found — carry status dots. Scope changes — what people did — carry a neutral dot: controls removed or restored, clauses excluded or returned to scope, standards added or removed, each with who did it and when. That second kind exists because a compliance record must be able to answer an auditor's first question — who changed this, and when? — about itself.
The ledger is append-only: nothing in the product can rewrite or delete a line.
When controls are removed, the removal line carries its own Restore — one click brings back exactly the controls that line recorded, statuses and audit history intact, and writes the restore as its own line. Removed controls are never destroyed; they are retired, and the ledger is the door back.