Home › Functions › Risk, Compliance & Governance

Have the evidence before anyone asks for it.

AI and software for risk, compliance and governance teams, across obligations, controls, evidence, policy and the reports you have to file.

One control, and whether you can prove it
The controlTested how, todayWhat the system does
Access reviews
A spreadsheet every quarter
Compared against the identity system, continuously
Vendor due diligence
A folder per vendor
Documents read, expiry tracked, gaps listed by vendor
Policy acknowledgement
An email chase before the audit
Tracked per person against the version in force
Segregation of duties
Sampled at year end
Checked on transactions as they post
Regulatory change
A circular in somebody’s inbox
Mapped to the obligations and owners it affects
Board reporting
Assembled the week before
Assembled from the register as the month runs

An auditor does not ask whether you have a control. They ask you to show it operating on a date, with the record.

In brief

We collect the evidence that your controls actually ran.

EigenSpark builds AI systems and the software around them for risk, compliance and governance teams. We connect the registers to the systems the controls actually run on, so evidence is collected as the month goes and never reconstructed before an audit. We test controls on live transactions, track policy and training acknowledgement per person, read vendor and licence documents into a register with their expiry dates, and map regulatory change onto the obligations and owners it touches. The officer decides on every finding.

Your systems

Inside the systems the controls actually run on.

Evidence lives in the operating systems, and that is where we go to get it.

SAP and OracleServiceNowMetricStream and ArcherYour identity providerYour HRMSGST portal and IMSMCA filingsYour policy repositoryContract repositoriesSIEM and log storesExcel registersInternal audit tools

Use cases

Twelve things we build for compliance teams.

The evidence first, then control testing, then documents and policy, then change and reporting.

Evidence collected as the month runs

Approvals, logs, reviews and exceptions captured from the operating systems on the date they happen, and filed against the control they prove.

Continuous Compliance Monitor →

Control testing on live transactions

Controls tested on the full population as it posts, so a failure is raised in the week it occurs and never in the year-end sample.

Continuous Compliance Monitor →

Access and segregation of duties

Entitlements reconciled against your identity system and your own conflict rules, with exceptions and their approvals listed continuously.

Continuous Compliance Monitor →

Vendor and licence documents

Registrations, certificates, insurances and licences read into a register with their expiry dates, and chased before they lapse.

Document Intelligence Engine →

Contract obligations tracked

Obligations, notice periods, penalties and renewal dates extracted from your contracts, with an owner and a date on each one.

Contract Risk Analyser →

Policy management and acknowledgement

Which policy version is in force, who has read it and who has not, tracked per person and chased without anybody writing an email.

Agentic AI →

Regulatory change mapped to owners

Circulars and amendments read and mapped onto the obligations, controls and owners they affect, with what changed stated in one line.

Generative AI →

Statutory registers and filings prepared

Registers, returns and annual filings assembled from the records you already hold, with the source of every figure shown for the signatory.

Continuous Compliance Monitor →

Third-party risk assessment

Vendors scored on documents held, financial signals, concentration and past performance, and refreshed as the underlying records change.

AI & Data Strategy →

Incident and whistleblower registers

Cases logged, routed and tracked against the timelines you owe, with the evidence for each step held together and access restricted.

Full-Stack Development →

Internal audit working papers

Populations selected, tests run and working papers drafted from live data, so audit time goes to judgement and the findings.

AI & Data Strategy →

Board and committee reporting

The compliance pack assembled from the register as the quarter runs, with each assertion linked to the evidence behind it.

Generative AI →

How an engagement runs

How we work with you.

Connect the register to the systems, automate one control, then hand it over.

01

Connect the register to the systems

Two to three weeks mapping your obligations and controls to the systems that hold the evidence, and to a named owner each. Everything else on this page depends on this.

  • Obligations mapped to systems and owners
  • Evidence source named for every control
  • The gaps listed, with what is missing said plainly
02

Automate one control

One control taken end to end: access review, segregation of duties, vendor documents or policy acknowledgement. Small enough to prove in a quarter and defensible in the next audit.

  • Tested on your own live data
  • Evidence kept with its date and its source
  • The compliance officer decides on every finding
03

Hand it to your team

Obligations, control definitions, thresholds, evidence rules and report formats live in a console your compliance team runs. A new regulation or entity does not need us.

  • Rules and definitions owned by compliance
  • Documentation and training for the people who run it
  • Deployed in your own cloud tenancy

Training

We train your compliance team to do this work with AI.

Ninety-minute hands-on sessions, run on your own obligations, controls and audit findings.

The compliance team

AI on obligations and evidence

Reading circulars, mapping obligations and drafting against your own register, with the judgements that must stay with a person named as such.

Walk away withA circular read into mapped obligations, and the drafting routine that produced it.

Internal audit and analysts

Testing the whole population

Querying the systems you oversee directly, writing tests that run on every transaction, and building working papers from live data.

Walk away withOne sampled test rewritten to run on every transaction, with its working paper.

The CRO, CCO and company secretary

Governing AI, and using it

What to require before a model touches a regulated process, how to evidence that to a board, and how to read a vendor’s compliance claim.

Walk away withA board-ready position on where AI is allowed, and the evidence it has to produce.

Compliance teams usually take Data & Analytics and AI & Machine Learning, with Leadership & Executive Readiness for the board-facing roles. The full catalogue is in Training & Enablement.

The engineering half

What sits under the AI.

Four layers of ordinary engineering. The first one is what makes an assertion provable.

01
Identity

One obligation, one control, one owner

An obligation that is not mapped to a system and a person is a sentence in a document. This layer is where a register becomes something you can test.

Obligation registerControl definitionsOwner and delegationEntity and locationRisk taxonomyEvidence classificationRetention schedule
02
Integration

The systems the evidence lives in

Your GRC tool stays the register. Most of the effort is reaching the operating systems where the control either ran or did not.

SAP and OracleServiceNowIdentity providerHRMSGST portal and MCAContract repositoriesLog stores and SIEM
03
Application

Screens built for a compliance officer

Built for the person who signs the assertion, with the finding, the evidence and the rule in one view, so a judgement can be recorded with its reason.

Finding queueEvidence workbenchControl libraryPolicy and acknowledgementRule consoleRole-based accessAudit log
04
Reporting

The numbers the board and the auditor see

Defined once and used everywhere, so the management assertion, the internal audit report and the board pack cannot disagree. Your team runs and owns it.

Control coverageTest pass rateOpen finding ageingEvidence completenessPolicy acknowledgementDocument expiry exposureRegulatory change closure

We also run the training that goes with it: SQL and data engineering, cloud, enterprise systems and cybersecurity, alongside the AI tracks. A compliance team that can query the systems it oversees writes better tests.

What we offer compliance teams

Four ways to work with us.

Most teams start with one control or the vendor document register, and use three of the four.

The obligations change by sector. See how this lands in BFSI or PSUs.

Security and controls

How we keep you in control.

The officer decides on every finding, evidence keeps its source and date, and nothing files itself.

01

The compliance officer decides

Findings, risk ratings and assertions go to the person accountable for them, with the evidence visible and the judgement recorded with its reason.

02

Evidence keeps its source and its date

Every item is stored with the system it came from, the moment it was captured and the control it proves, so it stands up when it is questioned.

03

Nothing files itself

No return, no filing and no board assertion is submitted by a system. It prepares and evidences, and your signatory decides.

04

The rule set belongs to you

Obligations, control definitions, thresholds and evidence rules are managed by your own team in a console, because the notifications keep coming.

FAQs

Questions compliance leaders ask us.

Do you replace our GRC platform?

No. ServiceNow, MetricStream, Archer or a set of spreadsheets stays the register. The work is connecting it to the systems where controls actually operate, so an assertion in the register is backed by evidence captured on the date, and so the fortnight before an audit stops being a reconstruction exercise.

Can an AI decide whether we are compliant?

No, and we would not build it that way. It tests, gathers evidence, flags exceptions and shows the rule behind each one. Whether a finding is a breach, and what to do about it, is a judgement with legal consequences, and it stays with your compliance officer. What changes is that the judgement is made on the full population and on time.

How do you keep up with regulatory change?

By holding the obligations as configuration your team owns, and by mapping a circular or an amendment onto the obligations, controls and owners it affects, with what changed stated plainly. A person confirms the mapping. The reason this is worth building is the volume: no compliance team can read everything and re-map the register by hand each time.

We are audited under several regimes at once. Does that work?

Yes, and it is the usual case. One control often satisfies several obligations, so we map the relationships once and collect the evidence once. Where regimes genuinely require different tests, they run separately and the register says which is which.

Can you help with the audit trail requirement?

Yes. The Companies (Accounts) Rules require accounting software to record an audit trail of each transaction and an edit log of every change with its date, and require that the trail cannot be disabled. It has applied since 1 April 2023 to companies. We check that the trail is on and complete across your systems, and we monitor for edits and for anything that suppresses it.

Where does the evidence sit?

In your own cloud tenancy. Compliance evidence is exactly the material you would least want outside your boundary, and it often carries personal data with its own retention rules. Where a hosted model is used for text work such as reading a circular, what is sent to it is agreed and recorded before anything is built.

Is all of this AI?

No, and the parts that are not are usually what makes the AI work. Mapping obligations to systems, connecting the identity provider, structuring the evidence store and building the rule engine are ordinary engineering, and they are most of the effort. The same is true of the training: alongside the AI tracks we run SQL, data engineering, cloud, enterprise systems and cybersecurity.

How large does a compliance team need to be for this to make sense?

The document register and expiry tracking work pays for itself with one compliance officer, because the cost of a lapsed licence has nothing to do with company size. Continuous control testing needs enough transaction volume for sampling to be genuinely inadequate, which is most companies with an ERP.

Related

Related pages.

The products this ships as, the services under them, and the industries where the obligations change.

Send us one control and its last audit finding.

Send the control description, how it is tested today and what the last audit said about it. We call you within 48 hours and go through where the evidence for it already exists, what would have to be connected, and what testing it continuously would involve.

Talk to us