AI and software for risk, compliance and governance teams, across obligations, controls, evidence, policy and the reports you have to file.
An auditor does not ask whether you have a control. They ask you to show it operating on a date, with the record.
In brief
EigenSpark builds AI systems and the software around them for risk, compliance and governance teams. We connect the registers to the systems the controls actually run on, so evidence is collected as the month goes and never reconstructed before an audit. We test controls on live transactions, track policy and training acknowledgement per person, read vendor and licence documents into a register with their expiry dates, and map regulatory change onto the obligations and owners it touches. The officer decides on every finding.
Your systems
Evidence lives in the operating systems, and that is where we go to get it.
Use cases
The evidence first, then control testing, then documents and policy, then change and reporting.
Approvals, logs, reviews and exceptions captured from the operating systems on the date they happen, and filed against the control they prove.
Continuous Compliance Monitor →Controls tested on the full population as it posts, so a failure is raised in the week it occurs and never in the year-end sample.
Continuous Compliance Monitor →Entitlements reconciled against your identity system and your own conflict rules, with exceptions and their approvals listed continuously.
Continuous Compliance Monitor →Registrations, certificates, insurances and licences read into a register with their expiry dates, and chased before they lapse.
Document Intelligence Engine →Obligations, notice periods, penalties and renewal dates extracted from your contracts, with an owner and a date on each one.
Contract Risk Analyser →Which policy version is in force, who has read it and who has not, tracked per person and chased without anybody writing an email.
Agentic AI →Circulars and amendments read and mapped onto the obligations, controls and owners they affect, with what changed stated in one line.
Generative AI →Registers, returns and annual filings assembled from the records you already hold, with the source of every figure shown for the signatory.
Continuous Compliance Monitor →Vendors scored on documents held, financial signals, concentration and past performance, and refreshed as the underlying records change.
AI & Data Strategy →Cases logged, routed and tracked against the timelines you owe, with the evidence for each step held together and access restricted.
Full-Stack Development →Populations selected, tests run and working papers drafted from live data, so audit time goes to judgement and the findings.
AI & Data Strategy →The compliance pack assembled from the register as the quarter runs, with each assertion linked to the evidence behind it.
Generative AI →How an engagement runs
Connect the register to the systems, automate one control, then hand it over.
Two to three weeks mapping your obligations and controls to the systems that hold the evidence, and to a named owner each. Everything else on this page depends on this.
One control taken end to end: access review, segregation of duties, vendor documents or policy acknowledgement. Small enough to prove in a quarter and defensible in the next audit.
Obligations, control definitions, thresholds, evidence rules and report formats live in a console your compliance team runs. A new regulation or entity does not need us.
Training
Ninety-minute hands-on sessions, run on your own obligations, controls and audit findings.
The compliance team
Reading circulars, mapping obligations and drafting against your own register, with the judgements that must stay with a person named as such.
Walk away withA circular read into mapped obligations, and the drafting routine that produced it.
Internal audit and analysts
Querying the systems you oversee directly, writing tests that run on every transaction, and building working papers from live data.
Walk away withOne sampled test rewritten to run on every transaction, with its working paper.
The CRO, CCO and company secretary
What to require before a model touches a regulated process, how to evidence that to a board, and how to read a vendor’s compliance claim.
Walk away withA board-ready position on where AI is allowed, and the evidence it has to produce.
Compliance teams usually take Data & Analytics and AI & Machine Learning, with Leadership & Executive Readiness for the board-facing roles. The full catalogue is in Training & Enablement.
The engineering half
Four layers of ordinary engineering. The first one is what makes an assertion provable.
An obligation that is not mapped to a system and a person is a sentence in a document. This layer is where a register becomes something you can test.
Your GRC tool stays the register. Most of the effort is reaching the operating systems where the control either ran or did not.
Built for the person who signs the assertion, with the finding, the evidence and the rule in one view, so a judgement can be recorded with its reason.
Defined once and used everywhere, so the management assertion, the internal audit report and the board pack cannot disagree. Your team runs and owns it.
We also run the training that goes with it: SQL and data engineering, cloud, enterprise systems and cybersecurity, alongside the AI tracks. A compliance team that can query the systems it oversees writes better tests.
What we offer compliance teams
Most teams start with one control or the vendor document register, and use three of the four.
Where a compliance programme starts.
Where a single workflow starts.
AI tracks, and the foundations under them.
Where the obligations change.
The obligations change by sector. See how this lands in BFSI or PSUs.
Security and controls
The officer decides on every finding, evidence keeps its source and date, and nothing files itself.
Findings, risk ratings and assertions go to the person accountable for them, with the evidence visible and the judgement recorded with its reason.
Every item is stored with the system it came from, the moment it was captured and the control it proves, so it stands up when it is questioned.
No return, no filing and no board assertion is submitted by a system. It prepares and evidences, and your signatory decides.
Obligations, control definitions, thresholds and evidence rules are managed by your own team in a console, because the notifications keep coming.
FAQs
No. ServiceNow, MetricStream, Archer or a set of spreadsheets stays the register. The work is connecting it to the systems where controls actually operate, so an assertion in the register is backed by evidence captured on the date, and so the fortnight before an audit stops being a reconstruction exercise.
No, and we would not build it that way. It tests, gathers evidence, flags exceptions and shows the rule behind each one. Whether a finding is a breach, and what to do about it, is a judgement with legal consequences, and it stays with your compliance officer. What changes is that the judgement is made on the full population and on time.
By holding the obligations as configuration your team owns, and by mapping a circular or an amendment onto the obligations, controls and owners it affects, with what changed stated plainly. A person confirms the mapping. The reason this is worth building is the volume: no compliance team can read everything and re-map the register by hand each time.
Yes, and it is the usual case. One control often satisfies several obligations, so we map the relationships once and collect the evidence once. Where regimes genuinely require different tests, they run separately and the register says which is which.
Yes. The Companies (Accounts) Rules require accounting software to record an audit trail of each transaction and an edit log of every change with its date, and require that the trail cannot be disabled. It has applied since 1 April 2023 to companies. We check that the trail is on and complete across your systems, and we monitor for edits and for anything that suppresses it.
In your own cloud tenancy. Compliance evidence is exactly the material you would least want outside your boundary, and it often carries personal data with its own retention rules. Where a hosted model is used for text work such as reading a circular, what is sent to it is agreed and recorded before anything is built.
No, and the parts that are not are usually what makes the AI work. Mapping obligations to systems, connecting the identity provider, structuring the evidence store and building the rule engine are ordinary engineering, and they are most of the effort. The same is true of the training: alongside the AI tracks we run SQL, data engineering, cloud, enterprise systems and cybersecurity.
The document register and expiry tracking work pays for itself with one compliance officer, because the cost of a lapsed licence has nothing to do with company size. Continuous control testing needs enough transaction volume for sampling to be genuinely inadequate, which is most companies with an ERP.
Related
The products this ships as, the services under them, and the industries where the obligations change.
Control tests and evidence against a live rule set.
→ ProductObligations, penalties and renewals from your contracts.
→ FunctionWhere the audit trail and the tax clocks are run.
→ FunctionVendor documents, and the award record.
→ IndustryWhere the regulator sets the tempo.
→ PillarThe engineering side, for systems compliance runs.
→Send the control description, how it is tested today and what the last audit said about it. We call you within 48 hours and go through where the evidence for it already exists, what would have to be connected, and what testing it continuously would involve.
Talk to us