Skip to main content

Security and Risk

Compliance

Software cannot make you compliant. What it can do is make compliance cheap to demonstrate, which is where most of the ongoing cost actually sits.

Definition

Compliance is meeting the rules that apply to you, and being able to show it.

What It Actually Means

Those are two separate jobs, and the second is where the time goes. Most businesses are broadly doing the right things. What they cannot do quickly is produce evidence of it on request, which is why compliance feels expensive out of proportion to the actual obligations.

What Software Can And Cannot Do

No product makes you compliant. Anything sold on that promise is overstating what it does, and the claim is worth treating as a signal about the seller.

What software does well is remove the manual assembly. Compliance costs tend to be concentrated in three activities, all of which are automatable:

Evidence collection. Someone exports from four systems, reconciles them by hand and builds a document. Every cycle, from scratch. This is the largest cost and the easiest to remove, because the evidence already exists and simply is not connected.

Proving order. Showing something was reviewed and approved by the right people in the right sequence. An audit trail answers this instantly and nothing else does, because the alternative is reconstructing intent from an email thread.

Catching gaps before someone else does. Records missing a required field, reviews overdue, consents never captured. A system can check continuously. A person checks when there is time, which is to say shortly before a deadline.

What software cannot do is make the judgement calls, decide what the rules mean for your situation, or substitute for advice. It also cannot fix a process that is genuinely wrong. It will simply document the wrong process very reliably.

What To Ask

  • What evidence do we currently assemble by hand, and how often? That list is the actual specification.
  • How long does a request take us to answer today? This is the number that improves, and it is worth writing down before any build.
  • What would we struggle to prove? More useful than asking what you comply with.
  • Who checks that the checks happened? Compliance processes fail quietly, usually because nobody owns the monitoring of the monitoring.

The Trap Worth Avoiding

The common failure is building a parallel compliance system: a separate place where evidence is recorded, alongside the systems where work actually happens.

It always decays. People do the work in one place and remember to record it in the other until a busy week, and after that the compliance record and reality diverge permanently. Worse, the divergence is invisible until someone checks, which is exactly the wrong moment.

Evidence has to be a by-product of doing the work, not an additional task. If approving a document produces the approval record automatically, the record is always accurate. If approving a document means also logging that you approved it, the record is accurate for about six weeks.

That principle decides most of the design, and it is the thing to hold suppliers to. Where this is a core operating requirement, it is worth building around deliberately: see compliance systems.

This is a general summary rather than advice on any specific regime. Where the stakes are high, take proper advice on what applies to you.

More terms are in the glossary.

Portrait of Alexander De Sousa, founder of Digital Royalty
Founder-led
“I’ve put everything I know into how this company works — the standards, the method, the care on every project. It runs through the whole team, and I hold us all to it.”

Alexander De Sousa · Founder LinkedIn

Featured on BBC Radio Solent

Get started

Tell us what you need

A few quick questions, then a straight answer from a real person — usually within a few hours.

Tell us what you're working on

Whether it's a new site, a platform, or a process that shouldn't be manual any more — we'll tell you honestly if we can help.