FIRSTVAL

05Compliance Twin

Assurance that speeds you up.

A live map of obligations, controls and evidence — continuously tested — so compliance becomes measurable throughput instead of an annual scramble.

North Star

Cost of assurance · Control pass rate

ValueNorth StarKPI / driver treeCausal modelDigital twinSimulationOptimizationInterventionAgentic executionReal-world outcomeAttributionEconomic value createdLearning

The stream

Automation → Capability → Value driver → Financial value

Automation

Continuous control testing

Capability

Evidence collected as work happens

Value driver

Assurance efficiency

Financial value

Lower audit and remediation cost

Automation

Regulatory change monitoring

Capability

Know the delta before the deadline

Value driver

Regulatory readiness

Financial value

Avoided fines and delays

Automation

Automated evidence packs

Capability

Audit-ready any day of the year

Value driver

Audit throughput

Financial value

Shorter audits, fewer findings

Value system

Value ≠ North Star ≠ KPI ≠ driver ≠ process metric.

The translation layer that connects a corporate objective to something an operating team can actually move on Monday.

Value

Trust and licence to operate

Economic outcome

Penalties avoided, capital and insurance cost reduced

North Star

Controls effective on first test

Outcome KPIs

Findings per auditRemediation timeRegulatory incidents

Driver metrics

Control coverageEvidence freshnessPolicy-to-control mappingTraining completion

Process metrics

Evidence collection hoursException ageAttestation turnaroundAlert false-positive rate

Causal model

Policy clarity and mappingControl coverageEvidence quality and freshnessFindings and exceptionsRemediation loadPenalty and capital exposureEnterprise value

Value leakage

Where the value goes missing today.

Leakage is multiplicative. Every gate that stays leaky discounts everything built upstream of it.

Evidence

Manual screenshot collection before every audit.

Thousands of hours

Mapping

New regulation not mapped to existing controls.

Duplicate work

Alerts

False positives consume the review team.

Real risk missed

Remediation

Findings closed late, re-opened next cycle.

Repeat exposure

Digital twin

Simulate the interventions before anyone funds them.

Instead of implementing ten recommendations and learning the result in six months, the twin stacks them first.

Findings per audit cycle

Current34
Continuous evidence capture26
Policy-to-control auto-mapping20
Alert triage with SLM classifier15
Remediation agent with owner routing11
Combined, optimized9

Guardrails

  • No automated adverse determination without human review
  • Full evidence chain retained
  • Regulator-explainable logic only

Constraints

  • Sector regulation
  • Audit calendar
  • Data residency and retention law

Automation

What runs without asking.

Control monitoring loop

Tests controls against live system state, not screenshots.

Control Testing Agent

Evidence pipeline

Collects, classifies and links evidence to controls.

Evidence Collection Agent

Change radar

Maps new regulation to affected controls and owners.

Regulatory Change Agent

Control Testing Agent

Runs continuous tests and opens findings.

Rules + SLM classification

Evidence Collection Agent

Assembles audit-ready packs with lineage.

SLM + RAG on control library

Regulatory Change Agent

Translates regulation into control deltas.

LLM + RAG on regulation corpus

Integrations

Where it plugs into the domain.

Vendor-agnostic by design. The twin reads and writes through whatever stack the domain already runs on.

Systems of record

  • GRC platform
  • IAM and directory
  • Ticketing / ITSM

Signals

  • Cloud and infra logging
  • Data lineage catalog
  • HR and training systems

Data & runtime

  • Warehouse
  • Policy engine
  • MCP connectors

Domain platforms we connect

GRC platforms

ServiceNow IRMArcherMetricStreamLogicGateOneTrustDiligent

Privacy & AI governance

OneTrust PrivacyTrustArcCredo AIHolistic AIIBM watsonx.governance

Security & evidence

SplunkMicrosoft SentinelWizVantaDrataQualys

Financial crime & screening

NICE ActimizeRefinitiv World-CheckComplyAdvantageLexisNexis Bridger

Policy & training

SharePointConfluenceWorkday LearningCornerstone

Data & runtime

SnowflakeDatabricksImmutable evidence storeMCP connectors

Plus anything else with an API — connectors are added per engagement, not sold as a platform lock-in.

Value

The levers, and what they move.

Cost

Replace manual sampling with continuous testing.

Cost of assurance

Speed

Unblock launches waiting on compliance review.

Time to approval

Resilience

Fewer findings, faster remediation.

Open findings · MTTR

Risk

What could go wrong, and what stops it.

Every risk in this domain has a named containment in the runtime — not a slide.

Automated screening producing discriminatory outcomes

Bias testing, human review of all adverse determinations

High

Over-reliance on AI evidence in a regulated audit

Every artifact source-linked and human attested

High

Regulatory change unnoticed

Horizon-scanning agent with named human owner per obligation

Medium

Compliance · Security

Built into the runtime, not bolted on.

EU AI Act

Governance backbone — maintains the AI system inventory and risk classification for every other twin.

  • AI inventory, risk classification and conformity records per system
  • Post-market monitoring and serious incident reporting process
  • AI literacy and human oversight roles documented

GDPR

  • Records of processing (Art. 30) maintained automatically
  • DPIA workflow triggered by new processing or model change
  • Breach detection to notification within 72 hours

Security

  • ISO 27001 / SOC 2 aligned control set
  • Continuous access recertification
  • Tamper-evident evidence storage

Controls & oversight

  • Control-to-risk graph mapping
  • Owner accountability per control
  • Independent review of agent findings

Agentic execution

Agents earn authority. They are not given it.

No agent in this twin controls anything it has not first proven in replay, evaluation, simulation and shadow.

01

Historical replay

Re-run the last 12 months. Would the agent have been right?

02

Offline evaluation

Scored against held-out outcomes, not opinion.

03

Digital twin

Simulated against the causal model under stress.

04

Shadow mode

Runs live, decides nothing. Divergence is logged.

05

Human recommendation

Proposes; a person executes and rates it.

06

Bounded pilot

One segment, capped exposure, hard rollback.

07

Human-supervised execution

Acts inside thresholds, humans approve exceptions.

08

Progressive autonomy

Authority widens only where evidence widened.

The unit of value

Don't buy transformation. Buy measurable movement.

This twin is contracted the way it is engineered: a baseline, a target, a guardrail, and an attribution method agreed in advance.

Baseline

34 findings, 61-day mean remediation

Target

Under 12 findings, remediation under 20 days

Guardrail

Zero reportable incidents introduced by automation

Proof / attribution

External audit results, cycle over cycle