05 — Compliance Twin
Assurance that speeds you up.
A live map of obligations, controls and evidence — continuously tested — so compliance becomes measurable throughput instead of an annual scramble.
North Star
Cost of assurance · Control pass rate
The stream
Automation → Capability → Value driver → Financial value
Automation
Continuous control testing
Capability
Evidence collected as work happens
Value driver
Assurance efficiency
Financial value
Lower audit and remediation cost
Automation
Regulatory change monitoring
Capability
Know the delta before the deadline
Value driver
Regulatory readiness
Financial value
Avoided fines and delays
Automation
Automated evidence packs
Capability
Audit-ready any day of the year
Value driver
Audit throughput
Financial value
Shorter audits, fewer findings
Value system
Value ≠ North Star ≠ KPI ≠ driver ≠ process metric.
The translation layer that connects a corporate objective to something an operating team can actually move on Monday.
Value
Trust and licence to operate
Economic outcome
Penalties avoided, capital and insurance cost reduced
North Star
Controls effective on first test
Outcome KPIs
Driver metrics
Process metrics
Causal model
Value leakage
Where the value goes missing today.
Leakage is multiplicative. Every gate that stays leaky discounts everything built upstream of it.
Evidence
Manual screenshot collection before every audit.
Thousands of hours
Mapping
New regulation not mapped to existing controls.
Duplicate work
Alerts
False positives consume the review team.
Real risk missed
Remediation
Findings closed late, re-opened next cycle.
Repeat exposure
Digital twin
Simulate the interventions before anyone funds them.
Instead of implementing ten recommendations and learning the result in six months, the twin stacks them first.
Findings per audit cycle
Guardrails
- No automated adverse determination without human review
- Full evidence chain retained
- Regulator-explainable logic only
Constraints
- Sector regulation
- Audit calendar
- Data residency and retention law
Automation
What runs without asking.
Control monitoring loop
Tests controls against live system state, not screenshots.
Control Testing Agent
Evidence pipeline
Collects, classifies and links evidence to controls.
Evidence Collection Agent
Change radar
Maps new regulation to affected controls and owners.
Regulatory Change Agent
Control Testing Agent
Runs continuous tests and opens findings.
Rules + SLM classification
Evidence Collection Agent
Assembles audit-ready packs with lineage.
SLM + RAG on control library
Regulatory Change Agent
Translates regulation into control deltas.
LLM + RAG on regulation corpus
Integrations
Where it plugs into the domain.
Vendor-agnostic by design. The twin reads and writes through whatever stack the domain already runs on.
Systems of record
- GRC platform
- IAM and directory
- Ticketing / ITSM
Signals
- Cloud and infra logging
- Data lineage catalog
- HR and training systems
Data & runtime
- Warehouse
- Policy engine
- MCP connectors
Domain platforms we connect
GRC platforms
Privacy & AI governance
Security & evidence
Financial crime & screening
Policy & training
Data & runtime
Plus anything else with an API — connectors are added per engagement, not sold as a platform lock-in.
Value
The levers, and what they move.
Cost
Replace manual sampling with continuous testing.
Cost of assurance
Speed
Unblock launches waiting on compliance review.
Time to approval
Resilience
Fewer findings, faster remediation.
Open findings · MTTR
Risk
What could go wrong, and what stops it.
Every risk in this domain has a named containment in the runtime — not a slide.
Automated screening producing discriminatory outcomes
Bias testing, human review of all adverse determinations
High
Over-reliance on AI evidence in a regulated audit
Every artifact source-linked and human attested
High
Regulatory change unnoticed
Horizon-scanning agent with named human owner per obligation
Medium
Compliance · Security
Built into the runtime, not bolted on.
EU AI Act
Governance backbone — maintains the AI system inventory and risk classification for every other twin.
- AI inventory, risk classification and conformity records per system
- Post-market monitoring and serious incident reporting process
- AI literacy and human oversight roles documented
GDPR
- Records of processing (Art. 30) maintained automatically
- DPIA workflow triggered by new processing or model change
- Breach detection to notification within 72 hours
Security
- ISO 27001 / SOC 2 aligned control set
- Continuous access recertification
- Tamper-evident evidence storage
Controls & oversight
- Control-to-risk graph mapping
- Owner accountability per control
- Independent review of agent findings
Agentic execution
Agents earn authority. They are not given it.
No agent in this twin controls anything it has not first proven in replay, evaluation, simulation and shadow.
01
Historical replay
Re-run the last 12 months. Would the agent have been right?
02
Offline evaluation
Scored against held-out outcomes, not opinion.
03
Digital twin
Simulated against the causal model under stress.
04
Shadow mode
Runs live, decides nothing. Divergence is logged.
05
Human recommendation
Proposes; a person executes and rates it.
06
Bounded pilot
One segment, capped exposure, hard rollback.
07
Human-supervised execution
Acts inside thresholds, humans approve exceptions.
08
Progressive autonomy
Authority widens only where evidence widened.
The unit of value
Don't buy transformation. Buy measurable movement.
This twin is contracted the way it is engineered: a baseline, a target, a guardrail, and an attribution method agreed in advance.
Baseline
34 findings, 61-day mean remediation
Target
Under 12 findings, remediation under 20 days
Guardrail
Zero reportable incidents introduced by automation
Proof / attribution
External audit results, cycle over cycle
Next twin
Process Twin →