Skip to content
kompendraBook a demo
Menu

One source of truth for regulatory compliance.

Map every obligation to a policy, a control, a test and its evidence. Reproduce any report, for any date, for any regulator.

You know how this goes.

  • Spreadsheets with version numbers

    Your monitoring plan is Plan_v14_FINAL.xlsx. Nobody is sure which copy the board approved.

  • Evidence lost in inboxes

    The proof that a test was done sits in someone's email, a shared drive, or nowhere.

  • A week to build an inspection pack

    When the regulator asks, you rebuild the history by hand and hope it matches what happened.

What you get

Compendium

Every obligation, in one versioned library.

  • Requirements from each regulator's rulebooks, maintained centrally and versioned.
  • Mark each one applicable, not applicable with a reason, or under review, per entity and licence.
  • When a requirement changes, you get a change task. Nothing changes silently.

More about Compendium

Monitoring plan and calendar

A monitoring plan that runs itself on time.

  • Build the year's plan per entity. Every test links to the controls and requirements it checks.
  • Due dates come from each test's frequency. Reminders go to the owner; overdue tests escalate to the reviewer.
  • Close each period with a signed report of every test, result, evidence hash and finding.

More about Monitoring plan and calendar

Evidence vault

Evidence you can prove, not just find.

  • Every file uploaded anywhere lands in one vault with its SHA-256 hash, uploader, time and linked records.
  • Files are never overwritten. A replacement is a new version.
  • Search by record, date, uploader, file type, hash or the text inside the document.

More about Evidence vault

Registers

Policies, controls and findings, all linked.

  • Each register has mandatory fields and an approval workflow you configure.
  • Every row links to the requirements and policies it serves. Unlinked rows are flagged.
  • Export any register to PDF with its approval chain, or to CSV.

More about Registers

How it fits together

A requirement is satisfied by a policy, implemented by a control, checked by a monitoring test and proven by evidence. Any gap becomes a finding with an action, and the signed attestation closes the loop.

The Kompendra object chainEight linked records: Requirement, then Policy, Control, Monitoring test, Evidence, Finding, Action and Attestation. A dashed link runs from Attestation back to Requirement, labelled "proves compliance with".Requirementcompendium clausePolicyinternal positionControlhow the firm compliesMonitoring testscheduled checkEvidencehashed, dated fileFindinggap or exceptionActionowner and deadlineAttestationsigned, PDF exportedproves compliance with

Frameworks

VARA rulebooks are loaded first. Other regulators follow as content in the same structure, not as custom code. TODO(Miles): confirm which frameworks are live at launch and the timing for FSRA, DFSA and CIMA

Built for the people who answer to regulators

  • Regional data residency

    Hosted on Google Cloud in Doha (me-central1). Your data, backups and audit-log exports stay in that region. The one exception is AI suggestions, which call an external model provider and can be switched off. TODO(Miles): confirm residency wording

  • Immutable audit log

    Every change is an append-only event with actor, time, and before and after state. Nothing is hard-deleted.

  • Built by a practising CCO and MLRO

    Kompendra is designed by a practising Chief Compliance Officer and MLRO, from inside a regulated firm.

See your own obligations in Kompendra.

We walk you through the compendium, a monitoring plan and the evidence vault, and show how your current spreadsheets and folders would move across.