PROOF

From a list of obligations to demonstrable compliance, month after month.

PROOF is the compliance officer's workplace. Which legal obligations does your organisation have, who monitors them, when were they last tested and what came out. Process owners attest through a personal link, the report to the board freezes when it is approved, and the cockpit shows where the gap is. Built and hosted in the EU.

From keeping track to proving it

Second-line compliance is continuous work: test every month, follow up deviations and show the board how the organisation stands. In a spreadsheet that work stays invisible until someone asks.

Now

The register lives in a spreadsheet

Law, article, owner and frequency sit in columns. What was tested last year is known only to whoever typed it in.

With PROOF

One register with a testing history

Per obligation the quoted legal text, the first-line owner, the control, the frequency and the evidence. Every test stays on record.

Now

Testing happens when there is time

The monitoring plan is an intention. At year end it turns out which themes were skipped.

With PROOF

Annual grid with coverage

Themes against months: planned, running, done or overdue. When you close a test, PROOF sets the next due date from the interval.

Now

Process owners confirm by e-mail

The confirmation sits in a mail thread. Whether everyone has replied, you count by hand.

With PROOF

Attestations through a personal link

The process owner gets a page of their own, no account needed. They choose fully, partly or not complied, explain and sign. After that the link is spent.

Now

The quarterly report is cut and paste

Figures from four files, and the question whether they were still right when the report went out.

With PROOF

A report PROOF fills itself

Coverage, deviations, remediation, attestations, signals and policies come from the application. Approving freezes the figures; a correction is a new report.

Now

New regulation arrives as a PDF

Someone reads the change and hopes the right colleague picks it up.

With PROOF

From signal to proposal

A regulatory signal searches your obligations, the controls in CRAFT and the risks in the Risk Heat Map for what it touches. You turn it into a proposal; the owner decides.

A selection from PROOF

Click a thumbnail for that screen, or the image itself for the full-size view.

Nl ex cockpit en1 / 6 shown

What you want to know about PROOF up front

What is PROOF?

PROOF is an application for second-line compliance monitoring. It records which legal obligations an organisation has, who monitors them, how often they are tested and what the testing found. Attestations from process owners, deviations with remediation actions and the periodic report to the board or supervisory board live in the same environment.

Who is PROOF for?

For compliance officers and other second-line functions that continuously, usually monthly, test whether the organisation complies with its obligations. PROOF works without an audit engagement and deliberately avoids audit jargon: obligation instead of norm, monitoring activity instead of work programme, deviation instead of finding. Process owners do not need to be users.

What does PROOF do in practice?

PROOF keeps an obligations register with testing history, plans monitoring activities in an annual grid with coverage, records deviations with cause and remediation actions, runs attestation rounds through a personal link per process owner, turns regulatory signals into proposals for the owner and drafts the board report with figures that freeze on approval.

How does PROOF differ from a spreadsheet?

A spreadsheet records whatever someone types. PROOF enforces rules: a deviation closes only when all remediation actions are done, an approved report is never recalculated, a signed attestation cannot be changed afterwards and every test stays on record. The cockpit therefore always counts the same rows you see after clicking through.

How are data and hosting handled?

Each organisation's data sits in its own database, separated from other organisations, on servers in the EU. Readers read, editors and administrators write. The register can only be extended: records are archived, never deleted. Attestations by process owners run through a link with an expiry date, without an account and without cookies.

The second line in its own language

Audit has engagements, work programmes and findings. Compliance monitoring has obligations, monitoring activities and deviations. PROOF speaks that language and builds its controls around it.

Compliance cockpit

One compliance score from six measures and a traffic light that is about today. Every tile opens exactly the rows the number counted, with a removable filter on top.

Monthly workbench

Overdue, open, waiting on someone else, done. A list you work through, with the year's coverage and incoming regulatory signals alongside.

Attestations without accounts

Process owners sign through a personal link that expires after 45 days. View as guest shows you beforehand exactly what they will see.

Approved means frozen

An approved report to the board, supervisory board or audit committee is never recalculated. Six open deviations stay six, even if two are closed later.

Cause before blame

For each deviation you choose between a design flaw in the process and a compliance error by an employee. That choice drives the remediation. A deviation closes only when every action is done.

Four ways to test

Desk check, sample, walkthrough or data query. A completed test sets the next date; a test that finds a deviation opens the deviation form straight away.

Connected to the first and third line

Test requests from Flowmap land in the workbench, proposals go to the owner in CRAFT or the Risk Heat Map, and a conversation fragment from Voice can be attached to a test as evidence.

Data separated per organisation

Your data sits in its own database per organisation on servers in the EU. Readers read, editors write, and the register can only be added to, never wiped.

From obligation to accountability in six steps

1

Record the obligations

Law, article, quoted text, first-line owner, control and testing frequency.

2

Plan the monitoring

Place the activities in the annual grid and manage coverage per theme.

3

Test and record

Carry out the desk check, sample, walkthrough or data query and keep the evidence with the activity.

4

Register deviations and remediation

Severity, cause and remediation actions with owner and deadline. Closing is possible only when everything is done.

5

Request attestations

Launch a round, process owners sign through their own link, you see the status per recipient.

6

Report to the board

Draft the periodic report, let PROOF fill in the figures and freeze them by approving.

Want to know where your organisation stands, and be able to show it?

Request a demo or get in touch for more information about PROOF for your compliance function.