attendo Compliance
Reports, controls and policies, with proof of every step
The whistleblowing channel, periodic controls with their evidence, policies signed by each person and expirations that alert you before the date. Every step keeps its date, its author and its fingerprint.
- Anonymous or named reports
- Policies signed with attendo eSign
- Blockchain fingerprint of what is signed
Quarterly review of system access
- Owner
- IT team
- Due
- September 30
- Checklist
- 7 of 9 items
- Evidence
- Access report attached
- Sep 1Control opened on its date
- Sep 12The owner starts the checklist
- Sep 19Alert: due in 11 days
- Sep 22Access report attached as evidence
If this sounds familiar, keep reading
Complying is not enough. You have to be able to show it.
The whistleblowing channel is an email inbox. Controls are checked in a spreadsheet. The new policy goes out by email and nobody knows who has read it.
The day an audit or a regulator’s request arrives, someone spends a week digging up emails, versions and signatures.
- Acknowledgment due
A channel that is just an inbox
No case file, no acknowledgment deadline and no way of knowing who has read each message.
- Control overdue
Controls that depend on memory
They get done when someone remembers, and the evidence stays in the inbox of whoever did them.
- Not signed
Policies with no acknowledgment
They get published, but you cannot prove who received and accepted them.
- No evidence
Documents someone can dispute
Versions that change and signatures nobody knows how to verify.
How it works
From the report to the closed case file, with a trail
Six steps. Reports, controls and policies live on the same platform and leave the same proof.
- Step 1
Set up the channel and the controls
The whistleblowing channel, the control types with their checklists and the owner of each one.
- Step 2
A report comes in
Anonymous or named. The case file opens, visible only to administrators, and attendo flags the acknowledgment deadline.
- Step 3
It is assessed with a checklist
The admissibility checklist records what was checked, by whom and when.
- Step 4
Controls arrive on their date
Each periodic control reaches its owner with its checklist, and the evidence is attached to the document.
- Step 5
Policies get signed
Each person receives the policy and signs it with attendo eSign. The envelope list shows who is missing.
- Step 6
Everything is on record
Every step stays on the timeline, and the fingerprint of what was signed and of each event is stored on the blockchain.
Whistleblowing channel
Every report, with its case file and its deadline
Whistleblowers choose how to identify themselves. Each report opens an internal case file, in its own menu section, that only administrators can see.
The channel is designed for the EU Whistleblower Directive (2019/1937) and, in Spain, Law 2/2023. What the law requires in your case is for your advisor to confirm.
- Anonymous or named reporting, as the whistleblower chooses
- Alert for the seven-day acknowledgment deadline
- Admissibility checklist before the investigation
- List, dashboard, settings and decisions reserved for administrators. No dashboard can read the channel, and its report does not identify the whistleblower
- Public pages with your brand and your CSS, which is reviewed so it cannot load files from other websites
- Every step on the timeline, sealed on the blockchain
Possible favoritism toward a supplier
- Intake
- Anonymous, by form
- Access
- Administrators only
- Acknowledgment
- Deadline flagged
- Admissibility
- Checklist in progress
- Mon 6:10 PMAnonymous report received through the channel
- Mon 6:10 PMAcknowledgment deadline started
- Tue 9:30 AMAcknowledgment sent from the case file
Periodic controls
Controls on their date, with their evidence
An access review, a supplier assessment or a contingency plan test are documents with their checklist and their owner. They open on their date and alert you before they are due.
Compliance · My team shows which team tasks are at risk of being missed. It is a dashboard of tasks and deadlines, not a regulatory compliance scorecard.
- Each control is a document with an owner, a due date and a checklist
- Evidence is attached to the control, with malware scanning
- Alerts before the due date, and overdue tasks in red
- Versioned checklists: you know which one each review used
- Owner approval by link, with a code
Checklist · Safety inspection
- Extinguishers accessible
- Exits marked
- First-aid kit stocked
- Electrical panel closed
Policies and legal terms
Every policy, signed by whoever has to sign it
The code of conduct, the acceptable use policy or the harassment protocol go out for signature from their record. The envelope list tells you who has signed and who has not.
Acceptance of each legal text is kept with its signature and its evidence record. And the fingerprint of the signed document is stored on the blockchain, so you can prove it has not changed.
- Internal policies signed with attendo eSign, with recurring signers
- Advanced or qualified electronic signature, with sealing
- Legal terms accepted with their signature and evidence record
- Blockchain fingerprint of every signed document
- Envelope list: sent, pending and completed
Service contract
Expirations
What expires alerts you before it does
Each expiration is a document with its date and its owner. A flow alerts you before the date and creates the renewal task, and the agenda puts it in front of whoever has to do it.
- Insurance, licenses, permits and contracts with their expiration date
- An alert before the date to whoever is responsible
- Tasks with owners, and a task agenda with “Me” and “My groups”
- A shared business calendar: deadlines account for holidays
- Your suppliers’ documents, with their expiration date, reviewed and with a warning before they expire
- The attendo Compliance home screen: signatures, policy acceptances and expirations in one list, with their reports and a dashboard you can edit
Document management
Every document, in its place and safe
Minutes, reports, contracts and evidence hang from the document that needs them, not from a shared folder. Search finds them months later.
- Files linked to the control, case file or policy they document
- Malware scanning of every attachment
- Tags and search across the whole server, closed items included
- A copy in your own S3 storage
- Permissions by profile and by field value
Multiple companies and traceability
One group, several companies, one trail
If your group has several companies, each one keeps its own records on the same platform. Control types, fields and permissions are configured without code.
- Several companies, lines of business and workspaces in the same instance
- Customer, supplier and partner portals, with no license and the same two-step verification
- Timeline with the author and time of every change
- Blockchain fingerprint of events and their evidence
- Access log, and two-factor authentication required by profile
Are you a consulting or advisory firm?
Your clients’ compliance has its own page
attendo Compliance is for your own company’s compliance. If you run the channel, the controls and the evidence for several clients, see compliance for consulting and advisory firms.
Who it is for
The most common industries. And any other.
attendo Compliance adapts to any industry and any company, in any country, with its own document types, fields and vocabulary, and no custom development. These are the most common ones, not the only ones.
Industries
Types of business
- Companies with compliance obligations and audits
- Companies that sell to other businesses
- Companies that sell projects or professional services
- Public administrations and agencies
Honesty
What attendo Compliance is not
Better to know before the demo. If your case calls for another tool, we will tell you.
- It is not a GRC suite
It does not include a risk matrix, a regulatory library or control mapping to standards. If you need those, a GRC suite is the better fit.
- No certifications of its own
attendo does not hold ISO 27001 or ENS. We walk you through its security controls on a technical call.
- The compliance dashboard measures tasks
Compliance · My team shows which team tasks and deadlines are at risk. It does not measure regulatory compliance.
- The resolution deadline is tracked by the investigator
attendo flags the acknowledgment deadline. It does not calculate the resolution deadline: whoever investigates the case file keeps track of it.
- Your organization applies the law
attendo is the tool. The system owner, the channel policy and the investigation are up to your organization and its advisors.
marIA in compliance
It finds the procedure. It does not decide for you.
-
Answers from your policies
You upload procedures, policies and protocols, and marIA answers your team citing the document each point comes from.
-
Answers questions about your controls
“Which controls are due this month and who owns them?” In plain language, read-only, and showing the query.
-
Summarizes the minutes
The recording or minutes of the committee meeting, summarized in a note on the document.
-
With the provider you choose
To keep data in Europe, you choose Scaleway or your Microsoft 365 Copilot. And you can leave AI switched off wherever you do not want it.
What it does not do: assess reports, decide whether a case file is admitted or give legal advice. Without AI, attendo Compliance works in full.
Integrations
Connected to what you already use
Sign-in is with Microsoft Entra ID, Google or Auth0, with two-factor authentication required by profile if you decide so. Attachments can be copied to your own S3 storage.
Attendance tracking, with clock-ins and breaks with a reason, lives on the same platform. With humaneo, native, you round out people management, except payroll.
Honest comparison
Where it fits (and where it does not)
We would rather you know now than at the third meeting.
| If your priority is… | attendo Compliance |
|---|---|
| Having the whistleblowing channel, controls and signed policies in one place, with proof of every step | attendo ComplianceThis is its home turf |
| Keeping compliance next to the rest of operations: contracts, suppliers, people and documents | attendo ComplianceA good fit: it is the same platform |
| A risk matrix, a regulatory library and control mapping to several standards | attendo ComplianceA GRC suite is the better choice. attendo does not include them |
| A vendor with its own ISO 27001 or ENS | attendo Complianceattendo holds no certifications. Raise it with us from the start |
Do you run compliance for other companies? See compliance for consulting firms. By department: regulatory compliance and legal and contracts.
Compare attendo vs. Excel and read whether a signature on a phone holds up. In the glossary: inspection checklist.
The rest of the platform
The rest of the platform, when you need it
Frequently asked questions
Frequently asked questions
What does compliance management software do?
It brings together what you have to comply with and what you have to be able to prove: the whistleblowing channel, periodic controls with their evidence, signed policies and expirations, with a trail for every step. attendo Compliance does this on the same platform as the rest of your company.
Does it work for Spain’s Law 2/2023 and the EU Whistleblower Directive?
attendo gives you the tool: anonymous or named reporting, a case file only administrators can see, an alert for the acknowledgment deadline and a trail for every step. Whether it covers everything the law requires of you is for your legal advisor to confirm.
Is it a GRC suite?
No. It does not include a risk matrix, a regulatory library or control mapping to standards. If you need those, a GRC suite is the better fit, and attendo can keep the channel, the controls and the signatures.
How do I get all staff to sign a policy?
You send it for signature with attendo eSign, with each person as a signer. The envelope list shows who has signed and who has not. If no signature is needed, an acknowledgment form or checklist will do.
What is the blockchain fingerprint?
A unique hash of every signed document and every timeline event, stored on the blockchain. If anyone disputes a document, you can prove it has not changed since.
Does the compliance dashboard measure regulatory compliance?
No. Compliance · My team shows which team tasks and deadlines are at risk of being missed. It is a work dashboard, not a regulatory one.
Does attendo hold certifications?
No. attendo does not hold ISO 27001 or ENS. We walk you through its security controls on a technical call and on the security page.
Does it work for a group with several companies?
Yes. Several companies, lines of business and workspaces share the same instance, each with its own records and the permissions of each profile.
Request a demo
Show us your next audit
Tell us what you will be asked for and we will show you how you would have it in attendo: the case file, the control with its evidence and the signed policy. If what you need is a GRC suite, we will tell you.
- With your operation, not a generic demo
- A real person from our team replies
- No cold calls afterwards
Would you rather talk first?
- Phone +34 902 750 677 · +34 910 053 530
- Email sales@attendo.me
- Monday to Thursday 9:30 AM to 6:30 PM and Friday 9:30 AM to 2:30 PM (Spain time)