attendo Compliance

Reports, controls and policies, with proof of every step

The whistleblowing channel, periodic controls with their evidence, policies signed by each person and expirations that alert you before the date. Every step keeps its date, its author and its fingerprint.

  • Anonymous or named reports
  • Policies signed with attendo eSign
  • Blockchain fingerprint of what is signed

If this sounds familiar, keep reading

Complying is not enough. You have to be able to show it.

The whistleblowing channel is an email inbox. Controls are checked in a spreadsheet. The new policy goes out by email and nobody knows who has read it.

The day an audit or a regulator’s request arrives, someone spends a week digging up emails, versions and signatures.

  • Acknowledgment due

    A channel that is just an inbox

    No case file, no acknowledgment deadline and no way of knowing who has read each message.

  • Control overdue

    Controls that depend on memory

    They get done when someone remembers, and the evidence stays in the inbox of whoever did them.

  • Not signed

    Policies with no acknowledgment

    They get published, but you cannot prove who received and accepted them.

  • No evidence

    Documents someone can dispute

    Versions that change and signatures nobody knows how to verify.

How it works

From the report to the closed case file, with a trail

Six steps. Reports, controls and policies live on the same platform and leave the same proof.

  1. Step 1

    Set up the channel and the controls

    The whistleblowing channel, the control types with their checklists and the owner of each one.

  2. Step 2

    A report comes in

    Anonymous or named. The case file opens, visible only to administrators, and attendo flags the acknowledgment deadline.

  3. Step 3

    It is assessed with a checklist

    The admissibility checklist records what was checked, by whom and when.

  4. Step 4

    Controls arrive on their date

    Each periodic control reaches its owner with its checklist, and the evidence is attached to the document.

  5. Step 5

    Policies get signed

    Each person receives the policy and signs it with attendo eSign. The envelope list shows who is missing.

  6. Step 6

    Everything is on record

    Every step stays on the timeline, and the fingerprint of what was signed and of each event is stored on the blockchain.

Whistleblowing channel

Every report, with its case file and its deadline

Whistleblowers choose how to identify themselves. Each report opens an internal case file, in its own menu section, that only administrators can see.

The channel is designed for the EU Whistleblower Directive (2019/1937) and, in Spain, Law 2/2023. What the law requires in your case is for your advisor to confirm.

  • Anonymous or named reporting, as the whistleblower chooses
  • Alert for the seven-day acknowledgment deadline
  • Admissibility checklist before the investigation
  • List, dashboard, settings and decisions reserved for administrators. No dashboard can read the channel, and its report does not identify the whistleblower
  • Public pages with your brand and your CSS, which is reviewed so it cannot load files from other websites
  • Every step on the timeline, sealed on the blockchain
See the whistleblowing channel

Periodic controls

Controls on their date, with their evidence

An access review, a supplier assessment or a contingency plan test are documents with their checklist and their owner. They open on their date and alert you before they are due.

Compliance · My team shows which team tasks are at risk of being missed. It is a dashboard of tasks and deadlines, not a regulatory compliance scorecard.

  • Each control is a document with an owner, a due date and a checklist
  • Evidence is attached to the control, with malware scanning
  • Alerts before the due date, and overdue tasks in red
  • Versioned checklists: you know which one each review used
  • Owner approval by link, with a code
See attendo Checklist

Policies and legal terms

Every policy, signed by whoever has to sign it

The code of conduct, the acceptable use policy or the harassment protocol go out for signature from their record. The envelope list tells you who has signed and who has not.

Acceptance of each legal text is kept with its signature and its evidence record. And the fingerprint of the signed document is stored on the blockchain, so you can prove it has not changed.

  • Internal policies signed with attendo eSign, with recurring signers
  • Advanced or qualified electronic signature, with sealing
  • Legal terms accepted with their signature and evidence record
  • Blockchain fingerprint of every signed document
  • Envelope list: sent, pending and completed
See attendo eSign

Expirations

What expires alerts you before it does

Each expiration is a document with its date and its owner. A flow alerts you before the date and creates the renewal task, and the agenda puts it in front of whoever has to do it.

  • Insurance, licenses, permits and contracts with their expiration date
  • An alert before the date to whoever is responsible
  • Tasks with owners, and a task agenda with “Me” and “My groups”
  • A shared business calendar: deadlines account for holidays
  • Your suppliers’ documents, with their expiration date, reviewed and with a warning before they expire
  • The attendo Compliance home screen: signatures, policy acceptances and expirations in one list, with their reports and a dashboard you can edit

Document management

Every document, in its place and safe

Minutes, reports, contracts and evidence hang from the document that needs them, not from a shared folder. Search finds them months later.

  • Files linked to the control, case file or policy they document
  • Malware scanning of every attachment
  • Tags and search across the whole server, closed items included
  • A copy in your own S3 storage
  • Permissions by profile and by field value
See document management

Multiple companies and traceability

One group, several companies, one trail

If your group has several companies, each one keeps its own records on the same platform. Control types, fields and permissions are configured without code.

  • Several companies, lines of business and workspaces in the same instance
  • Customer, supplier and partner portals, with no license and the same two-step verification
  • Timeline with the author and time of every change
  • Blockchain fingerprint of events and their evidence
  • Access log, and two-factor authentication required by profile
See security
Settings screen with the organization, work, sales and documents, catalogs, custom fields and templates sections.
Settings: organization, work types and custom fields, without touching code.

Are you a consulting or advisory firm?

Your clients’ compliance has its own page

attendo Compliance is for your own company’s compliance. If you run the channel, the controls and the evidence for several clients, see compliance for consulting and advisory firms.

Who it is for

The most common industries. And any other.

attendo Compliance adapts to any industry and any company, in any country, with its own document types, fields and vocabulary, and no custom development. These are the most common ones, not the only ones.

Types of business

  • Companies with compliance obligations and audits
  • Companies that sell to other businesses
  • Companies that sell projects or professional services
  • Public administrations and agencies

Honesty

What attendo Compliance is not

Better to know before the demo. If your case calls for another tool, we will tell you.

  • It is not a GRC suite

    It does not include a risk matrix, a regulatory library or control mapping to standards. If you need those, a GRC suite is the better fit.

  • No certifications of its own

    attendo does not hold ISO 27001 or ENS. We walk you through its security controls on a technical call.

  • The compliance dashboard measures tasks

    Compliance · My team shows which team tasks and deadlines are at risk. It does not measure regulatory compliance.

  • The resolution deadline is tracked by the investigator

    attendo flags the acknowledgment deadline. It does not calculate the resolution deadline: whoever investigates the case file keeps track of it.

  • Your organization applies the law

    attendo is the tool. The system owner, the channel policy and the investigation are up to your organization and its advisors.

marIA in compliance

It finds the procedure. It does not decide for you.

  • Answers from your policies

    You upload procedures, policies and protocols, and marIA answers your team citing the document each point comes from.

  • Answers questions about your controls

    “Which controls are due this month and who owns them?” In plain language, read-only, and showing the query.

  • Summarizes the minutes

    The recording or minutes of the committee meeting, summarized in a note on the document.

  • With the provider you choose

    To keep data in Europe, you choose Scaleway or your Microsoft 365 Copilot. And you can leave AI switched off wherever you do not want it.

What it does not do: assess reports, decide whether a case file is admitted or give legal advice. Without AI, attendo Compliance works in full.

See the attendo AI

Integrations

Connected to what you already use

Sign-in is with Microsoft Entra ID, Google or Auth0, with two-factor authentication required by profile if you decide so. Attachments can be copied to your own S3 storage.

Attendance tracking, with clock-ins and breaks with a reason, lives on the same platform. With humaneo, native, you round out people management, except payroll.

See integrations

Honest comparison

Where it fits (and where it does not)

We would rather you know now than at the third meeting.

If your priority is…attendo Compliance
Having the whistleblowing channel, controls and signed policies in one place, with proof of every stepattendo ComplianceThis is its home turf
Keeping compliance next to the rest of operations: contracts, suppliers, people and documentsattendo ComplianceA good fit: it is the same platform
A risk matrix, a regulatory library and control mapping to several standardsattendo ComplianceA GRC suite is the better choice. attendo does not include them
A vendor with its own ISO 27001 or ENSattendo Complianceattendo holds no certifications. Raise it with us from the start

Do you run compliance for other companies? See compliance for consulting firms. By department: regulatory compliance and legal and contracts.

Compare attendo vs. Excel and read whether a signature on a phone holds up. In the glossary: inspection checklist.

Frequently asked questions

Frequently asked questions

What does compliance management software do?

It brings together what you have to comply with and what you have to be able to prove: the whistleblowing channel, periodic controls with their evidence, signed policies and expirations, with a trail for every step. attendo Compliance does this on the same platform as the rest of your company.

Does it work for Spain’s Law 2/2023 and the EU Whistleblower Directive?

attendo gives you the tool: anonymous or named reporting, a case file only administrators can see, an alert for the acknowledgment deadline and a trail for every step. Whether it covers everything the law requires of you is for your legal advisor to confirm.

Is it a GRC suite?

No. It does not include a risk matrix, a regulatory library or control mapping to standards. If you need those, a GRC suite is the better fit, and attendo can keep the channel, the controls and the signatures.

How do I get all staff to sign a policy?

You send it for signature with attendo eSign, with each person as a signer. The envelope list shows who has signed and who has not. If no signature is needed, an acknowledgment form or checklist will do.

What is the blockchain fingerprint?

A unique hash of every signed document and every timeline event, stored on the blockchain. If anyone disputes a document, you can prove it has not changed since.

Does the compliance dashboard measure regulatory compliance?

No. Compliance · My team shows which team tasks and deadlines are at risk of being missed. It is a work dashboard, not a regulatory one.

Does attendo hold certifications?

No. attendo does not hold ISO 27001 or ENS. We walk you through its security controls on a technical call and on the security page.

Does it work for a group with several companies?

Yes. Several companies, lines of business and workspaces share the same instance, each with its own records and the permissions of each profile.

Request a demo

Show us your next audit

Tell us what you will be asked for and we will show you how you would have it in attendo: the case file, the control with its evidence and the signed policy. If what you need is a GRC suite, we will tell you.

  • With your operation, not a generic demo
  • A real person from our team replies
  • No cold calls afterwards

Would you rather talk first?

Which area do you want to see in the demo?

With your work email we prepare the demo around your case.

In one or two sentences.

If you chose Maintenance (CMMS)

If you chose Field work (Field Service)

If you chose Facility Management

If you chose any other area

Only if you would rather we call you.

Data protection. Controller: AxisOne Group SL. Purpose: preparing the demo you request and replying to you. Legal basis: your consent and the request you make. Recipients: we do not disclose your data; Cloudflare (website) and Brevo (email notices and confirmation) process it on our behalf. Rights: access, rectification, erasure, objection, restriction and portability, at privacy@attendo.me. More information in the privacy policy.

What happens when you send it. Someone from our team reads what you tell us and writes to you to agree on a time for the demo. Our hours: Monday to Thursday 9:30 AM to 6:30 PM and Friday 9:30 AM to 2:30 PM, Spain time.