Skip to main content

Compliance

Compliance is where you keep the commitments your business has made — to regulators, to customers, and to your own auditors — in one place you can show someone. If you need to know which policies are in force, whether a counterparty is on a federal list before you pay them, whether a subcontractor's insurance is about to lapse, or which control failed its last test, this is the module you work in.

What's included

PageWhat it's for
ComplianceThe hub — a tile per compliance tool, plus a tracker of overdue, upcoming, and completed items
Contractor ExclusionsScreen a counterparty against the federal debarment / suspension list before you add or pay them
Subcontractor InsuranceTrack subcontractors' certificates of insurance and get warned before coverage lapses
Policies & RulesCompliance policy sets — GDPR, HIPAA, SOX, PCI DSS, ISO 27001, or custom — with versioning
Governance PoliciesOrganisation-wide rules for data classification, access control, retention, and approvals
Compliance DocumentsUpload your policies for AI retrieval, and watch external framework documents for drift
Findings InboxFindings raised by automated checks and AI reviews, filtered by severity and status
Ask ComplianceAsk a question about your frameworks, controls, and policies and get a cited answer
Risk AppetiteSet how much risk you'll carry — thresholds that drive alerts and auto-remediation
Internal Controls (ICFR)Define controls, auto-test them against live finance events, and track deficiencies

Getting started

  1. Open Compliance in the sidebar. The Tools section lists every page above; the Compliance Tracker below it shows Overdue, Upcoming, and Completed counts pulled from your checklist.
  2. Write down what you already follow. Go to Policies & Rules, select New Policy, and give it a Name, a Policy Type, and an Effective Date.
  3. Set your tolerance. On Risk Appetite, choose an Overall risk appetite — the options are Conservative, Moderate, and Aggressive — then select Save risk appetite.
  4. Give the AI something to read. On Compliance Documents, use Upload a policy document, attach the file, and select Upload & ingest.
  5. Check Findings Inbox for anything already flagged.

Screening a counterparty

  1. Open Contractor Exclusions.
  2. Enter the Entity name. You can narrow the search with UEI (optional).
  3. Select Search.

SaaSy checks the name against the federal debarment and suspension list (SAM.gov) and returns any matches, each with its exclusion type and date. A clean result reads No matching exclusions — this counterparty is not on the federal list. Treat the result as a search of one public list, not as a clearance decision.

Tracking subcontractor insurance

Subcontractor Insurance is a register you keep by hand — SaaSy does not request certificates from your subcontractors or collect uploaded files. You enter the coverage details and SaaSy watches the dates.

  1. Open Subcontractor Insurance and select Add COI.
  2. Fill in the Subcontractor, Coverage type, Carrier, Policy #, Effective date, Expiry date, and Coverage limit.
  3. Save. The row's Status is then computed from the dates: Covered while the policy is current, a countdown such as 7d left as expiry approaches, and Expired once the date has passed. Waived and Pending are also available.

The cards across the top total your Active, Expiring within 30 days, Expired, and Total certificates.

Running internal controls

Internal Controls (ICFR) is a single page with two sections: Controls register and Deficiencies.

  1. Select New control. Give it a Code, Name, Objective, Process, Frequency, and Risk.
  2. Choose a Test type. approval_threshold and segregation_of_duties are tested automatically against your finance events; manual is not, and its Run now action stays disabled. Choosing approval_threshold reveals a Threshold field.
  3. Select Run now on a control to test it immediately, or View tests to see its history. Test runs record as passed, failed, or error.
  4. A failure raises a row under Deficiencies. Work it with Start remediation, which moves it from open to remediating, then Close to finish. Both steps ask for a Remediation note, so the trail explains itself later.

Availability

Compliance is enabled by default in the professional services, construction, manufacturing, nonprofit, and general packs. The agency, e-commerce, and SaaS packs hide it — you can switch it back on yourself under Settings → Navigation.

Everything above is available on every plan, with one exception: Subcontractor Insurance requires the Certified Payroll entitlement. That is included free with every plan, and can also be bought standalone for $99/mo if you're not on one. See Modules, packs, and plans for the full picture, and Payroll for the rest of what that entitlement covers.

SaaSy is not a tax, legal, or accounting advisor. Confirm your obligations with a qualified professional.