Compliance
Compliance is where you keep the commitments your business has made — to regulators, to customers, and to your own auditors — in one place you can show someone. If you need to know which policies are in force, whether a counterparty is on a federal list before you pay them, whether a subcontractor's insurance is about to lapse, or which control failed its last test, this is the module you work in.
What's included
| Page | What it's for |
|---|---|
| Compliance | The hub — a tile per compliance tool, plus a tracker of overdue, upcoming, and completed items |
| Contractor Exclusions | Screen a counterparty against the federal debarment / suspension list before you add or pay them |
| Subcontractor Insurance | Track subcontractors' certificates of insurance and get warned before coverage lapses |
| Policies & Rules | Compliance policy sets — GDPR, HIPAA, SOX, PCI DSS, ISO 27001, or custom — with versioning |
| Governance Policies | Organisation-wide rules for data classification, access control, retention, and approvals |
| Compliance Documents | Upload your policies for AI retrieval, and watch external framework documents for drift |
| Findings Inbox | Findings raised by automated checks and AI reviews, filtered by severity and status |
| Ask Compliance | Ask a question about your frameworks, controls, and policies and get a cited answer |
| Risk Appetite | Set how much risk you'll carry — thresholds that drive alerts and auto-remediation |
| Internal Controls (ICFR) | Define controls, auto-test them against live finance events, and track deficiencies |
Getting started
- Open Compliance in the sidebar. The Tools section lists every page above; the Compliance Tracker below it shows Overdue, Upcoming, and Completed counts pulled from your checklist.
- Write down what you already follow. Go to Policies & Rules, select New Policy, and give it a Name, a Policy Type, and an Effective Date.
- Set your tolerance. On Risk Appetite, choose an Overall risk appetite — the options are Conservative, Moderate, and Aggressive — then select Save risk appetite.
- Give the AI something to read. On Compliance Documents, use Upload a policy document, attach the file, and select Upload & ingest.
- Check Findings Inbox for anything already flagged.
Screening a counterparty
- Open Contractor Exclusions.
- Enter the Entity name. You can narrow the search with UEI (optional).
- Select Search.
SaaSy checks the name against the federal debarment and suspension list (SAM.gov) and returns any matches, each with its exclusion type and date. A clean result reads No matching exclusions — this counterparty is not on the federal list. Treat the result as a search of one public list, not as a clearance decision.
Tracking subcontractor insurance
Subcontractor Insurance is a register you keep by hand — SaaSy does not request certificates from your subcontractors or collect uploaded files. You enter the coverage details and SaaSy watches the dates.
- Open Subcontractor Insurance and select Add COI.
- Fill in the Subcontractor, Coverage type, Carrier, Policy #, Effective date, Expiry date, and Coverage limit.
- Save. The row's Status is then computed from the dates: Covered while the policy is current, a countdown such as 7d left as expiry approaches, and Expired once the date has passed. Waived and Pending are also available.
The cards across the top total your Active, Expiring within 30 days, Expired, and Total certificates.
Running internal controls
Internal Controls (ICFR) is a single page with two sections: Controls register and Deficiencies.
- Select New control. Give it a Code, Name, Objective, Process, Frequency, and Risk.
- Choose a Test type.
approval_thresholdandsegregation_of_dutiesare tested automatically against your finance events;manualis not, and its Run now action stays disabled. Choosingapproval_thresholdreveals a Threshold field. - Select Run now on a control to test it immediately, or View tests to see its history.
Test runs record as
passed,failed, orerror. - A failure raises a row under Deficiencies. Work it with Start remediation, which moves it
from
opentoremediating, then Close to finish. Both steps ask for a Remediation note, so the trail explains itself later.
Availability
Compliance is enabled by default in the professional services, construction, manufacturing, nonprofit, and general packs. The agency, e-commerce, and SaaS packs hide it — you can switch it back on yourself under Settings → Navigation.
Everything above is available on every plan, with one exception: Subcontractor Insurance requires the Certified Payroll entitlement. That is included free with every plan, and can also be bought standalone for $99/mo if you're not on one. See Modules, packs, and plans for the full picture, and Payroll for the rest of what that entitlement covers.
SaaSy is not a tax, legal, or accounting advisor. Confirm your obligations with a qualified professional.