DILIGENCE FOR INTERNAL CONTROL

Overlooked gaps in internal compliance because manual checking limit the sample size

Diligence reads the rule and the evidence side by side — claims against approvals, declarations against records, sign-offs against delegated limits — and shows you where behaviour departs from your own internal rules. Across every case, not a sample of thirty.

Second-line risk · Compliance · Internal audit · Information security
100%of cases reviewed, not sampled
5,300documents cross-checked
17breaches surfaced
On-premwith a full audit log
SEE IT WORK

See how Diligence works.

A TYPICAL COMPLIANCE REVIEW

Sound familiar?

You have a rule on expense limits, one on approvals, one on gifts, one on personal trading. Whether staff actually follow them is checked once a year, by pulling thirty cases and reading them by hand. The other few thousand are never opened. And a breach only shows up when someone puts the claim, the approval, the receipt and the policy side by side — four documents, one at a time.

  • A sample of thirtyThirty cases stand in for a few thousand.
  • One document at a timeBreaches only show when documents are compared.
  • Found a year lateThe annual review finds what happened eleven months ago.
  • Staff data can't leaveEmployee records cannot go through a public AI tool.
WHAT GOES WRONG

What we hear most.

We sample thirty cases a year and hope they are representative.
Head of internal control
The breach is only visible if you read the claim next to the approval.
Internal audit manager
We find out someone broke the policy eleven months after they did.
Head of operational risk
We can't put staff records through a public AI tool.
CISO
THE COST

What it costs you.

30 of 3,000

cases actually reviewed while the rest are never opened.

11 months

a breach can sit unnoticed between annual reviews.

Compliance risks

risk breaching laws because of the limited sample size

THE ALTERNATIVE

See who followed the rules, and who did not.

Behind Diligence, AI agents read the rule and the evidence together — claims against approvals, declarations against records, sign-offs against delegated limits — across every case rather than a sample.

Learn more about Diligence

Documents cross-examined

The claim, the approval, the receipt and the policy are read against each other.

Large sample size

AI helps your team review a larger sample more efficiently.

On-premise

Ensure information security with a private deployment on your own premises

USE CASES IN INTERNAL CONTROL

Multiple workflows, one platform.

Compliance, second-line risk, internal audit, HR and control owners.

Policy compliance monitoring

Compliance, legal, company secretarial, HR
WHAT DILIGENCE AUTOMATES

Policy versions, staff acknowledgement and attestation — then testing whether day-to-day behaviour matches the rule actually in force.

BUSINESS VALUE

A clear record of who is bound by which rule, and who is following it.

Expense, approval and delegated-authority checks

Risk, compliance, finance, business control owners
WHAT DILIGENCE AUTOMATES

Claims, invoices, approvals and sign-offs cross-examined against internal limits, across the whole population rather than a sample.

BUSINESS VALUE

Breaches found as soon as possible.

Conduct and declaration reviews

Compliance, HR, control room, technology risk
WHAT DILIGENCE AUTOMATES

Gift and entertainment logs, outside-interest and personal-trading declarations, and access rights tested against the rules staff signed up to.

BUSINESS VALUE

Consistent conduct oversight without sending staff data off-site.

HOW IT WORKS

Five steps.

  1. CollectPolicies, approval limits, claims, declarations and logs in one place.
  2. UnderstandDocuments structured so a claim, its approval and the rule can be compared.
  3. AssessEvery case tested against the rule that applies to it — not a sample.
  4. DecideExceptions routed to a named owner with the evidence attached.
  5. ReportA continuous view of compliance, and an audit log of every check run.
THE CHECKS

What Diligence catches.

CHECKWHAT DILIGENCE FLAGS
Approval missingUNAPPROVEDAn action taken with no sign-off on file.
Over delegated limitEXCEEDSApproved by someone without the authority for that amount or decision.
Policy not acknowledgedUNACKNOWLEDGEDStaff in scope who never acknowledged the rule they are held to.
Document contradictionsMISMATCHThe claim, the receipt and the approval do not agree with each other.
Undeclared interestsUNDECLAREDGifts, outside interests or personal trades that policy required to be declared.
Overdue remediationOVERDUEAn exception past its due date, weighted by the risk it carries.
Coverage gapsUNCOVEREDA rule with no check behind it, or staff no check currently reaches.
GOVERNANCE

Built to be defended.

Every finding is sourced

Each result links back to the evidence it was drawn from.

Your team is in control

All AI diagnosis can be edited by control by your team.

Oversight you can demonstrate

A continuous record, in the form a board or auditor expects.

Not a general-purpose AI tool

Full activity log, complete audit trail, and a private version you can deploy on your own premises.

PROOF

“We went from thirty cases a year to all of them.”

Claims, approvals and declarations are compared against the rule in force across the whole population — and it runs inside our own network, with a log of every check.

Head of internal control · Regional bank
100%of cases reviewed
On-premwith a full audit log
FAQ

Common questions.

Which internal-control activities can Diligence support?

Diligence supports policy management and governance, operational-risk and control assessments, and cybersecurity and operational-resilience assurance. It helps teams organise evidence, assess gaps, manage approvals, and track remediation.

How does Diligence improve policy management?

Diligence can support policy drafting, version control, review and approval routing, employee attestation, and comparisons between policies and relevant regulatory or framework requirements. It provides a clearer record of which policies are current, approved, and acknowledged.

Can Diligence identify policies affected by regulatory changes?

Yes. When obligations are mapped to policies and controls, Diligence can help identify documents that may need review following a regulatory update. This allows policy owners to prioritise updates and preserve evidence of governance actions.

How does Diligence support operational-risk assessments?

Diligence can guide control assessments, collect and review evidence, identify weaknesses, support risk and gap scoring, generate remediation recommendations, and track action plans. This helps teams focus attention on recurring, material, or overdue control issues.

Can Diligence support cybersecurity and resilience compliance?

Yes. It can map cybersecurity and operational-resilience frameworks to internal policies and controls, organise evidence, conduct gap checks, and support assessment and reporting workflows across multiple frameworks or jurisdictions.

Does Diligence replace control owners or compliance reviewers?

No. Diligence is designed to strengthen structured review and governance processes, not remove accountability. Control owners, risk teams, compliance professionals, and approvers remain responsible for validating assessments, exercising judgement, and making final decisions.

Want to see whether your staff are following your own rules?

Tell us which policies matter most and we'll show you what the documents say.

Your Privacy
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. Cookies are small text files that can be used by websites to make a user's experience more efficient.