What Is Compliance Software? A Field Guide to Six Categories, and the One Nobody Sells You

By Mike North Jul 7, 2026

Two people tell you they’re evaluating compliance software.

The first means a tool that will collect screenshots of their cloud configuration so an auditor can sign off on a SOC 2 report. The second means a system that will tell them whether the company they wired eight million dollars to last spring has quietly redomiciled to the BVI and added a director nobody in the fund has ever heard of.

Same phrase. Zero functional overlap. Neither person is using the term incorrectly, which tells you something fairly damning about the term.

We watch the same three mistakes on repeat. Firms buy GRC platforms and work out, four months in, that they’ve purchased a very expensive filing cabinet with nothing in it. Others buy identity verification and discover the product, entirely by design, stops working on day two of the relationship. And crypto funds buy on-chain analytics, assume entity risk is now covered, and are wrong in a way that only becomes obvious later.

All three mistakes get made by careful, intelligent people. That’s rather the point. The category names are doing the misleading here, not the buyers.

So this is a map. It covers what compliance software actually is, how it differs from a compliance management system, the six product categories that share the label, what each one genuinely does well, where each one stops, and how to work out which you need. Including the parts of the map we don’t occupy, and one part we sit directly next to and get confused with almost weekly.

What compliance software actually is

Strip away the marketing and compliance software does one of two things. It either helps you prove you are meeting a set of obligations, or it helps you see risk you would otherwise miss.

Those sound similar. They’re not, and the difference determines almost everything about what you should buy.

Proving obligations is a documentation problem. You need evidence, controls, policies, an audit trail, and something that will satisfy an examiner or an auditor who arrives with a checklist. The output is a defensible record.

Seeing risk is an intelligence problem. You need data from outside your own walls, a way to separate what matters from what doesn’t, and a route from a signal to a decision. The output is a warning, early enough to act on.

A great many products claim to do both. Very few do, and the ones that claim it most loudly tend to be strong at the first and thin at the second, because documentation is a tractable engineering problem and intelligence is a data problem that never really ends.

Compliance management versus a compliance management system

These get used interchangeably and they shouldn’t be.

Compliance management is the discipline. It’s the work: understanding which rules apply to you, translating them into policies people can follow, training staff, checking whether the policies are actually being followed, and fixing things when they aren’t. It exists whether or not you own any software at all. Plenty of organisations do it badly with expensive tooling and a few do it well with a spreadsheet and a diligent person.

A compliance management system, or CMS, is the structure that holds the discipline together so it survives turnover, growth and scrutiny. It’s the framework, not the app.

In regulated finance the term has a fairly precise meaning. The CFPB’s compliance management review procedures organise a CMS around a handful of components: board and senior management oversight, a formal compliance programme covering policies, training, monitoring and corrective action, oversight of service providers and third parties, consumer complaint handling, and independent compliance audit. Examiners assess each of those separately. Strong policies with a disengaged board is still a finding.

Here’s where the language gets muddled, and it matters. Most people who say “we’re buying a compliance management system” are buying software. But in the regulatory sense, the software isn’t the system. It’s a component of the system, and usually a fairly small one.

Get that backwards and you end up with the most common failure in this market: a beautifully implemented platform sitting inside an organisation with no functioning compliance discipline, producing tidy reports that describe a programme nobody is actually running.

Why a compliance management system matters, and the part everyone skips

The obvious answers first, because they’re true.

A CMS makes compliance survivable. It means the knowledge doesn’t live in one person’s head, so when they leave in month nine the programme doesn’t leave with them. It gives you a defensible position when a regulator, an auditor, an LP or an enterprise customer asks how you manage risk. And it creates the feedback loop between what you said you’d do and what you actually did, which is the only mechanism by which compliance programmes improve rather than drift.

Now the part that gets skipped, and it’s the reason this whole article exists.

Look again at the components of a CMS in the regulatory framing. Board oversight. Compliance programme. Complaint handling. Audit. And ongoing due diligence and oversight of third parties and service providers.

That last one is doing enormous work and almost nobody notices it.

It is outward-facing. It concerns entities that are not you. And critically, it is ongoing, not a check you perform once when the contract is signed. The regulator is explicit that outsourcing an operation does not outsource the responsibility for it.

So the requirement to continuously monitor external entities is already inside the definition of a compliance management system. It has been for years. What’s missing isn’t the obligation. What’s missing is software that serves it, which is a strange gap in a market this crowded, and the rest of this piece is largely about why that gap exists.

Two axes, and everything fits on them

Every product in this market answers two questions, whether or not its homepage frames them that way.

First: where is it looking?

Some tools look inward. At your own controls, your policies, your evidence, your configuration. The subject of the inquiry is you.

Others look outward. At the entities you’re exposed to. Counterparties. Portfolio companies. Customers. Vendors. Founders you’ve already backed and can’t unback. The subject of the inquiry is somebody else.

Second: when is it looking?

Some check at a single moment. Onboarding, audit, close. A gate you pass through and then leave behind you.

Others keep looking, indefinitely, and tell you when something moves.

Four quadrants. Every vendor on your shortlist lives in one of them, and the ones claiming to live in all four are usually strong in exactly one and thin everywhere else.

Inward-looking (your own controls)Outward-looking (other entities)
Point-in-timeManual audit prep. Spreadsheet-based control testing. The annual scramble.Identity verification at onboarding. Due diligence reports at close. Screening at signing.
ContinuousContinuous control monitoring: Vanta, Drata, Sprinto, Scrut.On-chain analytics (wallets, transactions). Entity risk intelligence (people, companies). The thinnest box on the map.

Hold onto that bottom-right box. It’s the interesting one, it’s more crowded than it first appears, and almost everything confusing about this market happens inside it.

Types of compliance software: the six categories

Six product types share the label. They are not substitutes for one another, and buyers routinely purchase one expecting the capabilities of another.

1. Identity verification (KYC and KYB)

Document verification, biometric checks, liveness detection, corporate entity confirmation, sanctions and PEP screening at signup. Sumsub is the name most people know. Persona and Onfido come up in most evaluations.

Worth splitting the acronyms, because buyers use them loosely and the products differ. KYC verifies an individual. KYB verifies a business, which is a considerably harder problem, because a business has an ownership structure, and ownership structures are sometimes designed by people who would prefer they weren’t understood.

In regulated markets this category is mature, fast and, frankly, very good. A well-built KYB flow verifies a corporate entity in under a minute. Twenty years ago that was a compliance analyst, a week, and three phone calls to a registry office in a time zone that didn’t answer.

The scope is what it is, and the vendors are honest about it. This is a gate. The check runs, it passes, the relationship begins. What the entity does on day four hundred was never something the product was built to see. That isn’t a criticism. It’s a design boundary, and ignoring it is how buyers end up disappointed by software that did precisely what it promised.

2. Security compliance automation

SOC 2, ISO 27001, HIPAA, GDPR. Evidence collection, control mapping, audit readiness, and the trust centre you link from your enterprise sales page so procurement stops emailing you.

Vanta and Drata built this category. Sprinto and Scrut have built serious businesses inside it, and it’s now competitive enough that pricing has actually come down, which is not something you can say about most compliance tooling.

This category didn’t merely automate an existing process. It changed the underlying model. Before Vanta, control testing was something you did in a panic three weeks before an audit, with a shared drive full of screenshots and a contractor charging by the hour. After Vanta, controls were monitored continuously and the audit became a byproduct rather than an event.

That was a real intellectual shift, not a feature. The market rewarded it accordingly, and the people who built it were right about something incumbents had missed for two decades. Hold that thought, because we’re coming back to it.

The boundary is simply that it points inward. It will tell you a great deal about your own security posture and nothing whatsoever about the company you invested in, the exchange your portfolio company settles through, or the person who appeared on your cap table in the last round.

3. GRC platforms

Risk registers. Policy management. Control libraries. Workflow engines. Board reporting. Archer, LogicGate, OneTrust, Hyperproof, Onspring, StandardFusion.

At genuine enterprise scale these are necessary, and the good ones are impressive pieces of engineering. If you’re a regulated institution with four hundred controls, eleven frameworks and a board risk committee that meets quarterly, you need a system of record. Spreadsheets stopped being viable at that scale a long time ago.

Go in with the right expectations, though. Implementation is measured in months. Six figures is normal. And you will need someone whose actual job is running the platform, which makes it a headcount conversation as much as a software one.

Then there’s the thing buyers tend to work out about four months in.

A GRC platform is a container. It is excellent at organising risk information, routing it, and producing something a board will accept without a fight. What it does not do is go out into the world and find any.

You still have to feed it. The platform is the shelf, not the groceries. Firms that buy GRC expecting external intelligence have bought a beautifully organised empty room, and then spend the better part of a year wondering why nothing ever appears in it. That isn’t the vendor’s fault. It’s a category misread, and an expensive one.

4. Risk data providers

Sanctions lists. PEP databases. Adverse media archives going back decades. Corporate registries and beneficial ownership records. LexisNexis Risk Solutions, Moody’s, Dow Jones, OpenCorporates.

Worth being precise about what these are, because the word “software” is quietly doing something misleading. These are, for the most part, data businesses. They’re inputs. Several are irreplaceable inputs, and any serious risk product in this market is consuming their feeds one way or another. Ours included, and we’d be foolish to pretend otherwise.

The question they force on you is build versus buy. If you have engineers, a data team and a clear specification, you can license the feeds and construct the intelligence layer yourself. Some large institutions do exactly this, and for a few of them it’s the right call.

Most who try it underestimate the second half of the problem. Coverage is the easy part. Relevance is the hard part.

A firehose of adverse media mentions is not risk intelligence. It’s a research project somebody handed you, and it arrives again every morning. Someone still has to decide what’s signal, what’s noise, what’s yesterday’s story with a fresh headline, and what needs a human looking at it before Friday. That layer is most of the work, and it’s the layer the data providers deliberately leave to you.

5. On-chain analytics

This is the one that gets mistaken for ours more than any other, and in crypto the mistake is expensive.

Chainalysis, TRM Labs, Elliptic. Wallet screening, transaction tracing, exposure scoring, fund-flow analysis. If a portfolio company’s treasury address received funds two hops from a sanctioned mixer, this is the category that tells you, and it tells you fast.

Look at where it sits on the map. Outward-facing, because it examines somebody else’s activity. Continuous, because it watches the chain in real time. Which puts it squarely in the bottom-right box, and is exactly why I said that box is more crowded than it first looks.

These are excellent products. In crypto they are close to mandatory, and a fund operating without on-chain screening today is making a choice I’d struggle to defend to an LP.

But here is the distinction that matters.

On-chain analytics looks at wallets and transactions. It answers: where did this money come from, and where is it going?

Entity risk intelligence looks at people and companies. It answers: who are these humans, what are they doing off-chain, and what has changed about them since we last checked?

Those are not the same question and they do not substitute for one another.

An on-chain platform will not tell you that a portfolio company’s newly appointed CFO was named in a fraud suit in Singapore six weeks ago. It won’t tell you the company redomiciled to the UAE in March and swapped two directors. It won’t tell you there are eleven fake Telegram channels impersonating the project’s support desk right now, quietly draining users who think they’re talking to the team.

None of that leaves a trace on a blockchain. None of it happens on a blockchain.

The reverse holds too, and it deserves saying plainly rather than burying. We don’t trace fund flows. If you need to know a wallet’s exposure to a sanctioned entity, you need on-chain analytics, and you should go and buy it from one of the three companies named above.

6. Continuous entity risk intelligence

The corner of the map that has stayed thin the longest.

The question: what has changed about the entities we’re exposed to, since the last time anyone actually looked?

Outward-facing, like the identity vendors. Continuous, like Vanta. Consuming the same feeds as the data providers. Adjacent to on-chain but pointed at a different object entirely. And structurally none of them.

Three properties define it. It watches external entities rather than internal controls. It runs indefinitely rather than firing once at a gate. And it’s event-driven, which means it surfaces changes when they happen rather than producing a report every ninety days describing a world that has since moved on.

This is where Beady AI sits, and I’ll be direct about our obvious interest in you finding the box interesting. But the box exists whether or not you ever buy anything from us. And the reason it stayed empty for so long is more interesting than any vendor pitch.

The parallel nobody has drawn out loud

Go back to what the security compliance vendors actually argued, because it’s the most useful thing anyone in this market has said in fifteen years.

Their case was that point-in-time control testing is structurally broken. An annual audit tells you your controls worked on one Tuesday in October. It says nothing about the other three hundred and sixty-four days. Controls need continuous monitoring, because control failures do not consult the audit calendar before occurring.

That argument was correct. It built several large companies. Nobody in security seriously defends the annual-audit model any more, and the people who once did have quietly stopped saying so out loud.

Now say the identical sentence on the other axis.

Point-in-time entity screening is structurally broken. Onboarding diligence tells you an entity was clean on the day you checked it. It says nothing about month fourteen. External risk needs continuous monitoring, because sanctions designations, corporate restructures, litigation and impersonation campaigns do not consult your quarterly portfolio review before occurring.

Same argument. Different axis. Still largely unmade.

And here’s the thing that should make it uncomfortable: as we saw earlier, the regulatory definition of a CMS already asks for continuous third-party oversight. The obligation has been sitting there the whole time. We’ve made this case at length in Beyond Onboarding, which is the long version of what this section compresses.

It isn’t a subtle observation, and I remain mildly surprised the market hasn’t caught up. But categories take time to become legible, and until somebody names a thing, nobody puts a line in the budget for it.

What compliance software actually means for your company

Beneath the category question there’s a blunter one. What changes, day to day, if you buy this?

Three things, and they’re worth being honest about because vendors tend to promise a fourth that doesn’t materialise.

It changes who does the work. Compliance tasks that consumed analyst hours get absorbed by software, and the analysts move up the stack from collecting things to deciding things. This is real, and it’s the main reason the category exists.

It changes how fast you know. The gap between something going wrong and someone noticing shrinks, sometimes from months to hours. In practice this is where most of the value sits, and it’s also the hardest thing to put on a pricing page.

It changes what you can prove. When an LP, an auditor or an enterprise buyer asks how you manage risk, you have an answer with a date on it rather than a story.

What it does not change, and here’s the fourth thing vendors imply: it does not give you a compliance function. Software cannot decide your risk appetite, own a decision, or take responsibility for one. If nobody in the building owns the output, the software is producing a very well-formatted record of nothing happening.

The challenges nobody puts on the pricing page

Five of them. They aren’t equally hard, and I won’t pretend otherwise, so they get unequal space.

Obligations only ever grow. New frameworks, new jurisdictions, new readings of old rules. Nothing gets retired. Your headcount will never track your obligations, and it isn’t going to start.

Evidence lives in four systems and an inbox. Tedious to assemble by hand. Also genuinely solved — this is what the security compliance vendors built their category on.

Alert fatigue. This is the one that kills programs.

Here’s how it actually goes. The platform gets installed. Alerts start arriving. For the first fortnight everyone reads them, because everyone is still faintly excited about the new thing. By week six, the hit rate has settled somewhere low, ignoring an alert has never yet cost anyone anything, and the channel has drifted into the same mental compartment as the building-maintenance emails.

Nobody decides this. It just happens.

And here’s the part I’d argue with, if a client told me they’d fixed it by having a word with the team: it is not a discipline problem. You cannot instruct people out of it. The behavior is an entirely rational response to a low-signal feed, and the only real fix is changing what reaches them — severity tiers, named owners, and far fewer things that warrant an interruption.

Third parties are everyone’s blind spot. You can outsource an operation. You cannot outsource responsibility for it. Regulators are explicit about this, and most firms are nonetheless running third-party oversight on a spreadsheet last updated when the contract was signed.

Nobody can prove a negative. A clean year looks identical from the outside whether your programme is excellent or whether you were lucky. The CFO can’t tell the difference. Nor, honestly, can you.

That last one is why we bothered building an ROI model rather than another page of scare statistics. If you’re holding a number up in front of partners, it needs to survive being taken apart.

What good compliance software actually buys you

Stated without the usual inflation.

  • Hours back. Evidence collection, screening and report assembly stop consuming analyst weeks. This is the benefit that is easiest to measure and the one most often oversold.
  • Speed of knowing. The lag between an event occurring and someone in your organisation being aware of it collapses. Detection latency is the metric that actually predicts outcomes, and almost nobody tracks it.
  • Consistency. The same checks run the same way every time, which matters enormously when the person who used to run them manually has left.
  • Defensibility. A dated, sourced record of what you knew and when you knew it. In a dispute, this is worth more than everything else combined.
  • Fewer surprises, and cheaper ones. Problems caught early are smaller. This is banal and it is also the entire economic argument.
  • Institutional readiness. LPs, enterprise buyers and banking partners increasingly ask how you manage this. Having an answer shortens sales cycles and fundraises, which is a commercial benefit dressed up as a compliance one.

Notice what isn’t on that list. Compliance software does not make you compliant. It makes a functioning compliance programme cheaper, faster and more consistent. If there’s no programme underneath, you’ve automated a vacuum.

What buying in the wrong quadrant actually looks like

Abstractions slide past. Here are the four failure patterns we see most, all recoverable, all avoidable, none cheap.

The empty container. A firm buys GRC expecting it to surface external risk. Nine months and a substantial implementation later, the risk register contains exactly what somebody typed into it. The platform is working perfectly. It was simply never a source of intelligence.

The onboarding-only fund. Excellent diligence at close, nothing afterwards. The fund is protected against risks that existed on the day it wired, and blind to every one that emerged since. Given that holding periods run to seven or eight years, that’s most of them.

The on-chain-only crypto fund. Wallet exposure monitored beautifully. Founder background, corporate structure and impersonation activity monitored not at all. Looking hard at one surface while a different surface moves behind it.

The firehose. The firm licensed data feeds directly, built a screening layer, and now receives four hundred alerts a week that nobody reads. Technically this is coverage. Functionally it’s indistinguishable from having nothing, and it cost more.

How to set up a compliance management system (and the four ways it goes wrong)

Most guidance on this describes a tidy linear process nobody has ever actually followed. More useful is knowing where it breaks, because the breaks are predictable and there are roughly four of them.

Breaking point one: you bought the software first.

The most common by a distance. Somebody sees a demo, the demo is genuinely impressive, procurement gets involved, and six weeks later there’s a platform and no programme.

The fix is unglamorous. Before you look at a single vendor, write down every rule, framework and contractual commitment that actually binds you. Not the impressive ones. That list is usually shorter than people expect and stranger too — when we did ours it contained two obligations nobody in the company had thought about in over a year. It’ll also cut your vendor shortlist roughly in half before you’ve had a call, which is a decent return on an afternoon’s work.

Breaking point two: nobody senior actually owns it.

Worth knowing if you’re not from a regulated background: when examiners assess a compliance management system, board and management oversight is graded as its own component, independently of your policies and your tooling. You can have beautiful documentation, a well-configured platform, trained staff, and still fail — because the person nominally in charge hasn’t looked at any of it since the implementation call.

Someone senior needs authority, budget and a line to whoever governs the organisation. Not a nominated volunteer.

Breaking point three: automating decisions you haven’t made.

Software encodes what you’ve already decided. If the policies don’t exist, what you’re automating is your own uncertainty, and you’re doing it at scale.

Write the policies first. Procedures, ownership, and an explicit statement of what happens when something goes wrong. This is the least interesting paragraph in this article and I’d skip it too, which is precisely why so many programmes have a hollow centre.

Breaking point four, and this is the expensive one: third parties.

Map everyone whose failure becomes your problem. Vendors, service providers, portfolio companies, counterparties.

Most firms do this once — at contract signature, or during diligence — and then never again. The regulatory framing is quite clear that this isn’t enough: ongoing oversight of third parties is expected, and outsourcing an operation does not outsource your responsibility for it. A map you built at signature and never updated isn’t oversight. It’s an archive.

So decide consciously. Periodic or continuous? And if periodic, be specific with yourself about the cost, because a quarterly check means a designation landing in week three goes unnoticed for eleven weeks.

Then, and only then, the shopping.

With obligations mapped and third parties listed, tool selection is close to mechanical. You’ll know whether you need evidence automation, a system of record, gate screening, continuous monitoring, or two of the above.

Route the outputs to named humans, with severity tiers and response windows, delivered into the tools the team already has open. And book the review now, six months out, while you still care enough to honour it — because a programme nobody tests drifts silently, and it will not announce that it’s doing so.

So which one do you actually need?

Answer honestly, because buying in the wrong quadrant is expensive and slow to discover.

You’re selling into enterprise, and you need SOC 2 or ISO 27001. Go to Vanta, Drata or Sprinto. Genuinely, go. This post isn’t for you, and neither are we.

You’re a large organization that needs a risk system of record, policy management and board reporting. That’s GRC. LogicGate, Archer, OneTrust. Budget accordingly, because it isn’t cheap and the implementation isn’t quick.

You’re verifying users or businesses at signup inside a regulated flow. That’s identity verification. Sumsub and its peers, and they’ll have you live faster than you expect.

You need to know where crypto funds came from and where they went. On-chain analytics. Chainalysis, TRM, Elliptic. There is no substitute and you shouldn’t go looking for one.

You’re building your own screening layer and want the underlying feeds. Go straight to the data providers, skip the middle, and budget honestly for the relevance layer you’ll have to build yourself.

You’re exposed to external entities where the risk emerges after the relationship starts. Portfolio companies. Counterparties. Founders you already backed. That’s the sixth category, and it’s the one nobody sold you, because until fairly recently nobody was selling it.

Most firms need two or three of these

Which is the part vendors are reluctant to say, so let’s say it.

These categories are complements, not substitutes, and a serious risk posture usually runs more than one at once.

A crypto fund of any size realistically needs on-chain analytics and entity risk intelligence, because the two watch different surfaces and neither sees the other’s. A fintech needs identity verification at the gate and continuous monitoring behind it, because verifying a customer once tells you nothing about who they became. A regulated institution needs a GRC system of record and something that actually feeds it.

Anyone telling you their single product covers the whole map is either confused about the map or hoping you are.

The future of compliance software: AI, prediction, and the traceability problem

Every vendor in this market now has AI on the homepage, ours included, so it’s worth separating what’s real from what’s decoration.

What’s real: the relevance layer. The genuine bottleneck in compliance has never been getting data, it’s deciding which of it matters. Language models are extremely good at reading ten thousand news articles and identifying the four that concern the entity you actually care about, in a language your team doesn’t read, from a regional outlet nobody has heard of. That capability didn’t exist five years ago and it changes the economics of monitoring completely.

What’s real but oversold: predictive analytics. The pitch is that AI will tell you which counterparty is going to become a problem before it does. Some of this works, particularly pattern detection across entities. Much of it is a correlation engine with a confident voice, and the confident voice is the dangerous part.

Which brings me to the thing I think the industry is going to have to reckon with, and soon.

An AI-generated risk report that cannot show you its sources is a liability, not an asset. If a model summarises an adverse media hit and the summary is subtly wrong, you have now made a decision on a hallucination and you have no way to discover it. Worse, you have a document that looks authoritative sitting in your file.

The only defensible pattern is one where every signal traces back to a primary source that a human can open, read and verify. The model’s job is to filter and prioritise, not to be believed. That distinction sounds pedantic right up until an examiner asks where a conclusion came from and the honest answer is that the AI said so.

We build to the traceable pattern, which is a commercial position as much as an ethical one. But you should be asking it of every vendor in this market, including us, and the answer should be a link rather than a paragraph.

Frequently Asked Questions

What is compliance software?
Software that either helps you prove you’re meeting a set of obligations, or helps you see risk you would otherwise miss. The term covers at least six distinct product categories that share almost no functionality, which is why buyers so often purchase one expecting the capabilities of another.
Compliance management is the work. Knowing which rules apply to you, writing the policies, training people, and checking whether anyone is actually following them.

A compliance management system is what keeps that work running after the person who built it resigns. It’s the structure, not the effort.

Software lives inside the system. It isn’t the system. Firms that buy it as though it were tend to find out about six months in, usually during an audit.
No. GRC platforms are systems of record with workflow engines: they organise, route and report on risk information. They do not go out and find any. If you need external intelligence, a GRC platform is a container waiting to be filled, not a source.
Yes. Pre-close diligence establishes a baseline: who is this entity today. Continuous monitoring answers a different question: what has changed since. Neither substitutes for the other, and a monitoring programme with no baseline has nothing to compare against.
No, and this is one of the most costly misunderstandings in the market. On-chain analytics traces wallets and transactions. Entity risk intelligence monitors the people and companies behind them: founder litigation, corporate restructuring, sanctions designations, impersonation campaigns. None of that happens on a blockchain. Most serious crypto funds need both.
It varies enormously by category. Security compliance automation typically runs in the low five figures annually for a startup. Enterprise GRC routinely reaches six figures before implementation, which is itself a multi-month project requiring dedicated headcount. Continuous risk intelligence sits between the two, and should be assessed against the expected cost of the events it prevents rather than against other software.
Security compliance platforms can be producing useful output within weeks. Enterprise GRC implementations are measured in months and occasionally years. Continuous monitoring can be running in days, because it consumes external data and doesn’t require you to reorganise your internal systems first.
No, and any vendor implying otherwise should worry you. AI is very good at the relevance layer: reading enormous volumes of material and identifying the fraction that matters. It cannot own a decision, set a risk appetite, or take responsibility. Insist that every AI-generated signal links back to a primary source you can verify yourself.

A last word about the word

“Compliance software” survives as a phrase because it’s convenient, not because it’s accurate. It’ll probably survive another decade for exactly the same reason, and analysts will keep drawing quadrants that put six unrelated businesses on one chart.

But it was never the useful question. The useful question, the one that actually determines what you should buy, is smaller and rather more awkward.

What are we trying to see, and how often do we need to see it?

Answer that honestly and the shopping gets considerably easier. Answer it badly and you’ll spend six figures finding out which quadrant you were in all along.

If your answer landed in the bottom-right box, that’s the corner we cover: continuous monitoring of portfolio companies, founders and counterparties across sanctions lists, adverse media, corporate registries and social impersonation, with every signal traceable back to its original source. Book a session and we’ll run it against your actual holdings rather than a demo set.

Mike North
Ceo and Cofounder of Company Name

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Mauris tincidunt vulputate efficitur. Pellentesque nec massa sed ante pharetra elementum. Phasellus ac ante vitae quam ultricies tincidunt ac vel odio.

Lorem ipsum dolor sit amet

Lorem ipsum dolor sit amet, consectetur adipiscing elit.

    Lorem ipsum dolor sit amet

    Lorem ipsum dolor sit amet, consectetur adipiscing elit.

    Ready to get started?

    Helping you go live in days, not weeks.