Platform · Audit trail and signed evidence
Evidence that anyone you send it to can check.
Every deliverable is signed and time-stamped when it's issued. Your examiner, your sponsor bank or your auditor can confirm on a public page, without an account, that the document in front of them is the one that was signed, unchanged.
The problem it removes
A PDF in an inbox proves nothing about itself
- A report passes through email and shared drives, and no one can say whether the copy in hand is the one that was issued.
- Workpapers live in a separate folder from the report, so tracing a conclusion back to its test takes a request and a wait.
- A citation in a report rarely says how carefully anyone checked it.
What you see
A signed record with its workpapers
Each deliverable carries its signature, its timestamp and the workpapers for every test behind it. Export it to Word, PDF or Excel for your own files; the signed evidence document travels with it.
| Check | Result |
|---|---|
| Signature | Valid signed by the engagement practitioner |
| Contents since signing | Unchanged |
| Timestamp (RFC 3161) | 2026-07-14 16:02:37 UTC |
| Workpapers | 14 tests, 14 workpapers |
| Citation | Label |
|---|---|
| 31 CFR 1020.320(b)(3) | To the pinpoint |
| 31 CFR 1010.230 | To the section |
| FFIEC Manual, CIP overview | Unverified |
Illustrative example with invented report details. The check confirms the document is unchanged since signing; it doesn't grade the conclusions.
How it works
Test, label, sign, stamp, share
- Test. Rules produce each result, and each test writes its own workpaper: the population, the rule, the exceptions.
- Label. Every citation carries a label saying how far it was checked: verified to the pinpoint, verified to the section, or unverified. AI drafts the report text around the results; it doesn't set a label or change a result.
- Sign. A practitioner reviews the work and signs. The signing key is held in a managed key service.
- Stamp. The signed document receives an RFC 3161 timestamp from a time-stamping authority, and a second, independent public timestamp as a backstop, so the time of signing can be shown later.
- Share. You send the portable evidence document to whoever needs it. They check it on the public verify page, without an account.
Guardrails
What it will never do
- Verification shows the document hasn't changed since it was signed. It doesn't certify that the conclusions are right; the practitioner who signed answers for those.
- It doesn't label a citation more strongly than the check performed. Some citations are marked unverified, and they say so.
- It doesn't make your records beyond challenge. It makes them checkable.
Where it shows up
The work this part does for you
Plain English
What this is, and how anyone does it
Reference articles from our library, cited to the published rules and standards. No sales copy.
- ReferenceAudit Evidence and Workpapers: What They Are and What They ContainWhat audit evidence and workpapers are, the documentation standards that govern them, what a workpaper contains, retention, integrity controls, and how examiners use them.
- Field GuideBSA/AML Independent Testing: The Third PillarThe third pillar in practice: what independent testing covers, who can perform it, how often it runs, and how examiners and sponsor banks read the findings.
Connected parts
What it works with
Talk to a practitioner
Book a 15-minute chat with our founder.
A real conversation with a senior compliance leader, to see if there's a fit. Not a sales call, not a demo, no pressure.