Compliance attestation software that turns every policy sign-off into regulator-ready evidence.
ReadSignFlow is regulatory compliance software for policy attestations — annual code-of-conduct cycles, conflict-of-interest declarations, and regulatory-change rollouts. It distributes policies over email, SMS, WhatsApp, a recipient portal, and QR, enforces a read gate, captures eIDAS and ESIGN/UETA-aligned signatures, chases outstanding staff with automatic T-7/T-3/T-24 reminders and manager escalations, and exports a one-click audit pack of signed PDFs plus an append-only event log. Free for up to 20 employees.
From the annual code-of-conduct cycle to COI declarations and MAR re-attestations, ReadSignFlow is regulatory compliance software that gets every in-scope employee to read, sign, and evidence the right policy version — with automatic reminders, manager escalations, and a one-click audit pack for the exam file.
Attestation season shouldn't be a spreadsheet exercise.
- 01 — The annual cycle still runs on mail-merges and pivot tables. Three colours of highlighting, a VLOOKUP against last month's HR export, and the last 10% of the population chased name by name while the deadline slips.
- 02 — Evidence that won't survive scrutiny. Sent-items screenshots and 'confirmed verbally' notes aren't an audit trail. When the regulator or internal audit samples ten names, you need signer identity, a UTC timestamp, and the exact policy version for every one.
- 03 — The in-scope population never stands still. Joiners, movers, leavers, and role changes mean the list you certified against in January is wrong by March. Attestation completeness is only as defensible as the population behind it.
Eight compliance workflows, one platform.
The attestation cycles, declarations, and regulatory-change rollouts a compliance function runs every year — with the chasing, versioning, and evidence handled for you.
- Annual policy attestation cycles — Run the annual code-of-conduct and policy-suite attestation as one campaign: segments for each entity, per-recipient deadlines, T-7/T-3/T-24 reminders, and manager escalations. Compliance reporting software is built in — a live completion figure the board pack can quote.
- Conflict-of-interest declarations — Distribute the COI policy and declaration for signature each cycle — outside business activities, close connections, personal interests — and hold the signed record per employee with a tamper-evident audit trail.
- Gifts & entertainment acknowledgements — Push the G&E policy, thresholds, and register procedure to every in-scope employee before the festive season. Non-responders are chased automatically; managers see who's outstanding.
- ABAC / anti-bribery attestations — FCPA and UK Bribery Act policy attestations with the read gate enforced — every employee scrolls the policy before they can sign, and every signature is bound to the document version.
- Insider trading & PAD acknowledgements — Target access persons and restricted-list staff with the market-abuse and personal-account-dealing policy using role and department segments. Each acknowledgement is timestamped against the exact edition signed.
- Regulatory-change rollouts — When a rule changes, publish the new policy version and re-attest only the affected segment. Document versioning shows precisely who signed which edition, and when — no blanket re-sends.
- SM&CR & individual accountability — Governance software for the accountability regime: capture acknowledgements of conduct rules, statements of responsibilities, and certification-regime policies individually — a signed, dated record per SMF and certified person, ready for the FCA.
- Whistleblowing policy acknowledgement — Prove every employee — including deskless and contractor staff reached via SMS, WhatsApp, or QR posters — has read the speak-up policy, in line with the EU Whistleblowing Directive.
What compliance teams actually send through ReadSignFlow.
The attestation cycles, declarations, and policy updates that need a signed record from every in-scope employee — versioned, deadlined, and audit-ready.
Ethics & anti-bribery
- Code of conduct & ethics attestations (annual)
- Anti-bribery & corruption policies (FCPA / UK Bribery Act)
- Gifts, entertainment & hospitality policies
- Conflict-of-interest & outside business activity declarations
Market & information conduct
- Insider trading & personal account dealing (PAD) policies
- Market abuse (MAR) & information-barrier procedures
- Confidentiality & data-protection undertakings
- Sanctions, AML & KYC policy updates
Governance & accountability
- SM&CR conduct rules & statements of responsibilities
- Whistleblowing & speak-up policy awareness
- Third-party & supplier code of conduct
- Regulatory-change bulletins & re-attestations
Built around the frameworks your programme answers to.
Attestation evidence, retention defaults, and audit-pack formats — a compliance tracking system shaped for the regulators, prosecutorial guidance, and standards a compliance function is measured against.
Frameworks covered: DOJ ECCP, FCPA, UK Bribery Act 2010, FCA SM&CR, SEC Rule 204A-1, FINRA Rule 3110, SOX (Sarbanes-Oxley), EU Market Abuse Regulation (MAR), EU Whistleblowing Directive, GDPR, 6AMLD (EU), OFAC Sanctions, ISO 37301, ISO 37001, COSO.
Frequently asked questions
Can ReadSignFlow run our annual compliance attestation cycle end to end?
Yes. Upload the policy suite into versioned folders, target the in-scope population with segments (department, entity, role), and set per-recipient deadlines. ReadSignFlow enforces a read gate, captures an eIDAS / ESIGN-aligned signature, sends automatic T-7, T-3, and T-24-hour reminders, escalates outstanding names to their manager, and shows live completion — no mail-merges, no spreadsheet chasing.
Does policy attestation tracking stay accurate as your workforce changes?
Yes. JML auto-enrolment syncs joiners, movers, and leavers from your HRIS (or via the REST API and CSV), so new joiners are automatically assigned the always-on onboarding attestations, movers pick up the policies for their new role or entity, and leavers drop off the outstanding list. Completion is always measured against the live population, not January's export.
What evidence do we get for a regulator, external auditor, or internal audit?
A one-click audit pack: the signed PDF for each attestation — signer identity, UTC timestamp, and the exact document version they signed — plus an append-only event log of every delivery, view, reminder, escalation, and signature. Signatures align with eIDAS (EU/UK) and the US ESIGN Act / UETA, and retention policies let you keep evidence for the periods your framework requires.
How much effort is it to launch a compliance attestation campaign?
A first campaign takes days, not weeks: upload the policy, sync or import recipients, set the deadline, and send. There is a free tier for up to 20 employees to prove the workflow, self-serve paid plans beyond that, and an Enterprise plan that adds SSO and EU/US data residency for regulated groups.
Can we send a third-party code of conduct to vendors who aren't employees?
Yes. Recipients don't need a corporate email address or an account — import third-party contacts via CSV or the REST API and ReadSignFlow delivers a secure magic link over email or SMS. Each counterparty reads through the read gate and signs, and the signature is captured with the same tamper-evident audit trail as your employee attestations.
How do I choose the best compliance software for policy attestations?
Start with the evidence a regulator or auditor will actually test: full-population records, not screenshots and samples. Generic GRC suites track risks and controls but often stop at 'policy published' — attestations need per-person, tamper-evident proof of who signed which version, on channels that reach frontline staff who never open email. ReadSignFlow is built for exactly that attestation layer, and its REST API pushes completion events into whatever wider tooling you run.
Product · Pricing · Security · Solutions · Resources · Book a demo