Conduct rules, AML refreshers, and attestations — captured as defensible evidence.

Capture conduct attestations and prove acknowledgement for SMCR/SEAR, MAR, personal-account-dealing, and DORA, ready for FCA/PRA/SEC/FINRA. Reach office, frontline, and contractor staff over email, QR, and the recipient portal — SMS and WhatsApp coming soon; remind automatically; and export an audit-ready evidence pack on demand.

Start free — up to 20 employees, no card · Sign in

From SMCR conduct attestations to sanctions and AML updates, ReadSignFlow captures a signed acknowledgement from every regulated person, against the exact policy version — with a tamper-evident trail built to support regulatory and internal-audit review.

The regulator expects evidence, not assurances.

Illustrative figures reflecting common industry patterns, not a specific published survey.

Built for the three lines of defense.

Every conduct, financial-crime, and policy workflow your compliance and risk teams run — with evidence built for regulatory review.

What compliance teams actually send through ReadSignFlow.

The conduct rules, sanctions updates, and supervisory policy changes that need a signed attestation — captured as defensible evidence the first time.

Trading & supervision

AML, KYC & sanctions

Conduct, cyber & attestations

Aligned to financial conduct oversight.

Templates, retention, and evidence formats built around the conduct and financial-crime regimes you report into.

Frameworks covered: FCA SMCR, PRA, SEC, FINRA, SEAR (Ireland), MiFID II, AMLD / MLR, OFAC / Sanctions, MAR (Market Abuse), GDPR (EU), SOX, DORA, ISO 27001, Operational Resilience.

Frequently asked questions

Can ReadSignFlow evidence SMCR conduct-rule attestations for each certified person?

Yes. Attestations are captured as personal sign-offs per senior manager and certified person — not a team email — each with signer identity, policy version, and a UTC timestamp. That gives you defensible, individual-level evidence for personal accountability under SMCR or SEAR.

How do we run annual attestation cycles across multiple legal entities?

Recurring cycles are scheduled per entity, jurisdiction, and role, and ReadSignFlow chases automatically with reminders and escalation to compliance for anyone outstanding. One tenant runs separate cycles across all your entities without duplicating the policy library.

What can we produce when the FCA or internal audit asks for attestation evidence?

A tamper-evident evidence pack — who attested to which policy version and when, with the full append-only trail behind every signature — exportable the same day. Retention is configurable, so records stay available over the multi-year horizons regulators expect.

Can ReadSignFlow reach staff who don't have a corporate email?

Yes — we deliver a secure magic-link over email, printable QR posters, and the recipient portal — which also runs on a shared tablet — so frontline and contractor staff read and sign on their own phone with no app and no login. SMS and WhatsApp delivery is in integration and coming soon.

Does it integrate with our HRIS or ATS?

Your HRIS or ATS pushes people and joiner/mover/leaver (JML) events to our REST API or webhooks — Workday, BambooHR, SuccessFactors and others can all do this, and no native connector is required or provided. Policy assignments then follow staff automatically as they join, move, or leave.

Where is our data hosted, and is it secure?

US-hosted (single region); an EU data region is planned (in progress). Data is encrypted in transit and at rest with AES-256, isolated per tenant, and protected by SOC 2 Type II and ISO 27001 controls (certification in progress) with an append-only, tamper-evident audit log.

Is an electronic acknowledgement legally defensible?

Every signature captures signer identity, intent, a UTC timestamp, and a tamper-evident audit trail, supporting eIDAS (EU/UK) and the US ESIGN Act / UETA.

How long does it take to go live?

Self-serve, most teams launch their first campaign in an afternoon: upload a policy, import recipients from a CSV, set a deadline, and send. Wiring your HRIS into the JML API takes days rather than a quarter-long implementation project.

Which languages can recipients sign in?

The recipient experience is available in five languages — English, Spanish, French, German, and Portuguese — so deskless staff can read and acknowledge policies in their own language. Documents themselves are shown in the language you upload them in.

My employer sent me a ReadSignFlow link — what is it?

It's a secure link your organisation uses to share a workplace policy or document with you and record that you confirmed reading it and acknowledged it — you read and sign on your phone, with no app and no account password. See readsignflow.com/for-recipients for what we record and what we'll never ask for.

ReadSignFlow · Product · Pricing · Security · Solutions · Resources · Enterprise · vs. e-signature · FAQ · Customers · About · Careers · For recipients · Status · Contact us · Start free · Sign in

Privacy · Terms · DPA · Acceptable use · Recipient terms · Cookies

ReadSignFlow on LinkedIn, YouTube, Instagram, and Facebook.