Conduct rules, AML refreshers, and attestations — captured as defensible evidence.
Capture conduct attestations and prove acknowledgement for SMCR/SEAR, MAR, personal-account-dealing, and DORA, ready for FCA/PRA/SEC/FINRA. Reach office, frontline, and contractor staff over email, SMS, WhatsApp, QR, and kiosk; remind automatically; and export an audit-ready evidence pack on demand.
From SMCR conduct attestations to sanctions and AML updates, ReadSignFlow proves every regulated person read and acknowledged the policy — with a tamper-evident trail your regulator and internal audit will accept.
The regulator expects evidence, not assurances.
- Personal — accountability under SMCR / SEAR. Senior managers are personally liable — you need defensible proof each individual attested, not a team email.
- Annual — cycles across multiple legal entities. Conduct rules, AML, and policy attestations repeat every year across entities, jurisdictions, and roles.
- Days — to evidence a single attestation cycle. Pulling who-signed-what from email and shared drives is slow and rarely complete when the regulator calls.
Built for the three lines of defense.
Every conduct, financial-crime, and policy workflow your compliance and risk teams run — with evidence regulators accept.
- SMCR / SEAR conduct attestations — Annual and ad-hoc conduct rule attestations per certified and senior manager, with role-based targeting and personal sign-off.
- AML & sanctions refreshers — Push KYC, AML, and sanctions-list updates the moment they change, with a tight SLA and escalation for outstanding staff.
- Policy & procedure attestations — Code of conduct, conflicts of interest, gifts & entertainment, market abuse — versioned and re-attested on change.
- Annual compliance cycles — Schedule recurring attestation cycles across entities and jurisdictions; ReadSignFlow chases and escalates automatically.
- Onboarding & role changes — JML automation assigns the right regulated-person packets on joiners and role moves, and retires them on leavers.
- Regulator & audit packs — One-click, tamper-evident evidence packs formatted for the FCA, PRA, SEC, and internal audit.
What compliance teams actually send through ReadSignFlow.
The conduct rules, sanctions updates, and supervisory policy changes that need a signed attestation — captured as defensible evidence the first time.
Trading & supervision
- Written Supervisory Procedures (WSP) updates
- Restricted / watch list bulletins
- Insider-trading window & blackout notices
- New product approval memos & desk procedures
- Branch operations updates (cash handling, dual control)
- Updated underwriting & lending guidelines
AML, KYC & sanctions
- OFAC / UK OFSI / EU sanctions list updates
- AML red-flag & suspicious-activity bulletins
- KYC / CDD procedure changes
- Customer-complaint handling SOP updates
- Annual AML & financial-crime training
- Beneficial-owner refresh attestations
Conduct, cyber & attestations
- Code of Ethics & personal account dealing (PAD)
- Gifts & hospitality and outside business activities
- SM&CR / fitness & propriety attestations
- Cybersecurity advisories & phishing alerts
- DORA / NYDFS Part 500 acknowledgements
- Whistleblower / Speak-Up policy reminders
Aligned to financial conduct oversight.
Templates, retention, and evidence formats built around the conduct and financial-crime regimes you report into.
Frameworks covered: FCA SMCR, PRA, SEC, FINRA, SEAR (Ireland), MiFID II, AMLD / MLR, OFAC / Sanctions, MAR (Market Abuse), GDPR (EU), SOX, DORA, ISO 27001, Operational Resilience.
Frequently asked questions
Can ReadSignFlow evidence SMCR conduct-rule attestations for each certified person?
Yes. Attestations are captured as personal sign-offs per senior manager and certified person — not a team email — each with signer identity, policy version, and a UTC timestamp. That gives you defensible, individual-level evidence for personal accountability under SMCR or SEAR.
How do we run annual attestation cycles across multiple legal entities?
Recurring cycles are scheduled per entity, jurisdiction, and role, and ReadSignFlow chases automatically with reminders and escalation to compliance for anyone outstanding. One tenant runs separate cycles across all your entities without duplicating the policy library.
What can we produce when the FCA or internal audit asks for attestation evidence?
A tamper-evident evidence pack — who attested to which policy version and when, with the full append-only trail behind every signature — exportable the same day. Retention is configurable, so records stay available over the multi-year horizons regulators expect.
Can ReadSignFlow reach staff who don't have a corporate email?
Yes — we deliver a secure magic-link over SMS, WhatsApp, QR posters, and shared kiosks, so frontline and contractor staff read and sign on their own phone with no app and no login.
Does it integrate with our HRIS or ATS?
Yes — ReadSignFlow syncs people and joiner/mover/leaver events from Workday, BambooHR, and SuccessFactors, plus a REST API and webhooks.
Where is our data hosted, and is it secure?
Hosted in EU and US data regions. Data is encrypted in transit and at rest (AES-256, via our cloud platform), isolated per tenant, and protected by SOC 2 Type II and ISO 27001 controls (certification in progress) with an append-only, tamper-evident audit log.
Is an electronic acknowledgement legally defensible?
Every signature captures signer identity, intent, a UTC timestamp, and a tamper-evident audit trail, supporting eIDAS (EU/UK) and the US ESIGN Act / UETA.
How long does it take to go live?
Most teams launch their first campaign within days: upload a policy, sync or import recipients, set a deadline, and send.
Which languages can recipients sign in?
The recipient experience is multilingual (including English, Spanish, and more).
My employer sent me a ReadSignFlow link — what is it?
It's a secure link your organisation uses to share a workplace policy or document with you and record that you've read and acknowledged it — you read and sign on your phone, with no app and no account password. See readsignflow.com/for-recipients for what we record and what we'll never ask for.
Product · Pricing · Security · Solutions · Resources · Book a demo