Audit evidence for every policy acknowledgement — the full population, not a sample.
ReadSignFlow is compliance audit software for the acknowledgement layer: it gives internal audit complete, tamper-evident evidence of policy acknowledgement — control-owner attestations, SOX 302 sub-certifications, and finding sign-offs captured with UTC timestamps in an append-only event log. Export the full population and the exception list in one click — signed PDFs plus the event trail — instead of sampling spreadsheets. Automatic reminders at T-7, T-3, and T-24h chase non-attesters in-period, with manager escalation when they still don't sign.
Stop ticking screenshots and sampling spreadsheets. ReadSignFlow is compliance audit software that captures control-owner attestations, sub-certifications, and policy acknowledgements with UTC timestamps in a tamper-evident, append-only log — and exports the complete population, exception list included, in one click.
Testing policy compliance shouldn't start with a PBC request.
- 01 — Evidence arrives as screenshots and spreadsheets. PBC requests come back as edited Excel lists and forwarded emails — no source timestamps, no document version, nothing you can tick back to a system of record.
- 02 — You sample because completeness can't be proven. Without a reliable population you fall back to 25-item samples and caveated conclusions, and IPE testing eats the budget before the real testing even starts.
- 03 — Exceptions surface at reporting, not in the period. Non-attesters and unsigned action plans only show up weeks later in fieldwork — too late to chase in-period, so findings age and the audit-committee pack slips.
Eight audit workflows, one evidence source.
Every attestation and acknowledgement your audit plan touches — captured once, timestamped, and exportable as a complete population with the exceptions already flagged.
- Control-owner attestations with a complete audit trail — Send quarterly attestation letters to every control owner with per-recipient deadlines. Each signature is UTC-timestamped and sealed into an append-only log, exportable as a signed PDF — audit and compliance software that hands you walkthrough-ready evidence, not a forwarded email.
- SOX 302 sub-certification support — Cascade sub-certification statements down the entity and process hierarchy ahead of the CEO/CFO certification. Automatic reminders at T-7, T-3, and T-24h chase stragglers, and the CFO gets a clean exception list, not a chasing thread.
- Policy-compliance population testing — Stop sampling 25 of 1,200. Export the entire acknowledgement population — recipient, document version signed, delivery channel, UTC timestamp — and test 100% of it in your analytics tooling in one pass.
- Remediation-action acknowledgements — When a finding closes with a control change, push the revised procedure to the affected team and capture a signed acknowledgement from every operator — evidence the remediation actually landed, not just that the memo went out.
- Audit-finding action-plan sign-offs — Route each management action plan to its named owner for a formal, deadline-bound sign-off. Non-response escalates to the owner's manager automatically, so agreed actions don't drift past the audit-committee date.
- Delegation-of-authority acknowledgements — Every approver signs the current DOA matrix — and re-signs on each version change. When you test an approval against the matrix, you have audit-ready documentation of exactly which limits that approver had acknowledged on that date.
- Periodic access-review attestations — Quarterly user-access-review confirmations from system and data owners, segmented by application or entity. The append-only log gives ITGC testers the who-signed-what-when trail without a screenshot in sight.
- Fraud-awareness acknowledgements — Annual fraud-awareness and whistleblowing-policy campaigns across the whole workforce — email for office staff, SMS and QR posters for plants and stores — with a live exception list of who still hasn't signed.
What internal audit actually collects through ReadSignFlow.
The attestation letters, sign-offs, and policy acknowledgements that become your test populations — captured with versions and timestamps, exceptions flagged as they happen.
Attestations & certifications
- Quarterly control-owner attestations (SOX 302 support)
- Annual delegation-of-authority acknowledgements
- Periodic user-access-review attestations
- Conflict-of-interest & related-party declarations
Policies under test
- Code of conduct & anti-bribery (FCPA / UK Bribery Act)
- Fraud-awareness & whistleblowing policies
- Expense, procurement & DOA policy refreshers
- Information-security & acceptable-use policies
Findings & remediation
- Audit-finding action-plan sign-offs
- Remediation-action completion acknowledgements
- Management-response confirmations
- Post-incident control-change acknowledgements
Built for the frameworks your workpapers cite.
Complete populations, tamper-evident logs, and per-event timestamps map directly to what ICFR testing, IIA standards, and your external auditors expect of acknowledgement evidence.
Frameworks covered: SOX §302 / §404 (Sarbanes-Oxley), COSO Internal Control — Integrated Framework, PCAOB AS 2201, IIA Global Internal Audit Standards, SEC ICFR requirements, UK Corporate Governance Code, J-SOX (Japan FIEA), FCPA, UK Bribery Act 2010, COBIT 2019, ISO 27001 (Annex A control audits), GDPR accountability (Art. 5(2) & 24), NAIC Model Audit Rule, DORA (EU financial entities).
Frequently asked questions
Can ReadSignFlow capture control-owner attestations as audit evidence?
Yes. A read gate ensures each owner actually opened and scrolled the attestation letter before signing, and every signature records signer identity, the exact document version, and a UTC timestamp — sealed into an append-only, tamper-evident event log. Signatures are aligned to eIDAS (EU/UK) and the US ESIGN Act / UETA, and export as a signed PDF per attester plus the full event trail.
How do I know the attestation population is complete when people join, move, and leave?
Recipients sync from your HRIS (or via API and CSV), and joiner/mover/leaver events keep segments current: a new AP manager who matches the control-owner segment is auto-enrolled into the always-on attestation campaign, and leavers drop out. The export shows the population as at the deadline, so you can reconcile it against headcount before you test.
What's included in a policy acknowledgement audit pack?
One click produces the signed PDF for every attester plus the append-only event log — sent, delivered, opened, read-completed, and signed events, each UTC-timestamped per recipient and channel — alongside per-recipient deadlines and a ready-made exception list of everyone still outstanding. It is the whole population, not a sample, in one export.
How much effort is it to run a quarterly attestation cycle?
Minutes, not a project. Upload the attestation letter (folders keep each quarter's version), pick the control-owner segment, set per-recipient deadlines, and launch. Reminders fire automatically at T-7, T-3, and T-24h, and non-response escalates to the owner's manager. The Free tier covers up to 20 employees, so you can pilot one full cycle before buying.
Is ReadSignFlow an audit-management or GRC platform?
No — it is the acknowledgement-and-attestation evidence layer. It does not plan audits, hold workpapers, or score control tests. It captures who read and signed what, when, on which version, with tamper-evident proof — and its REST API and HMAC-signed webhooks push those attestation events straight into your GRC or audit-management tool.
Is ReadSignFlow compliance audit management software?
It manages the audit-evidence side of compliance: population-complete sign-off records, a tamper-evident audit trail behind every acknowledgement, and a one-click export ready for testing. It is not a general audit-workflow suite — no audit plans, workpapers, or engagement scheduling — so audit teams run it alongside their audit-management tool and pull the acknowledgement evidence in over the REST API.
Product · Pricing · Security · Solutions · Resources · Book a demo