Audit evidence for every policy acknowledgement — the full population, not a sample.

ReadSignFlow is compliance audit software for the acknowledgement layer: it gives internal audit complete, tamper-evident evidence of policy acknowledgement — control-owner attestations, SOX 302 sub-certifications, and finding sign-offs captured with UTC timestamps in an append-only event log. Export the full population and the exception list in one click — signed PDFs plus the event trail — instead of sampling spreadsheets. Automatic reminders at T-7, T-3, and T-24h chase non-attesters in-period, with manager escalation when they still don't sign.

Stop ticking screenshots and sampling spreadsheets. ReadSignFlow is compliance audit software that captures control-owner attestations, sub-certifications, and policy acknowledgements with UTC timestamps in a tamper-evident, append-only log — and exports the complete population, exception list included, in one click.

Testing policy compliance shouldn't start with a PBC request.

Eight audit workflows, one evidence source.

Every attestation and acknowledgement your audit plan touches — captured once, timestamped, and exportable as a complete population with the exceptions already flagged.

What internal audit actually collects through ReadSignFlow.

The attestation letters, sign-offs, and policy acknowledgements that become your test populations — captured with versions and timestamps, exceptions flagged as they happen.

Attestations & certifications

Policies under test

Findings & remediation

Built for the frameworks your workpapers cite.

Complete populations, tamper-evident logs, and per-event timestamps map directly to what ICFR testing, IIA standards, and your external auditors expect of acknowledgement evidence.

Frameworks covered: SOX §302 / §404 (Sarbanes-Oxley), COSO Internal Control — Integrated Framework, PCAOB AS 2201, IIA Global Internal Audit Standards, SEC ICFR requirements, UK Corporate Governance Code, J-SOX (Japan FIEA), FCPA, UK Bribery Act 2010, COBIT 2019, ISO 27001 (Annex A control audits), GDPR accountability (Art. 5(2) & 24), NAIC Model Audit Rule, DORA (EU financial entities).

Frequently asked questions

Can ReadSignFlow capture control-owner attestations as audit evidence?

Yes. A read gate ensures each owner actually opened and scrolled the attestation letter before signing, and every signature records signer identity, the exact document version, and a UTC timestamp — sealed into an append-only, tamper-evident event log. Signatures are aligned to eIDAS (EU/UK) and the US ESIGN Act / UETA, and export as a signed PDF per attester plus the full event trail.

How do I know the attestation population is complete when people join, move, and leave?

Recipients sync from your HRIS (or via API and CSV), and joiner/mover/leaver events keep segments current: a new AP manager who matches the control-owner segment is auto-enrolled into the always-on attestation campaign, and leavers drop out. The export shows the population as at the deadline, so you can reconcile it against headcount before you test.

What's included in a policy acknowledgement audit pack?

One click produces the signed PDF for every attester plus the append-only event log — sent, delivered, opened, read-completed, and signed events, each UTC-timestamped per recipient and channel — alongside per-recipient deadlines and a ready-made exception list of everyone still outstanding. It is the whole population, not a sample, in one export.

How much effort is it to run a quarterly attestation cycle?

Minutes, not a project. Upload the attestation letter (folders keep each quarter's version), pick the control-owner segment, set per-recipient deadlines, and launch. Reminders fire automatically at T-7, T-3, and T-24h, and non-response escalates to the owner's manager. The Free tier covers up to 20 employees, so you can pilot one full cycle before buying.

Is ReadSignFlow an audit-management or GRC platform?

No — it is the acknowledgement-and-attestation evidence layer. It does not plan audits, hold workpapers, or score control tests. It captures who read and signed what, when, on which version, with tamper-evident proof — and its REST API and HMAC-signed webhooks push those attestation events straight into your GRC or audit-management tool.

Is ReadSignFlow compliance audit management software?

It manages the audit-evidence side of compliance: population-complete sign-off records, a tamper-evident audit trail behind every acknowledgement, and a one-click export ready for testing. It is not a general audit-workflow suite — no audit plans, workpapers, or engagement scheduling — so audit teams run it alongside their audit-management tool and pull the acknowledgement evidence in over the REST API.

Product · Pricing · Security · Solutions · Resources · Book a demo

ReadSignFlow on LinkedIn, YouTube, Instagram, and Facebook.