Compliance Intelligence
Compliance Intelligence is a regulatory change and obligation management platform built for United States banking compliance teams. It monitors global regulatory bodies for proposed changes, guidance, speeches and enforcement actions, and returns each update as a summary with red-lined changes against the source text, tagged for relevance so a team can see the likely impact immediately and trigger the reviews the change requires. Underneath sits a library of laws, rules and regulations spanning the state and federal regulatory perimeter, continuously updated and tagged against a taxonomy built for financial services. The obligation side is where the product does its most distinctive work: rather than leaving an institution to manage hundreds of overlapping requirements, its clustering identifies commonality across legal requirements and proposes a single rationalised obligation to manage against, dynamically linked back to the source regulations and carrying a full audit trail so the derivation can be traced. Applicability analysis draws on Wolters Kluwer's own subject matter experts alongside the models, and the company is explicit that the product combines structured regulatory data, human oversight and AI-powered workflows rather than relying on automation alone. A compliance risk management module using predictive analytics over proprietary enforcement data is announced as coming soon rather than shipped. The named users are compliance managers, chief compliance officers, legal and compliance decision makers and risk officers. Compliance Intelligence launched in the fourth quarter of 2025 and is sold by Wolters Kluwer Financial & Corporate Compliance, sitting within the OneSumX portfolio for regulatory change management. Wolters Kluwer N.V. is listed on Euronext and headquartered in the Netherlands.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
A real AI layer performing the product's distinguishing work, on a content and workflow platform that predates it. What the models actually do is named rather than gestured at: AI-powered monitoring scans regulatory bodies for updates, a proprietary AI tool curates the change summaries and tags each event to produce an impact assessment, and obligation clustering identifies commonality across legal requirements and generates a suggested rationalised obligation. That clustering is the capability the product is sold on and it is machine-produced. What sits underneath is not AI: a library of laws, rules and regulations across the state and federal perimeter, continuously updated and tagged against a financial services taxonomy, plus the workflow engine, which is substantially what the OneSumX regulatory change management line already was. The vendor's own framing places the AI as one of three ingredients rather than the mechanism, stating that unlike solutions relying solely on automation it brings together structured regulatory data, human oversight, and AI-powered workflows. Recorded and not credited: the compliance risk management module using predictive analytics over proprietary enforcement data is marked **coming soon**, so it is intent rather than a shipped capability.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real, architectural and documented, and no accuracy figure exists anywhere. The grounding is the strongest element of the record: changes are delivered as summaries with **red-lined changes against the source text**, so a reviewer can see what actually moved rather than trusting a paraphrase; obligations generated by clustering are **dynamically linked to source regulations**; the underlying library is described as comprehensive across the state and federal regulatory perimeter and continuously updated; and clustering output carries a **full audit trail for traceability**. Human subject matter experts are named as part of the applicability process. What is absent is measurement: no accuracy figure, no test set, no evaluation, no error rate and no hallucination disclosure under any name. A contradiction inside the vendor's own material is recorded because it is the evidence for this grade rather than an argument against it. Marketing asserts unparalleled accuracy and reliability and, in a launch post, guaranteeing accuracy, while the product FAQ describes the same functions far more carefully as AI-supported analysis that helps analyze obligations and **surface potentially relevant requirements, assisting teams with research and early impact assessment**. What the conflict reveals is that no measured figure stands behind the stronger claim, which is precisely the limb the top band asks for.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Human oversight is published as a design commitment and the product's own language is consistently assistive. The vendor states directly that it combines structured regulatory data, human oversight and AI-powered workflows rather than relying solely on automation, and the mechanics bear that out: obligation clustering **generates a suggested obligation for you to manage to** rather than creating one, automated workflows ensure that necessary reviews are triggered rather than dispensing with them, and applicability determination is described as combining subject matter experts with the technology. The FAQ is more careful still, describing AI as assisting teams with research and early impact assessment and surfacing potentially relevant requirements. So the review point exists and the professional decides. What is missing is the structure around it: no threshold is published at which anything acts unattended, nothing states which workflow steps proceed without approval, no confidence signal is described against a suggested obligation or an impact tag, and nothing addresses what happens when a relevance tag is wrong and a change is not escalated.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
No production evidence for this product was located. There is no named customer, no logo, no testimonial, no case study and no figure attached to any deployment of Compliance Intelligence on any surface read. Two impressive numbers appear on the product page and neither belongs to the product. Wolters Kluwer states it serves **over 10,000 banks and credit unions globally**, which is the parent's book of business across its whole compliance portfolio, and the page carries a **Chartis RiskTech AI 50 2025 top five global ranking for excellence in artificial intelligence**, which is a corporate ranking of Wolters Kluwer rather than an assessment of this product. Credit follows scope, and neither artifact names Compliance Intelligence, so both are recorded as description material and credited to nothing here. Some allowance is owed to timing rather than to disclosure: the product launched in the fourth quarter of 2025 and was under a year old at this check, so a thin deployment record is expected. That explains the absence without changing what is published.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Nothing addressing customer data in this product was located. There is no product-level security page, no data processing addendum, no trust portal and no customer agreement anywhere in the site inventory for Compliance Intelligence. The only governing document published is the global Wolters Kluwer Privacy & Cookie Notice, which is current at June 2026 but is scoped to the personal information of individuals who interact with Wolters Kluwer as visitors, contacts and account holders, and which states expressly that additional or different privacy notices may be provided for a specific Service. Nothing published therefore addresses whether an institution's obligations, control mappings, risk posture or examination material is used to train or improve models, how long it is retained, whether it is segregated from other customers' data, or which model providers see it. The gap has weight here because the data a bank puts into this platform is its own compliance exposure, which is sensitive in a specific way: it is the material a regulator would ask for. Searched the product page, the AI principles page, the global privacy notice and the site footer on 4 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
No position on advice versus tooling was located, on a product that determines regulatory applicability. Nothing published states that the product's output is not legal advice, nothing addresses the boundary between a machine-suggested obligation and a compliance officer's or counsel's own determination, and nothing describes what a professional must verify before relying on an applicability assessment. The absence is pointed rather than formal, for two reasons drawn from the vendor's own material. The product's central function is telling an institution which legal requirements apply to it and rationalising them into obligations, which is an applicability judgement with regulatory consequences. And the named users include **legal and compliance decision makers** alongside chief compliance officers, so a professional is expressly in the loop. No rule of professional conduct, regulator expectation or supervisory guidance on the use of automated tools in a compliance programme is cited anywhere. Searched the product page, the AI principles page, the global privacy notice and the site footer on 4 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A published governance position exists at corporate level, with no mechanism, owner or testing behind it. Wolters Kluwer publishes AI Principles setting out five commitments: privacy and security in design and deployment, transparency and explainability sufficient for users to understand and use the system appropriately, governance and accountability through development standards addressing risk management and issue remediation both during design and after deployment, **fairness and non-discrimination**, and a human-focused approach. Two things make this creditable to the product rather than parent material that does not travel. The principles state on their face that they guide the design, development and deployment of advanced technologies across Wolters Kluwer's products and services, and the page sits in the same navigation and footer as the product page on the same domain, so a buyer can establish the connection. What the principles are worth is limited by what they are: five single-sentence aspirations. No named owner is accountable for this product's model behaviour, no evaluation or testing regime is described, no results are published, no governance certification such as ISO 42001 is held, and nothing product-specific addresses how a clustering model that rationalises legal obligations is validated. A self-published principles page carries less weight than an audited framework.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
A generic corporate notice covers the product nominally and addresses none of what happens to customer content. The global Privacy & Cookie Notice is current at June 2026, version 1.5, and does carry real machinery: a controller framework across Wolters Kluwer N.V. and its subsidiaries, transfer safeguards naming EU Model Clauses and binding corporate rules, access limited to a need-to-know basis, an internal framework of policies and reasonable security standards, a full set of data subject rights with a working request route, and a stated position on retention. But every one of those provisions is about the personal information of people who interact with Wolters Kluwer, not about the regulatory and compliance data an institution puts into this platform. Retention is stated without any period, resting on data retention policies that are not published. Third parties are given only as categories, with affiliates, service providers, business partners and advertisers named as classes and **no individual processor identified anywhere**. No incident or breach notification commitment was located, no encryption standard is stated, and no product-level security documentation exists.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
No agreement governing the product is published. The site inventory carries two legal links in the global footer, a corporate Terms of Use and the Privacy & Cookie Notice, and no product-level agreement, master services agreement, subscription terms, service level document or acceptable use policy appears anywhere on the Compliance Intelligence page, in the OneSumX section, or in the footer. Every route on the product page resolves to connecting with an expert, booking a demonstration or requesting a return-on-investment analysis, so the contract is negotiated rather than published, which is the ordinary enterprise pattern and is nonetheless an absence for a disclosure index. No indemnity, liability cap, warranty on output, uptime commitment or insurance position could be located. That matters in a specific way here: the product tells a bank which obligations apply to it, and a missed or mis-clustered obligation is a supervisory finding, so allocation of loss is the question a buyer most needs answered before signing and nothing published answers it. The corporate Terms of Use was not opened in this pass and is named as a limit; it is a website terms page by position and title.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
No integration into practice or enterprise systems was located. The product page names no integration of any kind: no GRC platform, no core banking system, no document management system, no policy or control repository, no identity provider, and no API, developer documentation or connector catalogue. Nothing describes how obligations, controls or regulatory changes move between Compliance Intelligence and the systems a bank already runs, which is a live question because the wider OneSumX family includes separate products for policies and procedures, compliance risk and controls, compliance testing, complaint management and exam and inquiry management, and nothing published states how this product connects even to those. The one interoperability fact located is directional rather than technical: obligations are described as dynamically linked to source regulations inside the platform. Searched the product page, the OneSumX for Compliance Program Management navigation and the site footer on 4 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Neither the tenancy model nor any region is stated, and cloud delivery is not even made explicit. Nothing published describes how the product is delivered, whether it is single or multi-tenant, where customer data is stored or processed, which cloud or data centre is used, or whether any regional or on-premise option exists. The only geographic statements located concern the subject matter rather than the infrastructure: the regulatory library covers the United States state and federal perimeter, and monitoring scans global regulatory bodies. Those describe what the product reads, not where it runs. The corporate privacy notice addresses international transfers of personal information under EU Model Clauses and binding corporate rules, which establishes that Wolters Kluwer moves data across borders without saying anything about where this platform's customer data sits. For a product sold to United States banks under prudential supervision, where data resides is a question examiners ask directly, and nothing published answers it.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
No independent security attestation was located and none is claimed. There is no trust centre, no security page for this product, no SOC 2, ISO 27001 or other framework named anywhere, no auditor identified, no report offered at any access tier including on request, and no penetration testing or vulnerability disclosure programme mentioned. The only security statement located is in the global privacy notice and is expressed at the level of intent rather than assurance: an internal framework of policies and **reasonable security standards** across the businesses, access limited to a need-to-know basis, and appropriate technical and organisational measures, followed by an express statement that Wolters Kluwer cannot guarantee information will be absolutely safe from intrusion. Because nothing is claimed there is also nothing unsupported on display, so this rests on absence rather than on overclaiming. The gap is conspicuous for a product sold to regulated financial institutions, whose own examiners will require third-party assurance over material service providers.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Nothing about the model supply chain is published. No model is named, no version or family is given, no model provider is identified, no cloud or inference location is stated, and no commitment to notify customers when any of it changes was located. What the material offers instead are brand terms and adjectives: **Expert AI** as the portfolio name, a **proprietary AI tool** said to curate regulatory change summaries, cutting-edge AI, and advanced AI technology. Proprietary is the closest thing to a disclosure and it identifies ownership rather than architecture, saying nothing about whether third-party foundation models sit underneath. No subprocessor list exists at any level: the corporate privacy notice names only categories of recipient. A buyer in a supervised institution cannot establish from published material which models process its regulatory and obligation data, or whose they are. Searched the product page, the AI principles page, the corporate AI page, the global privacy notice and the site footer on 4 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. No pricing page exists for the product or anywhere in the OneSumX for Compliance Program Management section, no figure, band or range appears, and nothing states whether charging runs per seat, per institution, per module, by asset size or by regulatory coverage. Every route on the page resolves to a sales conversation, and the calls to action are explicit about it: connect with our experts, schedule a personalized demo, or **connect with our team for a detailed ROI analysis**. The last is worth naming precisely because it inverts the disclosure: the vendor offers to model the buyer's return before telling the buyer the cost. Under the standing rule that pricing evidence must lift this axis off the floor before a pricing row is owed, no VendorPricing row is written. Checked the product page, the OneSumX navigation, the solutions directory entry and the global footer on 4 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The segment is defined narrowly and precisely, which is unusual and useful. The product is stated to be designed specifically for financial institutions and, in the launch material, purpose-built for United States banking compliance teams. Coverage of subject matter is equally specific: a library spanning the state and federal regulatory perimeter, tagged against a taxonomy built for financial services, with monitoring extending to global regulatory bodies for changes, guidance, speeches and enforcement actions. The users are named individually in the product FAQ rather than left to inference, covering compliance managers, chief compliance officers, legal and compliance decision makers, and risk officers. Placement within the wider OneSumX compliance programme family is documented, so a buyer can see what this product does and what its siblings cover. What is absent is the boundary from the other direction: nothing states institution size or type limits, nothing addresses whether credit unions, insurers or non-bank lenders are served, no non-United States regulatory coverage is claimed for obligations, and nothing says where the product stops.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way.
No located term or policy addresses training either way. No product-level agreement, data processing addendum or security page exists for Compliance Intelligence, and the only governing document published is the global Wolters Kluwer Privacy & Cookie Notice, which is scoped to the personal information of individuals interacting with Wolters Kluwer rather than to the regulatory and obligation data an institution puts into the platform. That notice lists developing and improving new and existing products and Services as a legitimate interest, but applies it to relationship data and does not name machine learning, model training or customer content, so it does not answer the question in either direction. The notice itself states that additional or different privacy notices may be provided for a specific Service; none was located for this one. Searched the product page, the AI principles page, the global privacy notice and the site footer on 4 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
No located public material states how long customer content, queries or generated output are retained. The global privacy notice does address retention, but only for personal information and only in open terms: data is kept for the time necessary to achieve the purposes for which it was collected, in accordance with data retention policies that are not published, with anonymisation offered as an alternative to deletion. No period is given for anything. Nothing anywhere addresses the material this product actually holds, being an institution's obligation inventory, applicability determinations, control mappings and the regulatory change record built from them, and no deletion route, export commitment or end-of-subscription position was located. The one adjacent product statement runs the other way and is recorded because it implies durability rather than deletion: obligation clustering carries a full audit trail for traceability.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
No located public material addresses separation of customer data. Nothing states whether the platform is single or multi-tenant, no role or permission model is described, no administrator function is mentioned, and nothing addresses how one institution's obligation inventory and compliance posture is kept from another's. The question carries specific weight for this product because the obligation clustering feature works by identifying commonality across legal requirements, so a buyer would reasonably want to know whether that analysis is performed within its own tenant or across a pooled corpus, and nothing published says. The only access statement located is in the global privacy notice and concerns Wolters Kluwer's own staff rather than customer separation, limiting access to personal information to a need-to-know basis. Searched the product page, the AI principles page, the global privacy notice and the site footer on 4 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
The global privacy notice addresses compelled disclosure and commits to no notice. It lists governmental authorities, regulators and other third parties among the categories with which personal information may be shared, in response to a legal request, court orders, or as otherwise necessary to comply with applicable law. No commitment to inform the customer before or after such a disclosure appears, and no discretion over notice is reserved either. Two limits on the clause are recorded rather than glossed. It governs personal information under a notice scoped to individuals interacting with Wolters Kluwer, so it does not clearly reach an institution's obligation and compliance data held in the platform, and nothing else published addresses compelled disclosure of that material. No transparency report was located. The gap has a particular edge for a product sold to supervised banks, whose regulators may themselves be the requesting party.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Coverage is described by jurisdiction with no identification of the underlying corpus.
The corpus is described by regulatory perimeter and never identified as a collection. What is published is specific about scope: a comprehensive library of laws, rules and regulations across the state and federal regulatory perimeter, continuously updated and tagged against a taxonomy built for financial services, with monitoring extending to global regulatory bodies for proposed changes, guidance, speeches and enforcement actions, plus a body of proprietary enforcement data reserved for a module not yet shipped. That tells a buyer which jurisdictions and instrument types are in scope, which is the jurisdictional description this value records. It does not identify the collection: no individual regulator feed, data supplier or publication source is named, no update cadence is stated beyond continuously, nothing describes how completeness of the perimeter is assured, and no licensing basis is given for any content. Wolters Kluwer is itself a regulatory publisher, so the corpus is likely its own, but that is inference and the material does not say it.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
The vendor computes and surfaces subsequent history itself, with the method described.
The vendor maintains its own currency signal over the regulatory corpus, and that is the product's central function rather than an add-on. Regulatory updates are monitored continuously and delivered as summaries with red-lined changes against the source text, tagged for relevance, with automated workflows triggering the reviews a change requires. Obligations generated from those requirements are dynamically linked to the source regulations, so when an underlying rule moves the affected obligation is identifiable. That is the regulatory analogue of a treatment signal: a user is told when the authority an obligation rests on has changed, which is the question this signal asks. Two limits keep it below the top value. The signal is Wolters Kluwer's own rather than a licensed independent citator, and nothing published states how quickly a change is reflected, how completeness across the perimeter is assured, or whether any indicator appears on an obligation whose source has been superseded but not yet reviewed.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
No located public material describes what the system does when it cannot determine an answer reliably. The published language is consistently assistive, describing AI that helps analyze regulatory obligations and surfaces potentially relevant requirements, assisting teams with research and early impact assessment, and clustering that generates a suggested obligation for a human to manage to. Those establish that a person decides, not that the system signals when it is unsure. Nothing describes an abstention path, a no-answer state, or a confidence or coverage indicator attached to a relevance tag, an applicability determination or a suggested obligation, which is where it would matter most: a change tagged as not relevant is a change nobody reviews, and nothing published says whether the system marks such a call as uncertain. Searched the product page, the AI principles page and the corporate AI page on 4 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on both the product name Compliance Intelligence and the corporate name Wolters Kluwer. No court order, opinion or disciplinary record naming the product was located. The database tracks fabricated legal citations in court filings, and this product supports regulatory change and obligation management inside a compliance programme rather than producing court submissions, so its exposure to that specific failure mode is structurally low. This records the state of the public record on that date and is not a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No located public material engages professional guidance or a named authority on the use of the tool. Regulatory bodies are referenced generically as the objects of monitoring, described as global regulatory bodies and the state and federal regulatory perimeter, but a regulator whose rules are being tracked is the subject matter of the work rather than a source of guidance on how software should be used within a compliance programme. No supervisory expectation, examination manual, interagency guidance on model risk management or third-party risk, professional body publication or bar guidance is cited anywhere. The absence is notable in this market specifically, because model risk management guidance for United States banking institutions is well established and directly relevant to a bank deploying a machine-generated obligation inventory. Searched the product page, the AI principles page, the corporate AI page and the global privacy notice on 4 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Cost and effort savings are claimed and no billing or fee question is engaged. The published claims are framed around institutional cost rather than any measured figure: the solution is said to reduce the time compliance teams spend assessing applicability and identifying obligations, to allow compliance executives to focus on strategic priorities by reducing manual burdens, and to help institutions stay compliant while managing risks and reducing costs, with a detailed return-on-investment analysis offered through a sales conversation. Nothing addresses what happens to a fee, a budget or an internal chargeback when that work compresses, and no per-matter or per-obligation record of AI-assisted work is described as available for that purpose. The signal lands obliquely because the buyer is an in-house compliance function rather than a firm billing a client, so there is no external invoice on which the compression would appear.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
None of the material a client or examiner would ask for is published at any access tier. No subprocessor list exists: the global privacy notice names only categories of recipient, being Wolters Kluwer affiliates, service providers, business partners and advertisers, without identifying a single third party. No model provider is named anywhere, so nothing states who or what processes an institution's regulatory and obligation data. There is no published data processing agreement, no trust portal, no security documentation and no consent or notification pack, and no request route for any of it is offered. Nothing is gated behind a form or an agreement either, because nothing is offered to gate. The shortfall is sharper than the ordinary case because the buyer is a supervised financial institution whose own third-party risk management obligations require it to evidence exactly this about a material service provider. Searched the product page, the AI principles page, the global privacy notice and the site footer on 4 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
A real derivation record is published and it is attached to the AI step, which is better than most records in this band manage. Obligation clustering identifies commonality across legal requirements and generates a suggested obligation, and the vendor states that this comes with a full audit trail for traceability, so an institution can show how a rationalised obligation was derived from the underlying requirements. Obligations remain dynamically linked to their source regulations, regulatory changes arrive red-lined against source text, and the wider suite includes exam and inquiry management for producing material to a regulator. What is absent is the model dimension. Nothing states that the audit trail records which model or version produced a suggestion, no capture of what a human reviewed, amended or rejected before accepting a clustered obligation is described, and no guidance exists on disclosing AI involvement to an examiner, which is the disclosure that would actually be demanded here.