Corlytics
Corlytics is a regulatory risk intelligence platform for regulated firms, built around the sequence it calls Find, Understand, Implement and Evidence. Regulatory Monitoring collects regulatory notices, guidance and enforcement actions from regulatory bodies worldwide in real time and enriches them, using AI to classify documents against a taxonomy, summarise long and complex texts, and identify similarities across datasets for duplication detection and gap analysis. The Regulation Library holds that content as a digital set of obligations, supporting regulatory obligations management, regulatory change management with redline comparison of current against previous versions of a rule, and compliance monitoring. Regulatory Risk Analytics applies the company's regulatory risk models to give risk-based views of regulatory exposure for risk, audit and compliance teams, drawing on its own analysis of enforcement activity. Taxonomy Manager is sold in separate editions for firms and for regulators, and Corlytics counts regulators themselves among its client sectors. Policy management arrived with the acquisition of ClauseMatch and is sold as Corlytics Clausematch Policy Management, covering policy and procedure creation, approval, publishing and distribution against the underlying rules, with regulatory controls mapping tying obligations through to internal policies and controls. Impact assessment workflow, collaboration tools and audit trails for attesting to compliance sit across the platform, and APIs allow the obligations data to feed other risk and GRC systems. Corlytics Limited is registered in Ireland and is a wholly owned subsidiary of Green Horizon BidCo Limited, with group companies in England, Portugal and the United States; it holds ISO/IEC 27001, a SOC 2 Type 1 attestation, and ISO/IEC 42001:2023 certification of a business-wide AI management system. It serves banks, insurers, investment and hedge fund managers, payments firms and regulators, with a second vertical in health and life sciences.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of the enrichment that differentiates the product, layered on a data and workflow business that would survive without them. The Regulatory Monitoring page names three AI capabilities and describes what each does: classification, categorising regulatory documents against a comprehensive taxonomy to surface themes and risks; summarisation of large complex documents including regulations, alerts and policies; and rationalisation and mapping, identifying similarities across datasets to detect duplication and support gap analysis. The company describes an AI-driven approach combining machine learning and data science. What sits underneath and would remain is substantial: a regulatory content library sourced from regulatory bodies worldwide, obligations management, redline version comparison, policy management inherited from ClauseMatch, controls mapping, impact assessment workflow, audit trails and GRC APIs. There is also a human layer that pushes against a higher grade, with the same page describing comprehensive validation by subject matter experts as part of the methodology. That makes this the enrichment engine on a content-and-workflow platform rather than a product that is nothing without its models.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real and the method is described at least in outline, with no measured figure anywhere. Output grounds to primary material a reader can open, because what the platform delivers is the regulatory notice or rule itself, enriched rather than paraphrased, and the home page describes red and green lining of regulations so a user sees the actual changed text between the in-force version and its predecessor rather than a summary of it. The method is stated rather than gestured at: classification against a comprehensive taxonomy, summarisation, and rationalisation and mapping across datasets, described as combining machine learning and data science with, unusually for this corpus, comprehensive validation by subject matter experts as a stated part of the methodology. That human validation step is a real process claim and is the reason this sits above the band below. What is absent is any measurement: no accuracy rate, precision or recall figure, benchmark, test set or named failure mode was located for classification, summarisation or obligation extraction on any surface read on 1 September 2026, and accuracy is instead asserted through the words accurate and reliable.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Human involvement is asserted in two places and never connected to the AI output as a control. The Regulatory Monitoring page states that the methodology includes comprehensive validation by subject matter experts and describes the solutions as human focused, and the platform ships an impact assessment workflow that gathers assessments in a single location. Neither is described as an oversight mechanism over model output: the expert validation appears to be Corlytics' own production quality step on its content rather than a customer review point, and the impact assessment workflow is a place where a compliance officer records a decision rather than a described checkpoint the system routes to. Nothing located states what runs unattended, what threshold causes the system to defer or stop, where a reviewer sits relative to a classification or a generated summary, or what happens after an assessment is wrong. Two things would move this: a statement of which outputs are expert-validated before a customer sees them, and any description of behaviour at low confidence. Searched the home page, the Regulatory Monitoring page, the security page and the privacy notice on 1 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
No customer is named and no figure is attached on any surface read. Unusually for a vendor of this size there is no customer logo strip anywhere on the home page; what appears in its place is analyst and ranking material, including a Chartis Regulatory Intelligence Solutions 2025 vendor spotlight offered as a downloadable PDF, and award or index marks for RegTech100, AIFintech100, ESGtech100 and FinCrimeTech50, which are recognitions rather than deployment evidence. Two case study libraries exist and are linked repeatedly, one for financial services and a separate one for health and life sciences, described as showing strategies employed, technologies used and tangible results achieved. **Neither library was opened on 1 September 2026**, so a named, dated customer outcome was neither located nor excluded and this grade is rebuttable upward on one fetch. What can be said from the surfaces read is that the vendor's own claims about client results are made in general terms without attribution.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is asserted in general terms and none of the questions this axis asks is answered. No position on training was located: nothing states whether customer content, including the policies and obligations registers a firm holds in the platform, is used to train or improve models, which is a conspicuous silence for a company that holds ISO 42001 for a business-wide AI management system. No retention or deletion commitment for customer content exists, no segregation between customers, users or matters is described, and no data processing agreement is published. What is published is generic and sits in a privacy notice about personal data rather than platform content: appropriate access controls and user authentication, contractual confidentiality measures with staff, staff policies and training, and encryption. The security page adds contractual confidentiality for staff and a principle labelled Integration without elaboration. The scope problem compounds it: the privacy notice states in its opening that it covers individuals other than staff, customers and users of the application, so on its own terms it does not reach the customer relationship at all.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
A boilerplate disclaimer sits in the website legal notice while the marketing describes the product in interpretive terms. The legal notice provides that information is supplied as is without warranties of any kind, express or implied, including accuracy, timeliness and completeness, and that Corlytics is not liable for damages arising from the Site or any content accessed by use of it. That is a warranty disclaimer rather than a position on the line between an information tool and legal or compliance advice, and it is scoped to the website. Against it, the product is positioned around helping firms Understand and Implement regulation, with regulatory risk models, impact assessment and obligation extraction, and a partner site describes Corlytics as helping clients Find, Interpret and Analyse regulations. Nothing located states that the output is not legal advice, names a jurisdiction limit, or addresses the professional responsibility of the compliance or legal officer relying on it, which the category editorial identifies as where the exposure sits. Note that the legal notice was recovered only in part, through the R8 ladder after the page refused direct fetch, so a fuller advice-line statement may exist on it.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
This is the strongest governance evidence located in the corpus and it stops one limb short of the top band. Corlytics holds **ISO/IEC 42001:2023 certification for a business-wide AI management system**, announced in its own press release of May 2025 and, on the evidence of that release, the first dedicated RegTech to hold it. The detail is what makes it gradeable rather than decorative: the certification body is named as **A-LIGN** following independent audit, it was achieved in collaboration with Waystone Compliance Solutions as governance advisory, and the scope is stated as enterprise-wide, with every product, acquisition and process sitting inside the AI Management System framework. The standard is described as mandating bias mitigation, risk and resilience controls across the AI lifecycle, and as mapping to the EU AI Act and the UK National AI Strategy. **A named accountable executive exists**: Oisin Boydell, Chief Data Officer, speaks for the AI programme. The Regulatory Monitoring page carries the claim through into product copy, citing compliance with ISO 27001, ISO 42001 and the EU AI Act. What is missing is the third limb: no testing regime is described in the vendor's own terms and no result has been disclosed about uneven output across document types, jurisdictions or populations, so bias mitigation is certified as governed rather than evidenced as measured.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
A privacy notice covers personal data without addressing what happens to customer content after processing, which is this band exactly. What is published is real as far as it goes: retention tied to the life of the contract with deletion or anonymisation afterwards, a customer-facing breach commitment to notify without undue delay and report to the supervisory authority within the legally required period, security measures listed as access controls and user authentication, staff policies and training, incident and breach reporting processes, IP anonymisation, internal IT and network security, business continuity and disaster recovery, regular testing and review, and encryption, with a named Data Protection Officer in Luca Dalla Giacoma. Three gaps hold it here. No subprocessor list is published, only categories such as technical service providers. A Data Retention Policy and a Data Breach Management Policy are both referenced and neither is published. And the scope excludes the product: the notice states at its opening that it covers individuals other than staff, customers and users of the application, so nothing published addresses retention, deletion or handling of the regulatory content, obligations registers and policy documents a customer places in the platform. Note the internal inconsistency that the notice's own reader table nonetheless includes a Software User category.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing published addresses who bears the loss when the platform is wrong. No master services agreement, subscription terms, service agreement or data processing agreement exists anywhere on the property, and the customer application sits behind a sign-in at a separate subdomain with no terms exposed. The only contractual document published is a website legal notice, and it is scoped by its own language to the Site: it disclaims warranties of any kind including accuracy, timeliness and completeness for information on the Site, and excludes liability for direct, indirect, incidental, special, exemplary, punitive and consequential damages arising out of or in connection with the Site or any content on or accessed by use of the Site. That governs www.corlytics.com rather than the platform a customer licenses, which is the same shape as Anaqua in this corpus. No indemnity, no cap, no carve-out, no warranty on output and no insurance position covering the software was located. Searched the footer legal set, the security page, the privacy notice and the Regulatory Monitoring page on 1 September 2026; the legal notice itself refused direct fetch and was recovered in part through the R8 ladder.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integration is stated as a capability and not a single connection is named. The Regulatory Monitoring page lists APIs to enable integration with other risk or GRC systems in the firm, and describes the solution as eliminating manual data collection by integrating into existing systems; the regulatory controls mapping solution ties obligations through to internal policies and controls, which implies a destination system. What is absent is everything that would let a buyer or an implementer act on it: no named GRC, risk or document platform appears anywhere on the surfaces read, no API reference or developer documentation was located, no integration directory exists in the site navigation, and nothing describes what actually moves in which direction. That is a weaker position than the comparable vendor in this lane, which names five GRC partners on its home page. The Security and Resilience page lists Integration as one of eight bare principle labels with no elaboration. Checked the home page, the Regulatory Monitoring page, the security page and the full navigation on 1 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is implied and neither the tenancy model nor a region is stated. The Security and Resilience page lists Geo-specific hosting as one of eight guiding principles under the Information Security Manager section, which is a two-word residency claim with nothing behind it: no region, no data centre location, no hosting provider and no customer choice is described anywhere. The ISO 27001 scope statement confirms only that services are delivered from cloud solutions. Nothing states whether customers share infrastructure or receive a dedicated environment. The only geography published sits in the privacy notice and concerns personal data rather than platform content, committing that transfers outside the UK or EEA rely on an adequacy decision, European Commission approved contracts or other recognised safeguards, and directing the reader to contact the company for the specific mechanism used. Corporate presence is documented across Ireland, England, Portugal and the United States, which indicates where the group operates rather than where customer data sits. Checked the home page, the security page, the privacy notice and the Regulatory Monitoring page on 1 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The certification set is the broadest in the corpus and none of it is obtainable. Three attestations are claimed and two carry a named assessor: ISO/IEC 27001, published with an actual written scope statement covering all activities of Corlytics Limited in the delivery of data and software for legislation, regulation and document management services globally from its cloud solutions; SOC 2 Type 1, correctly identified as Type 1 assessing system design at a point in time rather than operating effectiveness, with the five Trust Services Criteria listed and **the report attributed to independent CPA Thoropass**; and ISO/IEC 42001:2023, whose certification body is named as **A-LIGN** in the company's own press release. An Information Security Manager role is described as owning the security programme. What keeps this out of the top band is access and currency: no certificate date, examination period or expiry appears for any of the three, no trust portal or document request route exists, and the security page closes by inviting the reader to contact the company for further information on its procedures, which is the sales-gated tier under 6.5. Note also that the home page presents these certifications in a strip alongside RegTech100, AIFintech100 and similar index marks, which are rankings rather than attestations.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor refers to its own machine learning and proprietary models without identifying anything underneath them. The Regulatory Monitoring page describes an AI-driven approach combining deep expertise in machine learning and data science with innovative methodologies, and the home page refers to unique regulatory risk models, but no model, model family, provider or architecture is named anywhere on the surfaces read. Nothing states whether any third-party foundation model is called at any point in classification, summarisation or mapping, which is the question a bank's own third-party risk process will ask of a supplier processing its obligations and policy estate. Where inference runs is not stated, and no commitment to notify customers when the model set changes was located. This is a notable gap set against the ISO 42001 certification, since a business-wide AI management system implies a maintained inventory of AI components that is simply not published. Checked the home page, the Regulatory Monitoring page, the security page and the privacy notice on 1 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. The site navigation was read in full on 1 September 2026 across solutions, client sectors, company, partners and news sections and contains no pricing entry. Every commercial route on every page read is a contact form or an Arrange a demo anchor. No rate, band, floor, currency, tier or package name appears, no per-seat, per-obligation or per-jurisdiction unit is identified, and nothing states what implementation or onboarding adds, which is material for a platform whose value depends on building a firm-specific obligations register. Nor is there an individual service agreement or order form published from which any of the commercial structure could be inferred, since no customer agreement of any kind is on the property.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is documented with unusual breadth and the boundary is left open. Eight client sectors get their own pages: global banks, private banks, hedge fund managers, investment managers, global insurers, payments and big tech, health and life sciences, and regulators themselves, which is a segment almost no vendor in this corpus addresses and which is backed by a distinct product edition in Taxonomy Manager for Regulators alongside Taxonomy Manager for Firms. Health and life sciences is a genuine second vertical rather than a mention, with its own solutions route and its own case study library. Practice coverage is named across regulatory monitoring and horizon scanning, obligations management, regulatory change management, compliance monitoring, controls mapping, policy and procedure management, regulatory risk analytics and non-financial risk management. What is not stated is where the product stops: no firm size, obligation volume, jurisdictional limit or statement of what the platform does not cover was located, and the buyer picture has a specific gap in that no page addresses legal or counsel as a function despite the platform being sold into regulatory change work that legal owns.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way.
No located term or policy addresses the question either way. There is no master services agreement, subscription terms or data processing agreement published anywhere on the property, so the document that would ordinarily carry the commitment does not exist publicly. The privacy notice concerns personal data and states in its opening that it covers individuals other than staff, customers and users of the application, so it does not reach the customer relationship. The Security and Resilience page addresses infrastructure and process without touching model training. This silence is conspicuous rather than ordinary here, because Corlytics holds ISO/IEC 42001 certification for a business-wide AI management system covering every product and process, and a customer cannot learn from any published source whether the policies and obligation registers it holds in the platform sit inside the training scope of that system. Searched the home page, the Regulatory Monitoring page, the Security and Resilience page, the privacy notice and the legal notice on 1 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
No located public material states how long customer inputs, queries or generated outputs are retained, or whether any of it can be configured or set to zero. The only retention statement published concerns personal data and is qualitative rather than periodic: Corlytics retains personal data for as long as the customer has an active contract, or as required for legal obligations and legitimate business needs, after which it is deleted or anonymised, with longer retention where a complaint or prospective litigation exists. A Data Retention Policy is referenced as holding the detail and is not published. Nothing at all addresses the regulatory content, obligations registers, policy documents or impact assessments a customer creates in the platform, which is the material that matters here. Searched the privacy notice, the security page, the legal notice and the product pages on 1 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
Nothing located addresses segregation between customers, teams or users. The nearest published statements are generic security measures in the privacy notice covering appropriate access controls and user authentication, which are stated as protections for personal data rather than as a described permission model, and a bare principle label reading Integration on the Security and Resilience page. The product implies a role structure without documenting one: policy management runs a creation, approval, publishing and distribution workflow that necessarily distinguishes authors from approvers, and the platform offers collaboration and sharing tools across departments and relevant regulatory content for business units, so content is evidently scoped to parts of an organisation. None of that is described as an enforced permission model, and nothing states whether AI classification or summarisation respects those boundaries at query time. Searched the privacy notice, the security page, the Regulatory Monitoring page and the policy management entry on 1 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
The situation is addressed and notice is never reached. The privacy notice provides that in the very rare situation where Corlytics is asked to disclose personal data in response to any legal request or court order, it will take legal advice before making any disclosure to ensure that the individual's rights and interests are considered before responding. That is a commitment to deliberate before responding, not a commitment to tell the customer a demand has arrived, and nothing elsewhere supplies one. Two limits belong on the record: the clause is scoped to personal data rather than to the customer content a firm holds in the platform, and no transparency report exists. The same notice separately lists regulatory authorities among the recipients of personal data. Checked the privacy notice, the legal notice and the security page on 1 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Coverage is described by jurisdiction with no identification of the underlying corpus.
The corpus is described by origin type and scale rather than by named source. Content is stated to be collected automatically and in real time from global regulatory bodies, comprising regulatory notices, guidance, enforcement actions and amendments, and the home page quantifies the problem space as 30,000,000 pages of regulatory text every year across multiple languages. No individual regulator, publisher, feed or data supplier is named anywhere on the surfaces read, no licence or rights basis is stated for any of it, and no update cadence is published beyond the claim of real time. The company also produces its own analysis layer over the source material, curating summarised analysis of enforcement notices, so part of what a customer receives is Corlytics editorial rather than primary text. Checked the home page, the Regulatory Monitoring page and the solutions navigation on 1 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
The vendor computes and surfaces subsequent history itself, with the method described.
The regulatory equivalent of a citator is a shipped feature. The home page describes red and green lining of regulations, and the platform tracks updates to live regulation so that a user sees the currently in force version against its predecessor with the changes marked, which is the vendor computing and surfacing subsequent history across its own corpus rather than licensing a treatment service from anyone else. Regulatory change management is built on the same mechanism, identifying what has moved and routing it to impact assessment. The method is described at the level of what the user sees rather than how currency is assured, and two limits belong on the record: no statement was located of how quickly a regulator's publication reaches the library, and the accuracy of the change detection itself is asserted rather than measured.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Nothing located describes what the system does when it cannot classify, summarise or map reliably, which is the question the index editorial makes decisive for this category. No abstention path, confidence score, coverage indicator or low-certainty flag is published for any of the three named AI capabilities. The nearest statement is a production quality claim rather than a runtime behaviour: the Regulatory Monitoring page describes comprehensive validation by subject matter experts as part of the methodology, which says that humans check the work without saying what triggers a check, what the reviewer sees, or what a user is shown when the machine was uncertain. Searched the home page, the Regulatory Monitoring page, the security page and the solutions navigation on 1 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the acquired brand ClauseMatch. No court order, opinion or disciplinary record naming either was located. This is a statement about the public record rather than a finding about the product. The failure mode fits imperfectly, since the output is a regulatory classification, summary or obligation mapping consumed inside a compliance function rather than a citation filed with a court; the analogous exposure would be a misattributed or superseded regulatory reference reaching a supervisor during an examination.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No engagement with professional responsibility or ethics guidance was located. Nothing addresses ABA Formal Opinion 512, guidance from the Law Society or Solicitors Regulation Authority, Law Society of Ireland guidance, or any regulator statement on the use of AI in a compliance function. The company engages extensively with AI regulation rather than professional conduct, naming the EU AI Act, the UK National AI Strategy, ISO 27001 and ISO 42001, and publishing a glossary of AI terms; those bind Corlytics as a developer rather than binding the compliance officer or in-house lawyer relying on the output. Searched the home page, the Regulatory Monitoring page, the security page, the privacy notice, the legal notice and the full site navigation on 1 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Efficiency and cost claims are made and nothing addresses billing or disclosure. The marketing promises elimination of manual data collection, prioritisation of compliance effort, and filtering out of irrelevant content to enhance the control environment, with the platform positioned on the volume problem of 30 million pages of regulatory text a year. The buyer is an in-house compliance or risk function rather than a firm billing a client, so the fee question this signal was written for lands obliquely, but it is not absent: consulting and advisory firms are named among the sectors served on the AscentAI-comparable segment lists, and nothing published addresses how an adviser using the platform should disclose AI-assisted regulatory analysis to the client it bills. No per-matter or per-assessment record of AI-assisted work is described for that purpose.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
Nothing that would support a client-side disclosure obligation is published. No subprocessor list exists: the privacy notice identifies recipients only by category, as staff, technical service providers acting as processors or sub-processors, regulatory authorities, professional advisers and any actual or potential buyer of the business, without naming a single one. No model or model provider is identified anywhere, so a firm cannot state which systems see its content. No data processing agreement, consent pack or client-facing disclosure material is published and no route to request one was located beyond a general contact form. Under the coverage test this fails at both ends, with neither infrastructure nor model providers named. The ISO 42001 certification is a governance credential rather than a disclosure artifact and does not answer what a client's AI clause asks. Searched the privacy notice, the security page, the legal notice and the full navigation on 1 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Part of the record exists and it was built for the supervisor rather than the court. Evidencing compliance is one of the four pillars the company organises its product around, described on the home page as evidencing compliance with a full audit trail and the ability to attest to compliance via dashboards and reporting tools, with impact assessments captured in a single workflow location. That gives a firm a defensible account of what was reviewed, by whom and when, which is the artifact a regulatory examination calls for. What it does not do is identify the machine's contribution: nothing states that the audit trail records which classifications or summaries were AI-generated, what corpus they drew on, or who validated them, so a user could not produce an AI-use disclosure or a verification certification from it. Checked the home page, the Regulatory Monitoring page and the solutions navigation on 1 September 2026.