§ 12.1
Did we know?
Every relevant change surfaces the day it is published, in language a director reads without counsel present. Ignorance stops being the failure mode.
Enterprise compliance software gets bought by whoever answers to the board when a rule change is missed: the CCO, the CISO, the General Counsel, the VP Risk. This page is the honest version of that conversation: what the enterprise plan is designed to guarantee, what it costs to get wrong, and how to talk to us before launch.
§ 12.1
Every relevant change surfaces the day it is published, in language a director reads without counsel present. Ignorance stops being the failure mode.
§ 12.2
The gap check, the drafted update, the approval, the control change: one thread, attributable, dated. The answer exists before the question is asked.
§ 12.3
The audit trail is append-only and exportable: for the auditor, the examiner, the regulator, or the board pack, without a quarter of evidence assembly.
Everything in Scale, plus the controls your security and procurement teams will ask about before anything touches your data. All of it is planned scope, stated now so the security review can start early. If you are mapping this against an existing stack, the GRC software and enterprise risk management software pages cover where the register sits.
Ready to talk? Write to team@complianceofficer.ai or request access with your company name and we reply within two business days.
GDPR authorities can fine up to 4 percent of global annual turnover for the severe tier. BSA/AML failures carry civil money penalties and, for individuals, criminal exposure. SOX section 906 certifications carry personal liability for the officers signing. Against those numbers, the platform's planned top tier is a rounding error, which is the point. The SOX figures are not abstract: under 18 U.S.C. 1350, a knowing false certification carries up to $1,000,000 and 10 years, and a willful one up to $5,000,000 and 20 years. Our SOX compliance guide sets out which sections reach a company at your filer status.
Enterprise buyers rarely have one compliance problem. They have the same problem in seven legal entities, under overlapping frameworks, with one team answering for all of it. The question that decides whether a platform survives that is not how many frameworks it lists. It is whether an obligation can exist once and apply differently per entity, because that is what determines how much duplicated work your team does every quarter.
| Ask this | Weak answer | What you want |
|---|---|---|
| How is an entity represented? | A tag, or a separate workspace per entity | A first-class object, so one control can be shared and one can be local |
| Can one control satisfy several frameworks? | Yes, by duplicating it under each framework | One control, many mappings, tested once and credited everywhere |
| Who can see what? | One global role model | Entity-scoped permissions, so a subsidiary controller sees only their scope |
| Does a rule change fan out? | A notification to an inbox | A change that names every affected entity, control and policy owner |
| How does the price scale? | Per entity, per framework, per user, stacked | One axis you can forecast, with the eighth entity costing less than the first |
The pricing row is where multi-entity deals go wrong. Per-entity pricing sounds fair and behaves badly, because it charges you most in exactly the year you reorganize. If you are building a budget case, the recorded figures across this category sit on our compliance software pricing benchmark and the planned tiers are on pricing.
A compliance platform sits next to your control documentation and your regulatory correspondence, so it gets reviewed harder than most tools of its size. We would rather state our position before launch than be vague about it in a questionnaire.
§ 99 · Final entry
Request access with your company name, or email team@complianceofficer.ai. Security review materials are ready before launch; nothing is charged today.