Working notes on every function of CAQA Compliance — what it holds, how it behaves, and how it hands off to the next step in the cycle.
Obligation registers
The register is the platform’s centre of gravity: a structured list of everything your organisation is required to do, drawn from legislation, standards, funding contracts and your own policies. Each entry records what the obligation is, where it comes from, who owns it, how often it recurs and what state it is in right now.
Registers per domain — regulatory, contractual, WHS, privacy, financial — rolled up into one organisation-wide view.
Each obligation carries its source clause, owner, cadence, evidence links and current status.
Full history on every entry, so you can show what was known and done at any point in time.
A library of the instruments that bind you — acts, regulations, standards, codes and contracts — broken down to clause level and mapped to the obligations they create. When an instrument changes, you can see exactly which registers, owners and calendars are affected.
Clause-level mapping between instruments and obligation register entries.
Version tracking for instruments, with change notes against affected obligations.
Coverage view: which clauses are mapped, which are consciously out of scope.
Every obligation gets a named owner and, where it matters, a deputy — so accountability survives leave, turnover and restructures. Allocation is by role as well as person, which means a handover reassigns a whole portfolio in one move.
Owner and deputy on every obligation; nothing can be saved as unowned.
Role-based allocation with one-step handover when people change.
Workload view per owner, so responsibility is visible before it becomes a problem.
Evidence is filed against the exact obligation and clause it satisfies — not into a shared drive where it goes to age. Documents, records, links and system exports sit on the obligation’s own timeline, so an audit request becomes a filter, not a scramble.
Attach files, links and records directly to obligations and their review events.
Evidence carries dates and authorship, building a defensible trail automatically.
Gap view: obligations whose latest cycle has no evidence yet.
Every dated duty in the registers — lodgements, renewals, reviews, attestation windows — lands on a shared compliance calendar. Reminders go to owners ahead of time and escalate past them if a deadline is at risk, so the calendar does the chasing.
Deadlines and review cycles generated straight from register entries.
Reminder and escalation ladders per obligation, tuned to how critical it is.
Forward view by team, month or regulator — what’s due, what’s at risk.
When people need to formally confirm something — a policy read, a control operated, a declaration made — the platform runs the attestation for you: who must sign, by when, against which obligation, with the signed record kept on the trail.
Attestation campaigns scheduled from the compliance calendar.
Each response is timestamped and stored against the obligation it confirms.
Chase lists and completion views for whoever runs the campaign.
When something goes wrong, it gets logged as a breach against the obligation it touched — classified for severity, assessed for reporting duties and escalated to the right people immediately. The record shows what happened, what it affects and who is acting on it.
Structured breach intake: what, when, which obligation, initial severity.
Escalation rules by severity, including flags for notifiable events.
Every breach links forward to its remediation actions and closure.
Corrective actions live on the same record as the breach or gap that caused them — each with an owner, a due date and a verification step before it can close. Root-cause notes stay attached, so recurring problems are visible as patterns, not surprises.
Action plans with owners, due dates and status, chased by the calendar.
Closure requires verification — someone confirms the fix actually holds.
Root-cause and recurrence views across breaches and audit findings.
Lodgements, notifications and returns are prepared where the data already lives. A submission record carries its due date, its draft, its internal approvals and the final filed version — so what was sent, when and by whom is never a matter of memory.
Submission workspace per lodgement: draft, review, approve, file.
Due dates come from the compliance calendar; the filed copy goes to evidence.
A clean history of everything lodged with each regulator.
Executives and boards get compliance posture straight from the registers — not from a deck assembled the night before. Standing reports show obligations by status, breaches and remediation in flight, attestation completion and what’s due next, all traceable back to the underlying records.
Board and committee packs generated from live register data.
Posture views by domain, owner and regulator, with drill-down to the record.
Trend lines on breaches, closures and on-time performance over time.