The complete module page

Compliance Control: the integrity program that holds up in an audit

Legal matrix, internal controls with effectiveness testing, risks, policies with acceptance by version, mandatory training, third party due diligence checked against the CEIS and CNEP sanction lists, conflict of interest declarations, incidents with remediation, a compartmentalized ethics hotline, a public reporting portal with protocol number and token, a program assessment based on Decree 11.129/2022, an obligations calendar you can export, access review with segregation of duties read from real permissions, operational privacy with a record of processing activities, impact assessment and the ANPD 3 business day deadline, attestation campaigns answered through a personal link, a committee with an agenda built on its own and anti retaliation follow up for whistleblowers. All in the same system that already holds the contract, the class, the supplier and the employee.

It is the GRC (governance, risk and compliance) layer of the platform, together with the Incidents & Continuity module. This is the full reference for the module on a single page: the nineteen admin screens, the public portal for the ethics hotline and campaigns, the library of ready made templates, the functional areas with every feature listed one by one, the design decisions that explain why the system refuses certain things, the boundaries with other modules and a glossary of integrity and privacy terms.

  • 19admin screens, from the program assessment to access review
  • 9assessment pillars, following art. 57 of Decree 11.129/2022
  • 34continuous monitoring checks, running on their own every day
  • 70items in the template library, from policies to investigation playbooks
  • 4confidentiality rules on the public portal, none of them optional

Inside the module

19 screens, in the order the work happens

Five groups in the admin menu. Legal compliance states what the company must comply with, handles privacy and reports to the committee, controls prove that it does and that nobody holds duties they should not, internal rules reach people through campaigns, integrity handles third parties and misconduct, and configuration covers what the module enforces on its own plus the public hotline portal.

01

Legal compliance

The list of obligations that apply to the company, with the assessment of each one and the evidence behind it.

7 screens
  • DashboardCompliance by framework, overdue and ineffective controls, what the ethics hotline has open and third party integrity coverage. From the hotline, only the count.
  • Program AssessmentA 0 to 100 score across nine integrity program pillars, calculated from what is already recorded, with the next steps that raise the score the most and traceability of each requirement down to control, test and evidence.
  • Obligations CalendarEvery program date in a single list, from the quarterly test to due diligence expiration, with overdue items on top and export to the calendar of whoever owns each deadline.
  • Legal MatrixRequirement by requirement, with applicability, criticality, review frequency, compliance status and attached evidence.
  • Privacy & LGPDRecord of processing activities with suggestions built from the modules the company uses, impact assessment for sensitive processing, security incidents involving personal data with the ANPD 3 business day clock, and data subject requests read live with the 15 day deadline.
  • Committee & ResolutionsCommittee meeting with the agenda built on the spot: open serious alerts, overdue hotline cases as a count only, risks above appetite, late actions and the program score. Attendance, minutes and resolutions that are born as remediation actions.
  • Committee ReportThe period dossier ready to print and attach to minutes, built from the same endpoints as the screens. From the ethics hotline, only counts, with any cell below 3 cases shown as "<3".
02

Controls and risk

The internal control that mitigates the risk, the test that proves it works and the matrix that shows where the company is exposed.

4 screens
  • Internal ControlsDescription, owner, frequency, type, last test, last result and next test date, calculated from the declared frequency.
  • Effectiveness TestsThe test recorded with sample, result and conclusion, updating the control in the same step.
  • Risks5x5 matrix with likelihood, impact, resulting level, company risk appetite and the mitigating controls linked to each risk.
  • Access ReviewWho can create and approve the same payment, read from each person's real permissions. Next to it, logins left behind by people who were let go, sensitive permissions without a second factor or unused for months, and payments made to suppliers that were rejected, sanctioned or have expired due diligence.
03

Internal rules and people

The policy in force, the version each person accepted and the training they were supposed to complete.

3 screens
  • PoliciesText, version, effective period and status. Publishing a new version supersedes the previous one, which keeps its acceptances intact.
  • TrainingMandatory training by audience, with deadline, proof of completion and the list of who is overdue.
  • Attestation CampaignsPolicy acceptance, the annual conflict of interest declaration or training acknowledgment launched to a whole audience, with a personal link answered on the portal, live participation and the deadline enforced by monitoring.
04

Integrity

The third party the company hires, the conflict the employee declares, the misconduct that surfaces and the channel it arrives through.

4 screens
  • Ethics HotlineCases with protocol number, category, assigned investigators, deadline and a log of who read each case. Anonymous reports store neither the reporter nor the IP, and a case coming from the public portal starts visible only to the hotline manager. The manager can also audit who read what across the whole hotline, and a substantiated case gets anti retaliation follow up at 30, 90 and 180 days.
  • Third Party Due DiligenceIntegrity assessment of the partner, with sanctions, PEP, written opinion, decision and expiration. Sanctions are checked against CEIS and CNEP in one click, by CPF or CNPJ. Without an expiration date, the record counts as pending.
  • DeclarationsConflicts of interest, gifts and hospitality declared by the employee, with a written review by whoever approved or rejected it.
  • IncidentsIncident with investigation, remediation actions, effectiveness verification and closure. An incident with an open action cannot be closed.
05

Configuration

The settings for whoever owns the module, plus the starter library of frameworks and requirements.

1 screen
  • ConfigurationModule activation, adopted frameworks, evidence locks, ethics hotline deadlines, opening of the public portal, continuous monitoring rules and library loading, with a history of who turned on what.

The problem and the fix

What changes day to day for the people who own the program

The pain

The legal compliance matrix is green because half the items were marked "not applicable" without anyone saying why.

With Partiu Formatura

The server refuses to mark a requirement as not applicable without a written justification. In the audit, the exclusion is defensible instead of becoming a nonconformity.

The pain

The company has sixty controls described in a document and none of them was tested this year.

With Partiu Formatura

A control is what was tested, not what was described. The next test date comes from the declared frequency, and an overdue control shows up on the dashboard before the audit.

The pain

The code of conduct was revised and nobody knows who accepted which text.

With Partiu Formatura

Acceptance is per version. Publishing a new version does not inherit acceptance from the previous one, and the record keeps the date, source address and exact version the person read.

The pain

The report arrived by email and went through four inboxes before reaching the person who should investigate.

With Partiu Formatura

A hotline with protocol numbers, investigators assigned per case and a mandatory read log. Anyone not on the case cannot open it, and every read is recorded.

The pain

The supplier was approved in a due diligence from three years ago and nobody has reviewed it since.

With Partiu Formatura

Due diligence without an expiration date is treated as expired, and third party coverage only counts records with a decision that are valid today.

The pain

The incident was closed with the action plan still pending, and nobody ever followed up on the plan.

With Partiu Formatura

An incident does not close with an open action. A completed action still goes through effectiveness verification, and an ineffective action does not go back to pending: a new one is opened.

The pain

The module was purchased and sat empty, because nobody drafts a code of conduct inside a data entry form.

With Partiu Formatura

The library ships policies, controls, risks, training tracks, action plans, due diligence playbooks and investigation playbooks ready to use, in neutral language for legal to adjust. None of it counts as compliance: policies start as drafts and controls start as never tested.

The pain

Reports from people without a company login arrive by email, in an inbox three people read.

With Partiu Formatura

The public portal takes the report without a login, returns a protocol number and a follow up token, and the case starts visible only to the hotline manager. The reporter's source address is not stored anywhere.

The pain

The committee report is built by copying numbers from five screens into a separate document, and the numbers stop matching.

With Partiu Formatura

The committee report comes from the same endpoints as the screens, in a print version and as CSV. Two calculation paths would diverge, and the meeting would argue about which is right instead of discussing the program.

The pain

A large client sent an integrity questionnaire and nobody can say where the program stands.

With Partiu Formatura

The assessment scores each pillar using the parameters of Decree 11.129/2022, calculated from what is recorded rather than from self assessment, with a short list of what is missing to raise the score.

The pain

The matrix says compliant, but the control for that requirement failed its last test and the evidence expired in March.

With Partiu Formatura

Traceability links each requirement to its control, test and evidence, and puts compliant items with nothing behind them at the top, before an auditor finds them.

The pain

The supplier landed on a government sanction list after being approved, and the company found out from the press.

With Partiu Formatura

Due diligence checks CEIS and CNEP on the Portal da Transparência by CNPJ, stores the dated result on the record itself and flags the active sanction, without erasing anything someone had already marked by hand.

The pain

The quarterly control test went overdue because the deadline lived on a screen nobody opened that month.

With Partiu Formatura

The calendar brings every program date together and goes to each person's calendar with a reminder one week ahead. And monitoring runs by itself every day, flagging new, serious problems in the notification bell.

The pain

The approval policy says whoever books a payment cannot approve it, but nobody checks whether the system lets the same person do both.

With Partiu Formatura

Access review crosses the conflict matrix with each user's real roles and permissions and shows the conflicting pair and which role grants each side. Anyone with full access appears once, highlighted, and not as twenty conflicts.

The pain

The employee left in June and his login was still active in September, with finance permissions.

With Partiu Formatura

An active login belonging to someone let go in HR becomes a daily alert, along with sensitive permissions without a second factor and those nobody has used in months. The screen exports the list for the periodic access review.

The pain

The photo link leaked on a Friday and the company only remembered the ANPD deadline the following Wednesday.

With Partiu Formatura

A personal data incident opens with the 3 business day clock counted from awareness, the relevant risk assessment using the ANPD resolution criteria and prefilled notices for the authority and data subjects. In Continuity, a personal data incident already has the button that opens this record.

The pain

To collect acceptance of the code of conduct, HR emailed four hundred people and then checked each reply in a spreadsheet.

With Partiu Formatura

The campaign picks the audience, generates each person's personal link and shows participation in real time. The person answers on the portal without a login, and the acceptance lands in the same per version acceptance table that already holds up in an enforcement action.

The pain

The report was investigated, the person was disciplined, and three months later the whistleblower was moved to another department with no explanation.

With Partiu Formatura

A case concluded as substantiated gets anti retaliation checks at 30, 90 and 180 days, visible only to the case investigators. An overdue check becomes an alert that shows only the protocol number.

How it works

The path information takes, from published law to the alert on screen

  1. 1

    The obligation comes in

    The library of frameworks and requirements is loaded per company, with one click by whoever configures the module, and legal adjusts wording, criticality and frequency to fit the company.

  2. 2

    Applicability is decided

    Each requirement gets a decision: it applies, and then needs an assessment, or it does not apply, and then needs a justification. A non applicable requirement leaves the matrix denominator.

  3. 3

    The control proves it

    The requirement points to the internal controls that support it, and each recorded test updates the control with the result and the next test date.

  4. 4

    The rule reaches people

    The policy comes out of the library as a draft, legal fills in the final section that depends on the company, and only then is it published and requires acceptance from the defined audience. Mandatory training requires proof of completion within the deadline.

  5. 5

    The misconduct surfaces

    Through the internal hotline, the public portal open to people without a login, a recorded incident or continuous monitoring, which scans the database every day with named checks.

  6. 6

    Remediation closes the loop

    An action with owner and deadline, effectiveness verification once completed, and the control adjusted so the same issue does not come back.

How the system behaves

24 decisions that explain everything else

They explain why the system sometimes does not do what you might expect, and why that is intentional.

"Not applicable" requires a justification

Marking a requirement as not applicable without saying why is the classic hole in a legal compliance matrix. The server refuses, and the justified requirement leaves the denominator: counting as pending what the company has justified would mean the matrix never closes, and users would learn to ignore the indicator.

A control is what was tested

A control description proves nothing on its own. Last test, last result and next due date are stored on the control itself, updated with every test, and the dashboard lists what is overdue and what failed without waiting for someone to build a spreadsheet.

Acceptance is per version

Publishing a new version of a policy does not inherit acceptance from the previous one, and a policy in force is not edited. That is exactly what the company needs to show in an enforcement action: that the person accepted the text in force, with date and source recorded.

The ethics hotline does not belong to the administrator

The hotline permission is the only one in the module that admin:all does not bypass, because in a report the person accused may be the system administrator. The permission opens the screen; viewing a case requires being on its investigator list or being the hotline manager.

Reading a report always leaves a trail

Opening a case records the read, and if the record fails to save, the read is refused. Every module has a write log; a read log exists only here and for OHS health data. The who read this case screen lives inside the case itself, which is where people look when a leak is suspected.

An incident does not close with an open action

Closing with a pending action plan is the most common way for a program to look effective without being effective: incidents vanish from the screen and actions are never followed up. A completed action still goes through effectiveness verification, and an ineffective action does not go back to pending, because that would erase the record that the first attempt did not work.

Due diligence without expiration is expired due diligence

A record with no expiration date would be approved forever, and a third party's integrity is not a permanent attribute: companies land on sanction lists after being approved. Coverage counts only what has a decision and is still valid today.

Monitoring rules do not store SQL

A rule points to a check named in code, and parameters carry only numbers and lists. An arbitrary query saved in a table and run later is injection with extra steps, and the flexibility of client configurable rules is not worth that risk.

On the internet, a protocol number alone is not enough

Inside the admin panel, looking up a case by protocol number is something only people past login and strict permission can do. On the public portal, protocol numbers are sequential per company, and the whole series can be enumerated in minutes. That is why an external case carries a twenty character token, shown once and stored only as a hash. There is no recovery by email, because it would destroy the anonymity that is the whole point of the hotline.

The portal does not distinguish between errors

A protocol that does not exist, a wrong token, another company's case and an expired retention period all return the same response. Telling them apart already gives information to whoever is probing the door. For the same reason, a closed hotline responds like a nonexistent address: saying it exists but is closed already reveals the company has the module.

The reporter's source address is not stored

Not in the report, not in the portal access log. Rate limiting uses a hash of the address with a salt generated when the process starts, which lives only in memory and dies with it. A company able to cross reference access logs with anonymous reports does not have an anonymous hotline, it has the appearance of one.

A template is a starting point, never ready made compliance

Applying the whole library cannot turn the dashboard green. Policies come in as drafts, controls come in as never tested and due today, risks come in as identified with no appetite. Declaring compliance nobody has verified is exactly the flaw the module exists to prevent.

The committee report carries no report content

It gets printed, circulated and attached to minutes. Putting investigation content in it would undo the compartmentalization the rest of the module maintains, so from the ethics hotline it includes only counts and distribution by category, even for people with hotline permission.

Assessment without a questionnaire

An assessment that depends on someone filling in a self assessment measures the goodwill of whoever filled it in and is out of date the next day. The score is calculated on the spot from what is recorded, and criteria with no basis are left out instead of counting as zero or as a hundred.

An empty check does not undo a marked sanction

CEIS and CNEP are federal registries. A state or international sanction marked by hand does not stop existing because the federal check came back empty. That is why the check only changes unverified to not listed, and adds the result to the details instead of overwriting them.

Whoever watches the log also leaves a trail

The access audit shows who read which hotline cases, and for that reason it is itself recorded in the log. A surveillance tool that does not log itself is a side door to the very content it is supposed to protect.

The bell only announces what is new

Repeating every day that the same control is overdue teaches people to ignore the notification, and a user trained to ignore alerts is worse than no alert at all. The daily run notifies only alerts created in that run, and the rest stays on the list.

The library is seeded per company

Legal requirements are open to interpretation, and each client's legal team adjusts wording, criticality and frequency. Pushing a global list to everyone at once would create matrices with hundreds of unassessed items at companies that have not even purchased the module.

Access is read, not declared

A written approval policy does not prove the system respects it. Access review reads each user's roles and permissions on the spot, and the conflict matrix lives in code, where it changes through a reviewed diff and not through a form anyone can edit.

The ANPD deadline never shows up later than it is

The clock counts business days and skips only fixed date national holidays. Movable, state or city holidays are not skipped, so the date shown can come one day earlier than the real one, never later. Erring toward an early warning costs little; erring the other way costs a late notification.

A suggested processing activity is not a record

The processing catalog shows up in full on first access, but nothing is saved until someone adopts the row. A record of processing that fills itself in looks finished to people who never checked the purpose and legal basis of each activity.

The campaign link reveals no more than it must

The personal link token is stored only as a hash, dies when the person answers and a token error never says whether the link existed. A campaign link leaked in an email thread cannot become a way to find out who is on the list.

Retaliation is followed inside the case's confidentiality

The anti retaliation check is about the whistleblower, so it goes through the same access control and the same read log as the case. Outside of it, the alert shows only the protocol number and the overdue milestone.

Small statistics identify people

In a hotline with few cases, "one harassment case in finance" tells you who it was. The report shows "<3" for every cell with one or two cases and does not cross category with severity, on screen or in CSV.

The boundaries

Where Compliance ends and the rest of the system begins

The module never keeps a second copy of anything. It reads what already exists and returns what it produced through the same path as the rest of the platform.

Quality and Compliance

When remediation is already being handled in the quality system, the incident action references that action instead of duplicating it. Compliance follows the same line, without keeping a second list that would diverge at the first update.

People Management

The audience for policy acceptance and mandatory training can be all active employees, read from the people registry. The module sees name, employee ID and job title, and nothing about salary or bank details.

Suppliers and Qualification

Due diligence links to the supplier already registered, and the alert for active suppliers with no due diligence comes from that cross check. Without the purchasing module installed, due diligence keeps working with the third party registered in compliance itself.

Legal and Collections

Litigation and advisory work stay in legal; the integrity program stays here. An incident that becomes a lawsuit, and a lawsuit that reveals a control failure, are linked from both sides without moving the record's owner.

Occupational Health and Safety

OHS is the other module with a mandatory read log, for the same reason: sensitive data is not read without leaving a trail. The sites registered there are reused here, so the two modules never disagree on how many the company has.

Company Map

Compliance keeps the evidence for a case; the map shows everything linked to the record cited in it. In an investigation, following the links saves the six screens the cross check would otherwise take.

Incidents & Continuity

Coordinated incident response lives in Continuity. When the incident involves personal data, its room opens the privacy record here, where the ANPD deadline runs, and serious Compliance alerts show up on the radar there with nothing from the ethics hotline.

Finance and Payables

Access review reads payables to find payments to suppliers with rejected, sanctioned or expired due diligence. The bill stays in finance, and only the cross check shows up here.

Governance

Who sees what, and what runs without anyone asking

10 separate permissions

Checked on screen and in the API too: hiding a button is not access control. And one of them, the ethics hotline, is checked without the administrator shortcut.

  • ViewDashboard, legal matrix, published policies and indicators. Changes nothing, and does not open ethics hotline cases.
  • RequirementsRequirements, applicability and compliance evidence.
  • ControlsInternal controls, effectiveness tests and risks.
  • PoliciesPublish policies and versions and track acceptance.
  • Ethics hotlineStrict: neither admin nor admin:all opens this screen. And those who have it only see cases where they are an investigator or the hotline manager.
  • Third partiesDue diligence and conflict of interest declarations.
  • IncidentsIncidents, investigations and remediation actions.
  • PrivacyRecord of processing, impact assessment and security incidents involving personal data. View sees the screens; saving requires this permission.
  • CommitteeCommittee meetings, minutes, attendance and resolutions that open actions.
  • ConfigurationFrameworks, monitoring rules, deadlines and locks.

Thirty four checks running on their own, every day

Continuous monitoring scans the database every day at 06:30 and records its findings. A finding that shows up again updates the existing alert; a finding that disappeared is closed with a resolution explaining why; and only new, serious alerts become notifications.

  • Control with overdue testAn active control whose next test date has already passed. A control not tested on time does not support the claim that it works.
  • Ineffective control with no actionThe test found a failure and no remediation was opened. This is the finding that weighs most in an audit.
  • Critical requirement noncompliantA high or critical obligation marked as noncompliant.
  • Requirement with overdue reviewThe declared frequency has passed and nobody reassessed the status.
  • Expired evidenceThe document that supported compliance is no longer valid.
  • Policy with pending acceptanceA policy in force with people on the list who have not yet accepted the current version.
  • Policy with overdue reviewThe policy review deadline passed with no new version and no confirmation.
  • Overdue caseAn ethics hotline case past its category deadline. The alert shows the count, never the content.
  • Third party without valid due diligenceDue diligence expired, with no declared expiration or nonexistent.
  • Supplier without due diligenceAn active supplier that has never gone through any integrity assessment.
  • Declaration with no reviewA declared conflict or gift sitting idle, waiting for a decision.
  • Late remediation actionAn action past its deadline and still pending.
  • Action with no effectiveness verificationA completed action nobody checked to see if it worked.
  • Overdue mandatory trainingA person with training required by the program past the deadline.
  • Risk above appetite with no controlA risk rated above the company's appetite with no active mitigating control.
  • Compliant with no valid evidenceA requirement declared compliant with no evidence within its validity. Compliance without proof is just a statement.
  • Critical requirement with no controlA high or critical obligation with no active internal control linked to it.
  • Compliant with ineffective controlThe requirement says compliant, and the control supporting it failed its last test.
  • Control with no ownerAn active control with no named owner, which nobody performs or tests.
  • Serious incident with no actionA high or critical severity incident, still open, with no remediation action recorded.
  • Sanctioned third party approvedDue diligence recorded a sanction and the decision was still approval without reservations.
  • PEP without enhanced due diligenceA third party involving a politically exposed person assessed at the simplified or standard level.
  • Case with no investigatorAn ethics hotline case nobody was assigned to investigate. The alert shows only the protocol number.
  • Conflicting dutiesA person with permissions the segregation matrix says cannot go together, such as booking and approving the same payment.
  • Former employee with accessA login still active for an employee let go in HR.
  • Sensitive access without second factorA user with sensitive permissions who logs in with a password only.
  • Unused sensitive accessSensitive permission for someone who has not logged in for longer than the limit, ninety days by default.
  • Payment to restricted third partyA payable in the period to a supplier with rejected, sanctioned or expired due diligence.
  • ANPD deadlineA personal data incident nearing the end of its 3 business days with no notification recorded.
  • Sensitive processing without impact assessmentA processing activity with sensitive or high risk data and no impact assessment.
  • Processing with overdue reviewA record of processing past its review date.
  • Late data subject requestA data subject request past 15 days. The alert shows only the protocol number and the days.
  • Overdue retaliation checkA 30, 90 or 180 day milestone of a substantiated case with no check recorded. Confidential: only protocol number and milestone.
  • Campaign past deadlineAn attestation campaign past its deadline with people who have not answered yet.

In practice

9 everyday situations, from problem to result

01

The green matrix that did not survive the first question

The scenario

The company showed up to the audit with its compliance matrix almost entirely green. The auditor asked for the evidence on three items and the justification for two marked as not applicable, and none of the five had an answer.

With the system

With the evidence lock turned on, declaring compliance requires an attached document, and marking a requirement as not applicable requires a written justification. Anything without backing shows as pending on the screen itself, before someone from outside asks.

The result

The matrix started showing less green and actually meaning something. Items without evidence became a work queue with owners and deadlines, instead of a surprise in the meeting.

02

The report that involved the administrator

The scenario

An ethics hotline case pointed to the conduct of someone with full system access. In any admin panel with an administrator shortcut, that person would read the entire report before any investigation began.

With the system

The hotline permission does not accept the administrator shortcut, the case opens only for the assigned investigators and the hotline manager, and every opening is recorded. The dashboard shows that cases exist, without showing which ones.

The result

The investigation was run by the committee that was supposed to run it. The read log showed, with names and times, who accessed the case from start to finish.

03

The code of conduct revised mid year

The scenario

The company revised its code of conduct in August. Four hundred people had accepted the January version, and nobody could say who was covered by which text.

With the system

The new version took effect and the previous one was marked as superseded, with its acceptances intact. An acceptance request went out to all active employees, and pending acceptances were visible person by person.

The result

Every acceptance record points to the exact version, with date and source. The question of which text this person accepted has a one line answer.

04

The report that came from outside the company

The scenario

A contractor working at a graduation witnessed serious misconduct. He has no login, does not want to identify himself, and the only channel was an email inbox read by three people in the back office.

With the system

The public portal took the report without sign up and returned a protocol number and token. The case started visible only to the hotline manager, who assigned the investigators, and the investigation's questions reached the person through the protocol itself.

The result

The investigation was run by the right people, and the reporter followed its progress without ever being identified. There is no record of his source address to be cross referenced later.

05

The program that got off the ground in one afternoon

The scenario

The company purchased the module and it sat empty for two months. Nobody had time to draft a code of conduct, list twenty controls and build the risk matrix from scratch.

With the system

The entire library was applied. The nine policies came in as drafts with the section legal needed to fill in, the controls came in as never tested and due that same day, and the risks came in identified with no appetite.

The result

The program now existed in writing and became a work queue with owners and deadlines. The dashboard stayed red, which is exactly what it should show a company that has not tested a single control yet.

06

The large client's integrity questionnaire

The scenario

Before renewing the contract, a corporate client required a questionnaire on the company's integrity program, using the parameters of Decree 11.129/2022. The answers were spread across twelve screens and the memory of two people.

With the system

The assessment showed each pillar's score with the number behind it: how many approved policies, how many acceptances, how many controls tested on time, how many third parties with valid due diligence. The next steps pointed to the three criteria dragging the score down the most.

The result

The questionnaire was answered with numbers instead of adjectives, and the three gaps became an action plan before the renewal meeting.

07

The approved supplier nobody reviewed

The scenario

An event partner had been approved in an old due diligence with no expiration date. Three years later, it showed as approved in the spreadsheet and as a risk in any public search.

With the system

Due diligence with no expiration is treated as expired, so the partner stopped counting toward third party coverage and started showing up in the daily alert. The new assessment required a written opinion for the decision.

The result

Integrity coverage of the database now reflects who is actually assessed today, and the decision about the partner was recorded along with its reasoning.

08

The audit that asked who approves what

The scenario

The external auditor asked for the list of people who can book and approve payments. The company's answer was the approval policy in PDF.

With the system

Access review showed four people holding both sides of the conflict, the role granting each permission and a former finance employee whose login had stayed active since leaving. The list was exported to CSV and became a working paper.

The result

Two roles were split, the login was blocked the same day and the conflicting duties check started running daily so the problem would not quietly come back.

09

The leak that arrived on a Friday afternoon

The scenario

A spreadsheet with graduates' CPF numbers was sent to the wrong supplier on a Friday. The team decided to wait until Monday to figure out what to do.

With the system

The incident was opened in Continuity as personal data, and the room's button opened the privacy record with awareness filled in. The clock already showed the end of the 3 business days, the relevant risk assessment followed the resolution criteria and the notice came from the template with its placeholders reviewed.

The result

Notification to the ANPD and data subjects was recorded on time, and the processing activity involved got an impact assessment it never had.

Glossary

Integrity terms, explained in plain language

The admin panel is written in Portuguese. If you came looking for compliance industry terms, this is what each one means inside the module.

FrameworkCompliance reference
The set of obligations the company adopts as its baseline, whether a law, a standard or a group policy. The matrix is measured per framework.
Legal matrixCompliance matrix
The list of applicable requirements with the status of each one. It is the first document an audit asks for.
Internal controlControl
The procedure the company performs to meet an obligation. Here it only counts when it has been tested within the declared frequency.
Effectiveness testControl testing
Verification, by sample, that the control works in practice and not just on paper.
5x5 matrixLikelihood x impact
Risk rating on five levels of likelihood and five of impact, whose product falls into a band configured by the company.
Risk appetiteRisk appetite
The level of risk the company is willing to live with without requiring an additional control. Above it and with no control, the system raises an alert.
Due diligenceIntegrity due diligence
Assessment of the third party before and during the business relationship, with written opinion, decision and expiration.
PEPPolitically exposed person
Someone who holds or has held a relevant public office, or is closely related to someone who does. The field has three states, because unverified is different from is not.
Conflict of interestConflict declaration
A personal or financial relationship that could influence a professional decision, declared by the employee and reviewed by the company.
Ethics hotlineWhistleblowing
The channel for reporting misconduct, with protocol number, compartmentalized confidentiality and the option of anonymity.
Follow up tokenExternal case key
The twenty character code given to people who report through the public portal. It is shown only once, stored only as a hash and cannot be recovered, because recovery would require knowing who the person is.
Non retaliationAnti retaliation
The ban on any reprisal against people who report in good faith or cooperate with an investigation. Retaliation is a serious violation in itself, and the code of conduct in the library says so in those words.
RemediationAction plan
What is done after misconduct is identified, with owner, deadline and effectiveness verification.
Continuous monitoringContinuous monitoring
The automatic scan that checks the program every day, instead of discovering the failure in the annual audit.
Decree 11.129/2022Brazilian Anti Corruption Law regulation
The decree that regulates Law 12.846/2013. Article 57 lists the parameters used to evaluate an integrity program, and they are what organize the assessment pillars.
CEIS and CNEPFederal sanction registries
The registry of disreputable and suspended companies (CEIS) and the national registry of penalized companies (CNEP), maintained by the CGU and searchable on the Portal da Transparência.
TraceabilityTraceability
The link from each requirement to the control that meets it, the test that proves the control and the evidence that documents it all. Where the chain breaks, compliance is only declared.
Segregation of dutiesSoD
The rule that the same person cannot perform both ends of a sensitive operation, such as booking and approving a payment.
Access reviewUser access review
The periodic check of who has access to what, to remove what was left over from role changes, departures or old exceptions.
Record of processingROPA
The record of personal data processing activities required by art. 37 of the LGPD, with purpose, legal basis, data, data subjects and retention.
RIPDData protection impact assessment (DPIA)
The data protection impact report, done for sensitive or high risk processing, with the risks and the measures that reduce them.
Security incidentBreach notification
An event that compromises personal data. When there is relevant risk to data subjects, the ANPD and the data subjects must be notified within 3 business days.
Attestation campaignAttestation
A request for acceptance, declaration or acknowledgment sent to a whole audience at once, with a personal link and participation tracking.

FAQ

The questions that come up when evaluating the module

Do I need to turn on the whole module at once?

No. The short path is the legal matrix plus evidence, which already answers the first question of any audit. Controls and tests, policies with acceptance, the ethics hotline, third parties and incidents come later, each with its own permission.

Can the system administrator read the reports?

No, and that is deliberate. The ethics hotline permission is checked without the administrator shortcut, and even those who have it only see cases where they were assigned as investigator or are the hotline manager. Every case opening is recorded, and the read is refused if that record fails to save.

Can I use compliance without the People Management module?

Yes. The link to the people registry is optional: without it, acceptance requests and the training list work with an explicit list of people. The same goes for suppliers and OHS sites.

Can the company create its own monitoring rules?

It can turn on, turn off and adjust the parameters of each of the thirty four rules provided, within the limits each one declares. What it cannot do is store an arbitrary query for the system to run later, because that would be injection with extra steps and would open the entire database to anyone able to write a line in the table.

Does the requirements library come prefilled?

It comes available, and loading it is one click by whoever configures the module, per company. Loading is idempotent by framework and requirement code, so it can be rerun later without duplicates, and legal adjusts wording, criticality and frequency to fit the company.

How does this relate to LGPD?

Consent terms, consent records and data subject requests stay in the LGPD module and the privacy portal. Compliance Control handles the operational side of the program: the record of processing activities, the impact assessment and security incidents with the ANPD 3 business day deadline. Data subject requests are read from there live, with the 15 day deadline, without copying.

Do people answering a campaign need a panel login?

No. Each person receives a personal link and answers on the public portal, with no login. The link dies as soon as the answer arrives, and the acceptance goes to the same per version record the panel already uses.

Does access review require setting up the conflict matrix?

No. The matrix ships ready in code, built only with permissions that exist in the panel, and the screen reads users' roles and permissions live. Anything it cannot read in the environment shows as unavailable, and the rest keeps working.

Can people who do not work at the company file a report?

Yes, through the public ethics hotline portal, at the company's own address, with no login and no sign up. The person receives a protocol number and a follow up token, and uses them to come back, read the investigation's replies and send more information. Their source address is not stored anywhere.

I lost my follow up token. Can I recover it?

No, and that is deliberate. The token is stored only as a hash, and an email recovery flow would require linking the case to an identity, which is exactly what an anonymous hotline does not do. The way forward is to file a new case referencing the previous one.

Do I have to write the code of conduct and controls from scratch?

No. The library includes nine policies, twenty two controls, eighteen risks, eight training tracks, six action plans and the due diligence and investigation playbooks, in neutral language. Each policy has a final section with what depends on the company, and none of it is applied as compliance: policies start as drafts, controls start as never tested.

How is the integrity program score calculated?

Using the parameters of art. 57 of Decree 11.129/2022, organized into nine pillars. Each pillar has weighted criteria, measured on what is already recorded in the module: approved policies, acceptances given, controls tested on time, valid due diligence, cases investigated on time. There is no questionnaire, and criteria with no basis are left out of the calculation.

Does the CEIS and CNEP check need any setup?

It needs a free access key from the Portal da Transparência, configured once on the server. Without it, the check button does not appear. The search uses the third party's CPF or CNPJ, and every result is stored with its date on the record itself.

Can I bring the program deadlines into my calendar?

Yes. The obligations calendar exports a calendar file with each deadline as an all day event and a reminder one week ahead. Reimporting the file updates the events instead of duplicating them.

What happens when a test fails the control?

The control is marked as ineffective, the dashboard highlights it, and monitoring demands that a remediation action be opened. Until there is an action, the ineffective control with no action alert stays open, with critical severity.

An integrity program that stays standing when someone from outside asks

We can open the module with your frameworks, apply the template library in front of you, show the legal matrix, controls, ethics hotline and public portal in action, and talk through the rollout path for your situation.