Platform and intelligence · Compliance Control

Integrity program that survives an audit

Program assessment based on the parameters of Decree 11.129/2022, a legal requirements matrix with traceability down to control and evidence, internal controls with effectiveness testing, compliance risks, policies with recorded acceptance, mandatory training, third party due diligence checked against CEIS and CNEP, conflict of interest and gift declarations, incidents with remediation, an obligations calendar you can export and an ethics hotline. Access review crosses segregation of duties with real permissions, finds logins of people who left and payments to restricted suppliers. Privacy keeps the record of processing activities, the impact assessment and the ANPD 3 business day deadline. Campaigns take acceptance and conflict declarations to each person through a link, and the committee decides with an agenda built on its own. The hotline is compartmentalized on purpose: viewing a case requires a dedicated permission the administrator cannot bypass and being on that case's investigator list, every read is logged, and a substantiated case gets anti retaliation follow up.

The problem and the solution

What changes when Compliance Control works inside the platform

This is connected information about classes, graduates and events across 14 modules, replacing scattered spreadsheets and messages.

Without the platform

Information about Compliance Control lives in separate spreadsheets, and nobody knows which version is current.

With Partiu Formatura

14 modules share the same class, graduate and event records.

Without the platform

A request for a number takes time because someone has to combine data from several places.

With Partiu Formatura

Program Assessment and Traceability and Obligations Calendar update together, with figures ready for the next meeting.

Without the platform

The process depends on who is working that day, and its history disappears.

With Partiu Formatura

Everyone follows the same workflow, with recorded actions and role-based permissions.

Without the platform

Connecting with other departments means exporting spreadsheets and entering data again.

With Partiu Formatura

Compliance Control shares information directly with other areas of the platform.

How it works

How information moves through Compliance Control

Each step is a real module in this area. Its output moves to the next step without anyone entering the same information again.

What is available in Compliance Control

Program Assessment and Traceability

The integrity program grade, and the requirement-by-requirement proof that it holds up.

  • Nine pillars of art. 57 of Decree 11,129/2022, with a score from 0 to 100 per pillar and overall
  • Criteria measured on what is already registered, without a questionnaire and without self-assessment
  • Baseless criteria do not weigh against or in favor
  • Next steps: the criteria that get the most marks, with link to the screen that resolves
  • Traceability of each requirement to control, up-to-date testing and current evidence
  • Highlight for requirements declared compliant with nothing to support them
  • Open remediation action straight from gap, and program note in dashboard and committee report

Obligations Calendar

Every program date in a single list, and in the calendar of the people responsible for them.

  • Control test, reviews, validity, due diligence and training validity, deadline for action
  • Horizon of three to twenty-four months, with the losers at the top
  • Renewed diligence and redone training do not appear in the old version
  • Export to calendar with reminder seven days in advance, without duplication when reimporting
  • Spreadsheet export, with ethics hotline deadlines kept out of the calendar for confidentiality

Internal Controls and Effectiveness Test

Designed control is one thing; control that works is another, and testing separates the two.

  • Internal control linked to the requirement it addresses and the risk it mitigates
  • Type, frequency and responsible party declared in the control design
  • Effectiveness test with sample, results and evidence
  • Ineffective result opens a pending issue with owner and deadline, it is not just recorded
  • History of tests per control, to see if it has gotten worse or better
  • Indicator of effective controls against the total tested

Compliance Risks

Probability and impact in the 5x5 matrix, with controls that reduce each risk.

  • Risk assessed by probability and impact, with calculated level
  • Classification by configurable range, recorded in the evaluation
  • Heat matrix with count per cell, clickable to filter
  • Controls linked to risk, with visible mitigation effect
  • Declared treatment: mitigate, transfer, avoid or accept
  • Acceptance requires justification, because it is the company assuming the risk on purpose

Policies, Acceptances and Training

The published policy, who accepted it, when, and who has not yet.

  • Versioned policy: publishing freezes the version and acceptance points to the accepted version
  • Acceptance registered by person, with date and origin
  • Collection from those who are pending, without a list made in hand
  • Mandatory training with workload and evidence of completion
  • Term of training, with notice before expiry
  • Policy revocation requires written reason

Compartmentalized Ethics Channel

The case is only seen by those who investigate that case, and every reading leaves a trace.

  • Own permission that the administrator profile does not bypass
  • List of investigators by case: anyone who is not on it receives the same response as a non-existent case
  • Mandatory Read Track: If access registration fails, reading is refused
  • Protocol generated for the whistleblower to follow without identifying themselves
  • Anonymous report accepted, with the same investigation flow
  • Conclusion classified as valid, unfounded or inconclusive, with the reason
  • Audit of accesses of the entire channel for the manager, with reading after hours and reading without current designation
  • The audit consultation is also recorded in the trail

Third Parties, Statements and Incidents

What comes from outside your own operation, and what to do when something goes wrong.

  • Third-party due diligence with questionnaire, documents and risk note
  • One-click consultation with CEIS and CNEP using CPF or CNPJ, with the result recorded in the registry
  • Empty query never undoes a hand-marked sanction
  • Periodic reevaluation, with warning when validity expires
  • Declaration of conflict of interest and gift received, per person and per period
  • Severity incident, investigation and remediation action with owner and deadline
  • Action linked to the control test that originated it, when applicable
  • Verification of the effectiveness of the remediation, so that the action does not close just because it was carried out

Continuous Monitoring

Rules named in the code, never SQL stored in a table.

  • Twenty-three named checkers, each checking a specific program condition
  • Automatic execution every day, with notification only of new alerts of high or critical severity
  • Monitored traceability gaps: compliant without evidence, critical requirement without control, control without owner
  • Adjustable parameters on the screen, within the limits of each tester
  • Alert opened when the condition appears and closed alone when it disappears
  • Alert handling with classification, including false positive with reason
  • Execution registered, to distinguish an alert that disappeared from a routine that did not run
  • Panel with what is open, by gravity
  • No rules accept free consultation: flexibility that does not pay for the injection risk

Auditoria Interna, KRIs e Frameworks

Plano anual baseado em risco, papéis de trabalho revisados, achados com follow-up e o painel que vai para o conselho.

  • Universo auditável por processo e unidade, com risco inerente e data da última auditoria
  • Plano anual montado pela priorização de risco, versionado e aprovado na pauta do comitê
  • Cadastro de auditores com área de origem e impedimentos declarados
  • Trabalho de auditoria com escopo, período, equipe e status
  • Programa com procedimentos por objetivo de controle
  • Papel de trabalho com amostra, evidência anexada, conclusão e revisor diferente de quem preparou
  • Trabalho que não conclui com papel sem revisão nem com achado sem plano do gestor
  • Achado com criticidade, recomendação, plano do gestor, prazo e dono
  • Achado virando ação no mesmo fluxo de remediação, com follow-up e alerta de vencido
  • Linha de defesa declarada em controle, risco e teste, com a área de quem testou registrada
  • Auditor impedido de testar controle da própria área, com exceção registrada quando necessária
  • Auditoria da qualidade aparecendo no universo sem sair do módulo de Qualidade
  • Indicadores de risco calculados por fórmula nomeada em código, lendo inadimplência, chargeback, incidentes graves, rotatividade, acidentes e não conformidades críticas
  • Apetite e tolerância por indicador, com medição diária, série histórica e tendência
  • Alerta automático quando o indicador sai da faixa, pelo monitoramento contínuo
  • Bibliotecas de ISO 27001, COSO e SOX carregadas por empresa e mapeadas para os controles internos existentes
  • Cobertura por framework calculada da matriz e Declaração de Aplicabilidade gerada
  • Painel do conselho com mapa de calor de risco residual, tendência dos indicadores, execução do plano e achados vencidos
  • Exportação do painel em PDF, guardada com o retrato do período

Access Review and Segregation of Duties

What each person can really do in the system, not what the approval policy says.

  • Conflict matrix written in code, reviewable by diff, using only permissions that exist in the panel
  • Conflicts such as booking and approving payables, approving purchases and registering suppliers, managing users and auditing
  • Reads the roles and direct permissions of every active user in the company
  • For each conflict, which role grants each side, so the fix is removing a role instead of guessing
  • Full access shown once per person, highlighted, instead of turning into dozens of conflicts
  • Active login of an employee let go in HR, linked by user or email, without counting people who were rehired
  • Sensitive permission without two factor authentication
  • Sensitive permission for someone who has not logged in for longer than the configured limit
  • Payable open or paid in the period to a supplier with rejected, sanctioned or expired due diligence
  • The most recent due diligence of each supplier counts, not the first record
  • Any part the environment does not have installed shows as unavailable, without taking down the others
  • CSV export for the periodic access review
  • Five daily checks: conflicting duties, former employee with access, sensitive without second factor, sensitive unused and payment to a restricted third party

Privacy & LGPD

The operational side of data protection: what the company processes, the impact and the deadline when something leaks.

  • Record of processing activities under art. 37 of the LGPD, with purpose, legal basis, data categories, data subjects, sharing, retention and processor
  • Fourteen processing activities suggested from the active modules: graduate registration, billing, photos and galleries, facial biometrics, tickets, HR, field staff and CRM
  • Suggestions shown before anything is saved, and adopting one creates the editable row
  • Flags for sensitive data, children and teenagers' data and international transfer
  • Impact assessment per processing activity, with likelihood and impact risks and the calculated level
  • Security incident involving personal data, with affected data subjects and categories and relevant risk assessment using the criteria of ANPD Resolution CD/ANPD 15/2024
  • A 3 business day deadline to notify the ANPD and data subjects, counted from the business day after awareness
  • Prefilled notices for the authority and data subjects, flagging the placeholders still missing
  • Deciding against the relevant risk criteria requires a longer justification
  • Privacy record opened straight from the Continuity incident room, with title, description and awareness already filled in
  • Data subject requests from the privacy portal and the app read live, with the 15 day deadline
  • Four checks: ANPD deadline, sensitive processing without impact assessment, processing with overdue review and late data subject request

Attestation Campaigns

The program reaching each person, with no mass email and no reconciliation spreadsheet.

  • Three types: policy acceptance, annual conflict of interest declaration and training acknowledgment
  • Audience by active users, by role or by HR employees with an email
  • Deadline, launch, closing and exempting people who do not need to answer, with a reason
  • A personal link per person, with the token stored only as a hash and killed as soon as the answer arrives
  • Answer on the public portal, with no login, and the same response for a wrong or nonexistent token
  • Acceptance saved in the per version acceptance table, with date and source, respecting one acceptance per version
  • A declaration with no conflict is approved on the spot, and one with a conflict goes to the review queue
  • Training acknowledgment recorded for someone to check, not as an approval
  • Live participation per campaign, person by person
  • Reminder to the manager through the bell and resending pending links
  • Check for campaigns past their deadline with incomplete participation

Committee and Resolutions

The meeting that decides, with the agenda ready and the decision that becomes an action.

  • Agenda built on the spot with open critical and high alerts
  • Overdue ethics hotline cases included only as a count, with no protocol number
  • Risks above appetite, late remediation actions and the program assessment score
  • Meeting scheduled and held, with attendance recorded and minutes
  • Resolution with owner and deadline that creates the remediation action in the same step
  • History of meetings and decisions, so the next meeting follows up on the last one
  • Ethics hotline statistics in the report with cells of 1 or 2 cases shown as "<3"
  • Case category not crossed with severity in the report, on screen or in CSV

Checklist

Everything included in Compliance Control

All 124 features in this area, grouped by module so you can compare systems item by item.

  • Nine pillars of art. 57 of Decree 11,129/2022, with a score from 0 to 100 per pillar and overall
  • Criteria measured on what is already registered, without a questionnaire and without self-assessment
  • Baseless criteria do not weigh against or in favor
  • Next steps: the criteria that get the most marks, with link to the screen that resolves
  • Traceability of each requirement to control, up-to-date testing and current evidence
  • Highlight for requirements declared compliant with nothing to support them
  • Open remediation action straight from gap, and program note in dashboard and committee report
  • Control test, reviews, validity, due diligence and training validity, deadline for action
  • Horizon of three to twenty-four months, with the losers at the top
  • Renewed diligence and redone training do not appear in the old version
  • Export to calendar with reminder seven days in advance, without duplication when reimporting
  • Spreadsheet export, with ethics hotline deadlines kept out of the calendar for confidentiality
  • Library with frameworks and obligations for the events sector in Brazil, ready to import
  • Requirement with origin, criticality and verification frequency
  • Applicability declared by branch: obligation that is not valid for the unit does not become a pending obligation
  • Evidence attached to the requirement, with validity and expiration notice
  • Compliance status per requirement, with written reason
  • Compliance panel by framework, with the proportion met
  • Internal control linked to the requirement it addresses and the risk it mitigates
  • Type, frequency and responsible party declared in the control design
  • Effectiveness test with sample, results and evidence
  • Ineffective result opens a pending issue with owner and deadline, it is not just recorded
  • History of tests per control, to see if it has gotten worse or better
  • Indicator of effective controls against the total tested
  • Risk assessed by probability and impact, with calculated level
  • Classification by configurable range, recorded in the evaluation
  • Heat matrix with count per cell, clickable to filter
  • Controls linked to risk, with visible mitigation effect
  • Declared treatment: mitigate, transfer, avoid or accept
  • Acceptance requires justification, because it is the company assuming the risk on purpose
  • Versioned policy: publishing freezes the version and acceptance points to the accepted version
  • Acceptance registered by person, with date and origin
  • Collection from those who are pending, without a list made in hand
  • Mandatory training with workload and evidence of completion
  • Term of training, with notice before expiry
  • Policy revocation requires written reason
  • Own permission that the administrator profile does not bypass
  • List of investigators by case: anyone who is not on it receives the same response as a non-existent case
  • Mandatory Read Track: If access registration fails, reading is refused
  • Protocol generated for the whistleblower to follow without identifying themselves
  • Anonymous report accepted, with the same investigation flow
  • Conclusion classified as valid, unfounded or inconclusive, with the reason
  • Audit of accesses of the entire channel for the manager, with reading after hours and reading without current designation
  • The audit consultation is also recorded in the trail
  • Third-party due diligence with questionnaire, documents and risk note
  • One-click consultation with CEIS and CNEP using CPF or CNPJ, with the result recorded in the registry
  • Empty query never undoes a hand-marked sanction
  • Periodic reevaluation, with warning when validity expires
  • Declaration of conflict of interest and gift received, per person and per period
  • Severity incident, investigation and remediation action with owner and deadline
  • Action linked to the control test that originated it, when applicable
  • Verification of the effectiveness of the remediation, so that the action does not close just because it was carried out
  • Twenty-three named checkers, each checking a specific program condition
  • Automatic execution every day, with notification only of new alerts of high or critical severity
  • Monitored traceability gaps: compliant without evidence, critical requirement without control, control without owner
  • Adjustable parameters on the screen, within the limits of each tester
  • Alert opened when the condition appears and closed alone when it disappears
  • Alert handling with classification, including false positive with reason
  • Execution registered, to distinguish an alert that disappeared from a routine that did not run
  • Panel with what is open, by gravity
  • No rules accept free consultation: flexibility that does not pay for the injection risk
  • Universo auditável por processo e unidade, com risco inerente e data da última auditoria
  • Plano anual montado pela priorização de risco, versionado e aprovado na pauta do comitê
  • Cadastro de auditores com área de origem e impedimentos declarados
  • Trabalho de auditoria com escopo, período, equipe e status
  • Programa com procedimentos por objetivo de controle
  • Papel de trabalho com amostra, evidência anexada, conclusão e revisor diferente de quem preparou
  • Trabalho que não conclui com papel sem revisão nem com achado sem plano do gestor
  • Achado com criticidade, recomendação, plano do gestor, prazo e dono
  • Achado virando ação no mesmo fluxo de remediação, com follow-up e alerta de vencido
  • Linha de defesa declarada em controle, risco e teste, com a área de quem testou registrada
  • Auditor impedido de testar controle da própria área, com exceção registrada quando necessária
  • Auditoria da qualidade aparecendo no universo sem sair do módulo de Qualidade
  • Indicadores de risco calculados por fórmula nomeada em código, lendo inadimplência, chargeback, incidentes graves, rotatividade, acidentes e não conformidades críticas
  • Apetite e tolerância por indicador, com medição diária, série histórica e tendência
  • Alerta automático quando o indicador sai da faixa, pelo monitoramento contínuo
  • Bibliotecas de ISO 27001, COSO e SOX carregadas por empresa e mapeadas para os controles internos existentes
  • Cobertura por framework calculada da matriz e Declaração de Aplicabilidade gerada
  • Painel do conselho com mapa de calor de risco residual, tendência dos indicadores, execução do plano e achados vencidos
  • Exportação do painel em PDF, guardada com o retrato do período
  • Conflict matrix written in code, reviewable by diff, using only permissions that exist in the panel
  • Conflicts such as booking and approving payables, approving purchases and registering suppliers, managing users and auditing
  • Reads the roles and direct permissions of every active user in the company
  • For each conflict, which role grants each side, so the fix is removing a role instead of guessing
  • Full access shown once per person, highlighted, instead of turning into dozens of conflicts
  • Active login of an employee let go in HR, linked by user or email, without counting people who were rehired
  • Sensitive permission without two factor authentication
  • Sensitive permission for someone who has not logged in for longer than the configured limit
  • Payable open or paid in the period to a supplier with rejected, sanctioned or expired due diligence
  • The most recent due diligence of each supplier counts, not the first record
  • Any part the environment does not have installed shows as unavailable, without taking down the others
  • CSV export for the periodic access review
  • Five daily checks: conflicting duties, former employee with access, sensitive without second factor, sensitive unused and payment to a restricted third party
  • Record of processing activities under art. 37 of the LGPD, with purpose, legal basis, data categories, data subjects, sharing, retention and processor
  • Fourteen processing activities suggested from the active modules: graduate registration, billing, photos and galleries, facial biometrics, tickets, HR, field staff and CRM
  • Suggestions shown before anything is saved, and adopting one creates the editable row
  • Flags for sensitive data, children and teenagers' data and international transfer
  • Impact assessment per processing activity, with likelihood and impact risks and the calculated level
  • Security incident involving personal data, with affected data subjects and categories and relevant risk assessment using the criteria of ANPD Resolution CD/ANPD 15/2024
  • A 3 business day deadline to notify the ANPD and data subjects, counted from the business day after awareness
  • Prefilled notices for the authority and data subjects, flagging the placeholders still missing
  • Deciding against the relevant risk criteria requires a longer justification
  • Privacy record opened straight from the Continuity incident room, with title, description and awareness already filled in
  • Data subject requests from the privacy portal and the app read live, with the 15 day deadline
  • Four checks: ANPD deadline, sensitive processing without impact assessment, processing with overdue review and late data subject request
  • Three types: policy acceptance, annual conflict of interest declaration and training acknowledgment
  • Audience by active users, by role or by HR employees with an email
  • Deadline, launch, closing and exempting people who do not need to answer, with a reason
  • A personal link per person, with the token stored only as a hash and killed as soon as the answer arrives
  • Answer on the public portal, with no login, and the same response for a wrong or nonexistent token
  • Acceptance saved in the per version acceptance table, with date and source, respecting one acceptance per version
  • A declaration with no conflict is approved on the spot, and one with a conflict goes to the review queue
  • Training acknowledgment recorded for someone to check, not as an approval
  • Live participation per campaign, person by person
  • Reminder to the manager through the bell and resending pending links
  • Check for campaigns past their deadline with incomplete participation
  • Agenda built on the spot with open critical and high alerts
  • Overdue ethics hotline cases included only as a count, with no protocol number
  • Risks above appetite, late remediation actions and the program assessment score
  • Meeting scheduled and held, with attendance recorded and minutes
  • Resolution with owner and deadline that creates the remediation action in the same step
  • History of meetings and decisions, so the next meeting follows up on the last one
  • Ethics hotline statistics in the report with cells of 1 or 2 cases shown as "<3"
  • Case category not crossed with severity in the report, on screen or in CSV

Want to see Compliance Control in your operation?

See a demonstration using your own numbers, with no obligation. A conversation will help you decide whether the module solves your needs.