01 ViVE Comply

Compliance and controls

A rule is only a control if something checks it

ViVE Comply lets compliance teams define what must happen, then check actual execution against those rules. Every case in scope can be evaluated against the rules that apply to it, with the supporting evidence available for review.

Overall SLA, five days: 2.4M onboarding cases evaluatedshare of open and closed cases
met the promisestill open, still movablealready missed
Five rule types
out of the box
configured, not coded
Every case
evaluated
no sampling
Risk flagged
before breach
while the case can still move
Evidence down
to the event
ready for audit

02 What Comply is for

Sampling tells you about the sample. Comply checks the population in scope.

Periodic sampling can miss what happened outside the sample. ViVE Comply evaluates applicable rules across the full population in scope using the same process data as the rest of RE-ViVE.

  • Which open cases are at risk of missing the SLA?
  • Where is a mandatory step being skipped, and by whom?
  • Are approvals happening before the thing they approve?
  • Has anyone raised and approved the same transaction?
  • Which control has degraded since last quarter?
  • Can we show the auditor the evidence, not the policy?
  • See risk before the breach

    Open cases can be evaluated against their thresholds while work is still in progress, so teams can see which cases are approaching a breach and act sooner.

  • A control you can demonstrate

    Each rule has a definition, a population, a result and supporting execution evidence.

  • Audit evidence without a fire drill

    When a review request arrives, the supporting evidence is already available: the case, rule, activity, timestamp and actor behind the result.

03 The five compliance types

Configure controls without custom development

Five core rule types are configured by selecting activities and setting the relevant thresholds or conditions — without custom scripting.

overall sla

End to end, against the promise

A threshold on total elapsed time for the case. Open cases are projected forward; closed cases are settled.

SLA 5 d5.0 d+2.1 dtotal elapsed time per case

breach — 7.1 d against a 5 d promise

activity sla

A threshold on a single step

Each activity carries its own limit, so a slow step is attributable even when the case as a whole still clears.

CheckScreenApprovetime used against each step limit

breach — screening 6.2 d against a 2 d limit

mandatory activities

A step that must always happen

Nominate the activities that cannot be absent. Comply finds the cases that completed without them.

RaiseCheckKYCOpenabsentrequired activity never recorded

violation — 4,102 cases closed without screening

sequence activities

Order that has to hold

Declare that one activity must precede another. Cases where the order inverted are listed, not averaged away.

designedApproveReleaseobservedReleaseApprovepayment released before sign-off

violation — 812 releases preceded their approval

segregation of duties

Two steps, two people

Pair the activities that must not share an actor. Comply checks the resource on each event, including automated ones.

RaisedApprovedu.patelu.patelsame actor on both sides

violation — 37 transactions raised and approved by one user

x-r and x-s controls

Two additional control templates

X-R and X-S are available as additional control templates alongside the five core rule types. Set the scope and conditions, and the applicable cases are evaluated using the same Execution Data Model.

COPY NEEDED: confirm what X-R and X-S expand to and the exact rule each enforces, so this card can describe them as specifically as the five above.X-R controlX-S controlevery case

out of the box — no development required

ViVE Comply reads the same Execution Data Model as ViVE Optim and ViVE Insights, so control results, process measures and dashboards use the same underlying process data.

04 Risk before it happens

Finding a breach early gives you time to act

When source data is refreshed during the life of a case, open work can be checked against its thresholds before the case closes — giving teams time to reassign, escalate or expedite.

SLA thresholdSLA — day 5now markernow — day 3.2elapsed and projectedelapsedprojected, on current paceday 6.8axis012345678flagged 1.8 days before the breach, while the case can still be reassigned or expedited
The same projection runs across the open population, so the question stops being how many cases breached last month and becomes how many are about to.
  • One rule for historical and current monitoring

    Use the same rule definition for historical reporting and current monitoring when the underlying data is available.

  • Exposure, not just counts

    Breaches carry the value, customer and product behind them, so a hundred small cases and one large one are told apart.

  • Trend on the control itself

    Whether attainment is improving or drifting, period on period, on the population rather than a sample of it.

05 Evidence for audit

Every result drills to the evidence behind it

A control result includes the rule, population, outcome and the underlying execution evidence. Reviewers can trace a result back to the activities, timestamps and actors that produced it.

Control evaluation, period to 31 Aug2.4M cases in scope · 0 sampled
controlrulecaseresultevidence
SLA-01Overall SLA 5 dONB-4471902breach41.2 d elapsed
ACT-04Credit check ≤ 2 dORD-991027pass1.4 d
SEQ-03Approve before ReleaseORD-882140violationrelease 14:02, approve 16:41
SOD-02Raise / approve separationINV-77219violationu.patel on both events
MAN-01KYC screening presentONB-4102338violationactivity absent, case closed
ACT-04Credit check ≤ 2 dORD-991184pass0.6 d

For controls configured across the full population, every case in scope is evaluated against the applicable rule, and each result can open the execution sequence behind it.

The value is population-level visibility: attainment reflects the cases in scope rather than only a selected sample.