Citation-first compliance / regime-agnostic engine
forAI Risk Management
Source-cited regulatory gap analysis. Every claim in your report carries a verbatim quote and a clause path back to the statute it comes from. Currently shipping for data protection (UK GDPR), AI systems (EU AI Act, applying from 2 August 2026), digital assets (MiCA), building safety, construction and employment; we build the rule set for your regime as part of your first engagement.
The problem
One
Engine
Primary-legislation compliance, made readable
Most compliance regimes share the same problem. The duties live in primary legislation that is dense, cross-referenced, and not designed for the people who have to comply with it. The gap between “we are doing the right things” and “we can demonstrate to the regulator that we are doing the right things” is where the exposure lives.
The status quo for smaller firms is a spreadsheet. A compliance manager downloads the statute, tries to map duties onto operational reality, and discovers the documentation drifts behind the practice. The next interaction with the regulator is the first time anyone tests whether the mapping was right.
The advice market is thin at the SME end.Specialist lawyers and consultants are available, but their per-hour rates do not scale to a single building, a single AI system, or a single payment product. The gap analysis is the bit that does not need to be a lawyer's job, as long as every claim cites the statute.
The compliance-tech market sells horizontal automation. Vanta, Drata, OneTrust automate evidence collection for security frameworks. None of them does primary-legislation gap analysis for the regimes where the duties live in statute and the evidence is your operational records. That is the gap Complian fills.
How it works
01
Declare your profile
Tell us your firm, your role, the regulatory regime you operate under, and the evidence you already hold. Two minutes, three steps. No account required.
02
Engine runs the gap analysis
Layer 1 deterministic rules filter the obligations that apply to your profile. Each retrieves the verbatim statutory clause from our ingested corpus. An LLM classifies your declared evidence against each obligation with a citation-first output schema.
03
Receive a per-customer report
Personalised gap analysis with every claim traced to the source clause it derives from. Met / Partial / Gap / Uncertain status per obligation, plus a "what’s coming for you" panel of relevant forthcoming regulatory change.
What we cover today
Live
UK GDPR (retained Regulation 2016/679)
Controller and processor duties: lawful basis, consent, special-category data, data-subject rights, records of processing, security, breach notification, DPIAs and DPO designation. 22 deterministic rules across the operative articles, every claim cited to legislation.gov.uk.
Live
EU AI Act (Regulation 2024/1689)
Provider and deployer duties for AI systems: prohibited practices, high-risk classification, risk management, data governance, technical documentation, human oversight, conformity assessment, registration, post-market monitoring and serious-incident reporting. 19 deterministic rules, every claim cited verbatim to EUR-Lex. General application from 2 August 2026.
Live
MiCA (Markets in Crypto-Assets, Regulation 2023/1114)
Duties for crypto-asset service providers and token issuers serving the EU: authorisation, white papers, marketing communications, governance, prudential safeguards, safekeeping of client assets, complaints and conflicts. 20 deterministic rules across Titles II–V, every claim cited verbatim to EUR-Lex.
Live
UK Building Safety Act 2022 Part 4
Principal Accountable Person and Accountable Person duties for higher-risk buildings in occupation: the Act plus its four operative statutory instruments. 29 deterministic rules, every claim cited to legislation.gov.uk.
Live
Construction (Design and Management) Regulations 2015
Client, Principal Designer, Principal Contractor, Designer and Contractor duties across the project lifecycle. 14 deterministic rules, every claim cited to legislation.gov.uk.
Live
Employment Rights Act 1996
Core employer duties for England employers: written particulars, itemised pay, deductions, time off, notice, fair dismissal and redundancy. 17 deterministic rules, every claim cited to legislation.gov.uk.
Build queue
UK cryptoasset regime (FCA)
Final FCA rules published 30 June 2026, regime expected in force 25 October 2027. Our UK digital-assets rulebook is scaffolded and activates against the final Handbook text. The first customer in the regime shapes it as the SME-review reference.
We do not list regimes we have not committed to. If you want a specific regime added, say so on the discovery call and we will scope it in writing before you commit.
Why it's different
Questions
Which regulatory regimes do you cover today?
Six live today: the UK GDPR (controller and processor duties), the EU AI Act (provider and deployer duties for AI systems, applying from 2 August 2026), MiCA (crypto-asset service providers and token issuers serving the EU), the UK Building Safety Act 2022 Part 4, the Construction (Design and Management) Regulations 2015, and the Employment Rights Act 1996. The UK cryptoasset regime (FCA final rules published June 2026) is scaffolded next. Every other regime is built per first customer: we ingest the relevant primary legislation, author the Layer 1 rule set, and run it against your profile as part of your first engagement.
How can the same engine handle regimes as different as Building Safety and Financial Services?
The engine separates methodology (retrieval, applicability filtering, LLM classification, verbatim verification) from the regime-specific corpus (the primary legislation and the deterministic rules that map a profile to applicable obligations). Methodology composes. Per-regime work is the rule-authoring and the SME review: substantial but linear, not architectural.
Why should I trust the output?
Every claim is anchored to a verbatim quote from the source statute that must pass a substring-match check against our ingested corpus before it appears on your report. Hallucinated obligations cannot pass that gate. Combine that with a per-customer applicability layer so your report contains only obligations your profile actually falls under.
What happens if my industry is not yet covered?
You give us your industry on the discovery call. We scope the rule-set build (which primary legislation to ingest, which roles and building types matter, what a representative profile looks like). You become the first customer in that regime at preferential pricing in exchange for SME-review reference. Typical first-regime build: 30-50 hours of engineering plus an SME review.
Are you a lawyer or a regulator?
Neither. Complian is an independent compliance-tech project. The report is decision-support that traces every claim back to the statute. For interpretation of contested provisions affecting your specific situation, you need a regulatory lawyer or domain SME for your regime. We name this on every report.
How much does this cost?
Pricing is being calibrated against the first cohort of customers per regime. The first customer in each regime gets preferential pricing in exchange for being the SME-review reference. The discovery call is the right place to scope this for your situation.
How is this different from Vanta, Drata, or OneTrust?
Those are horizontal compliance-automation platforms built on integrations: they read your system state and check it against security-control frameworks (SOC 2, ISO 27001). Complian is a regulatory gap-analysis engine: citation-first, designed for primary-legislation regimes where the obligations sit in statute and the evidence is your operational records. Even where coverage overlaps on paper, as with data protection, the analysis is different in kind: we read the UK GDPR as statute and trace every claim to the article it comes from. Different shape, different buyer.