A board that says it is in control is making a claim. A supervisory authority, accountant or auditor asks for the evidence behind that claim. That evidence does not consist of an intention or a policy document alone. It consists of a chain: which obligation applies, who is responsible for it, what evidence demonstrates that the obligation is being met, and which control checks that this evidence continues to hold true. If a link is missing, the claim collapses.
The question "are we in control" is therefore actually four questions. Do we know which obligations apply to us. Does someone consider themselves the owner of this. Is there evidence that demonstrates that the obligation is being met. And is there a control that periodically tests that evidence. A board that has an answer to each of these four questions can show a file. A board that only has an answer to the first question has a list — and a list is not demonstrability.
Many organisations have an overview of regulations. What is often missing is the link per obligation: who is the owner, what is the evidence, which control exists. Without that link, a list remains a collection of separate points. Who should be the owner of an obligation is not a formality in this regard; without a designated owner, an obligation disappears between departments, and no one notices until evidence is requested.
A second reason lists are not sufficient: policy and practice diverge. An organisation may have a procedure documented without that procedure being followed. What is the difference between policy and practice touches on the core of what a control actually tests: not whether a document exists, but whether practice corresponds to what the document describes. An assurance engagement asks about the latter, not the former.
The Compliance Check maps out which obligations apply and links an owner, a form of evidence and a control to each obligation. The result is not advice and not a judgement on how well an organisation is performing. It is a structure: a register showing, per obligation, who is responsible for what and how that can be demonstrated. That structure is what a board needs to show something concrete, rather than giving an assurance, when asked.
What the Compliance Check does not do: it does not tell you whether an obligation is actually being met. That remains up to the organisation and, where relevant, the accountant or assurance provider. The Check organises and makes visible where evidence and control are missing; it does not supply that evidence itself. Anyone looking for a statement on the quality of compliance will not find a judgement here. Anyone looking for a structure to make that compliance demonstrable themselves, will.
This approach does not replace legal advice on which exact threshold, deadline or article applies. Those details shift, differ per situation and depend on the precise text of the regulation as it stands at any given moment. For that current text and the precise conditions, this page refers to the source itself, not to a summary that can become outdated.
A second limit: regulation is not static. An obligations register that is correct today may be incomplete next year. How often does an obligations register change is therefore not a side issue but part of demonstrability itself: a register without a maintenance rhythm is a snapshot, not evidence of ongoing control.
A third limit concerns the European context specifically. The same European rule turns out differently per member state: different thresholds, different deadlines, different supervisory authorities. An organisation that only knows the European text and not the national implementation is missing part of the obligation. How do you keep track of national implementations without a subscription jungle describes why this point is underestimated more often than expected, and why it is precisely this national layer that surprises boards.
When an accountant or assurance provider issues a statement on compliance with reporting obligations, they ask not for an intention but for a file: source documents, a documented owner per subject, and a control mechanism that demonstrates that the process is repeatable, not one-off. What does an assurance statement require of your file describes those requirements more concretely. A board preparing for this would do well to build the file before the question is asked, not after.
This approach establishes what must happen and who does it. It says nothing about how much time that takes, or about which part of that work remains manual and which part can be automated. Anyone wondering how much capacity an obligations register, the gathering of evidence and the maintenance of controls structurally requires, and which part of that can be taken over by AI, will find the work scan from FTE TO AI for that: it calculates, per task, which part of the work qualifies for that, independent of the question of exactly which obligations apply.
The Compliance Check is under construction. Anyone who wants to use the outcome as soon as it becomes available can sign up for the waiting list.
Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.