What this page covers
Regulatory Compliance explains the Smartflow controls that support audit, data sovereignty, and regulated loan operations.
Before you start
- Your compliance owner has confirmed the applicable jurisdiction.
- Your IT owner has confirmed the deployment boundary.
- Your business owner has confirmed which workflows are in scope.
Control areas
- Data sovereignty - Smartflow is deployed inside the approved customer environment.
- Human oversight - Users review and approve extracted data before it is accepted.
- Source evidence - Extracted fields link back to source document evidence.
- Access control - Roles and permissions limit what users can see and do.
- Review traceability - Review and approval activity is captured for audit support.
Regulatory alignment reference
- MAS TRM / RODS - Usually asks for data governance, traceability, and operational control. Smartflow supports this through evidence-linked fields and bank-controlled deployment.
- HKMA operational resilience guidance - Usually asks for controlled third-party and operational risk management. Smartflow supports this through dedicated deployment and controlled access.
- APRA CPS 234 / CPS 230 - Usually asks for information security and operational risk controls. Smartflow supports this through role-based access, review traceability, and customer-controlled infrastructure.
- EU AI Act - Usually asks for logging, transparency, and human oversight for AI-supported processes. Smartflow supports this through human review, source evidence, and activity traceability.
Steps
- Confirm which regulatory frameworks apply.
- Confirm which Smartflow workflows are in scope.
- Confirm where documents and extracted data will be stored.
- Confirm who can review, approve, export, and administer data.
- Confirm the audit evidence your institution needs to retain.
- Review the deployment and workflow setup with compliance before pilot start.
Tips
- Treat this page as a planning aid, not legal advice.
- Keep compliance, IT, and operations owners aligned on the same scope.
- Use field-level source evidence during internal reviews.
- Escalate jurisdiction-specific questions to the Smartflow and bank compliance owners.
Troubleshooting
- Compliance asks for a specific control mapping -> Confirm the framework and request a scoped response.
- Audit evidence is incomplete -> Check that the workflow includes review and approval steps.
- A user has too much access -> Review the role assignment and group membership.