Skip to main content

What this page covers

Regulatory Compliance explains the Smartflow controls that support audit, data sovereignty, and regulated loan operations.

Before you start

  • Your compliance owner has confirmed the applicable jurisdiction.
  • Your IT owner has confirmed the deployment boundary.
  • Your business owner has confirmed which workflows are in scope.

Control areas

  • Data sovereignty - Smartflow is deployed inside the approved customer environment.
  • Human oversight - Users review and approve extracted data before it is accepted.
  • Source evidence - Extracted fields link back to source document evidence.
  • Access control - Roles and permissions limit what users can see and do.
  • Review traceability - Review and approval activity is captured for audit support.

Regulatory alignment reference

  • MAS TRM / RODS - Usually asks for data governance, traceability, and operational control. Smartflow supports this through evidence-linked fields and bank-controlled deployment.
  • HKMA operational resilience guidance - Usually asks for controlled third-party and operational risk management. Smartflow supports this through dedicated deployment and controlled access.
  • APRA CPS 234 / CPS 230 - Usually asks for information security and operational risk controls. Smartflow supports this through role-based access, review traceability, and customer-controlled infrastructure.
  • EU AI Act - Usually asks for logging, transparency, and human oversight for AI-supported processes. Smartflow supports this through human review, source evidence, and activity traceability.

Steps

  1. Confirm which regulatory frameworks apply.
  2. Confirm which Smartflow workflows are in scope.
  3. Confirm where documents and extracted data will be stored.
  4. Confirm who can review, approve, export, and administer data.
  5. Confirm the audit evidence your institution needs to retain.
  6. Review the deployment and workflow setup with compliance before pilot start.

Tips

  • Treat this page as a planning aid, not legal advice.
  • Keep compliance, IT, and operations owners aligned on the same scope.
  • Use field-level source evidence during internal reviews.
  • Escalate jurisdiction-specific questions to the Smartflow and bank compliance owners.

Troubleshooting

  • Compliance asks for a specific control mapping -> Confirm the framework and request a scoped response.
  • Audit evidence is incomplete -> Check that the workflow includes review and approval steps.
  • A user has too much access -> Review the role assignment and group membership.

Related features