POPAYCompliance

Compliance you can prove on a Tuesday morning.

Proof that you are compliant tends to live in training records, contracts, certificates and any number of spreadsheets, each in a different system. Popay Compliance sits on top of the HR processes you already run and ties them to the standards you have to meet, so the evidence is there because the work happened.

The Popay Compliance dashboard: one compliance rate, the twelve-month trend and the active standards
One compliance rate. One sealed pack. Every quarter.
Sound familiar?

You are probably compliant. Proving it is the hard part

The obligations themselves are rarely the problem. Onboarding checklists get completed, training gets followed, contracts get signed. What is missing is the layer above it: one place where every obligation is registered, followed up and evidenced.

Pain

The proof sits in training records, contracts, certificates and a stack of spreadsheets, each in a different system.

Popay Compliance: Every requirement points at one activity your processes already complete, so the evidence is collected where the work happens.

Pain

Nobody can say how compliant you are right now.

Popay Compliance: One rate, measured against every active standard, with a target line and twelve months of trend behind it.

Pain

Every audit turns into a project: the evidence is rebuilt by hand, under time pressure, by the people who can least afford it.

Popay Compliance: The pack builds in one click, and you can let it happen on its own every quarter.

Pain

The rules keep moving. CSRD, pay transparency, the AI Act.

Popay Compliance: They live in the standards registry alongside GDPR, ISO 27001, SOC 2 and your own policies, preconfigured on request.

Four pillars

One layer of proof on top of the work you already do

Compliance sits on top of your HR processes: it ties the activities you already run to the standards you have to meet, and turns the result into a number and a pack you can hand over.

It starts in Employee lifecycle

Every requirement points at one activity in an onboarding, offboarding or mobility profile, refined per population. When that activity completes, whether somebody ticked it off or a system handled it, that completion is the evidence.

Standards and requirements

A standard, a set of requirements, each pointing at one activity, marked mandatory or advisory, with a deadline and a piece of evidence expected where it matters. Recognised standards can be delivered preconfigured on request.

One rate, and where it breaks

Of all the processes running, in how many did every mandatory step happen on time. You see that number against your own target and over twelve months, per process type. When it drops, the heatmap shows which step caused it.

The sealed audit pack

One file per quarter an auditor can read straight away: which standards apply, where you stand, and the evidence under every figure. You decide how much detail goes in and which personal data stays masked. The pack seals only once everyone who has to sign has signed, inside the company and outside it.

The audit pack

Sealed, signed, and still verified long after

Every quarter you bundle the standards registry, the trend, the GDPR audit and the evidence behind them into one pack.

Nothing has to be gathered first, because the evidence has been collecting itself all quarter. One click and it is generated, or you let it generate itself, quarter after quarter.

Once sealed it is fixed. Every sealed pack sits in one place, where Popay keeps checking the checksums and the signatures and records who opened or downloaded which one. You set how long they are kept, and a correction arrives as a new version pointing back at the one it replaces.

The audit pack library: sealed quarterly packs with their compliance rate, checksums and sign-off
What it looks like

Every role has one clear job

For the HR Director

One number that answers how your processes are doing, months before an auditor asks for it.
Sign the quarterly pack, or route it to whoever holds that role in your organisation.
Walk into a board meeting or an audit with the same figure you have been steering on all year.

For the compliance officer

Build the standards and their requirements, each one pointing at an activity that already runs.
Follow up what is overdue, per standard and per process type, without going to look for it.
Assemble the pack: the period, the sections, the evidence depth, the masking, the sign-off chain.

For the line manager

The steps you have to complete for your own team, inside the flow you already work in.
A reminder before something is late, and an escalation only when it stays that way.
No separate compliance tool to learn.

For the data protection officer

Sign the packs that carry GDPR requirements, with the GDPR audit already inside them.
Decide what stays masked before a pack leaves the building.
An access log showing who opened or downloaded which pack, and when.

For the auditor, internal or external

Download a sealed pack and verify it yourself: the checksum and the signatures travel with it.
The standards registry, the trend and the underlying evidence, in one bundle.
A correction arrives as a new version linked to the one it replaces, so the trail stays whole.
Questions

Frequently asked

How is the compliance rate calculated?+

It is the share of records in which every mandatory step was completed on time, measured against the target you set yourself. Every quarter the standing is recorded, with twelve months of trend per process type, so you can see the figure rise or fall before anyone asks for it.

Does Popay Compliance cover standards such as CSRD, EU pay transparency and the EU AI Act?+

You build your own standards and their requirements, and on request we deliver recognised standards preconfigured. Every requirement points at one activity that already runs in your HR processes, so you record what you have to demonstrate without setting up a separate track for it.

Does this work if our HR processes run outside Popay?+

Compliance reads the activities from the Popay modules, first of all from Employee lifecycle. Where a process runs in another system, that information comes in through Popay Connect. What is recorded nowhere cannot be demonstrated either.

Can an auditor verify the pack themselves?+

Yes. The checksum and the signatures travel with the pack, so whoever receives it can establish for themselves that it is untouched. The standards registry, the trend and the underlying evidence sit in the same bundle.

Is Compliance a separate module, or part of Core HR?+

It is a layer on top of the modules you already use. It reads what happens in your people's ordinary flow and turns that into the figure and the pack. Your people carry on working in the screens they know.

Curious what your own compliance rate would look like?

We will walk through your standards, your processes and what a sealed pack would hold.