Skip to content

Regulatory Intelligence

Regulatory Intelligence is OrviQ's answer to a question every compliance function has to answer continuously: has anything changed that we need to act on?

It watches the sources you tell it to watch, detects that something new has appeared, classifies it with AI assistance, and puts it in front of a person. It does not decide that a change matters, and it does not create obligations.


Why it exists

Most compliance failures that begin outside the organisation begin the same way: a regulator published something, and nobody noticed in time. The manual alternatives — an inbox rule, a subscription newsletter, a monthly check of a website — fail quietly and are impossible to evidence.

Regulatory Intelligence makes the monitoring itself auditable. You can show which sources you watch, when each was last checked, what was found, who triaged it, and what happened next.


Who uses it

RoleUse
Compliance AnalystDay-to-day triage of the change feed
Compliance ManagerDeciding which sources to monitor and reviewing triage decisions
Regulatory AffairsRegistering new authorities and sources as the perimeter changes

Requires the Regulatory Intelligence entitlement.


Where it fits in OrviQ

Note the two human gates. Neither is optional, and neither can be performed by the system.


Core concepts

Source. A monitored publication point. Each source carries an authority, a source type and a status.

Source typeWhat it is
webpageA page that is polled for change
document_feedA structured feed of published documents
manualA source whose updates are recorded by a person
Source statusMeaning
activeIncluded in sweeps
pausedRetained but not swept
retiredKept for the historical record, no longer monitored

Sweep. A tenant-scoped run across active sources. Sweeps can be triggered on demand for a single source ("check now") or across the tenant. A sweep is a technical execution — it produces events, and it deliberately does not create entries in the GRC Calendar.

Regulatory Change event. The record that something was detected: which source, when, what changed, and an AI-assisted classification of what kind of update it appears to be. Events are the unit of triage.

Triage. The human decision on an event. An event can be accepted and sent onward to extraction, or dismissed with a reason. Dismissed events are retained, not deleted — being able to show that you considered something and consciously decided it did not apply is itself evidence.


What the AI does, and does not do

AI classifies detected updates to help you prioritise the queue. Its output is advisory.

AI doesAI does not
Summarise what appears to have changedDecide the change applies to you
Suggest a classification for the updateCreate requirements
Prioritise the triage queueDismiss anything
Extract candidate requirements when you send an item to Smart ExtractPublish a candidate as a requirement

See AI in OrviQ for the platform-wide authority boundary.


Getting started

  1. Identify your perimeter. List the authorities whose publications bind you, and the specific pages or feeds where they publish.
  2. Register sources in Regulatory Sources (/reg-intel/sources), one per publication point. Requires reg_intel.manage.
  3. Run a first sweep to establish a baseline. The first sweep of a new source establishes what "unchanged" looks like.
  4. Work the change feed in Regulatory Changes (/reg-intel/changes) as events arrive. Requires reg_intel.triage.
  5. Send relevant changes to extraction so the text becomes candidate requirements.

Permissions

PermissionGrants
reg_intel.readView sources and detected changes
reg_intel.manageRegister and maintain sources
reg_intel.triageAccept or dismiss detected changes
reg_intel.sweepRun the tenant-scoped source monitoring sweep

Example

A bank monitors three authorities. Its Regulatory Sources register holds nine sources: three circular pages, three consultation pages and three enforcement-notice feeds.

A sweep detects a new circular on outsourcing notification thresholds. The event appears in the change feed with an AI summary noting it appears to amend notification timelines.

The Compliance Analyst reviews it, confirms it is in perimeter, and sends it to Smart Extract. Extraction proposes eleven candidate requirements. The Analyst publishes eight, merges two and rejects one as duplicative of an existing obligation.

Those eight requirements then enter the normal pipeline: scope, applicability, mapping, evidence, assurance. Nothing about the bank's compliance position changed at the moment of detection — it changed when people made decisions, and each of those decisions is on the record.


Troubleshooting

"A sweep runs but no events appear." Either nothing changed, or the source is paused. Check the source status and its last-checked timestamp.

"Events keep appearing for cosmetic page changes." Some pages carry dynamic elements. Prefer a document feed where the authority offers one, or move the source to manual and record updates deliberately.

"I dismissed something I should not have." Dismissed events are retained and can be reviewed. Dismissal is a recorded decision with an actor, not a deletion.

"Regulatory Sources is not visible in navigation." The Regulatory Intelligence entitlement is not enabled for your tenant, or you lack reg_intel.read.


OrviQ Enterprise Governance, Risk & Compliance Platform