Regulatory obligation assurance

LCA Hub

Know which obligations apply to your firm, whether your own policies meet them, and where the evidence sits. Not in someone's spreadsheet. On the record.

Obligation register

Day one

The obligation register arrives loaded, so the first assessment happens before any configuration programme does.

Policy coverage

Your wording

Coverage is measured against the policies your firm actually wrote, not against a summary of them.

Decision log

Every decision

Who decided what, when, and on what basis, kept so it can be reconstructed years later.

The problem

Most of compliance is not the thinking. It is the assembly.

The obligations are knowable. The policies exist. The evidence exists somewhere. What is missing is the managed relationship between the three, and the cost of that gap lands on one person.

The mapping lives in a spreadsheet

One person owns the workbook that says which policy meets which obligation. It is months out of date, nobody else can defend it, and it leaves the firm when they do.

Evidence is assembled on demand

The examiner asks for proof and the team starts digging through the share drive. The cost is not the evidence. It is finding it, and then proving it was current at the time.

Posture is a feeling, not a number

The board asks how compliant the firm is. The honest answer is a judgement, expressed with confidence, backed by nothing that survives a challenge.

AI arrived and nobody can evidence how it decides

The firm now has AI systems sitting in regulated decision paths, an EU AI Act deadline against them, and no register, no oversight checkpoint and no decision log to show for it.

What this is

The measured relationship between the rule and your policy.

It is

An assurance platform for legal, compliance and audit

  • A managed register of the obligations a regulation places on your firm.
  • A measured view of whether your own written policies meet them, with the reasoning kept.
  • A record of the evidence that proves each obligation, and who is responsible for it.
  • Assurance work routed to a named owner, approved by someone else, and dated.
It is not

Four things people expect it to be

  • A document management system. Keep the documents where they are.
  • An enterprise suite that models every risk and process in the firm before it produces anything. That programme is the one that is still being configured a year in.
  • A surveillance or trade monitoring system.
  • A filing agent. It does not submit returns to a regulator on your behalf, and it does not make the compliance decision. A named person in your firm does that.

Repositories store policies but never tell you whether they meet the law. Suites model the world but cost a year to configure. LCA Hub is deliberately the bridge between them.

What changes

The same questions, with an answer you can hand to someone.

Today With LCA Hub
TodayWe do not actually know which of our policies meets which obligation.
With LCA HubYou do, with a status and a written rationale behind every one.
TodayWhen the regulator asks for evidence, we go digging through the share drive.
With LCA HubYou open the obligation and read what evidence it requires, where it lives, who owns it and whether it is on file.
TodayThe mapping is one person's workbook, and it is indefensible the day they leave.
With LCA HubIt is a system record with ownership and dates, which anyone can pick up and defend.
TodayCompliance posture is a feeling.
With LCA HubCoverage per thematic area, severity per finding, and a record of how each was reached.
TodayThe examination story gets assembled in a panic, three weeks before the visit.
With LCA HubIt is assembled continuously, as a by-product of the work being done anyway.
Capabilities

What you get.

Six things the platform does, described as what they produce for you. Open any entry.

The record it produces06 entries

The regulation and the obligations it places on your firm are already there, each with its article reference and a written statement of what meeting it looks like.

Why it mattersNobody has to agree a taxonomy in a workshop before the first assessment can happen.

Held in the record

Your own policies are assessed against the obligations in scope, and each obligation ends up with a status, a severity where it is not met, and the reasoning that produced it.

Why it mattersCoverage becomes something you measured, rather than something you asserted.

Held in the record

Ask what an article requires and get a plain answer with the passages it was built from shown beside it, so the answer can be checked rather than taken on trust.

Why it mattersCounsel reads the source and the obligation from one place, and nothing is asserted about the regulation without a citation.

Held in the record

For each obligation: what has to be on file to prove it, who is responsible for producing it, how long it has to be kept, and whether it is there today.

Why it mattersThe examiner question gets answered from a record instead of from a search.

Held in the record

Audits and assessments are assigned, reviewed and approved through a chain, and the person who raises an item cannot be the person who approves it.

Why it mattersIndependence is evidenced rather than asserted, which is the part an auditor actually tests.

Held in the record

Examiner requests are logged with their reference, deadline and owner, and the response is drafted in the record and linked to the obligations and evidence it relies on.

Why it mattersCorrespondence leaves individual inboxes, and the file is complete when it is submitted rather than reassembled afterwards.

Held in the record
How it works

Understand, decide, act, prove.

Four steps. The same four whether the subject is an AI Act obligation, a policy review or a regulator request.

1

Understand

Choose the regulation. The obligations it places on your firm are already loaded and readable, with the article text alongside. Ask what an article requires and read the answer with its source.

2

Decide

Upload a policy. Coverage against the obligations in scope comes back with a status, a severity and the reasoning. You triage what matters, and a named person confirms the status that stands.

3

Act

Assign the remediation, the assessment or the regulator response to the person who owns it. It moves through review and approval, and you can see where it is and what it has cost.

4

Prove

Attach the evidence, sign it off, and keep the trail. Months later you can reconstruct what was known, who decided it, and on what basis.

The detail is in the demonstration. How coverage is determined, and why a weak match never quietly becomes a met obligation, is something we show working against one of your own policies rather than describe on a web page.
Trust and assurance

Built for people who have to defend the decision.

Human oversight

The tool proposes, a person disposes

Analysis output is advisory. A named person confirms the status that stands on the record, and the reasoning behind the proposal is visible while they do it.

Audit trail

Evidence and audit trail

Every record carries who created it, who changed it and when. Assisted assessments and questions put to the platform are logged, which is exactly what an AI Act examiner asks to see.

Data residency

Your tenancy, your data

Deployed in your environment or in ours, by region, so data that must stay in the EU stays in the EU. Each customer is isolated, and one organisation can separate its own legal entities inside a single instance.

Self-governance

We govern our own AI

We keep a control register for the AI inside the product, covering oversight, logging, grounding, access and separation of duties. We will walk it with your technical team, and we will tell you which controls are in place and which are not.

Where accountability sits. LCA Hub identifies the obligations that apply, measures your policies against them with the reasoning kept, records who decided what and when, and holds the evidence. It does not ensure or guarantee compliance, and no platform can. Accountability for compliance stays with your organisation, which is where the regulator puts it.
Who it is for

Written to the person whose name is on the attestation.

CCO
Signs the attestation

Chief compliance officer

Posture becomes a number per regulation and per thematic area that survives being challenged, and the answer to the board question traces back to article text.

CM
Owns the mapping

Compliance manager

The obligation to policy mapping stops being a personal spreadsheet, and the remediation list arrives ranked with the next action attached to each finding.

IA
Owns the opinion

Head of internal audit

One source of truth for what is required, how it was tested and where the proof is, with the approver chain evidencing independence rather than asserting it.

Operates across
Financial services Asset and investment management Insurance Providers and deployers of AI systems Compliance consultancies Regulated technology
Coverage

Regulations and thematic areas.

The EU AI Act is loaded today, with its full text held alongside the obligations and classified into the thematic areas a coverage report rolls up to. The obligation model itself is not specific to one regulation.

Regulation loaded EU AI Act
Thematic areas a coverage report rolls up to
Risk management Data and data governance Technical documentation Record keeping and logging Transparency Human oversight Accuracy, robustness, cybersecurity Quality management Conformity assessment Deployer obligations and FRIA General purpose AI models
Questions we are asked

Straight answers.

No, and nobody can. What LCA Hub produces is narrower and more useful: the obligations that apply to you, identified and cited; a measured view of whether your policies meet them, with the reasoning kept; work that is owned, dated and approved by someone other than the person who raised it; and evidence held against the obligation it proves. If a regulator asks how you reached a position two years ago, you can reconstruct it. Compliance remains your firm's responsibility, and any vendor who tells you otherwise is selling you a liability.

You should not take it on trust, and the product is built on that assumption. Nothing the analysis produces becomes the position of record until a named person confirms it, and the reasoning is on the screen while they decide. Answers about the regulation come back with the source passages beside them so they can be checked against the text. Every assisted run and every question is written to an audit log. The concession is the point: a tool that quietly marked things compliant would be worse than no tool at all.

No. LCA Hub sits above the operational stack rather than replacing it. The document store keeps the documents, the identity provider keeps the identities, the regulator portals keep the filings. What the platform owns is the obligation model and the assurance record on top of them. Integration with what you already run is scoped during the pilot.

The register is loaded before you start, which removes the phase that usually consumes the first year: agreeing a taxonomy and populating it before a single obligation has been assessed. A policy uploaded is a policy assessed. That is the shape of the first working session, and it is what we would rather show you than describe.

In your tenancy, in the region you choose, deployed in your own environment or in ours. Each customer's data is isolated, and an organisation running several legal entities can separate them inside a single instance. We will answer the residency and access questions in writing during the pilot rather than in a marketing sentence.

Next step

Bring one of your own policies.

The demonstration that tells you the most is the one run against a policy your firm actually wrote, measured against a regulation you actually have to meet. That is what we would rather do than present slides.

What happens next A short qualifying call to understand which regulation and which policies matter to you, then a working demonstration against your own scenario. Typically 45 minutes.

FAQs

What is LCA-Hub?+

LCA-Hub is a legal, compliance and audit automation platform that turns dense regulation into a managed register of obligations, the policies that satisfy each one, and the evidence that proves it. It ships pre-loaded with the EU AI Act, so a team starts from a structured obligation set rather than a blank page. The aim is to make a regulation workable on day one.

What is an obligations register, and why does it matter?+

An obligations register is a structured list of every legal and regulatory requirement that applies to your organisation, each linked to the control or policy that meets it and the evidence that demonstrates compliance. It matters because auditors and regulators increasingly want to see the thread from a specific rule to the proof you follow it. A register is what lets you answer “show me” instead of “trust me”.

Does LCA-Hub cover the EU AI Act?+

Yes. LCA-Hub comes pre-loaded with the EU AI Act (Regulation (EU) 2024/1689), broken into its obligations so you can map each one to your systems and controls. That includes the duties already in force, such as the Article 5 prohibitions and the Article 50 transparency rules, alongside the high-risk obligations that the Digital Omnibus deferred to 2 December 2027. You inherit the structure and spend your effort on the mapping.

How does obligation mapping reduce audit effort?+

When every obligation is already linked to its policy and evidence, an audit becomes a matter of retrieving what is on file rather than reconstructing it under time pressure. Evidence sits ready. Teams that keep the register current spend far less time preparing for each audit cycle, and the saving compounds because the same register serves every framework you are assessed against.

Can LCA-Hub handle more than one regulation?+

Yes. The register is framework-agnostic, so the same obligation-to-evidence structure works across the EU AI Act, GDPR, DORA and the sector rules you add. Where two regulations demand similar controls, mapping them once and reusing the evidence saves duplicating the work. One register, many frameworks.

How does LCA-Hub help?+

LCA-Hub gives you a live obligations register, the policy and evidence links that satisfy each obligation, and audit-ready reporting drawn straight from it, pre-loaded with the EU AI Act. If an auditor asked you to trace one obligation to the evidence that proves it, how long would that take today? Book a demo and put your hardest obligation to the test.