Regulatory compliance
Compliance frameworks are configured, not compiled in.
The regulator, the inspection framework and the statutory clock all change by jurisdiction. None of them is hardcoded.
Configurable compliance
Compliance frameworks are configured, not hardcoded
The regulator, the inspection framework, the background-check scheme, the professional register and the statutory clocks are all per-jurisdiction values resolved from a governed record.
| Area | What commvita does |
|---|---|
| Clinical safety | DCB0129 and DCB0160 hazard log, clinical risk management and a safety case, with the hazard raised alongside the change it assesses |
| Audit trails | Append-only, SHA-256 hash-chained and re-verified on every read, so tampering is evident rather than merely prohibited |
| Information governance | Asset register, records of processing, retention and disposal with legal hold, and data lineage |
| Data protection | Lawful basis per purpose, special-category handling, and impact assessments as a register rather than a folder |
| Consent management | Recorded, versioned and withdrawable, with withdrawal shown rather than the record hidden |
| Access control | Role hierarchy, organisation scope, delegation with expiry, and default deny on special-category domains |
| Cyber security | Cyber Essentials controls, ISO 27001 Annex A mapping and a remediation roadmap that states its own gaps |
| Regulatory reporting | A registry of every statutory return with deadlines computed on the correct working-day or calendar basis |
| Research governance | Ethics approval, access requests, an extract ledger and re-identification risk controls |
| Data residency | Recorded per jurisdiction and surfaced in the API — and the API states plainly that recording is not enforcement |
Governance
Know what you hold, control how it is used, prove it on demand.