Home/Platform/Governance Platform
GOVERNANCE PLATFORM

Put governance inside every material business action

Policy, jurisdiction context, approvals, delegated authority, segregation of duties, evidence, audit readiness, governed AI and analytics — evaluated around the action itself, not filed away as documents.

POLICY-AWAREHUMAN-ACCOUNTABLERECORD-EVIDENTSOURCE-QUALIFIED

Exact capability availability, jurisdiction coverage and implementation behavior depend on approved product and deployment status. No certification, guaranteed compliance or regulated-outcome claim is made on this page.

GOVERNANCE DECISION WORKSPACE
ILLUSTRATIVE — FICTITIOUS DATA

Supplier bank-detail change

ACT-081 · Northstar UK Ltd · United Kingdom
SOURCE STATUS
Trigger: Supplier master change request
Source: Procurement · V3 ·● CURRENT
Requested: Creditor account change
POLICY RESULT
POL-081-32■ BLOCKING
SoD Rule■ CONFLICT
Jurisdiction● COVERED - UK
AUTHORITY AND DELEGATION
Approver: Treasury authority > $50k reqd
Segregation:! REQUESTER EXCLUDED
EVIDENCE
Received:4 of 5
Missing:! BANK VERIFICATION
Restricted: 3 days
Control outcome: evidence required. Two independent reasons block progression. This is a machine-evaluated outcome, not an authorization.
HUMAN DECISION — SEPARATE AND ATTRIBUTABLE
Status: Awaiting authorized reviewer
Assigned: Maya Chen · Treasury Director
Permitted: Request evidence · escalate · reject · record exception

The control outcome and the human decision are stored as separate records. A control outcome never constitutes authorization on its own.

What is the ZoikoSuite Governance Platform?

ZoikoSuite Governance Platform is designed to bring policy, jurisdiction context, approvals, delegated authority, segregation of duties, evidence, audit readiness, governed AI and analytics into business decision workflows. It helps authorized teams understand required controls, route appropriate human review and preserve decision evidence. Exact capability availability, coverage and implementation behavior depend on approved product and deployment status.

Four facts govern this page. The ten capability labels are canonical. Governance is evaluated around business actions, not only stored as documents. Control outcomes, human authorization, evidence and audit context are distinct things. And route, availability, jurisdiction, certification and regulated-outcome claims are source-governed rather than inferred from the taxonomy.

WHY GOVERNANCE MUST BE OPERATIONAL

A policy nobody evaluates at
the moment of decision is
documentation

The difference is not whether the policy exists. It is whether the policy was evaluated against this action, by this authority, with this evidence, at this moment — and whether that is provable afterwards.

DIMENSIONGOVERNANCE AS DOCUMENTATIONGOVERNANCE AS OPERATION
Where the policy livesA repository, reviewed periodicallyEvaluated against the specific action, with its version recorded
When it appliesWhen someone remembers to checkAt the moment the action is proposed
Who may decideAssumed from job title or org chartEvaluated against delegated authority, scope, limit and effective dates
Conflicting dutiesDetected during a later review, if at allEvaluated as a segregation rule before the decision is offered
EvidenceAssembled retrospectively for an auditRequired, tracked and reported as counts and states while work proceeds
ExceptionsAn email thread or a spreadsheet rowA record with owner, compensating control, approval, effective period and expiry
JurisdictionA country listCoverage state plus source, effective date and review requirement at point of use
Proof afterwardsReconstructed from systems and memoryA decision record retaining the sources and versions used at the time
CANONICAL GOVERNANCE CAPABILITIES

Ten capabilities, each
answering one question

These labels and their order are canonical. Each carries the question it answers during a decision, plus its current publication state.

CAPABILITY 01

Governance Control Plane

Coordinates the posture of every other control into one common status and immutable audit record.

“What is our operational posture right this second across all functions?”

CAPABILITY 02

Policy Management

Presents policy text, bounds, review cadence and historical changes to policies, and the specific decisions where each policy applied.

“Which policy version applied, and when was it last revised?”

CAPABILITY 03

Jurisdiction Intelligence

Binds operational controls with coverage status, source authority, effective date and review requirement at point of use.

“Is this action covered by an approved policy in this jurisdiction?”

CAPABILITY 04

Workflow & Approvals

Explicit review stages, deadlines, escalation pathways, and the segregation of duties applied to each decision.

“Who must review, who must authorize, and whose review has timed out?”

CAPABILITY 05

Delegated Authority

Role, scope, limits and delegation window that state what authority the person acts under for each decision.

“Did this person have authority to make this decision at the moment they decided?”

CAPABILITY 06

Segregation of Duties

Enforces incompatible role and action boundaries, with compensating controls when an unavoidable conflict occurs.

“Can this person propose and also approve this decision?”

CAPABILITY 07

Evidence Management

Pre-execution gathering of supporting context, receipts, confirmations, and reports that document the decision.

“What is the evidence pack, and who is its custodian?”

CAPABILITY 08

Audit Readiness

Proof of any decision, boundary change or exception in an export-ready format suitable for external review.

“Can an auditor trace this decision without contacting us?”

CAPABILITY 09

Governed AI

Guards against machine authority: ensures that models only advise, never self-authorize, and that human review is stamped on all actions.

“Did machine intelligence act within its governed boundary?”

CAPABILITY 10

Governance Analytics

Identifies systemic failure patterns, repeated exceptions, review-chain bottlenecks, and long-tail governance drift.

“Where in our operation are reviews timing out, and why?”

GOVERNANCE SURFACE PATTERN

Nine regions, in a fixed order

Fields and layouts scale to fit the action context. The control outcome and the human decision occupy separate containers and are never merged.

01Entity Key
OPERATING ENTITYNorthstar UK Ltd.
PARENTNorthstar Holdings Inc.
JURISDICTIONUnited Kingdom (GB)
ACCOUNT CODEAC-20491-UK
02Why this action and from where
TRIGGERSupplier change request submitted via Procurement connector
SOURCE IDREQ-SUP-2024-003VERIFIED FEED
INTENTBank detail amendment prior to scheduled payment execution
03Policy and jurisdiction
POLICY IDVERSIONEFFECTIVEPOLICY NAMESTATUS
POL-002-Supplier Bank Change Controlv3.201 Jan 2024Dual-party verify threshold > £10k• ACTIVE
POL-018-Dual Signoff Thresholdv2.015 Mar 2023Mandatory CFO signoff above £25k• ACTIVE
JUR-GB-Statutory Obligationv1.014 Feb 2024UK statutory payment register compliance• PROFESSIONAL REVIEW
COVEREDJurisdiction coverage status: United Kingdom (GB) — 3 active policies, 0 gaps detected.
04Authority and segregation
ROLE & SCOPETreasury Authority — UK Entity Tier 2
LIMIT£50,000 per transaction; £250,000 daily
EFFECTIVE DATES01 Jan 2024 — 31 Dec 2024
SEGREGATION RULECANNOT APPROVE OWN INITIATED REQUISITIONS
05Evidence
Evidence pack: 4 items• Bank verification receipt: VERIFIED• Supplier sign-off: ATTACHED• Call-back audit log: PENDING
06Responsibility
PROPOSERDaniel FosterProcurement Specialist
REVIEWERAisha Al-MansoorLegal Counsel
APPROVERMaya ChenFinance Controller
AUDIT CUSTODIANauto-payments-v2Machine identity
07Control Outcome
• Eligible for approval decision• Actions required• Evidence approval... current• Escalated• Blocked• Professional Review

Six defined outcomes. There is deliberately no ambiguous “Pending” state, because a control outcome is never itself a final authorization.

08Human Decision
DECISION RECORDDEC-2024-SUP-0019
DECIDING PARTYMaya Chen · Finance Controller
DECISIONAPPROVED with condition: call-back completed before payment run
EXECUTION TIMESTAMP12 Aug 2024 14:22:08 UTC
09Audit Record
EVIDENCE SEALSEAL-SHA256-4c9b88e1a8f921...
SOURCES RECORDEDProcurement feed, CLM clause extract, bank API verification receipt
RETENTION POLICY7 years statutory UK commercial records retention
GOVERNANCE CONTROL PLANE

An orchestrator, not a
second copy of every
control

The control plane composes outputs from policy, jurisdiction, workflow, authority, segregation, evidence and professional-review controls into one decision context and one auditable record. Being explicit about what it does not own is what keeps the architecture honest.

WHAT IT DOES NOT OWN
  • Authoring policy lifecycle — owned by Policy Management
  • Jurisdiction source library — owned by Jurisdiction Intelligence
  • Evidence vault ingestion — owned by Evidence Management
  • Analytics data lake & reporting data aggregation — owned by Governance Analytics
ARCHITECTURAL INVARIANTS
NO SILENT ALLOW

If a required connector is degraded, the affected controls are flagged for review and not silently bypassed as pass-through.

NEVER SELF-EVALUATING

Every control evaluation requires documented authorization outside the module being evaluated.

SEGREGATION OF DUTIES

An override require distinct authority and distinct justification; it is never a permission rolled into general administrative root. There is a permanent audit trail.

HISTORICAL INTEGRITY

A decision record retains policy versions and source states evaluated at the time, even after later revisions.

POLICY MANAGEMENT

Applicability and effective state, before document library

The useful question is not where the policy is stored. It is which version applied to this action, and whether two policies disagreed.

POLICY LIFECYCLE
DraftAuthor, scope, intent
ReviewInternal / legal validation
ApproveAuthorized with signature
ScheduledFuture effective start date
EffectiveAudited for next version
SupersededArchived historical
Emergency change — separately labeled

Neither silence nor authority bypassed. Fast-track emergency changes require retroactive review, full audit trail preservation, and the control status that will transition to authorized state.

POLICY REGISTRY — TWELVE ACTIVE POLICIES
POLICIES WITH SOURCE, OWNER, EFFECTIVE PERIOD AND CURRENT STATE
PolicyVersionSourceOwnerStatusEffective PeriodNext Review
Supplier Master Change Controlv3Group Finance CommitteeOperations● EFFECTIVE01 Apr 2024 →Oct 2027
Data Retentionv2Internal Control FrameworkCompliance● EFFECTIVE01 Apr 2024 →Apr 2027
Payment Authority Thresholdsv3Board delegation scheduleTreasury● SCHEDULED01 Jan 2025 →Dec 2027
Intercompany Threshold — groupv4Group FinanceTreasury▲ CONFLICT · RESOLUTION01 Jan 2024 →Current
Intercompany Threshold — localv2Local finance policyEntity controller▲ CONFLICT · RESOLUTION01 Mar 2024 →Dec 2027
Supplier On-boarding v1v1Procurement policyProcurement■ SUPERSEDEDto 31 Mar 2024
Conflicting policies remain an explicit unresolved state. The two intercompany thresholds now disagree. The platform refuses to silently pick the stricter or newer one—it marks the action outline with an authorized decision record for source, version and reason for the evaluation.

A source-governed policy is evaluated against every action, because decisions take place in real time against the versions that actually governed them at call time (which cannot change after a fact), and not legacy or retroactively adjusted specifications.

JURISDICTION INTELLIGENCE

Coverage state, source date and review requirement travel together

A country list is not coverage. Every jurisdictional rule carries where it came from, when it was last verified, and whether qualified review is still required.

SIX COVERAGE STATES
CoveredPartialReview requiredSource staleConfiguration requiredOut of Scope
JURISDICTION REGISTRY — SCOPE AND POLICY STATE PER RULE
JURISDICTION RULES WITH AUTHORITY REFERENCE, VERIFICATION DATE AND OPERATIONAL CONTEXT
JurisdictionRule / RegulationStatusStatutory SourceSource DateLast Verified
United KingdomPayment authorization records● COVEREDStatutory book standardApr 202401 Jan 2024
GermanyPension funds administration● PARTIALCommercial code §1Feb 202323 Jul 2024
IndiaWithholding tax and filing▲ SOURCE STALECorporate Income Tax ActNov 202214 Feb 2024!
SingaporeFiling parent submission● CONFIGURATION REQUIREDCompanies ActFeb 202403 Jul 2024
Brazil■ OUT OF SCOPE
Stale source, affected scope highlighted. The India rule is past its review date and unverified. Controls depending on it are warned and the governance outcome reflects this rather than passing through as compliant.

Coverage describes software configuration and source currency. It is not legal advice, and it does not assume that a jurisdiction's requirements are fully met—a good decision retains the source version used at the time.

WORKFLOW, DELEGATED AUTHORITY AND SEGREGATION OF DUTIES

Four duties, four independent permissions

Propose, review, approve and execute are permissioned separately. Holding one grants nothing about the others.

DUTY 01

Propose

Create or submit the proposal; prepare initial approval/action data.

Independently permissioned
DUTY 02

Review

Examine the action, its evidence and its control outcome.

Independently permissioned
DUTY 03

Authorize

Authorize within delegated scope, limit and effective dates.

Independently permissioned
DUTY 04

Execute

Carry out the authorized action; trigger external system.

Independently permissioned
DELEGATED AUTHORITY PROFILE — CLAIRE CHEN
AUTHORITY PROFILE
Role / Position:Treasury Director · Maya Chen
Delegated scope:Treasury payments under £100,000
Entity / Jurisdiction:UK01 (London)
Policy source:Treasury delegated authority regulation schedule
Effective period:01 Jan 2024 to 31 Dec 2024
Segregation constraint:Cannot approve own proposals
Status date:Valid delegation through current cycle
Revocation:Automatic on role change or manual intervention
Verified by:Audited and sealed by HR / Legal
Boundary: Configured authority in software does not create legal or corporate authority; it mirrors an underlying authorization that must exist in legal or governing documentation.
SEGREGATION RULE: SOD-TREASURY-001
SOD RECORD
Propose/review vs Execute:Disallow and stop release if proposer/reviewer matches the execution agent
Enforcement mode:Hard boundary — system blocked until exception / overrides resolved
Materiality context:Any transaction over £10,000 or high-risk vendor
Compensating control:None accepted
Owner:Compliance
Changed on:01 Jul 2024 →
Exception:Requires board executive waiver
LIFECYCLE STEPS AND THEIR CURRENT SEPARATION STATUS
Propose: [Maya Chen] (Cannot also execute, rule active)
Review: [David Ross] (Cannot also execute)
Approve: [Dr. Sarah Thorne] (Director review logged)
Execute attempt: Request blocked
Effective and applied status: All conditions met except execution attempt
Closure: Fully audited; record immutably kept for audit trail

Rule is deliberately separated from user identities, stored in definitive ledger. Even an owner cannot perform all functions in the chain.

EVIDENCE MANAGEMENT AND AUDIT READINESS

Seven evidence states, and words we will not use

Evidence health is reported as counts and states. The terminology boundary matters as much as the model.

RECEIVED
6

Items received for the current action.

VERIFIED
4

Proven true by source-verified confirmation.

MISSING
1

Required by the rule set.

UNVERIFIED
1

Held by system but not yet verified.

STALE
1

Failed to meet the freshness rule.

DISPUTED
0

Active ongoing dispute on file.

EXEMPTION ON RECORD
1

Under active waiver.

SEALED

Evidence dossier is sealed after approval and held for audit. Changes create an audit exception with timestamp.

EVIDENCE MANIFEST FIELDS
Manifest IDAction crypt-hashEntity / jurisdictionSources and versionsEvaluator appliedApprovalsBefore / afterActorsTimestampReceiptsRetention state
AUDIT TRAIL

A read-only event timeline with filters, preserving the decision and evidence context. Shows every compliance check on action without operational interruptions and without retrospective reconstructed logs.

TERMS THIS PLATFORM DOES NOT USE
GuaranteedAuditor-approvedLegally compliantZero-error rateInviolableAutomated Regulatory Acceptance

What is used instead: Evidence dossiers with provenance packages, audit trail and history, conformance qualifiers ("evaluated and tamper-sealed" and reason codes) and only where a qualified technical capability has been objectively addressed — and no such claim is made on this page.

GOVERNED AI

Sources first, limitations second, finding third

The visual order is deliberate: a reader sees what the model was allowed to look at, and what it could not resolve, before they see what it concluded.

01Authorized sources
In scope:CTR-0012 (contract record · supplier master agreement)
Source state:Unforeseen records outside user permission
Excluded:Attaching employee files — outside ingestion permission; so excluded from summary model
02Limitations, conflicts and missing information
Limitations:Model is blind to local languages, relies on summarisation
Missing context:Cheque vs wire rule (drafted, not in scope) at ProcureGen record
Conflict:Supplier bank record reference withheld; synchronous for invoice charge item
03Proposed finding

Clause 6.2 appears to require advance notice before a remittance change takes effect. Reference: CTR-0012, p. 7 §6.2; viewable in the record.

This is a proposal for a human reviewer. It carries no delegated or execution authority.

04Required reviewer
Role:General Counsel or delegate
Before boundary:Execution and payment remain prohibited. Legal interpretation of contract remains out.
Resolution state:Professional review required before a release attempt is permitted
AI OUTPUT ENDS HERE
05Human decision
Reviewer:Aisha Al-Mansoor · General Counsel
Decision:Accepted in part; note added
Reason:Withheld advance notice waived internally; supplier instructed to apply in next agreement
Action:Approved the underlying invoice without notice; record detailed in provisioning
Status:Obligation override logged today in ACT-081
06Audit record
Model / service ID:Prompt-id:48 · v4:sonnet
System context:Action: object not requesting vote
Evaluator context:Syscontext, including all in-scope data and activity
Sealed:Retained unaltered; exemplar demonstrator record
Decision entry:Revision and time change, with author and time
Final human decision:Signed and approved with authority token
AUTHORITY

Governed AI holds no independent delegated authority and performs no silent tutorial execution. It cannot approve, and it cannot be configured to approve.

FALLBACK

If the AI service is unavailable, the non-AI governance path remains usable. Policy evaluation, authority checks, evidence and human review do not depend on it.

GOVERNANCE ANALYTICS

Definition-led, never score-led

Each metric publishes its formula, denominator, source and scope. Every figure drills through to the contributing records within your permission.

Approval aging

count of open approvals grouped by age band

Unit:Hours
Denominator:Open approvals in scope
Source:Workflow service
Scope:Threshold visits

Policy exceptions

exceptions agreed / policy evaluations in period

Unit:Rate
Denominator:Evaluations in period
Source:Decision log
Scope:Version-specific

Authority failures

actions blocked for insufficient authority / actions requiring authorization

Unit:Rate
Denominator:Actions requiring authorization
Source:Authority service
Scope:Compliance

Segregation conflicts

count of SoD rule violations detected before execution

Unit:Count
Denominator:Not applicable — a count
Source:SoD tracker
Scope:Per rule or user

Evidence completeness

items with all required evidence / items requiring evidence

Unit:Rate
Denominator:Items requiring evidence
Source:Restricted counts (unverified)
Scope:Evidence service

Overdue obligations

obligations past due date / obligations due in period

Unit:Rate
Denominator:Obligations due in period
Source:Obligation register
Scope:Entity-scoped

Recurring exceptions

identities repeated with >1 exception in period

Unit:Categories
Denominator:Action identities with exceptions
Source:Exception log
Scope:Auditing findings

No global governance score

not published

A single governance score would obscure how much of the metric above produced it. Nothing publishes without a governed definition, denominator and source.

WHAT AFFECTS A METRIC ONCE WE START TO WORK
No dataPartial dataStale dataConflicting dataRestricted dataDefinition changedExport provisionsExport error

Every cited claims a text summary and a drill-down method, with keyboard-operable drill-down. A metric whose definition changed shows that fact rather than silently comparing two different measures.

CROSS-MODULE GOVERNANCE AND DEGRADED STATES

One governance model, six modules, explicit handoffs

Governance travels with the action across modules. Where a source or service fails, the platform says so rather than falling through to permitted.

CROSS-MODULE HANDOFFS · ACT-081
ILLUSTRATIVE — FICTITIOUS DATA
CROSS-MODULE STAGES FOR PROPOSED BANK-DETAIL CHANGE (ACT-081) ACROSS SIX MODULES
StageModuleHandoff StateGovernance ActionEvidence SealStatus
Procurement intakeProcurement Operations● SEALEDSupplier bank-detail change requestedProcurement v3 digest● COMPLETED
Statutory reviewLegal & Contracts● EVALUATEDJurisdiction scope confirmed under UKContract register record● EVALUATED
Supplier verificationSupplier & Commercial Ops▲ DEGRADEDBank verification connector timed out! EXCEPTION REGISTERED▲ DEGRADED
Account payableAccounts Payable● CONDITIONAL ON RECOVERYBlocked pending supplier master verificationAP check register ledger● BLOCKED
Treasury clearanceTreasury & Cash Position● PENDINGAuthority tier > $50,000 flagged for secondary reviewTreasury ledger seal● PENDING
Accounting exposureAccounting & General Ledger● PENDINGIntercompany threshold reviewLedger reconciliation● PENDING
External transferBank connector● BLOCKEDRelease blocked across bank API gateway: pre-clearance failedAPI audit trail sealed● BLOCKED
Degraded-state handoffs are explicit and named. When the bank verification connector fails, the platform surfaces the degraded state rather than assuming passed.
EIGHT DEGRADED STATES ACROSS SERVICES
Unreachable

A defined service or external connector timed out. Never falls through to permitted; marks action as degraded pending resolution.

Stale data

Source data has passed its freshness threshold. Warns downstream components and requires revalidation before critical steps.

Conflicting sources

Two registered sources produce conflicting outputs. Retains both readings and blocks progression pending human arbitration.

Missing context

Required context (such as entity jurisdiction or tax residency) is absent. Halts policy evaluation until context is supplied.

Revoked credential

A key or token used for verification has been revoked. All decisions relying on it are marked for review.

Configuration required

A required policy or control rule has not been configured for this entity or scope. Blocks rather than assuming a default.

Degraded dependency

A secondary service required for complete evidence collection is unavailable. Allows partial progress with explicit warnings.

Emergency bypass

An emergency bypass was invoked. Records the authorizing identity, reason and timestamp, and schedules mandatory retrospective review.

PAGES AND PROCUREMENT

Where governance claims are verified

Every mock-up on this page is illustrative and uses fictitious data. These are the routes where controls and evidence are actually checked.

Capability availability

Registry-governed

Route state, publication state, claim state, 'as-of-ref' state and availability qualifier come from the Capability Publication Registry, with a named owner and validation date.

ALL TEN ROUTES REQUIRE APPROVAL
Decision architecture

How a governed action runs

DOCUMENTED
DESIGNED TO SUPPORT REVIEW
AVAILABLE
Professional boundary

The Governance Platform does not provide legal, tax, accounting, audit or regulatory advice, and does not guarantee compliance, certification, or auditor or regulator acceptance. Qualified professionals remain responsible for regulated judgment.

APPLIES TO ALL TEN CAPABILITIES
CANONICAL REGISTER IDENTIFIER

Operational file runtime, no fork

Analytical definitions map to operational reality at runtime.

StandardisationFootprintSystem of RecordAcceptable
Version and execution ID: ZS-GP-2024
NEXT STEP

Bring the control that keeps failing

The most useful conversation starts from a specific control that is hard to evidence today — an approval nobody can prove occurred, a policy nobody can evaluate synchronously, an exception that went unrecorded. We will be candid about what is configurable and what needs validation.

All capability availability, jurisdiction coverage and implementation behavior depend on approved product and deployment status. No certification, guaranteed compliance or regulated-outcome claim is made on this page.

Bring your hard control to the platform tour
FREQUENTLY ASKED QUESTIONS

Scope, GRC comparison, authority and boundaries

Direct first sentences, then qualified detail. Every answer is present in the page source.

It brings policy, jurisdiction context, approvals, delegated authority, segregation of duties, evidence, audit readiness, governed AI and analytics into business decision workflows.

Ten canonical capabilities compose one decision context and one auditable record. Exact availability, coverage and implementation behavior depend on approved product and deployment status. See the ten capabilities

NEXT STEP

Govern your global
operations with
confidence

Unify finance, workforce, legal, tax, compliance, and commercial operations under one governed platform.

MULTI-ENTITYMULTI-JURISDICTIONAUDIT-READY ARCHITECTURE
SECONDARY-AUDIT STRATEGY
BUILD QA - LOGO

ZoikoSuite logo — reversed
zoikosuite-logo-reversed.svg / .eps
height: 34-38px - light/medium/all-light version
for the dark footer - slot: /brand/logo/

ZoikoSuite®

Governed Business Operations Intelligence Platform.
A Zoiko Tech platform. A Zoiko Group company.

INSIGHTS SUBSCRIPTION

Governance, compliance, and enterprise operations insights.

By subscribing you agree to receive ZoikoSuite insights. See the Privacy Policy. You can unsubscribe at any time.

SOCIAL MEDIA

Medium and Vimeo icons stay hidden until the official accounts are active.

BUILD QA - FLEX-SET

Social icons UI spacing for inline flex-set
default 8-log - 28/28 viewBox - transparent supply path - surmountable +0.2 - low-flare pur-elements - width & layout correct