Put governance inside every material business action
Policy, jurisdiction context, approvals, delegated authority, segregation of duties, evidence, audit readiness, governed AI and analytics — evaluated around the action itself, not filed away as documents.

Exact capability availability, jurisdiction coverage and implementation behavior depend on approved product and deployment status. No certification, guaranteed compliance or regulated-outcome claim is made on this page.
Supplier bank-detail change
ACT-081 · Northstar UK Ltd · United KingdomThe control outcome and the human decision are stored as separate records. A control outcome never constitutes authorization on its own.
What is the ZoikoSuite Governance Platform?
ZoikoSuite Governance Platform is designed to bring policy, jurisdiction context, approvals, delegated authority, segregation of duties, evidence, audit readiness, governed AI and analytics into business decision workflows. It helps authorized teams understand required controls, route appropriate human review and preserve decision evidence. Exact capability availability, coverage and implementation behavior depend on approved product and deployment status.
Four facts govern this page. The ten capability labels are canonical. Governance is evaluated around business actions, not only stored as documents. Control outcomes, human authorization, evidence and audit context are distinct things. And route, availability, jurisdiction, certification and regulated-outcome claims are source-governed rather than inferred from the taxonomy.
A policy nobody evaluates at
the moment of decision is
documentation
The difference is not whether the policy exists. It is whether the policy was evaluated against this action, by this authority, with this evidence, at this moment — and whether that is provable afterwards.
| DIMENSION | GOVERNANCE AS DOCUMENTATION | GOVERNANCE AS OPERATION |
|---|---|---|
| Where the policy lives | A repository, reviewed periodically | Evaluated against the specific action, with its version recorded |
| When it applies | When someone remembers to check | At the moment the action is proposed |
| Who may decide | Assumed from job title or org chart | Evaluated against delegated authority, scope, limit and effective dates |
| Conflicting duties | Detected during a later review, if at all | Evaluated as a segregation rule before the decision is offered |
| Evidence | Assembled retrospectively for an audit | Required, tracked and reported as counts and states while work proceeds |
| Exceptions | An email thread or a spreadsheet row | A record with owner, compensating control, approval, effective period and expiry |
| Jurisdiction | A country list | Coverage state plus source, effective date and review requirement at point of use |
| Proof afterwards | Reconstructed from systems and memory | A decision record retaining the sources and versions used at the time |
Ten capabilities, each
answering one question
These labels and their order are canonical. Each carries the question it answers during a decision, plus its current publication state.
Governance Control Plane
Coordinates the posture of every other control into one common status and immutable audit record.
“What is our operational posture right this second across all functions?”
Policy Management
Presents policy text, bounds, review cadence and historical changes to policies, and the specific decisions where each policy applied.
“Which policy version applied, and when was it last revised?”
Jurisdiction Intelligence
Binds operational controls with coverage status, source authority, effective date and review requirement at point of use.
“Is this action covered by an approved policy in this jurisdiction?”
Workflow & Approvals
Explicit review stages, deadlines, escalation pathways, and the segregation of duties applied to each decision.
“Who must review, who must authorize, and whose review has timed out?”
Delegated Authority
Role, scope, limits and delegation window that state what authority the person acts under for each decision.
“Did this person have authority to make this decision at the moment they decided?”
Segregation of Duties
Enforces incompatible role and action boundaries, with compensating controls when an unavoidable conflict occurs.
“Can this person propose and also approve this decision?”
Evidence Management
Pre-execution gathering of supporting context, receipts, confirmations, and reports that document the decision.
“What is the evidence pack, and who is its custodian?”
Audit Readiness
Proof of any decision, boundary change or exception in an export-ready format suitable for external review.
“Can an auditor trace this decision without contacting us?”
Governed AI
Guards against machine authority: ensures that models only advise, never self-authorize, and that human review is stamped on all actions.
“Did machine intelligence act within its governed boundary?”
Governance Analytics
Identifies systemic failure patterns, repeated exceptions, review-chain bottlenecks, and long-tail governance drift.
“Where in our operation are reviews timing out, and why?”
Nine regions, in a fixed order
Fields and layouts scale to fit the action context. The control outcome and the human decision occupy separate containers and are never merged.
| POLICY ID | VERSION | EFFECTIVE | POLICY NAME | STATUS |
|---|---|---|---|---|
| POL-002-Supplier Bank Change Control | v3.2 | 01 Jan 2024 | Dual-party verify threshold > £10k | • ACTIVE |
| POL-018-Dual Signoff Threshold | v2.0 | 15 Mar 2023 | Mandatory CFO signoff above £25k | • ACTIVE |
| JUR-GB-Statutory Obligation | v1.0 | 14 Feb 2024 | UK statutory payment register compliance | • PROFESSIONAL REVIEW |
Six defined outcomes. There is deliberately no ambiguous “Pending” state, because a control outcome is never itself a final authorization.
An orchestrator, not a
second copy of every
control
The control plane composes outputs from policy, jurisdiction, workflow, authority, segregation, evidence and professional-review controls into one decision context and one auditable record. Being explicit about what it does not own is what keeps the architecture honest.
- •Authoring policy lifecycle — owned by Policy Management
- •Jurisdiction source library — owned by Jurisdiction Intelligence
- •Evidence vault ingestion — owned by Evidence Management
- •Analytics data lake & reporting data aggregation — owned by Governance Analytics
If a required connector is degraded, the affected controls are flagged for review and not silently bypassed as pass-through.
Every control evaluation requires documented authorization outside the module being evaluated.
An override require distinct authority and distinct justification; it is never a permission rolled into general administrative root. There is a permanent audit trail.
A decision record retains policy versions and source states evaluated at the time, even after later revisions.
Applicability and effective state,
before document library
The useful question is not where the policy is stored. It is which version applied to this action, and whether two policies disagreed.

Neither silence nor authority bypassed. Fast-track emergency changes require retroactive review, full audit trail preservation, and the control status that will transition to authorized state.
| Policy | Version | Source | Owner | Status | Effective Period | Next Review |
|---|---|---|---|---|---|---|
| Supplier Master Change Control | v3 | Group Finance Committee | Operations | ● EFFECTIVE | 01 Apr 2024 → | Oct 2027 |
| Data Retention | v2 | Internal Control Framework | Compliance | ● EFFECTIVE | 01 Apr 2024 → | Apr 2027 |
| Payment Authority Thresholds | v3 | Board delegation schedule | Treasury | ● SCHEDULED | 01 Jan 2025 → | Dec 2027 |
| Intercompany Threshold — group | v4 | Group Finance | Treasury | ▲ CONFLICT · RESOLUTION | 01 Jan 2024 → | Current |
| Intercompany Threshold — local | v2 | Local finance policy | Entity controller | ▲ CONFLICT · RESOLUTION | 01 Mar 2024 → | Dec 2027 |
| Supplier On-boarding v1 | v1 | Procurement policy | Procurement | ■ SUPERSEDED | to 31 Mar 2024 | — |
A source-governed policy is evaluated against every action, because decisions take place in real time against the versions that actually governed them at call time (which cannot change after a fact), and not legacy or retroactively adjusted specifications.
Coverage state, source date
and review requirement travel
together
A country list is not coverage. Every jurisdictional rule carries where it came from, when it was last verified, and whether qualified review is still required.

| Jurisdiction | Rule / Regulation | Status | Statutory Source | Source Date | Last Verified |
|---|---|---|---|---|---|
| United Kingdom | Payment authorization records | ● COVERED | Statutory book standard | Apr 2024 | 01 Jan 2024 |
| Germany | Pension funds administration | ● PARTIAL | Commercial code §1 | Feb 2023 | 23 Jul 2024 |
| India | Withholding tax and filing | ▲ SOURCE STALE | Corporate Income Tax Act | Nov 2022 | 14 Feb 2024! |
| Singapore | Filing parent submission | ● CONFIGURATION REQUIRED | Companies Act | Feb 2024 | 03 Jul 2024 |
| Brazil | — | ■ OUT OF SCOPE | — | — | — |
Coverage describes software configuration and source currency. It is not legal advice, and it does not assume that a jurisdiction's requirements are fully met—a good decision retains the source version used at the time.
Four duties, four independent
permissions
Propose, review, approve and execute are permissioned separately. Holding one grants nothing about the others.
Propose
Initiate a record, amendment or workflow transition with purpose and origin metadata.
Create or submit the proposal; prepare initial approval/action data.
Review
Evaluate statutory, policy, contractual and jurisdictional compliance without execution authority.
Examine the action, its evidence and its control outcome.
Authorize
Commit delegated entity approval within established thresholds and scope boundaries.
Authorize within delegated scope, limit and effective dates.
Execute
Apply the permitted transition, trigger external connectors, and seal the audit evidence.
Carry out the authorized action; trigger external system.

Segregation rules evaluate dynamically on every state transition. An administrative superuser credential cannot bypass separation of duties.
Rule is deliberately separated from user identities, stored in definitive ledger. Even an owner cannot perform all functions in the chain.
Seven evidence states, and
words we will not use
Evidence health is reported as counts and states. The terminology boundary matters as much as the model.
Items received for the current action.
Proven true by source-verified confirmation.
Required by the rule set.
Held by system but not yet verified.
Failed to meet the freshness rule.
Active ongoing dispute on file.
Under active waiver.
Evidence dossier is sealed after approval and held for audit. Changes create an audit exception with timestamp.
A read-only event timeline with filters, preserving the decision and evidence context. Shows every compliance check on action without operational interruptions and without retrospective reconstructed logs.
What is used instead: Evidence dossiers with provenance packages, audit trail and history, conformance qualifiers ("evaluated and tamper-sealed" and reason codes) and only where a qualified technical capability has been objectively addressed — and no such claim is made on this page.
Sources first, limitations
second, finding third
The visual order is deliberate: a reader sees what the model was allowed to look at, and what it could not resolve, before they see what it concluded.
Proposed change matches prior signatory format, but bank sort code requires secondary verification under POL-002 v3 before invoice INV-4471 release.
The platform never displays “AI approved” or “AI authorized”. Machine findings are permanently distinct records that require authenticated human sign-off.
Every prompt, source extract, confidence score and human decision record is retained in an immutable audit ledger with cryptographic verification.
Clause 6.2 appears to require advance notice before a remittance change takes effect. Reference: CTR-0012, p. 7 §6.2; viewable in the record.
This is a proposal for a human reviewer. It carries no delegated or execution authority.
Governed AI holds no independent delegated authority and performs no silent tutorial execution. It cannot approve, and it cannot be configured to approve.
If the AI service is unavailable, the non-AI governance path remains usable. Policy evaluation, authority checks, evidence and human review do not depend on it.
Definition-led, never score-led
Each metric publishes its formula, denominator, source and scope. Every figure drills through to the contributing records within your permission.
Review Aging
Current timestamp minus state entry timestamp
Exception Rate
Dispensations approved / total decisions evaluated
Authority Overrides
Count of emergency or tier-escalated decisions
Segregation Conflicts
Attempted self-approvals blocked by policy
Connector Degraded Time
Minutes since last verified synchronisation status
Evidence Completeness
Attached mandated documents / required evidence count
Jurisdiction Coverage
Mapped statutory rules / active operating countries
Where Full Reporting Lives
ZoikoSuite produces verified operational events, not offline BI charts
Underlying records and formulas drill down directly from each metric. A score cannot hide behind an opaque calculation.
Approval aging
count of open approvals grouped by age band
Policy exceptions
exceptions agreed / policy evaluations in period
Authority failures
actions blocked for insufficient authority / actions requiring authorization
Segregation conflicts
count of SoD rule violations detected before execution
Evidence completeness
items with all required evidence / items requiring evidence
Overdue obligations
obligations past due date / obligations due in period
Recurring exceptions
identities repeated with >1 exception in period
No global governance score
A single governance score would obscure how much of the metric above produced it. Nothing publishes without a governed definition, denominator and source.
Every cited claims a text summary and a drill-down method, with keyboard-operable drill-down. A metric whose definition changed shows that fact rather than silently comparing two different measures.
One governance model, six modules, explicit handoffs
Governance travels with the action across modules. Where a source or service fails, the platform says so rather than falling through to permitted.

| Stage | Module | Handoff State | Governance Action | Evidence Seal | Status |
|---|---|---|---|---|---|
| Procurement intake | Procurement Operations | ● SEALED | Supplier bank-detail change requested | Procurement v3 digest | ● COMPLETED |
| Statutory review | Legal & Contracts | ● EVALUATED | Jurisdiction scope confirmed under UK | Contract register record | ● EVALUATED |
| Supplier verification | Supplier & Commercial Ops | ▲ DEGRADED | Bank verification connector timed out | ! EXCEPTION REGISTERED | ▲ DEGRADED |
| Account payable | Accounts Payable | ● CONDITIONAL ON RECOVERY | Blocked pending supplier master verification | AP check register ledger | ● BLOCKED |
| Treasury clearance | Treasury & Cash Position | ● PENDING | Authority tier > $50,000 flagged for secondary review | Treasury ledger seal | ● PENDING |
| Accounting exposure | Accounting & General Ledger | ● PENDING | Intercompany threshold review | Ledger reconciliation | ● PENDING |
| External transfer | Bank connector | ● BLOCKED | Release blocked across bank API gateway: pre-clearance failed | API audit trail sealed | ● BLOCKED |
A defined service or external connector timed out. Never falls through to permitted; marks action as degraded pending resolution.
Source data has passed its freshness threshold. Warns downstream components and requires revalidation before critical steps.
Two registered sources produce conflicting outputs. Retains both readings and blocks progression pending human arbitration.
Required context (such as entity jurisdiction or tax residency) is absent. Halts policy evaluation until context is supplied.
A key or token used for verification has been revoked. All decisions relying on it are marked for review.
A required policy or control rule has not been configured for this entity or scope. Blocks rather than assuming a default.
A secondary service required for complete evidence collection is unavailable. Allows partial progress with explicit warnings.
An emergency bypass was invoked. Records the authorizing identity, reason and timestamp, and schedules mandatory retrospective review.
Where governance claims are verified
Every mock-up on this page is illustrative and uses fictitious data. These are the routes where controls and evidence are actually checked.
Registry-governed
Route state, publication state, claim state, 'as-of-ref' state and availability qualifier come from the Capability Publication Registry, with a named owner and validation date.
How a governed action runs
The Governance Platform does not provide legal, tax, accounting, audit or regulatory advice, and does not guarantee compliance, certification, or auditor or regulator acceptance. Qualified professionals remain responsible for regulated judgment.
Operational file runtime, no fork
Analytical definitions map to operational reality at runtime.
Bring the control that keeps failing
The most useful conversation starts from a specific control that is hard to evidence today — an approval nobody can prove occurred, a policy nobody can evaluate synchronously, an exception that went unrecorded. We will be candid about what is configurable and what needs validation.
All capability availability, jurisdiction coverage and implementation behavior depend on approved product and deployment status. No certification, guaranteed compliance or regulated-outcome claim is made on this page.
Scope, GRC comparison, authority and boundaries
Direct first sentences, then qualified detail. Every answer is present in the page source.
It brings policy, jurisdiction context, approvals, delegated authority, segregation of duties, evidence, audit readiness, governed AI and analytics into business decision workflows.
Ten canonical capabilities compose one decision context and one auditable record. Exact availability, coverage and implementation behavior depend on approved product and deployment status. See the ten capabilities
Govern your global
operations with
confidence
Unify finance, workforce, legal, tax, compliance, and commercial operations under one governed platform.
ZoikoSuite logo — reversed
zoikosuite-logo-reversed.svg / .eps
height: 34-38px - light/medium/all-light version
for the dark footer - slot: /brand/logo/
ZoikoSuite®
Governed Business Operations Intelligence Platform.
A Zoiko Tech platform. A Zoiko Group company.
Governance, compliance, and enterprise operations insights.
By subscribing you agree to receive ZoikoSuite insights. See the Privacy Policy. You can unsubscribe at any time.
Social icons UI spacing for inline flex-set
default 8-log - 28/28 viewBox - transparent supply path - surmountable +0.2 - low-flare pur-elements - width & layout correct