What Nimmy does
Seven parts, and the order matters: each one is only useful because the one above it holds.
A corpus we hold, not a search of the web
Nimmy ingests from regulators, standards bodies, industry associations, courts and legislatures, and indexes every document into its own corpus: full text, structure, metadata, citations and embeddings. Search, summaries and answers all run against that index. Nothing in the product goes to the live web while somebody is waiting for a page.
Each document is snapshotted as it was published, hashed, and versioned when it changes — regulators edit pages quietly, and a snapshot is how you prove what a rule said on the day you read it. A new version arrives with a redline against the one before it. Onboarding a source includes its archive, so a lookback works from the first day rather than the first year.
The obligation register is the hinge
A regulation becomes obligations; obligations map to policies, risks and controls; what nothing covers becomes an issue. That chain is the product, and the register is where it turns.
One row per requirement, whatever its source — a regulation, a contract, a licence, an undertaking, or a rule the organisation wrote in one of its own policies. Each legal entity that carries a requirement has its own applicability decision, its own owner, its own mappings and its own compliance risk, because two entities may meet the same clause in different ways.
When a new version of a source supersedes the one an entry cites, the entry follows the clause through the redline where the wording survives, including a renumbering. Where it does not, a person is asked what the amendment means. A register that quietly drifts from its sources is worse than no register.
Risks and controls read from what actually happened
A risk is scored by a person and keeps every score it was ever given. Its exposure is computed from that score against the appetite and everything that has happened since — a control that holds it failing, an incident, an indicator crossing a threshold — rather than stored in a field that goes stale between reviews.
A control has a versioned design, operates in named entities, and is read as operating, degraded, failed or not observed from the signals it produces. Three lines assure it: the owner attests a period against those signals, a tester rates design and operation, a review concludes on it.
Policies are versioned, with effective dates, approval by somebody other than the author, and a review cycle. The requirements a policy states go onto the obligation register cited to the clause they were written in.
Regulatory change, worked rather than watched
Detected changes are routed to the teams and entities whose subscription profiles match, and land in a queue: triage, applicability per entity, impact assessment, implementation, closure. The same change arriving through three sources is one item, not three.
Closing takes two people. Whoever did the work requests it and records what is left and why; somebody who neither requested it nor owns the change agrees. Every transition writes an audit event.
Assurance, issues and incidents
A review by any of the three lines runs over a named scope of risks and controls and ends in a determination, with a conclusion per thing it looked at — a process can be effective and one control inside it not.
A review’s findings are issues, not a separate record somebody later converts into one. An issue has a source rather than a parent, so a failed control test, a regulatory exam point and something a person simply noticed all land in one list with one way of being fixed.
An incident is something that happened, with no root cause of its own: what gets fixed is the issue underneath it. An incident cannot close until somebody answers the reporting question, against rules the tenant writes rather than rules we infer.
AI that cites, and never decides
Extraction, classification, summaries, impact drafts and communications are all grounded in the indexed corpus and return citations to the paragraphs they came from. A function that cannot produce citations returns an error rather than prose.
Nothing drafted by a model is published, sent, or written into a register without a person confirming it, and that confirmation is in the audit log. Any tenant can switch individual AI functions off.
Reporting and exports
One faceted view over every repository in the platform — registers, queue, corpus, annotations, engagement and the audit trail. Filter it, save it, export it to CSV, XLSX, PDF or DOCX, and schedule it weekly, monthly or quarterly. Every export is recorded.
Outbound integrations push to ServiceNow, Jira, Archer, Confluence and Teams, and never without a person. Nimmy is the source of truth for its own registers; it exports to enterprise systems and does not take dictation from them.
Seeing it
Access is by invitation while Nimmy is in pilot. Write to us and say what you carry and which regulators you answer to.