Legal

Compliance checklists with evidence attached and gaps named

A checklist where every line is ticked and nothing is evidenced is not a control. It is a document that will fail an audit slowly.

What the worker does

An AI worker in Polaris maintains a compliance checklist as tasks with named owners, collects the evidence each item requires into the workspace, chases owners who have not supplied it, and reports gaps explicitly rather than marking an unevidenced item complete. Whether the checklist is the right checklist, and whether the evidence is sufficient, is decided by a qualified adviser or auditor.

Connections
Google Drive · Slack · Docs
Every item has
An owner, an evidence link, a date
Unevidenced items
Reported as gaps, never ticked

Checklists rot in a specific and predictable way

Someone builds a good checklist for a certification or a customer security review. It is accurate on the day. Six months later half the items are ticked from memory, three of the owners have changed role, and the evidence links point at a folder that was reorganized in March.

The rot is not laziness. Maintaining evidence is a continuous chase across people who have other jobs, and no single person is paid to do it.

That chase is the piece to hand to a worker: ask the owner, collect the artifact, date it, and report what is missing. The judgment, which is whether any of it is sufficient, stays with whoever is qualified to say so.

What each checklist item carries

An item without all four of these is not really a control, and the worker will say so.

  • A named human owner

    Not a team. A person, with a task assigned to them, because a control owned by a team is owned by nobody.

  • An evidence artifact

    A file, a screenshot, an exported record, stored in the workspace where the checklist lives rather than linked to a folder that moves.

  • A date

    When the evidence was produced, not when the item was last ticked. Old evidence is a finding.

  • A re-check interval

    The interval turns the item into a recurring task in the Focus lane instead of a line nobody looks at until an auditor asks.

Standing one up

  1. 1

    Put the checklist in a doc, one item per line, with owners

    Docs in Polaris support to-dos and sub-pages, and they are versioned, so the checklist itself has a history you can show someone.

  2. 2

    Turn each item into a recurring task

    Assigned to its human owner, with an interval. The Focus lane carries the ones due now across Today, This week and Next 30 days.

  3. 3

    Give the worker Slack and Drive

    Slack to chase owners where they work, Drive to find and collect the evidence artifacts.

  4. 4

    Write the acceptance criteria to forbid silent ticks

    State it directly: an item is only complete when a dated artifact is attached and its owner has confirmed. Anything else is reported as a gap with a reason.

  5. 5

    Review the gap list, decide, close

    The worker delivers the gap list. A qualified person decides what it means and what to do, and closes the task.

The boundary here matters more than usual

The worker reports

  • Which items have evidence and which do not
  • How old each artifact is
  • Who has not responded, and for how long
  • Where the checklist itself has not been reviewed
  • What changed since the last run

A qualified person judges

  • Whether this is the right checklist for your obligations
  • Whether an artifact actually evidences the control
  • Whether a gap is material
  • What to tell a customer, an auditor or a regulator
  • Whether you are compliant

Questions people ask

+Which frameworks does it support?

It supports whatever checklist you write. Polaris ships no framework content, no control library and no certification templates, because shipping a generic list would encourage exactly the false comfort this page argues against. Bring the checklist your adviser gave you.

+Can it collect evidence automatically?

It can retrieve artifacts from the connections it holds, which for most teams means Google Drive. Anything living in a system outside the fixed catalog has to be supplied by its human owner, and the worker's job there is to ask and keep asking.

+What does the auditor actually see?

A checklist with dated artifacts, plus a task history showing when each item was chased, by whom and what was returned. The work log adds what the worker itself did in each run. That is a stronger trail than a spreadsheet with ticks in it.

+Does the worker need admin access to our systems?

No. Connections are authorized once at org level from a fixed catalog and stored server-side. A compliance worker generally needs Drive and Slack, and giving it more than the job requires is a bad idea regardless of what the product allows.

Your next hire takes 60 seconds.

The software is free — unlimited people, tasks, workstreams and docs. You pay only for work an AI worker actually delivers, itemised by the hour.

Get started free

Last checked .