Legal
Compliance checklists with evidence attached and gaps named
A checklist where every line is ticked and nothing is evidenced is not a control. It is a document that will fail an audit slowly.
What the worker does
An AI worker in Polaris maintains a compliance checklist as tasks with named owners, collects the evidence each item requires into the workspace, chases owners who have not supplied it, and reports gaps explicitly rather than marking an unevidenced item complete. Whether the checklist is the right checklist, and whether the evidence is sufficient, is decided by a qualified adviser or auditor.
- Connections
- Google Drive · Slack · Docs
- Every item has
- An owner, an evidence link, a date
- Unevidenced items
- Reported as gaps, never ticked
Checklists rot in a specific and predictable way
Someone builds a good checklist for a certification or a customer security review. It is accurate on the day. Six months later half the items are ticked from memory, three of the owners have changed role, and the evidence links point at a folder that was reorganized in March.
The rot is not laziness. Maintaining evidence is a continuous chase across people who have other jobs, and no single person is paid to do it.
That chase is the piece to hand to a worker: ask the owner, collect the artifact, date it, and report what is missing. The judgment, which is whether any of it is sufficient, stays with whoever is qualified to say so.
What each checklist item carries
An item without all four of these is not really a control, and the worker will say so.
A named human owner
Not a team. A person, with a task assigned to them, because a control owned by a team is owned by nobody.
An evidence artifact
A file, a screenshot, an exported record, stored in the workspace where the checklist lives rather than linked to a folder that moves.
A date
When the evidence was produced, not when the item was last ticked. Old evidence is a finding.
A re-check interval
The interval turns the item into a recurring task in the Focus lane instead of a line nobody looks at until an auditor asks.
Standing one up
- 1
Put the checklist in a doc, one item per line, with owners
Docs in Polaris support to-dos and sub-pages, and they are versioned, so the checklist itself has a history you can show someone.
- 2
Turn each item into a recurring task
Assigned to its human owner, with an interval. The Focus lane carries the ones due now across Today, This week and Next 30 days.
- 3
Give the worker Slack and Drive
Slack to chase owners where they work, Drive to find and collect the evidence artifacts.
- 4
Write the acceptance criteria to forbid silent ticks
State it directly: an item is only complete when a dated artifact is attached and its owner has confirmed. Anything else is reported as a gap with a reason.
- 5
Review the gap list, decide, close
The worker delivers the gap list. A qualified person decides what it means and what to do, and closes the task.
The boundary here matters more than usual
The worker reports
- Which items have evidence and which do not
- How old each artifact is
- Who has not responded, and for how long
- Where the checklist itself has not been reviewed
- What changed since the last run
A qualified person judges
- Whether this is the right checklist for your obligations
- Whether an artifact actually evidences the control
- Whether a gap is material
- What to tell a customer, an auditor or a regulator
- Whether you are compliant
Questions people ask
+Which frameworks does it support?
It supports whatever checklist you write. Polaris ships no framework content, no control library and no certification templates, because shipping a generic list would encourage exactly the false comfort this page argues against. Bring the checklist your adviser gave you.
+Can it collect evidence automatically?
It can retrieve artifacts from the connections it holds, which for most teams means Google Drive. Anything living in a system outside the fixed catalog has to be supplied by its human owner, and the worker's job there is to ask and keep asking.
+What does the auditor actually see?
A checklist with dated artifacts, plus a task history showing when each item was chased, by whom and what was returned. The work log adds what the worker itself did in each run. That is a stronger trail than a spreadsheet with ticks in it.
+Does the worker need admin access to our systems?
No. Connections are authorized once at org level from a fixed catalog and stored server-side. A compliance worker generally needs Drive and Slack, and giving it more than the job requires is a bad idea regardless of what the product allows.
Related
Legal operations work an AI worker can carry
Tracking, chasing, assembling and watching. Everything a legal team spends time on that is not actually practicing law.
Knowing that a source changed, on the week it changed
A worker watches the public pages you nominate, quotes what changed, and dates it. What the change means for you is a question for your adviser.
A register of what you actually signed
Finance tracks what a vendor costs. Legal needs to know what you promised them, what they promised you, and which of those promises has a date on it.
Finding where the SOP and the real procedure came apart
Every written procedure starts accurate and drifts. A worker compares the document to how the work actually ran and reports the difference.
Hire an AI paralegal
It organises the paperwork and surfaces the dates and clauses, and it stops well before the point where anything becomes advice.
Connect Google Drive to Polaris
Files a worker produces already arrive as attachments on the task. Files your team already keeps in Drive are the part still waiting.
Acceptance criteria
Written before the work, checkable after it, and binary either way.
Work log
The record that makes an unwatched run reviewable afterwards.