Case study · Compliance engineering

Regulator-ready reporting with every figure traceable

A WA resources services contractor assembled its monthly and quarterly compliance reports by hand, collecting licences, inductions, maintenance and incident records from email, shared drives and paper over several days each cycle. We built a central evidence store with automated collection, expiry escalation and a report generator that produces submission-ready output. Expired certifications are now caught months before an audit rather than during one.

Client · WA resources services contractor Sector · Resources services Engagement · Discovery, build, rollout Duration · Eight months to full cycle Status · In production, all reports automated Delivery model · Incremental build, capped monthly

Evidence lived wherever it happened to land. A licence renewal arrived as a PDF attached to an email sent to a supervisor's personal address. Induction records were held by the training provider and forwarded monthly as a spreadsheet. Maintenance records existed in the maintenance system, in a site folder, and in some cases only as a signed sheet in a folder in a ute. Incident reports were written after the fact, sometimes days later, and filed in a shared drive folder whose naming convention had drifted three times in five years. There was no register that said what evidence was required, what had been received, and what was missing.

We delivered one evidence store and a reporting layer on top of it. Every required item is defined once — what it is, who is responsible, how long it is valid, and where the authoritative source is — and the system either collects it automatically from that source or prompts for it and records what was supplied, by whom and when. Expiry is tracked with escalation at ninety, sixty and thirty days to the person accountable, not to a generic mailbox. Reports are generated from the store rather than assembled from it, so a figure in a submitted report can be traced back through the calculation to the specific documents that produced it.

Engagement facts

Evidence types34 defined and tracked
Source systems6 integrated
Report templates9 (3 regulator, 6 client)
Certification records3,900 under management
Reporting cycleMonthly, quarterly, annual
Default retention7 years, class-dependent
Expiry escalation90 / 60 / 30 days
Users110 across five roles
Data residencyAWS ap-southeast-2

01The problem

Assembling a monthly compliance pack took between five and seven working days, most of which was spent finding things rather than writing anything. Someone worked through a checklist, asked each site supervisor for their records by email, chased the ones who had not replied, opened each attachment to confirm it was the right document for the right period, and pasted the resulting figures into a template. The quarterly pack was larger and took longer, and because two people shared the work depending on who was available, the pack was not assembled the same way twice.

The consequence of having no register was that gaps were invisible until they mattered. An expired high-risk work licence was discovered during a client audit, which is the worst possible time to discover it. A maintenance record missing from a quarterly submission was noticed only when the client queried the total. And because evidence was held in personal mailboxes and site folders, the departure of a supervisor could remove the only copy of a record that a regulator might later ask for. Nobody in the business could answer, at any given moment, what percentage of required evidence was actually held.

  • Evidence held in email, shared drives, provider portals and paper
  • Five to seven days per monthly pack, mostly spent locating records
  • No register of what was required, held, or missing
  • Expired certifications found during audits rather than before them
  • Assembled differently depending on who was available
  • Single copies of records held in personal mailboxes

02Constraints and non-negotiables

External formats are not stable. The regulator revises its reporting template most years, sometimes changing not only layout but definitions, and several client-imposed reports change on contract renewal. Any design that hard-coded today's spreadsheet layout would break on the next revision, and the break would be discovered at submission time, which is the one moment it cannot be tolerated.

Evidence also has to be defensible. Once a document is accepted, it must be immutable and time-stamped, because a report figure that quotes a certificate needs to show the certificate as it was at the time, not as it is now. Some records are privacy-sensitive — medical assessments and parts of incident reports — and must be visible to a small number of roles only, while remaining provable to an auditor. Auditors do not accept totals: they ask how a figure was derived and expect to be walked back to source documents. Retention obligations point in two directions at once, since record-keeping rules require keeping some material for years while privacy expectations argue for deleting other material sooner. And field staff, who are the only people able to capture some evidence at source, work on sites with poor connectivity and limited patience for additional administration.

  • Regulator and client templates revised at least annually
  • Evidence immutable and time-stamped once accepted
  • Privacy-sensitive classes visible to restricted roles only
  • Auditor traceability from report figure back to source document
  • Retention rules that conflict between record-keeping and privacy
  • Field capture required on sites with unreliable connectivity

03What we built

The evidence store is the foundation. Each required item is a typed record with an owner, a validity period, an authoritative source, and a retention class. Documents are written to object storage with versioning and object lock, so an accepted document cannot be edited or quietly replaced; a correction is a new version and the old one remains retrievable. Six source systems — training provider, maintenance system, payroll, incident system, fleet telematics and the finance system — feed records automatically on a schedule, with the remainder captured by upload or by the mobile capture path.

On top of that sits everything the compliance team actually touches. Expiry tracking escalates at ninety, sixty and thirty days to the accountable person by name, and continues to a second level if the first does not act. The report generator builds each submission from the store against a versioned template, resolves every figure from identified evidence, and writes out a report that lists its own sources. An exception dashboard shows what is missing, what is unverified, what expires within sixty days and what has failed collection. Role-based access restricts sensitive classes, and every view, download and approval is logged.

04The hard parts and how we solved them

Schema drift was the central engineering problem. We deliberately did not map our data model onto the regulator's spreadsheet; we mapped it onto a stable internal representation of obligations, evidence and periods, and then mapped that onto each external template through a versioned transformation. When a template changes, the change is one new transformation beside the old one, the old submissions remain reproducible, and a diff between the two is reviewed before anything is submitted. That separation is the reason an annual template revision is now a scheduled task rather than a crisis.

Provenance was the second. A report figure is not a number in a cell; it is the output of a named calculation over a specific set of evidence versions, and the report carries that set with it. Every generated submission stores the evidence identifiers and the transformation version used, so an auditor asking why a figure was 34 rather than 31 can be shown the three documents and the rule. Reports are deterministic: regenerating the same period produces the same output unless evidence changed, and any change is recorded.

The remaining problems were judgement rather than architecture. Missing evidence cannot block a submission, because a late report is itself a breach, so unverified items are allowed through as explicitly declared gaps with the reason recorded and surfaced on the exception dashboard — the submission states what it could not substantiate instead of hiding it. Retention rules that conflict were resolved by class, with a documented matrix, legal hold that overrides deletion, and a deletion process that records what was destroyed and under which rule. Field capture succeeded only when we stopped asking for it separately: capturing a pre-start inspection or a ticket became a step inside the job the crew was already doing, on a phone that works offline, with the alternative being a phone call to a supervisor rather than a form nobody filled in.

05Rollout and change management

We automated one report first: the monthly regulator submission, chosen because it recurred often enough to prove the approach quickly and was not the most politically sensitive. For two cycles the team assembled the pack by hand as well, compared the two outputs figure by figure, and signed off the comparison before the manual assembly was retired. That parallel period found eleven mapping errors, all of which were the kind that only appear with real data.

Evidence backfill ran alongside. Rather than attempting to load history wholesale, we backfilled the current period and one prior period completely, then loaded older material by class as it was requested, so no one spent weeks scanning paper that nobody would ever ask for. Site supervisors were trained in a single session built around the dashboard they would actually see, and the exception queue was given a named owner with a weekly review, which is what turned escalation from notifications into action.

06Results, and what we would do differently

Preparing the monthly pack now takes about five and a half hours, almost all of it review rather than collection, against five to seven working days before. Ninety-six per cent of evidence records are collected from source systems without anyone asking for them. Expired certifications have not occurred in the fourteen months since full rollout, against eleven discovered in the preceding year, and the most recent client audit raised one minor finding where the previous audit raised seven.

One thing went wrong in the second month of live reporting. The regulator had changed its definition of a reportable incident — narrowing it in a way that altered a count — and our generator had cached the previous year's template and transformation. Because generation is automatic, the pack was produced and very nearly submitted against the old definition. Nobody was alerted, because nothing had technically failed. We now treat a template revision as a change requiring explicit acknowledgement: transformations are pinned to a version, a new revision blocks generation until a named person reviews the diff and approves it, and a submitted report can never be silently regenerated. The report in question was corrected before submission and no incorrect figure reached the regulator, but the near miss changed how we handle every external schema we work with.

What we would do differently is start the evidence register earlier. We built collection and reporting first because they were the visible wins, and the register — the definition of what is actually required — was treated as configuration. It is the part that makes the rest defensible, and it should have been the first deliverable rather than the third.

5.5 hrs
Monthly pack, was five to seven days
96%
Evidence collected without manual chase
0
Expired certifications in 14 months, was 11 a year
1
Audit finding, down from seven
Compliance team reviewing a submission before it is lodged
The time saving is real, but what changed the job is that we no longer guess. If an auditor asks where a number came from, we show them the documents, and if something is missing we say so in the submission rather than hoping nobody looks.
Compliance Manager, WA resources services contractor
Delivery notes

Stack and delivery notes

The platform runs on AWS in the Sydney region, with the application in containers, a managed PostgreSQL database for the register and audit records, and object storage with versioning and object lock for documents. Collection runs as scheduled jobs on a queue with per-source failure alerting.

PHP / Laravel Vue 3 PostgreSQL Amazon S3 (object lock) AWS Lambda Redis queues Docker Terraform CloudWatch Power BI
Related work

Other delivered systems

Reporting problems usually turn out to be data problems upstream. These case studies cover the same ground from different directions. Request a quote if you would rather discuss your own reporting obligations first.

Field Service Operations Platform

Capturing work evidence at source for mobile crews across regional Western Australia.

ERP & CRM Integration Hub

One governed layer feeding downstream systems, with reconciliation instead of silent mismatch.

Legacy Platform Cloud Migration

Proving recovery objectives for an application that had never had a test environment.

Inventory & Warehouse System

Lot and serial traceability built on an append-only ledger across four warehouse sites.

Dreading the next reporting cycle?

A 45-minute scoping call, no obligation. We will tell you honestly what can be automated and what cannot.

Request a Quote