AI intelligence system

ComplianceIQ

From document summary to document-to-document verification.

A verification engine that reads contracts, policies, procedures and regulatory text together and reports where they contradict each other, where evidence is missing and where an obligation has no controlling procedure.

Enterprise Legal & Compliance Regulated Industries Document AI Contradiction detection
Sector
Legal, Risk & Compliance
Year
2025
Duration
7 months
Team
6 people
Platforms
Web · API
Status
In production
ComplianceIQ — visual identity for the case study
Claim-level Unit of analysis Not document-level
Both sides Shown per finding Passage against passage
4,000+ Documents in corpus Reference deployment
Cited Every finding To document, clause and page

01 — The problem

The compliance function held four thousand documents. Contracts committed the business to controls that internal policy did not require. Policies referenced procedures that had been superseded. Nobody knew, because verifying it meant reading everything against everything.

Summarisation tools made this worse rather than better. A good summary of a bad policy is still a bad policy, and summarising each document separately is exactly the wrong operation when the problem lives between documents.

02 — What we did

We built for the space between documents. Obligations, controls and definitions are extracted as structured claims with their source location attached, then compared across the corpus. The unit of analysis is the claim, not the file.

Findings are asserted with both sides shown. A contradiction is reported as two passages side by side with the reasoning between them, so a compliance officer verifies in seconds instead of taking the system's word for it.

Summarising each document separately is the wrong operation when the problem is between them.
Interface

What it looks like in use

Two of the screens that carry the most weight in daily use, rebuilt here from the production design system.

complianceiq.aurezalabs.com/finding/882
Finding 882 · contradictionHIGH
MSA-2024-11 §7.3 · retain 7 yearsCLAUSE A
POL-DATA rev 9 §4 · purge at 24 monthsCLAUSE B
Both cannot hold for customer recordsCONFLICT
Owner · data governanceTRIAGED
Cited to page and clause

Both sides, side by sideA contradiction is presented as two passages with the conflict stated between them, so an officer verifies in seconds.

complianceiq.aurezalabs.com/coverage
Framework coverage4,112 DOCS
Access control12 / 12
Data retention7 / 9
Incident notification · no controlling procedure0 / 3
74% requirements covered

Coverage stated, not assumedEach requirement shows the control that satisfies it, or shows plainly that nothing does.

Capabilities

What the system does

Grouped by the job each set of capabilities exists to do, rather than by which team built it.

Ingestion and extraction

01 · Making documents comparable

Multi-format ingestion

Contracts, policies, procedures and regulatory text from documents, scans and content systems.

Clause extraction

Obligations, controls, definitions and exceptions extracted as structured claims with precise source anchors.

Definition resolution

Defined terms resolved per document, since the same word often means different things in two contracts.

Version awareness

Supersession chains tracked so comparison runs against the controlling revision.

Cross-document verification

02 · The core capability

Obligation mapping

Every external obligation mapped to the internal policy and procedure intended to satisfy it.

Contradiction detection

Claims that cannot both hold surfaced with both passages and the conflict stated explicitly.

Gap detection

Obligations with no controlling procedure, and controls with no evidence requirement attached.

Regulatory mapping

Framework requirements mapped onto the internal control set with coverage stated per requirement.

Review and reporting

03 · Getting it used

Citation-linked findings

Every finding opens directly onto the source passages on both sides.

Triage workflow

Findings routed by severity and owner with accept, dispute and remediate states.

Change impact

When a document changes, everything downstream that depended on it is re-verified and flagged.

Audit reporting

Coverage and exception reports generated from the live finding set.

Architecture

How it is put together

Layer by layer, with the reason each one exists — because the reason is usually the interesting part.

01Ingestion

Format-agnostic pipeline with layout-aware parsing and OCR for scanned material, preserving structure and page anchors.

  • Layout parsing
  • OCR
  • Structure preservation
02Claim extraction

Structured extraction of obligations, controls and definitions with span-level source anchors.

  • Extraction models
  • Span anchoring
03Comparison engine

Candidate pair generation via semantic retrieval followed by entailment and contradiction classification.

  • pgvector
  • NLI models
04Verification

A validator requiring both supporting spans before any finding is published, discarding unsupported detections.

  • Span validator
  • Claude
05Workspace

Side-by-side review interface with triage, ownership and change-impact tracking.

  • React
  • PDF.js
  • PostgreSQL

Technology

Document AI

  • Layout parsing
  • OCR
  • NLI models
  • pgvector

Backend

  • Python
  • FastAPI
  • PostgreSQL
  • Celery

Frontend

  • React
  • TypeScript
  • PDF.js

Platform

  • Kubernetes
  • S3
  • Audit logging
Outcome

What changed

Measured against how the operation ran before, not against a benchmark chosen after the fact.

  • Conflicts between documents became visible. Contradictions that had survived years of separate reviews were surfaced in the first full pass.

  • Coverage is stated, not assumed. Each regulatory requirement shows the control that satisfies it, or shows that none does.

  • Verification takes seconds per finding. Both passages are shown, so an officer confirms rather than investigates.

  • Document changes trigger re-verification. Downstream dependencies are re-checked automatically.

How it ran

  1. Months 1-2

    Corpus analysis

    Assessed document types, formats and how badly supersession chains had degraded.

  2. Months 3-4

    Claim extraction

    Structured extraction with span anchoring, validated against manually marked-up documents.

  3. Month 5

    Comparison engine

    Retrieval-based pairing and contradiction classification with the span validator.

  4. Months 6-7

    Review workspace

    Side-by-side interface, triage workflow and change-impact re-verification.

Related work

From the same practice

All fifteen projects

Manufacturing & Production Quality

LineTrace

From defect detection to defect causality.

A multimodal system that correlates line video, machine telemetry, batch records and operator actions to explain why a defect happened, not merely that it did..

2025 · 10 months
Telecommunications & Network Operations

NetCause

Not alarm detection. Failure hypothesis reduction.

A correlation engine that turns an alarm storm into a short ranked list of probable root causes by reasoning over network topology and fault propagation rather than alarm counts..

2025 · 8 months
Oil & Gas · Asset Integrity

PipeIntegrity

From a single inspection to longitudinal asset integrity.

A vision system that detects and localises pipeline deterioration, then tracks each defect across inspection cycles so maintenance is prioritised by progression rather than by appearance..

2024 · 9 months
Something similar?

Running into the same problem ComplianceIQ solved?

Tell us what you run. We will reply within two business days with what we would build for your situation — and, just as usefully, what we would leave out.