Notes · Reviewed 10 September 2026
Evidence that stays true: compliance records as data, not a folder tree
A folder of certificates is only current in the week before an audit. Holding the same information as structured data changes what the organisation can answer, and when.
Most compliance information is held as documents in folders. A register in a spreadsheet, an assessment in a report, evidence in a directory named after the year. Everyone knows the arrangement is imperfect and everyone tolerates it, because the alternative gets presented as a software purchase, and the software purchases have mostly disappointed.
The problem is not the folders. It is that the information has no structure, so nothing can be asked of it.
The question you cannot answer
A compliance function should be able to answer this in minutes: which of our statutory inspections are overdue right now, on which assets, and who owns each one?
With documents in folders, answering it means somebody opening things. The answer takes days. It is out of date by the time it is compiled. Worst of all, nobody asks the question between audits, because asking it is expensive. The organisation ends up knowing its compliance position twice a year, by appointment.
What structure means in practice
Not a new system. A shape. The same information, recorded so its parts are related to one another instead of described in prose:
- The duty, and which obligation it comes from.
- The asset or process it attaches to.
- The frequency and the owner.
- The event: what was done, when, by whom.
- The evidence: the artefact that proves the event, held against it and not filed somewhere else.
Once those relations exist, the overdue-inspections question is a query, not a project. So is “show me everything relating to this asset”, which is what gets asked after an incident, usually at the worst possible moment.
Why it usually fails
Two ways, both avoidable.
The first is a parallel system. A compliance platform is bought, the information is entered once, and then the work carries on in the maintenance system, the document system and somebody’s inbox. Within a year the platform is a museum. One rule avoids this. The record has to be populated from where the work already happens. If keeping it true is a second job, it will not be kept true.
The second is buying a product before understanding the duties. The structure has to come from the obligations: what you are required to do, on what, how often. An organisation that has not established that will adopt whatever model the software assumes, which is someone else’s estate and someone else’s regulator.
What changes
Reporting stops being assembled and starts being generated. That sounds like an efficiency. It is really a governance change. When a board paper is produced from the record instead of compiled for the meeting, the position in the paper is the position, and it can be interrogated in the room. Nobody has to take on trust that the summary reflects the evidence, because the summary is the evidence, arranged.
The second change is less obvious. When the current position is cheap to obtain, people start asking for it. At that point compliance stops being an event twice a year and becomes something the organisation knows.
Where “digital twin” comes in, and where it does not
A structured, maintained model of your assets and processes is a reasonable thing to call a digital twin. That is the sense in which the term is worth using: the ISO 19650 idea of information that is current, accountable and findable. It is not a three-dimensional visualisation of the site, and the visualisation will not answer the overdue-inspections question. Be wary of anything sold as the second when what you need is the first.