The idea the product is built on
What is provable compliance?
Provable compliance means the evidence that a legal duty was met is produced by doing the work, recorded at the moment it happens, and traceable back to the event that produced it. The opposite is asserted compliance: the claim exists, but the record behind it is assembled afterwards from memory, email and whoever still works there.
The mark is two mirrored E’s — employer and employee — closing around a seal. The seal is the point: the record is what makes the claim hold.
Employer · Employee · Compliantly · (EEK-lee)
Why “we did it” is not the same as “we can show it”
Most organisations genuinely do the work. Committees get constituted, training runs, cases get heard. What fails is the second half: a year later, the person who ran it has moved on, the confirmation is in a mailbox nobody can open, and the date is somebody’s best recollection. The duty was met and the organisation still cannot demonstrate it.
Under questioning that gap is indistinguishable from not having done it at all. This is why the useful unit is not a policy document or a certificate, but a control that carries its own evidence — and why the honest question to ask of any compliance claim is not “did you?” but “show me where that came from.”
How the evidence gets made
Five steps, and the direction matters: the work produces the record, rather than someone describing the work into a record afterwards.
-
01
Obligation
A duty the statute places on the employer, carrying the provision it comes from.
-
02
Control
The obligation becomes a running control with one owner and one due date.
-
03
Event
Doing the work emits an event — a committee constituted, a training run, a case closed.
-
04
Record
The event writes to the register the law requires, at the moment it happens.
-
05
Audit pack
The export is assembled from those records, and every figure resolves back to its event.
The vocabulary
These terms are used precisely throughout this site, so they are worth defining once. They describe our operating model, not any statute’s language.
- Obligation
- A single duty a statute places on an employer, recorded with the provision it comes from. One law produces many obligations, and they rarely share an owner or a deadline.
- Control
- An obligation made operational: one owner, one due date, one current status. A control is the difference between knowing a duty exists and running it.
- Event
- Something that actually happened — a committee constituted, a session delivered, a case closed. Events are recorded when they occur, not reconstructed later.
- Register
- The record a statute requires be kept. In a provable system the register is written by the event rather than maintained alongside it.
- Provenance
- The trail from a figure in a report back to the event that produced it. Provenance is what makes a number defensible instead of merely stated.
- Audit pack
- An export assembled from the registers, built to be read by someone who was not in the room — a regulator, an auditor, a board, or a foreign parent.
- Aggregate floor
- The minimum group size below which no figure about people is released at all. It is what stops an aggregate from quietly identifying an individual.
What a proof layer is not
Four kinds of tool sit near this problem and solve a different part of it. None of them is a competitor to be beaten; the distinction is just worth being clear about, because buyers frequently already own one and reasonably ask whether that covers it.
| Category | What it does | Where the proof layer sits |
|---|---|---|
| Training providers | deliver sessions and issue certificates, usually for one law. | Completion records are evidence for one control among many. EECly works alongside whoever runs your training. |
| Governance and infosec platforms | automate control evidence for security frameworks. | Same instinct, different obligations. Those frameworks are voluntary and contractual; these nine are statutory and Indian. |
| HR systems | run payroll, leave, performance and the employee record. | They own the system of record for employment. They do not answer whether a statutory duty is currently met, or prove it. |
| Assistance and wellbeing programmes | provide care — counselling, helplines, clinicians. | They deliver the help. Nothing about an individual using it reaches the employer, and the proof layer sits outside it. |
Questions people ask
- What does "provable compliance" mean?
- Provable compliance means the evidence that a legal duty was met is produced by doing the work, at the time it happens, and can be traced back to the event that produced it. The opposite is asserted compliance, where the claim exists but the record supporting it is assembled afterwards from memory, email and whoever still works there.
- How is that different from just keeping records?
- Keeping records is a separate activity that can be skipped, delayed or done from recollection. In a provable system the record is a by-product of the work, so there is no version of events where the task happened and the evidence did not.
- Why does provenance matter if the number is correct?
- Because a regulator, auditor or board is not testing the number, they are testing whether you can show where it came from. A correct figure with no trail behind it and an invented one look identical under questioning.
- Does provable compliance require surveillance of employees?
- No, and it is close to the opposite. What has to be provable is that the employer met its obligations — that a committee exists, that training ran, that a deadline was hit. None of that requires the employer to see an individual employee’s complaint, counselling or health data, and in EECly it cannot.
- Which laws does this apply to in India?
- EECly covers nine: PoSH, Mental Healthcare Act, Maternity Benefit, RPwD, Night-shift safety, Occupational health, Vigil mechanism, DPDPA, BRSR. Each carries its own committees, registers, deadlines and consequences, and each is usually owned by a different person inside the same company.