Compliance: your rules applied, every check recorded
A compliance check is worth what its consistency and its audit trail are worth: the same rule applied to every file, and the evidence of what was verified. Your agent applies your business rules file by file, states for each rule what was found and keeps the full record of the check. Hosted in France: the data examined stays with you. The compliance team draws the conclusion and decides what follows.
Updated on
The result distinguishes three cases: rule satisfied, element not found in the file, situation to examine.
The full record of the check is kept.
🔗 Sourced · internal rules and the documents in the files
Concluding that something is compliant, or deciding what follows, rests with the compliance team: it is a binding act.
✎ Support · material gathered, human conclusion
A Blue Lemon Agent compliance agent applies your business rules file by file, distinguishes rule satisfied, element not found and situation to examine, and keeps the full record of every check. It never concludes that something is compliant: that act belongs to the team. It runs on local inference or is hosted in France: the data examined stays with you, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
These figures describe our offer, not results measured at a client. How large the gain is on your number of rules and volume of files checked is confirmed by a pilot.
What does an AI agent bring to your compliance checks?
A consistent, documented check across every file beats a thorough check on a sample.
! The issue
A compliance check rests on applying a rule identically and on the evidence of what was verified. Both requirements are mechanical, and that is what makes them automatable: the agent puts every file through every rule, with the document its finding rests on, and keeps the full record.
✓ Our answer
The compliance team has a check that is exhaustive, consistent and documented, and concentrates its expertise on the situations the rule does not settle. Concluding that something is compliant and deciding what follows are binding acts that stay human. Local inference or an isolated resource hosted in France: the data examined during the checks does not leave the company.
The data examined during the checks: sovereignty & compliance
A compliance check by its nature examines the most sensitive data in the files. Here is how the architecture of our agents protects it.
Local inference
The agent can run on a machine belonging to your organisation: no data examined and no check result leaves the network.
Hosting in France
Otherwise, a dedicated and isolated resource hosted in France, under French law — your files and your applicable rules: processing and access within the European Union targeted by the architecture.
Reduced extraterritorial exposure
For the data examined during the checks, the architecture aims to reduce exposure to the Cloud Act and FISA 702; being located in France or in the European Union does not, on its own, guarantee immunity.
Isolated resource
No pooling: an environment strictly dedicated to your company and its internal rules.
Full record of every check
The rule applied, the finding and the supporting document are kept for every file; encryption, role-based access and logging that can be used in an audit.
AI Act: governed deployment
The agent is strictly in support; no compliance conclusion is drawn and no follow-up is decided automatically; traceability and human oversight from end to end.
What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.
- The applicable location is that of the architecture set out in the quotation and verified before commissioning.
- Local execution is announced only for the configuration explicitly described and accepted in the quotation.
- The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
- Roles and permissions are configured and accepted for the identities and systems actually connected.
- The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
See the agent at work
4 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.
A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.
· An annual obligation has no evidence for 2026, and the date passed on 30 June. The 2025 evidence is on file; the 2026 evidence does not exist.
· Eleven obligations name an owner who has left the company, three of them with a deadline within four months.
· Evidence filed in April is an undated screenshot. It stands for three obligations.
· An external inspection is announced for October and twelve obligations within its scope have not been reviewed since 2024. morning-watch_4-flags.pdf4 flags · 1 deadline passed
⛓ Source · the company's obligations register, evidence filed, assignments, inspection letter
What I record: your register enters this obligation with a deadline of 30 June each year. The 2025 evidence is on file, dated 12/06/2025. No document has been filed for 2026.
What that may mean, and the three readings are not equivalent: the obligation was met and the evidence was not filed; it was not met; or it no longer applies — a threshold may have changed, an activity ceased.
The third deserves putting: your register dates from 2023, and four obligations still appear in it although the corresponding activity was sold in 2025. I flag them separately.
What I do characterise, and it is exactly what your register asks for: the finding — rule met, item not found, situation to be examined. This one is item not found for 2026, carried at the date it was overrun. The word breach stays with the compliance team, because it is assessed against the applicable text, your situation and sometimes a tolerance — and because, written by them, it is enforceable.
What I provide: the obligation as you entered it, last year's evidence, the name of the owner assigned, and the exact date it was overrun. obligation_no-2026-evidence.pdf3 possible readings · 4 possibly spent obligations
⛓ Source · register of 14/03/2023, 2025 evidence of 12/06, assignments
Routing follows what can be recovered: an overrun deadline goes to the assigned owner and their manager, both — an owner who has left does not react; an orphan obligation to management, because assigning an owner is an act of organisation; unusable evidence to whoever filed it; an announced inspection to management and every owner in scope, as soon as the letter arrives.
With a chase: 48 h on an overrun deadline, 7 days on the rest, and a weekly calendar within 60 days of an announced inspection.
Then a quarterly summary: by obligation and by type of missing evidence, never by owner.
What this one pass has already given you: a deadline overrun since 30 June routed to the assigned owner and their manager, 11 obligations reassigned before a departure let them lapse, 12 obligations brought back inside the October inspection window, and four your register was still demanding for a business sold in 2025.
From tomorrow: the inspection file builds itself as you go instead of being rebuilt in three weeks of all-hands effort. Access stays yours — opened role by role, logged read by read, withdrawn on a word, and nothing leaves your walls. The characterisation is yours, and I hand it back in minutes: the obligation as you entered it, last year's evidence, the assigned owner, the exact date of the overrun.
The next step is ready: give me the date of your review and I will walk the register obligation by obligation. The weekly calendar for the October inspection starts on the word “yes”.
✎ Framework · no compliance declaration — the register is the company's own
What I record: an image filed on 14/04, showing a configuration screen. No visible date in the image, no capture timestamp, nothing establishing when the screen was in that state.
What it is meant to prove: three obligations, two of them annual.
Why that is a practical rather than a formal problem: on inspection day the question asked is "on what date were you in that state?" An undated capture answers "at some point". And evidence that dates nothing proves nothing about an obligation carrying a deadline.
What I did instead of rejecting it: I looked for something that would date it. The system log carries the change at 14/04, 09:12; set against the capture, it turns that image into dated evidence. The internal attestation linking the two is written — three lines pointing at the log entry — and awaits the operator's signature. What evidence is worth is said before the inspector, not here: I hand it over dated rather than commented.
What I propose: a list of your 47 pieces of evidence filed this year, sorted by what they can establish. 31 carry an enforceable date, 9 an internal date, 7 no date.
The 7 concern 14 obligations — that is where the file risk concentrates. 47-pieces_7-undated.pdf31 dated · 9 internal dates · 7 undated
⛓ Source · evidence of 14/04, 47 pieces filed this year, related obligations
What I check: that a document is attached, that it carries a date, that the date falls within the period the deadline covers, and that the document is not attached to another obligation as its sole justification.
What I do not check: that the content of the document establishes what the obligation requires. An annual inspection report can be dated, complete, and cover a partial scope — that has to be read, and read by somebody who knows the text.
What that gives across your 84 obligations: 62 have a dated document within the period; 14 have a document where I cannot tell whether it covers the scope; 8 have no document at all.
The group of 14 is the one to look at, and it is the most reassuring in appearance: the box is ticked, a document exists, and nobody has read what it covers.
What I provide for those 14: the obligation, the document, and the sentence or sentences of the document that define its scope. That is a two-minute read, not a full re-reading. 84-obligations_14-to-read.pdf62 covered · 14 to read · 8 with no document
⛓ Source · 84 register obligations, attached documents, declared scopes
What I record: eleven obligations carry the name of a person no longer with the company. The departures range from 2024 to May 2026.
What that produces: deadlines keep running, reminders go to an address that no longer exists, and nobody receives anything. Three of these obligations have a deadline within four months.
What it reveals about the process: leaving the company triggers closing access, returning equipment and final pay. It does not trigger reassigning regulatory obligations, because nobody has listed them at that point.
What I put in the file, and it is not nothing: a proposed name for each of the eleven, with what justifies it. The appointment stays your act of organisation — entrusting a regulatory obligation commits the person appointed, and that is precisely what makes it effective. Eleven boxes to tick, and from the next day reminders go to an address that exists.
What I provide: the eleven, their deadline, the department the obligation attaches to, and the last evidence filed with its author — that is often the best-placed person, and they are sometimes still here.
Of the eleven, seven have their last evidence filed by somebody other than the assigned owner. 11-obligations_orphaned.pdf3 with deadlines · 7 with an author still present
⛓ Source · 11 obligations, leavers register, authors of the last evidence
What I record: four obligations attach to an activity sold in 2025. They still appear in the register, with deadlines falling and reminders going out.
What that produces: four overrun deadlines every year, swelling a counter of overdue obligations. And a counter permanently showing overruns nobody handles teaches people to stop looking at the counter.
What I keep, and why I keep it: the four stay in the register. An obligation removed from a register disappears from the record, and one must be able to show, in 2028, that it applied until 2025 and was met until then.
What I propose: marking them "spent as of 30/09/2025", with the date and the reason, and keeping their earlier evidence. The register keeps its memory and stops producing noise.
And a question the other way, which I put without being able to answer it: did the 2025 sale give rise to new obligations? My register contains only what you put in it — and an obligation that is not in it will never make me flag anything. 4-obligations_activity-sold.pdfSpent, not removed · 1 open question
✎ Framework · no obligation removed — dated and reasoned extinction
The scope announced in the letter: it covers a family of obligations which, in your register, amounts to twelve. None has been reviewed since 2024.
What I looked at for each: evidence present, evidence dated, date within the period, owner in post.
· 5 are complete — dated document, legible scope, owner identified.
· 4 have a document whose scope requires reading.
· 2 have an undated document.
· 1 has had no document since 2024.
What I do forecast, and it is the figure that serves you: the state of the file, not the verdict. As things stand, 5 obligations out of 12 can be presented as they are; the other 7 need 11 person-days in all, 6 of them for the one with no document. The outcome of the inspection belongs to the inspector — a complete file is not a compliant file, and they may find what I was unable to read. What I can hold to is that they will have nothing to ask for twice.
What I propose: a calendar for the eight remaining weeks, starting with the one with no document — reconstituting it takes longest, and it is the only one that cannot be caught up the night before.
And a point of method: everything produced between now and October will be dated August or September 2026. That shows, and it is better known before somebody notices. 12-obligations_october-inspection.pdf5 complete · 4 to read · 2 undated · 1 with none
⛓ Source · inspection letter, 12 obligations in scope, evidence filed
What is kept: the obligation as you entered it, the evidence and its dates, successive owners, deadlines and overruns, and extinctions with their reason.
What is not kept, and cannot be: no compliance certificate, no compliance rate, no score per obligation or per department, and no opinion on the scope of a text.
Why "no compliance rate": a rate is computed on what is in the register. A company whose register is incomplete shows an excellent rate, which is exactly the reverse of reality. The figure would reward the omission.
And "no certificate": a document produced by a tool saying "compliant" is a document an inspector can request. It defends nobody, and it puts the company's own assertion against it.
What the quarterly summary contains: the next six months' deadlines, undated evidence, orphan obligations, and extinctions declared. Four factual indicators. what-is-kept.pdf5 items kept · 4 never produced
✎ Framework · retention periods to be set by the company
Analysing documents against the control rules is the heart of the work: for each rule I read the documents on file and look for what the rule requires, not what the document says. A three-page certificate can satisfy one rule and stay silent on two others — I report rule by rule, never document by document. What a neighbouring agent completes: fine extraction of data from a poorly scanned document belongs to a dedicated document agent, ordered separately; here I read what is readable and flag what is not.
Findings are qualified in three states, never two — and the difference between the last two is what spares you an inspection you did not prepare for:
· Rule satisfied — 6,918 findings. A document is attached, it carries a date, and that date falls inside the window the rule requires.
· Element not found — 874 findings. Nothing on file answers the rule. That is a gap, not a breach: I name the document expected and the person who holds it.
· Situation to examine — 340 findings. A document exists and something is off: date outside the window, different scope, version earlier than the rule. Those call for a human eye, and I say which of the three reasons brought them out.
What I never write: "compliant". A satisfied rule is a finding about a document; the compliance of a company is a judgement, and it belongs to whoever signs it.
A figure against me: 41 of the 340 "to examine" were in fact satisfied rules, all on evidence supplied as photographs, whose date appeared in the image and not in the file. The date shown inside the document is now read before the file date: 6 re-qualifications across the following 2,100 checks.
✎ Framework · rules applied, documents analysed, findings qualified
For every file checked, five elements are kept together and never come apart: the rule in the version in force that day, the qualified finding, the supporting document and its digital fingerprint, the date and time of the check, and the author — me, or the person who re-qualified it. 8,132 lines this month, 87,400 since go-live.
Why the version of the rule matters more than the rule: your 38 rules have seen 9 changes in eighteen months. A check run under a rule since amended is neither wrong nor right — it is dated. Without the version, an inspector reads last year's checks against today's rule, and you have nothing to put against it.
The log is append-only: a re-qualification is written after the fact, with its reason; it does not erase the original finding. Of the 41 re-qualifications just mentioned, all 41 original findings are still readable, next to what corrected them.
The foundation is a sovereign AI, and that is not brochure wording: the agent runs on a machine you designate — your own, or your hosting provider's in France, under French law — an architecture designed to reduce exposure to extraterritorial legislation, location alone not guaranteeing immunity. None of your evidence leaves your walls to be analysed, access is granted by role, it is logged, and it is withdrawn with a word, effective at the next check. A register of obligations and its evidence is exactly the kind of file you do not hand to a service whose reading place you do not know.
✎ Framework · audit trail kept file by file · sovereign foundation
Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit →
What does the agent actually do?
One agent, several kinds of check. All these uses work in support, subject to your approval.
Applying the rules
Puts every file through every rule, without exception.
Qualified findings
Distinguishes rule satisfied, element not found and situation to examine.
Audit trail
Keeps the rule, the finding and the supporting document for every file checked.
Analyse documents against the control rules
To extract the data from the documents checked, a dedicated document agent completes the picture.
Sovereign AI
The hosting and confidentiality foundation the agent rests on.
Need to go further?
These agents handle a different business process, with their own owner and their own price. They are added to this one.
In 15 minutes we identify the most relevant agent — without oversizing the project.
How many files can a compliance team check?
By taking on the mechanical application of the rules, the effort shifts towards the situations that call for expertise. How large the gain is depends on your volume and remains to be confirmed by a pilot.
The stages of your AI agent project
Audit & scoping
15 minutes to target the use case with the best return.
Quote or direct sign-up
A catalogue offer is bought online; a specific need gets a costed quote.
Design
We design the agent and its guardrails.
Integration & testing
We connect your tools to the agent, which is itself hosted in France.
Rollout
Going live and training your team.
Operation
Continuous supervision and improvement.
One package, one agent
A regulatory control agent (rules, findings, traceability), installed and operated for you.
Setup + controlled subscription
- Installation, configuration and training for your teams
- Operation, human oversight, updates and support
- Sovereign hosting in France, a dedicated and isolated resource
All inclusive, no setup fee
- Setup included (installation, configuration, training)
- Operation, human oversight, updates and support
- Sovereign hosting in France, managed end to end
On site, you own it
- Hardware installed on your premises (you own it)
- French / European AI models run locally
- Secure remote maintenance (Pro support included)
Four guarantees that matter to your checks
Related resources
Your questions, our answers
Does the agent conclude that a file is compliant?
What does "element not found" mean?
Can the record be used in an audit?
How are the rules formalised?
Is the data checked protected?
How long does it take to deploy this agent?
Other agents for control
Let's size up the potential in your checks
15 minutes to frame your rules and your files — hosted in France, supervised, with no commitment.