← All journeys Confidential · NDA Compliance journey · UK GDPR · FCA SMCR · EU AI Act

A hire that can survive
the regulator.

How a bank's compliance officer signs off a Vault Hire-sourced hire and how the AI Compliance Response Platform turns a 6-week customer due-diligence questionnaire into a 3-day exercise.

Compliance officer
01

The pack lands in the compliance inbox

Once the recruiter accepts the offer, the bank's compliance officer is notified. They open the candidate's compliance pack directly — no emails, no PDFs, no manual chasing.

Vault overview
Fig 01 · Compliance officer's view of Sarah's pack.

What this step does

The compliance officer sees the same readiness card the candidate did during onboarding. Every section is signed, hashed, and dated.

Compliance officer
02

Pack readiness summary

A traffic-light view of every required artefact — RTW, SMCR refs, background checks, sanctions screen — with what's signed, what's still in-flight, and any items that need re-validation.

What this step does

Every red flag is actionable. The compliance officer can request additional evidence directly from the candidate, with a one-click endpoint that surfaces in Sarah's vault as a vault-access-style request.

Compliance officer
03

Six-year SMCR lookback

SYSC 22 mandates six years of regulatory references. Sarah's vault already contains signed references from HSBC and Barclays — both arrived through Vault Hire, both content-hashed, both dual-signed by the referee.

SMCR tab
Fig 03 · SMCR Regulatory References — the rail every banking hire rides on.

What this step does

The SMCR pack is what stops most hires dead for 6+ weeks. Vault Hire pre-positions it. The compliance officer's job becomes reading, not chasing.

Compliance officer · DPO
04

Article 12 inference register

The EU AI Act requires automated-decision-making logs. Vault Hire records every AI inference — model, prompt-redacted, output, candidate sign-off — and surfaces them per hire.

What this step does

  • Every AI overview draft Sarah saw and either approved or edited.
  • Every model version used (e.g. Claude Sonnet 4.5 build XYZ).
  • Article 50 disclosure: what Sarah was told the AI was doing.

The compliance officer can confirm with one glance that no automated decision affected Sarah's hire — the AI only produced text she explicitly endorsed.

Compliance officer · DPO
05

DSAR & rectification log

If Sarah submits a UK GDPR Article 15 request, the bank's DPO sees what was exported, when, by whom. Same for Article 16 (rectification) — every edit to her record is logged.

Audit trail
Fig 05 · Audit trail with the DSAR download button.

What this step does

Operational subject-rights requests stop being a 30-day ticket — they're self-service for the candidate and audit-visible to the bank.

Compliance officer · external auditor
06

AI Compliance Response Platform

When the bank's customers ask Vault Hire's compliance team to fill out a due-diligence questionnaire (DDQ / SIG / CAIQ), the AI Compliance Response Platform drafts answers from the audited knowledge base — NDA-gated, human-verified.

AI Compliance Response Platform
Fig 06 · The AI Compliance Response Platform interior.

What this step does

Customer due-diligence questionnaires typically take a fintech vendor 4-6 weeks per response. Vault Hire's tool delivers a verified-AI draft in hours, with every answer pinned to a knowledge-base source.

Compliance officer
07

Sign-off & sealed archive

What "done" looks like

  • Compliance officer e-signs the final pack.
  • Pack is hash-chained and frozen; nothing can be silently edited.
  • Vault Hire emits a notarised receipt linking the hire's records to a Merkle root.
  • The bank's WORM archive ingests the receipt directly.

This is the artefact the FCA examines if it ever inspects the hire. It exists by default — no extra work, no marketing-glossy "compliance dashboard" needed.

Confidential · NDA required

Access not granted

The Vault Hire journey docs are confidential under NDA. Please request access and use the link emailed to you to view this page.

Request access