Most monitoring tools are designed for the person looking at the screen. Tiles, colours, a ranked list of things to worry about. That is fine, and we have a screen like that too. But the person looking at the screen is not the person who decides whether a second-line risk function can adopt the tool. That decision belongs to internal audit, and increasingly to the regulator behind them.
Their question is different. Not "is this number right?" but "show me how you know". A risk function cannot put a figure in front of a committee unless it can trace that figure back to a document, a page and a person, and it cannot use a tool that makes tracing harder than the spreadsheet it replaced.
Every figure traces to a page
So the first design rule in ExactCov is that every number on every screen carries a citation. A threshold points at the clause that set it, in the stored copy of the executed schedule, on the page where it appears. A NAV observation points at the notice it came from, with the passage highlighted. A test result names the observation it tested, the comparator observation it tested against, and the basis it used. Click the headroom figure and the two notices open side by side with the clause between them.
The stored document is the version that was read. If an amendment arrives, the new document is stored alongside the old one, and terms that changed point at the amendment from its effective date. Nothing is overwritten. The auditor can open the register as it stood on any date and see what the tests would have said that morning.
Every write is audited
The second rule is that there is no unaudited write. Every insert and every update goes through one path that stamps who did it, when, and from what. Tables that hold observations, test results and limit changes are append-only: a correction is a new row that supersedes the old one, never an edit. A limit that was resized on a NAV and later reversed shows both events, with the actor for each.
This applies to the system as much as to people. When the engine marks a fund stale, re-runs a test or proposes a limit, that action is in the trail under the engine's name with the rule that drove it. Internal audit's most common finding on monitoring tools is a figure that changed with no record of why. We treat that as a bug class, not a policy.
A number a risk officer cannot defend is not a risk number. It is a rumour with a decimal point.
The unglamorous half of due diligence
The same audience asks the security questions, and they deserve straight answers rather than a slide. ExactCov is Cyber Essentials certified. Data is encrypted in transit and at rest and held on UK and EU infrastructure, with residency fixed per tenant. We commission an independent penetration test annually and share the summary under NDA. Documents are never used to train models, and a tenant can elect zero data retention so that a document is deleted once its terms are extracted and cited. Single sign-on, a custom data processing agreement, and private or on-premises deployment are available on enterprise terms. The detail is on our security page.
None of that is a feature in the sense that a dashboard is a feature. It is the condition for being allowed in the building. We would rather say so plainly than discover it in month four of a procurement.
Why it makes the product better anyway
Designing for the auditor turns out to be good for the person at the screen too. Citations make disputes short: the analyst and the credit officer look at the same page instead of arguing about a spreadsheet cell. Append-only history makes "what did we know in March" a query rather than a reconstruction. And a system that can explain every number is a system that its users learn to trust, which is the only way a monitoring tool ever replaces the spreadsheet next to it.