A Tax Control Framework You Can Actually Prove
Tax and risk teams map fiscal risks to controls, test those controls at two levels, attach the evidence, and produce the reports an auditor asks for — with a history that cannot be quietly rewritten.
Industry
Tax & Compliance
Solution
Risk & Control Governance
Engagement
~13.5 Months, Ongoing
Services
Enterprise Development

Proving It, Two Years Later
A tax control framework is how a large organisation demonstrates that its tax risks are known, controlled and monitored. Running one in spreadsheets is possible. Proving it to an auditor two years after the fact — showing which control was tested, by whom, against what evidence, and that nobody has edited the answer since — is not.
The intake is honest that the client's before-state is not documented, so we do not claim one. What is documented, in detail, is what the platform had to be able to withstand: an audit.
The Problems We Set Out to Solve
These are the engineering problems the codebase records solving. They are what separates a governance platform that survives an audit from one that merely looks like it would.
One tenant, many legal entities — and no real wall between them
Financial figures visible to roles with no business seeing them
Evidence documents served from links that stayed valid for a decade
A control framework whose history could be edited after the fact
Time and period logic drifting between the dashboard, the cron and the email
Scope First, Then Everything Else
Every mechanism below exists because an auditor will eventually ask a question the platform has to be able to answer with certainty.
Scope Enforced on the Server
A five-level hierarchy from company down to establishment, with scope resolved and asserted server-side on every request — so an out-of-scope entity is unreachable, not merely unrendered.
Financial Data Masked Before It Leaves
A server-side sanitiser strips financial fields from the response itself, with a matching mask in the interface. The payload is clean, not just the screen.
Evidence Links That Expire
Decade-long public storage URLs replaced with short-lived, signed download references plus access logging — so a link stops working and every retrieval is attributable to someone.
A History That Cannot Be Rewritten
An immutable audit-event trail, plus frozen, versioned and checksummed period snapshots. A closed period can be read and proven — never quietly changed.
What the Platform Does
Company Structure
Companies, master legal entities, legal entities, business units and establishments — the five-level hierarchy every permission is resolved against.
Users & Roles
Eight role levels from view-only partner through tax and risk managers to the platform operator, behind one permissions map.
Process Register
Business processes with their steps and linked risks, each opening into an interactive flowchart.
Risk Register
Operative and interpretative fiscal risks mapped to processes and risk areas, with likelihood, impact and a computed assessment.
Level I Controls
The operational control register and execution log — who is responsible, who is accountable, how often it runs, and what the last execution concluded.
Level II Monitoring
Test of design and test of effectiveness cycles — planned, executed and reviewed, each with its evidence attached.
Action Plans
Remediation plans linked back to the control or risk that raised them, with owners and due dates.
Risk Control Matrix
The full risk-to-control matrix with initial assessment, supporting documentation and control owner — the report an auditor opens first.
Risk Map & Archive
The current risk map, plus frozen, versioned and checksummed snapshots of every closed period.
Evidence Register
Control execution with its evidence, held together so a test and its proof cannot drift apart.
Activity & Approval Logs
User activity, approval and validation, and test-of-design/effectiveness activity — each a separate, queryable log.
Reporting Suite
Sixteen report modules over the same scoped data, each exportable to Excel or PDF, each obeying the caller's role and entity scope.
Partner Portal
Partner management with tenant switching, scoped tokens and genuine read-only sessions.
Audit Trail
A per-company immutable history of every event — the thing the whole platform exists to be able to produce.
Serverless, Multi-Region, Audit-Grade
Frontend
Backend
Data & Auth
AI & Delivery
Ticket by Ticket, Over Thirteen Months
- 1
Multi-Tenant Foundation
The five-level entity hierarchy and the scope resolver that every later feature is enforced against — built first, because retrofitting it is impossible.
- 2
RBAC & Enterprise SSO
Eight role levels behind a permissions map, plus SAML single sign-on and SSO-only accounts for enterprise identity lifecycles.
- 3
Risk & Control Core
The risk register, Level I execution, and the Level II design and effectiveness testing cycles on top of them.
- 4
Evidence & Audit
Immutable audit events, short-lived signed document references with access logging, and frozen checksummed period snapshots.
- 5
Reporting Suite
Sixteen report modules over the same scoped data, each exportable, each obeying the caller's role and entity scope.
- 6
Multi-Region Delivery
Three hosting targets on a branch-per-environment pipeline, with scheduled jobs and notifications on shared period logic so nothing drifts.
What Was Delivered
8
RBAC Role Levels
16
Compliance Reports
84
Data Collections
5-Level
Legal-Entity Hierarchy
A closed period can be read and proven but never quietly changed — snapshots are frozen, versioned and checksummed.
A user scoped to one legal entity cannot reach another's data, because scope is asserted on the server rather than applied in the interface.
Financial figures are stripped from the response before it leaves the API, not merely hidden on the screen.
Evidence documents are behind short-lived signed links with access logging, replacing URLs that had been valid for the better part of a decade.
Frequently Asked Questions
Yes — that is exactly what this platform was built to withstand. It keeps an immutable audit-event trail plus frozen, versioned and checksummed period snapshots, so a closed period can be read and proven but never quietly changed. You can show which control was tested, by whom, against what evidence, and that nobody has edited the answer since.
Services Behind This Build
Explore Other Case Studies
Building a governance, risk or compliance platform?
We build multi-tenant systems where access, evidence and history hold up under audit — not just under demo.
Talk to a Delivery Expert

