Compliance Agent — Plain-English Guide
Audience: reviewers, compliance officers, marketing leads. No technical background needed. Engineering version: technical.md. Back to the agents index.
In one line
It reads content against your own written rulebook and tells you what a reviewer would stop — quoting the exact phrase and citing the rule it came from.
The problem it solves
In regulated financial services, the risk isn't usually a dramatic mistake. It's an ordinary sentence that reads fine to a marketer and reads badly to a regulator: a rate stated as a promise, a comparison with no source behind it, a competitor described a little too warmly.
Catching those means someone reads every piece against every rule, every time. That doesn't scale, and attention fades by the fortieth draft.
The Compliance Agent does that read consistently, then hands the judgement back to a human.
It runs at two different moments
This is the part worth internalising, because the two are genuinely different jobs:
1. On a news article, before you write
"If we wrote something based on this, would that create risk?"
Some topics can't be covered at all without repeating something restricted. Better to know before anyone drafts.
Where: the Discovery card → "Run AI compliance agent".
2. On a finished draft, before you publish
"This is about to go out under our name. Is every claim defensible?"
The bar is higher here. A journalist reporting a rate is reporting a fact. The moment you republish it, it becomes your claim. Same sentence, different liability.
Where: the blog studio → Compliance.
You press the button
It does not run automatically, and that's deliberate — an automatic review becomes background noise people click past. A review you asked for is a review you read.
Two things do run in the background, and they aren't this agent:
- A keyword scan for blocked phrases, on every draft save and feed read. Edit a blocked term and it takes effect immediately, no re-run needed.
- A quality check during generation that can ask the writer to try again.
The AI agent is the deeper read, on demand.
What you get back
A list of findings. Each one has:
- A severity — high, medium or low
- The exact phrase that triggered it, quoted from your text
- What to change, in one sentence
- The rule it fired on, from your own rulebook, with the reasoning that rule was written for
Plus a list of rules it checked and found clean — so you can see the review was thorough, not just that it found three things.
Severity means something specific
| Severity | What it means |
|---|---|
| High | Cannot be sent without sign-off. This blocks publishing. |
| Medium | Can proceed, but edit it first |
| Low | Worth knowing, nothing more |
Working through findings on a draft
Each flagged phrase is highlighted in the editor. Hover it and you get a card with these choices:
| Action | What happens |
|---|---|
| Apply previous ruling | Only appears when someone already decided this exact kind of thing. One click, same outcome as "Not an issue" |
| Ask AI to fix | Sends a rewrite request to the chat. The suggestion comes back showing only the paragraphs that changed, with Accept and Reject on the card. Nothing changes without your approval |
| Full review | Opens the side panel with everything, including cleared rules |
| Not an issue | Dismisses that finding |
Ask AI to fix shows you what changed, not a whole new article. The reply lands in the chat as a short list — Edited · Heading, old wording struck through, new wording under it — so you can read the two lines that moved instead of comparing two full drafts. If you want the whole thing side by side it's still one click away under View full body. Accept and the fix goes into the editor; that finding moves to Fixed by AI and stops blocking publication.
That last part is checked, not taken on trust: a finding only counts as fixed while the flagged phrase is genuinely gone from the draft. Undo the edit and the finding comes straight back.
About dismissing: a dismissal sticks. It survives re-running the agent — you already judged that phrase, and having it reappear would train people to ignore the panel. You can undo it in the "Dismissed as non-issues" section. Regenerating the draft from scratch clears them, because it's new text.
Edits make the review stale. Change the draft and the highlights drop away, because the review no longer describes what's on screen. Run it again.
It remembers what you already decided
Say you write MSME in full once at the top of a draft, then use the acronym after that. The agent flags every later use, you dismiss it — and next week, on a different draft, you do the whole thing again.
So the first time you dismiss something, the system writes down the general version of your decision: "an acronym already spelled out earlier in the draft doesn't need spelling out again." Next time that comes up, the finding arrives with a Previously accepted badge, the note explaining what was decided and how many times, and a one-click Apply previous ruling.
Three things worth knowing about it:
- It never edits your rulebook. These live in their own list, on their own page — Compliance Exceptions. Your sourced rules are untouched, which is what makes a bad exception safe to just delete.
- It never hides a finding. Even once you've told the agent about an exception, it must still report the flag — it just says it recognises your earlier call. Nothing disappears quietly.
- You decide when it counts. A newly learned exception starts off. Off, it still shows reviewers the badge and the one-click resolve. Only when an admin turns it on does the agent itself get told about it — because that changes how every future draft is reviewed, and that should be somebody's decision.
Dismissing the same thing again costs nothing and just raises the counter. And if the AI is unavailable, your dismissal still works — you simply don't get a note out of it.
The publishing gate
A high-severity finding blocks "Send to CMS" until a human acknowledges it.
This is enforced on the server, not just hidden in the interface — there's no way around it by refreshing or clicking faster.
To clear it, a reviewer uses "Acknowledge and allow sending". That's stamped against the current version of the draft, so if someone edits afterwards, the gate comes back.
The check is refreshed at the moment you publish. If the draft has been edited since the last review, pressing Send re-runs the agent once before deciding — so you're never publishing against a verdict about text that no longer exists. If that re-check can't run, publishing is refused rather than allowed through on an out-of-date review.
Publishing is always a human action. The gate doesn't decide anything — it only guarantees a person read the findings before deciding.
Your rulebook is the whole product
The agent has no built-in opinion about Indian financial regulation. It applies your rules, which live in the Compliance Intelligence Centre.
Each rule you write carries:
- What it says
- Why it exists — the reasoning
- Where it came from — the source or circular
That "why" is what makes findings useful. Instead of "this violates rule 12", you get the reasoning behind rule 12, so you can judge whether it genuinely applies here.
Up to 40 rules per tenant. Admin access to edit. IIFL's 22-rule book can be loaded in one command.
A rule the agent invents is thrown away. Every citation is checked against your actual rulebook before you ever see it. It cannot make up a rule and attribute a finding to it.
Two behaviours that look like bugs but aren't
An empty result is normal and correct. The agent is explicitly instructed not to flag an article for merely being about finance, for naming a company neutrally, or for reporting verified facts. If you review ten clean articles and get ten empty results, it's working. An agent that flags everything gets ignored, which is worse than one that flags nothing.
No rulebook means no review — not a pass. If you haven't written rules, or the AI service is unavailable, the agent returns nothing to report rather than this is clean. The keyword scan still runs. Silence is never treated as approval.
What it does not cover
- Video scripts and hooks get the keyword scan but no AI review.
- Only one checkpoint, at the end. The roadmap sketches an RBI checkpoint at three points in the creative process — during content selection, during creation, and at approval. Today there's one, on blogs, at the end.
- Keyboard users can reach every finding through the side panel, but the hover cards need a mouse.
- No record of who acknowledged what beyond the version stamp.
- Very long articles — it reads the opening portion, not every word.
Subagents
Two framings, then a set of lenses. All in one call today; each lens is a distinct question a reviewer would ask.
- Source reviewer — would writing from this article create risk?
- Draft reviewer — this publishes under our name; is every claim defensible?
- Claim auditor — restricted claims, guaranteed returns, unverified performance or ranking claims
- Competitor watch — is a named competitor presented favourably?
- Regulatory reviewer — personalised advice, or a claim needing a disclaimer the brand cannot make
- Brand-avoid checker — conflicts with the brand's own avoid guidance
Deterministic, deliberately not subagents: the citation resolver (drops any rule id the model invented) and the finding merger (an exact blocked-phrase match outranks a model paraphrase of the same evidence). The model proposes; these adjudicate.