GRC software that actually gets used.
Most compliance programmes don't fail on the data model. They fail quietly — an audit slides past its date and nobody is told. AuditGauge is built around the chase: every audit has an owner, every slip has a reminder, and every stall lands on a named person.
Illustrative data
Built by RCS Tech — the team behind ProcurePulse and TRAXX, building enterprise software for regulated industries since 1999. AuditGauge grew out of the contract-audit and risk layer of that platform.
Compliance programmes rarely fail because a field was missing. They fail because a scheduled audit slid past its date and the only thing that changed was a number on a dashboard nobody opened.
We have seen it first-hand: a well-modelled audit engine, with an "overdue" status that nothing ever sets. The data model is fine. Nothing pushes.
AuditGauge treats adoption as the product. Overdue is computed on every read, never stored and forgotten. Every audit carries its own reminder ladder. An audit with no owner is treated as worse than a late one — because there is nobody to chase — and gets its own, earlier ladder. Completing an audit schedules the next cycle automatically, so a programme never silently ends after round one.
Compliance is never one person's job.
AuditGauge gives each role the view it needs — and makes sure the hand-offs between them are on the record.
See what is slipping before the regulator does.
- Escalated, overdue and unowned audits in one health strip
- Stalled audits arrive with a name and a day count
- Overdue notices and obligations escalate themselves
- Every threshold is configurable to your programme
Spend the day auditing, not chasing.
- Weighted parameters snapshot into findings automatically
- Evidence attached to the finding it supports
- Corrective actions tracked from open to verified
- One-click PDF audit report for sign-off
Know exactly who accepted which risk, and why.
- No risk is accepted on one signature — every acceptance shows both
- Justification depth scales with severity
- §189 related-party contracts flagged without board approval
- Delegation-of-authority bands route approvals by value
Your instance. Your database. Your rules.
- Dedicated deployment and database per customer
- Cloud-hosted or inside your own network
- REST API with a published OpenAPI specification
- Role and permission model enforced on every endpoint
One subject. Every risk, audit and obligation attached to it.
A contract, a vendor, an asset, a business unit — anything you govern is a subject. Risks, audits, compliance profiles, obligations, notices and the discussion around them all hang off it, so the full picture is one click away.
Four-eyes risk acceptance. One signature is not enough.
Risks are scored likelihood × impact. Accepting one is a decision with a trail, not a status change — and the higher the score, the more the system asks for.
- Justification length scales with severity: a critical risk needs a real argument, not a sentence
- High risks require a reason category; critical risks require the residual risk after mitigation
- A risk is not accepted until a second person countersigns — never the acceptor. Until then it sits in plain sight as pending, and the rule is enforced in the database, not just the screen
- Critical acceptances are gated to the most senior role
- Title
- Single-vendor concentration, facilities
- Reason category
- Vendor remediation committed
- Inherent
- 4 × 4 = 16
- Residual
- 2 × 3 = 6
Illustrative data
Audits that produce a score you can defend.
Define what you check once, with weights. Every audit snapshots the active parameters into findings, so the score means the same thing in March as it did in December.
- Parameters by category and frequency, maintained by hand or bulk-loaded from Excel
- Compliant, partial, non-compliant or not-applicable — weighted into one score
- Evidence files attached to the exact finding they support
- Corrective actions with owner, target date and a verified close-out
- Sign-off and acknowledgement recorded; PDF report on demand
| Parameter | Wt | Result |
|---|---|---|
| PF / ESI challan verification | 3 | Non-compliant |
| Minimum wages compliance | 3 | Compliant |
| Invoice vs. attendance reconciliation | 2 | Partial |
| Service level adherence | 2 | Compliant |
| Insurance certificate on file | 1 | Pending |
Illustrative data
The dates that cost money, watched for you.
Deliverables, SLAs and statutory filings are tracked as obligations. Formal notices run through a proper lifecycle. Contract renewals count down on a fixed ladder.
- An overdue high-priority obligation raises a risk on the register by itself
- Notices move draft → sent → acknowledged → responded → closed, with a numbered register
- A notice past its response date escalates automatically — nobody has to notice
- Renewal reminders at 120, 90, 60, 30, 14, 7 and 1 day, with open risks and obligations attached
| T-60 reminder | Sent to owner |
| Open risks on this contract | 2 |
| Open obligations | 1 overdue |
| Notice NTC-202609-0003 | Escalated |
Illustrative data
The discussion is part of the evidence.
When an auditor asks "who knew, and when?", the answer should not be in someone's inbox. Every subject carries a permanent discussion thread and a full change history.
- Messages cannot be edited after posting — on the record means on the record
- Threaded replies and pinned messages keep long discussions readable
- Participants are notified in-app, and by email once SMTP is configured
- Per-record activity log with a field-level before-and-after for every change
Vendor SLA report is three weeks overdue. Has anyone followed up?
Emailed their compliance team yesterday. Response promised by Friday.
Report received and attached to the finding as evidence.
Illustrative data
Nine modules. One data model. No integrations to build between them.
Risk register
Likelihood × impact scoring, mitigations, residual risk, and two-signature acceptance with severity-scaled justification.
Weighted audit engine
Parameters, findings, evidence, corrective actions, sign-off — scored by weight and exported as a PDF report.
Adoption engine
Reminder ladders, ownership prompts, named escalation and automatic scheduling of the next audit cycle.
Statutory compliance profiles
Related-party, TDS, stamp duty, MSME, e-waste and dispute-resolution terms captured per subject.
Counterparty risk & ESG
Risk tiering across financial, delivery, quality and compliance scores, yearly ESG ratings, and a sanctions-screening log.
Approval workflows
Multi-step approvals by role or named approver, value bands from your delegation of authority, SLA escalation, and maker-checker on master data.
Obligations, notices & renewals
Three registers with their own daily sweeps: overdue obligations raise risks, overdue notices escalate, renewals count down.
Chat-on-record
An immutable, threaded discussion on every subject, with a per-record activity log beside it.
Audit trail & exports
Every write logged with user, time and diff; retention with archiving; CSV export of every register.
Statutory compliance is a first-class record — not a custom field.
Global GRC suites treat Indian requirements as a configuration exercise you pay a partner for. In AuditGauge they are part of the model, on every subject, from day one.
- Companies Act 2013 §189 — related-party contracts flagged when a board approval reference is missing
- MSMED Act — 45-day payment-term compliance tracked per counterparty
- Income-tax TDS — applicable section (194C, 194J, 194I, 194Q, 195) recorded on the contract
- Stamp duty — paid status and amount on record
- E-Waste (Management) Rules 2022 — CPCB-authorised recycler certificate number and expiry
- Dispute terms — governing law, jurisdiction, arbitration seat and confidentiality level
- TDS section
- 194C
- Stamp duty
- Paid ₹12,500
- MSME (45 days)
- Compliant
- Confidentiality
- Restricted
- CPCB recycler cert.
- Expires 31 Mar 2027
- Arbitration seat
- Bengaluru
Illustrative data
Between a spreadsheet and an eighteen-month implementation.
Most teams are choosing between two bad options. AuditGauge is the third.
| What matters | Spreadsheets & email | Large GRC suites | AuditGauge |
|---|---|---|---|
| Overdue audits chase their owner | Nobody is told | Configurable, usually by a partner | ✓ Built-in ladder, on by default |
| Unowned work surfaced | Invisible | Report you have to run | ✓ Its own earlier reminder ladder |
| Two-signature risk acceptance | An email thread | Workflow to be designed | ✓ Enforced, with severity-scaled justification |
| Indian statutory fields | Whatever you remember to add | Custom configuration | ✓ Part of the model |
| Evidence of who changed what | Version history, at best | ✓ Audit log | ✓ Every write, with before/after |
| Time to first live audit | Immediate, and unmanaged | Typically a multi-quarter programme | Designed for weeks — one register at a time |
| Data isolation | Shared drives | Varies by edition | ✓ Own instance and database |
A general comparison of approaches, not of any specific vendor's product. Capabilities of individual GRC suites vary by edition and implementation.
A compliance system has to be the easiest one to audit.
Single-tenant by design
Every customer gets a dedicated application instance and its own PostgreSQL database. Your data is never in a table next to someone else's.
Least-privilege roles
Administrator, Compliance Officer, Auditor and Viewer roles over granular permissions, checked on every API call — not just hidden in the interface.
Immutable audit trail
Who, what, when, from where, and the before-and-after values. Filterable, exportable, and archived on a retention schedule you set.
Cloud or on-premise
Hosted for you, or deployed inside your own network where data-residency or regulator expectations require it. Same product either way.
Open REST API
Everything the interface does goes through a documented REST API with an OpenAPI specification, so AuditGauge fits into the systems you already run.
Works with your other systems
A subject can point at a record that lives elsewhere — a contract in your procurement system, an asset in your register — without copying that system's data.
Phased. Not a big-bang go-live.
Start with the register that hurts most. Add the rest on your timeline.
Load your subjects
Contracts, vendors, assets or business units — entered directly or referenced from the systems that already own them.
Define what you audit
Bring your checklist as weighted parameters. Bulk-load from Excel, then set the cadence.
Name the owners
Assign auditors and risk owners. From here the reminder ladders and escalations run themselves.
Run the first cycle
Findings, evidence, corrective actions, sign-off, PDF report — and the next cycle is already on the calendar.
Built for organisations that answer to a regulator.
Banking & financial services
Vendor and outsourcing risk with two-signature acceptance, a sanctions-screening log, and an audit trail that stands up to inspection.
Manufacturing
Contract-labour and statutory audits on a fixed cadence, MSME payment-term tracking, and e-waste disposal compliance.
Pharma & life sciences
Evidence-backed audit findings with verified corrective actions, and a permanent record of the discussion behind every decision.
IT & business services
Client-contract obligations and SLAs tracked to the day, with renewals counted down and notices managed through a formal register.
Infrastructure & real estate
Large contract portfolios with stamp duty, governing-law and dispute terms on record, and counterparty risk tiering across suppliers.
Shared services & GCCs
One governance layer across business units, with delegation-of-authority bands routing approvals to the right level.
Questions worth asking first.
What is AuditGauge?
AuditGauge is governance, risk and compliance (GRC) software. It combines a risk register, a weighted audit engine, statutory compliance profiles, counterparty risk, approval workflows, and registers for obligations, notices and renewals — all attached to the contracts, vendors, assets or business units you govern.
How is it different from other GRC platforms?
It is designed around adoption rather than data capture. Overdue status is computed live, every audit has a reminder ladder, unowned audits are surfaced earlier than late ones, stalled work escalates to a named person, and completing an audit schedules the next one. Indian statutory requirements are part of the core model rather than custom configuration.
Who is behind AuditGauge?
AuditGauge is built by RCS Tech, the company behind ProcurePulse and TRAXX, which has built enterprise software for regulated industries since 1999. AuditGauge began as the contract-audit and risk layer of that platform and is now a standalone product.
Do we need any of your other products to use it?
No. AuditGauge is fully standalone — every subject can be entered directly. If you do run other systems, a subject can reference a record that lives there without duplicating its data.
Where is our data held?
Each customer has a dedicated application instance and a dedicated database. AuditGauge can be hosted for you or deployed on-premise inside your own network.
How long does implementation take?
Deployment is phased by design. Start with a single register — typically audits or risk — so a first live cycle can be running within weeks, then add further modules on your own timeline.
Can we tune the reminders and escalation thresholds?
Yes. Lead times, overdue intervals, the escalation threshold and the roles that receive escalations are all configurable. A monthly statutory check and an annual surveillance audit do not deserve the same cadence.
How is AuditGauge priced?
AuditGauge is newly launched and we are onboarding a small group of founding customers with direct access to the product team. Book a demo and we will discuss pricing against your scope.
See AuditGauge on your own audit programme.
Thirty minutes, walked through live against the registers that matter to you.
- The adoption engine running on a mid-flight audit programme
- A critical risk taken through two-signature acceptance
- An audit scored, evidenced and exported as a PDF report
- Your deployment options — hosted or on-premise
We are onboarding founding customers now. You will speak to the people who build the product.