HINT for Compliance & Risk

Your assistant drafts controls fast. HINT keeps every claim tied to evidence.

HINT keeps frameworks, control owners, evidence and exceptions in plain-text notes beside compliance documents. Your assistant reads the rules for the business unit before it drafts or maps a control.

The package is named for the role: @openhint/hintbook-compliance-officer.

Where it helps

Three situations your team will recognize

Before: A control sounds complete but nobody owns it.

Ownership is part of the control

The responsible role, cadence and evidence expectation remain attached instead of disappearing into polished prose.

Before: An exception becomes an undocumented permanent practice.

Exceptions carry expiry and approval

The assistant sees the boundary, approver and review date whenever it works on the affected unit.

Before: A framework requirement is quoted from memory.

Regulatory statements need a source

Missing authority is flagged for compliance review rather than turned into a confident citation.

See it

A real factory control from the demo

The Wonka compliance demo keeps the factory control grounded in SRC-1.

demo-wonka-compliance/units/factory/controls.md.hint ↗

# control overview-1 {#compliance_officer_overview}

Approved control grounded in SRC-1.

# source SRC-1

../../sources/approved.md

What your assistant does next

It drafts the control with its declared source and asks for any missing owner, evidence or cadence before presenting the record as complete.

What your AI assistant receives
<control name="overview-1">
  Approved control grounded in SRC-1.
</control>
<source name="SRC-1">../../sources/approved.md</source>

Your boundaries stay visible

What it will never do

  • Invent a regulation, clause number or control requirement.
  • Treat an exception without approval and expiry as permanent policy.
  • Claim operating effectiveness without declared evidence.

FAQ

Questions compliance & risk ask

Does this prove compliance?

No. It keeps requirements, controls and evidence expectations connected; assurance still depends on actual operation and review.

Can it map more than one framework?

Yes. Framework and requirement blocks can share controls while retaining distinct sources and applicability.

Can auditors use the same repository?

Yes. Compliance and audit books can coexist, with the task-specific vocabulary ordered first.

For your technical colleague

The vocabulary

A hintbook is a vocabulary for your profession—installed, not written by you.

framework
Names a compliance framework and its applicability.
requirement
Records a sourced obligation from the framework.
unit
Sets the organizational scope a rule applies to.
control
Defines an owned action intended to address a requirement.
evidence
Names the artifact that demonstrates control operation.
mapping
Connects controls to the requirements they address.
exception
Records an approved deviation, owner and expiry.
redflag
Marks a condition that requires escalation.

Manual setup

Bootstrap is read-only: it prints instructions for the assistant. The assistant performs the installation.

npm install -g @openhint/cli
hint config
hint add @openhint/hintbook-compliance-officer
hint apply
hint verify units/factory/controls.md
hint emit units/factory/controls.md

Hintbook repository ↗ · Demo repository ↗

Works with