Willow Compliance Desk · Active development

Run compliance work as an evidence-backed operating process.

Compliance Desk brings regulatory scope, customer risk, due diligence, controls, monitoring, evidence, reviews, competence, governance and regulatory change into one practical workspace. It gives Jersey and Guernsey teams a clearer operating record of what was reviewed, what was decided, what evidence supports it and what needs attention next.

Jersey Guernsey / Bailiwick
Development status: Compliance Desk remains in active development and will be made available for general use once it reaches the standard we are happy with. Follow development updates on the Willow Software blog.
Hosted purchasing currently off In-House purchasing currently off Try the live demo Renew hosted access View product guide (PDF)

Current Compliance Desk 0.16.12 / schema 18 walkthrough · authenticated demo interface, professional reporting, protected evidence and Hosted/In-House operation · silent video.

Regulatory scope

Record what the organisation believes applies, the source, the rationale, ownership and review date.

Customers & reviews

Keep relationship risk, CDD/EDD, ownership, screening, SOF/SOW, review history and evidence together.

Controls & assurance

Connect risks, controls, monitoring, findings, actions and supporting evidence.

Management oversight

See due work and exceptions without reducing compliance to an invented percentage.

Current jurisdiction support

Built around Jersey and Guernsey operating contexts.

Compliance Desk is jurisdiction-aware, but it does not decide the organisation's regulatory perimeter. Teams record the scope decision, source, rationale and review evidence that apply to their own business.

Jersey

JFSC and Jersey context

Record regulatory scope and permissions, customer and financial-crime work, controls, monitoring, competence, governance and evidence against the Jersey sources relevant to the organisation.

Guernsey / Bailiwick

GFSC and Bailiwick context

Keep Guernsey/Bailiwick scope, review, financial-crime, competence, governance and assurance records separate where the regulatory source or decision differs.

Compliance operations

One connected workspace from perimeter decision to evidence.

Regulatory Scope

Document regulated activities, licences/registrations, applicability basis, sources and review dates.

Customers & Reviews

Run onboarding, periodic, trigger and enhanced reviews with CDD/EDD, screening, connected parties and risk rationale.

Financial Crime / MLRO

Use a restricted internal reporting route with encrypted sensitive case content and appointment-based access.

Controls & Monitoring

Record controls, monitoring plans and tests, samples, findings, remediation and follow-up evidence.

Risk & Assessments

Run structured assessments, capture risk decisions and turn identified gaps into owned actions.

Governance & Compliance Function

Model operational teams and formal appointments separately from software permissions, then build attributable management reporting.

Training & Competence

Record role/activity requirements, competence evidence, supervision, reviews and CPD where a real requirement applies.

Regulatory Watch

Review configured official sources, assess change impact and create controlled internal follow-up.

Evidence Packs

Assemble controlled evidence manifests and exports with attributable approvals and integrity fingerprints.

Risk-based reviews

Review work follows the organisation's actual risk model.

Set the review basis and next review date, record what changed, reassess risk and due diligence, link tasks and evidence, and retain reviewer and checker decisions. Compliance Desk does not invent a universal review timetable.

No invented universal CPD or review target. Requirements vary by role, activity, organisation and jurisdiction. Record the source and target that genuinely apply.

Regulatory Watch

External change starts a controlled internal decision.

Watch configured official sources

Regulatory Watch helps collect and review configured source changes relevant to the organisation. It is an operational aid, not a guarantee of exhaustive or real-time coverage.

Assess and evidence the response

Record impact or no-impact reasoning, affected scope, controls, risks, owners, due dates, implementation evidence and closure. Important changes must still be verified at the official source.

Try it before you buy it

Shared Compliance Desk demo

Resets every 3 hours

This is a public test workspace. Several people can sign in at the same time. Test records and uploaded demo files are cleared and rebuilt every three hours.

Emailcompliancedemo@testuser.com
PasswordComplianceDemo!2026

The login page shows the same test details. Mail, webhooks, network retrieval and sensitive configuration changes are disabled in the shared demo.

Hosted or In-House

One maintained application, two deployment models.

Current maintained application build: 0.16.12 · database schema 18.

Hosted SaaS

Willow operates the application

Willow provisions the workspace and maintains hosted code and database deployment centrally.

12 months £349 · 5 years £1,299

In-House

Operate it on infrastructure you control

The maintained application can run as a licensed single-organisation installation on infrastructure you control, with a signed application update mechanism for entitled releases.

12 months £349 · 5 years £1,299

Hosted pricing

Prepaid access with no automatic subscription.

Renewal extends the same workspace and retains the existing compliance records and evidence.

12 months
£349

One hosted Compliance Desk organisation with product updates during the paid term.

5 years
£1,299

The same organisation workspace and records for the full five-year term.

Regulatory maintenance boundary: Willow Software maintains Compliance Desk as a software product and may update workflows, labels, examples and documentation as public regulator material changes. No software vendor can guarantee that those materials capture every organisation-specific rule, legal change, effective date or interpretation. Your organisation remains responsible for checking official sources and obtaining legal or regulatory advice where appropriate. See the Compliance Desk responsibilities and limitations.

Questions

Compliance Desk FAQ

What experience and industry input sit behind Compliance Desk?

Compliance Desk is informed by personal experience, extensive research and ongoing input from people who work in Jersey's finance industry. My late wife was Head of Compliance at a number of local finance firms in Jersey and later established her own regulatory consultancy. I helped her set up the business, including its website, business plan, branding and internal documents. To do that properly I had to learn a great deal about compliance and risk, including AML/CFT and how the different parts of a compliance framework fit together.

I am a software developer rather than a career compliance professional and I have not worked day to day as part of a compliance team within a regulated firm. That distinction is important. Understanding the rules, terminology and risk framework is not the same as having practical experience of the way a compliance team works every day. Turning that knowledge into an application structure that is genuinely useful in a real finance office has therefore been one of the most difficult parts of developing Compliance Desk.

To bridge that gap I am liaising with finance professionals who work in the industry and using their practical feedback to guide the fundamentals of how teams carry out everyday compliance work. I also continue to research the underlying regulatory material and test the application's structure against real-world scenarios. Compliance Desk is intended to support, organise and evidence compliance work while leaving regulatory interpretation and professional judgement with the people responsible for it.

Does Compliance Desk decide which laws or rules apply?

No. Regulatory Scope records the organisation's applicability decisions and their source. The organisation and its advisers remain responsible for determining what applies.

Can it manage CDD, EDD, screening, ownership and SOF/SOW?

Yes. Those records can be kept together with customer risk, connected parties, review decisions, evidence, actions and review dates. The software does not make suspicious-activity, sanctions or legal decisions on the customer's behalf.

Does it impose a standard customer-review or CPD frequency?

No. The organisation records the risk-based review basis and any applicable competence or CPD requirement. Different roles, sectors and jurisdictions can have different requirements.

Is Regulatory Watch guaranteed to catch every change?

No. It is an operational aid. Important changes must be verified at the relevant regulator or official source, including effective dates and transition arrangements.

Can an auditor or reviewer inspect the system without editing it?

Yes. The Auditor / Reviewer role is read-only and can be used for controlled inspection of information made available for review.

Can Compliance Desk be installed in-house?

Yes. The maintained application is available as a licensed single-organisation In-House edition. Availability and purchasing controls are shown on this page.