← artifacts

Compliance Control Tower — External Risk Management System

Summer project as an AI & Legal Compliance intern at Epiroc. Product owner and designer.

Problem

The internal system for informing general managers across 30+ operating units in North America was dormant, and failed on three counts.

  1. Ensuring regulation applicability

    Managers received homogenous quarterly regulatory updates covering 150+ regulations, with no specification to their business practice or country (US, CA, MX).

  2. Reading and understanding obligations

    Reviewing that volume of obligations would have taken roughly 400 hours, so managers forewent it completely — meaning the relevant obligations were missed along with the rest.

  3. Ensuring follow-up actions and routing

    General managers need to route obligations to the relevant team members so action is taken before a regulation’s effective date.

Solution

I proposed a revamped system, sitting between the developer team and compliance administration to understand what admins needed from the system and to fold in feedback from general managers.

I used Claude to help design it, drafting multiple wireframe iterations against that feedback.

System flow

A few featured parts of the system flow.

Intake screen listing regulations for Q2 2026 in a table, with columns for effective date, compliance area, region, risk level, routing progress and status.
Intake — every regulation on file, synced from the register database and divided by quarter, waiting to be triaged.
A single compliance project seen by a manager, with a summary, a note explaining why the regulation applies to their unit, and a four-step checklist working back from the effective date.
Project detail — steps are planned backward from the effective date, and each one states why the regulation reached that unit.
Configure and route screen for a single regulation, showing a manager-facing summary, a risk level selector, a four-step project lifecycle with due dates, and a checklist of managers to route to.
Configure & route — the risk level sets the playbook, which fills the project lifecycle; the admin then picks the operating units in scope.
A general manager's dashboard showing counts of actions required and in progress, a list of active compliance projects with step progress, and response-rate metrics by compliance area across North America.
Manager dashboard — only the projects routed to that manager’s units, alongside response rates across North America.

All names and figures shown are mock data. No internally protected Epiroc information appears in these screenshots.

Impact

The system is expected to surface and route only five obligations to each manager — a 97% cut in volume — while keeping a multi-step review process to ensure compliance and protect against penalties.

Reflections

Clean source data was paramount to the system working at all, and was the most difficult roadblock.

Acquiring permissions for a new Azure system, and including an AI integration within it, proved the hardest problem in the company’s infrastructure.

Agnès Charton