Audit Readiness
Prove where every extracted value came from
Every field Staple extracts carries a record of where it came from: source document, extraction time, model version, and confidence level. A built-in audit trail from document to ERP that you can verify on demand.

The problem: extraction without proof
Your document processor extracts a figure from an invoice and puts it in your ERP. Six months later, an auditor asks where that figure came from.
Your team searches email, shared drives, and filing cabinets. They match timestamps, cross-reference file names, and rebuild the chain from memory and metadata. Two people spend a week on it. They produce a narrative, not proof.
This works when auditors give two weeks of notice and a narrow scope. It stops working when a regulator asks for field-level evidence across six months of transactions within 48 hours. Asian language characters and jurisdiction-specific compliance requirements make reconstruction harder still.
Every document processor on the market has this gap. They extract data. But they do not prove where it came from.
Every extracted field carries its own verification record.
Query any value and retrieve its full extraction history.

How Staple verifies data

Every field carries its own audit trail
When Staple extracts data from a document, it attaches a verification record to every field at the moment of extraction. The audit trail becomes a property of the data itself, not a log you search through. The record also captures which model and rule version produced each value, so a result is always explained against the logic that actually produced it. No additional configuration. No separate logging system.

Retrieve evidence, do not reconstruct it
When an auditor or regulator requests traceability, you query the field. Staple gives you the source document, extraction time, processing model, and confidence score. What used to take two people and a week becomes a query that returns in seconds.

Verify nothing has changed
If a value is changed after extraction, either in transit, in storage, or in your ERP, the verification record breaks. You can confirm at any point that the data in your system matches what was extracted from the source document. This is the difference between “we have an audit trail” and “we can prove the data has not been altered.”

Built for AI governance frameworks
AI governance frameworks like ISO 42001, the EU AI Act, and Singapore's MAS AIRG all require the same thing: show how the AI arrived at this output. Staple provides that evidence at the field level, embedded in the data itself.
Technical details
MSD (Metastructured Data) is an open standard. Any system, not just Staple, can produce and consume MSD-compliant data.
What the Metastructured Data contains for each field:
Source document reference
Extraction timestamp
Processing model and version
Confidence score
Cryptographic signature
Integration
MSD travels with each field through your existing integrations. No additional middleware or logging infrastructure required
See data verification on your own documents
Book a demo to see how a verification record attaches to every extracted field.
FAQ
What does audit readiness mean in Staple?
Audit readiness means every document Staple processes can be reconstructed on demand: what was received, extracted, verified, changed, and approved, with the source, rule, reviewer, and timestamp behind each step. The evidence is captured as processing happens, so it is ready when an auditor asks rather than rebuilt afterwards.
What is recorded for each field?
Staple keeps a per-field history recording every state change a field passes through, in sequence, with the source document, the model or rule that produced it, the reviewer, a timestamp, and the before and after value. This means you can trace any single value back to its origin, not just the document as a whole.
Does Staple track which model or rule version produced a result?
Yes. Configurations, extraction models, and validation rules are versioned, so you can see which version was in force when a given document was processed. A result produced months ago can be explained against the exact logic that produced it, not against today's configuration.
Can we export evidence for an audit or dispute?
Yes. Staple produces exportable evidence packages for audit, disputes, and regulatory examination. Audit logs export as CSV or JSON for offline review or reconciliation, so evidence can be attached to a report or handed to an examiner directly.
How does this support AI governance requirements?
Frameworks including ISO 42001, the EU AI Act, and Singapore's MAS AIRG all require the same thing: showing how an AI system arrived at a given output. Because every field carries its model version, rule, confidence score, and reviewer, that evidence exists at field level rather than being inferred after the fact.