Skip to main content

Store compliance documents

Store compliance documents

Use this when... you need to upload, organise, review, or retire documents connected to compliance work, such as DBS evidence, consent records, policies, breach evidence, safeguarding documents, GDPR records, tutor onboarding checks, or branch-specific compliance files.

Before you start... decide whether the document should be stored in TuitionFlow at all, who should be able to see it, and how long your organisation needs to keep it. Compliance documents often contain sensitive personal information. Do not upload documents into general notes, messages, or broad-access areas just because it is faster.

The TuitionFlow compliance dashboard showing document, GDPR, safeguarding, checks, and audit areas.

Use Compliance as the controlled place for sensitive operational documents.

What belongs in compliance documents

Compliance documents should support a clear operational or legal need. Examples include consent evidence, policy acknowledgements, training certificates, DBS-related documentation, GDPR request files, audit evidence, breach review files, safeguarding process notes, and branch compliance records.

Avoid storing duplicate copies of everything. If a document is already retained in an approved external system, record the reference rather than uploading another copy unless your process requires it.

Step 1: Choose the right record

Attach the document to the most specific record available: student, family, tutor, employee, compliance case, GDPR request, breach, or organisation policy. If the document affects several people, store it in the central compliance area and reference related records carefully.

Expected outcome: authorised users can find the document from the record where they naturally need it.

Step 2: Name the file clearly

Use a factual file name that explains the content without exposing unnecessary sensitive detail. Include a date, person or branch reference where appropriate, and document type. Avoid vague names like “scan” or “important”.

Step 3: Set visibility and review date

Check who can access the file. Sensitive documents should be visible only to authorised users. Add an expiry, review, or renewal date where relevant, especially for checks, certificates, policy acknowledgements, and time-limited evidence.

The TuitionFlow employees and tutors area where compliance documents may relate to staff onboarding or checks.

For tutor and employee documents, check the staff record as well as the compliance dashboard.

Step 4: Keep the document current

When a newer version is uploaded, mark the old version according to your process. Do not leave several competing versions active without explanation. If a document is no longer needed, archive or delete it only if your retention policy allows it.

Common mistakes

  • Uploading sensitive files to messages. Use the correct compliance document area.

  • Using unclear filenames. Future admins need to recognise the document quickly.

  • Keeping expired documents active. Add review dates and renewal owners.

  • Sharing documents too broadly. Restrict access according to need.

Troubleshooting

A user cannot see a document: check their role, document visibility, branch access, and whether the file is attached to the expected record.

A document appears in the wrong place: move or re-upload it to the correct record, then remove the misplaced copy if policy allows.

A document contains too much personal data: ask the compliance owner whether a redacted copy or shorter summary should be used instead.

Retention and audit

Review compliance documents periodically. Check expired documents, documents without owners, duplicate uploads, and files stored against inactive records. Keep an audit trail of important changes so the organisation can explain what was retained, changed, or removed.

Document categories

Keep categories simple enough for admins to use consistently. Useful categories might include tutor checks, safeguarding, consent, GDPR, breach evidence, policies, training, and branch compliance. If categories become too detailed, people will choose different labels for the same type of document and search will become unreliable.

Redaction and minimisation

Before uploading, ask whether the whole file is needed. Sometimes a redacted copy, certificate confirmation, or short compliance summary is safer than storing a document with extra personal information. If redaction is used, keep the redacted file clearly named and avoid leaving unredacted copies in downloads folders.

Owner handoff

If one admin uploads a document for another owner to review, record the handoff. The reviewer should know what was uploaded, why it matters, what decision is needed, and when the document must be reviewed again. This prevents documents from becoming passive storage with no operational action.

Next actions

After uploading a compliance document, confirm the owner, visibility, review date, and linked record. Then check whether the document changes any onboarding, scheduling, safeguarding, GDPR, or compliance follow-up work.

Did this answer your question?