The typical implementation process for Complete Control:
1. Project Initiation & Assessment:
Action: Form an implementation team, define the project scope, and conduct a detailed review of your current contract processes (from renewal request).
Goal: Establish clear objectives (e.g., reducing contract cycle time) and define the system requirements.
2. Configuration & Design:
Action: Configure the Complete Control platform to mirror your organization's specific workflows, approval hierarchies, user roles, and security settings.
Goal: Customize contract templates, set up data fields, and design the system's structure to match your business rules.
3. Data Migration & Integration:
Action: Clean, organize, and import existing contracts and related metadata from legacy systems or spreadsheets into the new platform. Connect the software with other core systems (e.g., ERP, CRM) if required.
Goal: Create a central, complete contract repository and ensure data flows correctly between systems.
4. Testing & User Acceptance Testing (UAT):
Action: The implementation team and key end-users test the system rigorously to ensure all configured workflows, integrations, and reports function as expected.
Goal: Verify the system meets the defined requirements and obtain formal user sign-off.
5. Training & Go-Live (Deployment):
Action: Conduct tailored training sessions for administrators, power users, and general end-users. The system is then officially launched for daily use.
Goal: Ensure all users are proficient and begin actively managing new and existing contracts within the platform.
6. Post-Implementation & Optimization:
Action: Provide ongoing user support, monitor system performance, and gather feedback.
Goal: Make minor adjustments, onboard additional departments, and optimize the system to maximize return on investment (ROI).
Customisation
Complete Control supports multiple customization layers spanning configuration, integrations, data structures, workflows, and reporting to fit specific business needs.
Core configurability: The platform provides a central contract register with structured metadata and advanced search, enabling tailored taxonomy, fields, and portfolio organization aligned to internal categories and reporting needs. Role-based access lets organizations align permissions to functions (e.g., CFO, procurement, legal, business units), supporting granular control over who can view, edit, or approve specific contract classes or values. Built-in reminders can be tuned to upcoming renewals and terminations, so notice periods and escalation paths can match internal policies for renegotiation and supplier management.
Workflow and operations: Operational workflows are streamlined with digital signing, quick uploads, and cost monitoring that can be adapted to the organization’s approval patterns and review cadence, reducing administrative time while reflecting existing processes rather than forcing new ones. The system is designed to support finance, procurement, and legal teams with configurable process touchpoints, allowing these stakeholders to embed the tool into procurement and sales planning cycles and ongoing contract oversight. Customer success-led onboarding and training allow tailoring of setup, roles, and routines during implementation, with a dedicated CSM to adjust configurations over time as needs evolve.
Integrations and API: Complete Control integrates with ERP, CRM, and financial systems such as Tripletex, Visma.net, and Microsoft Dynamics 365, enabling customization of data flows and reducing duplicate entry across systems. An open API is available to connect with other business-critical tools, allowing custom integrations for ingestion, synchronization, or event-driven updates that reflect unique enterprise architectures. This integration layer supports seamless workflows and improved data quality, making it possible to tailor how contract data appears in downstream planning, budgeting, or analytics environments.
Financial and reporting customization: Financial visibility is configurable via detailed reports on actual and booked values, payment schedules, and cash flow, making it possible to tailor planning views and export structures to Excel for further modeling. Organizations can align reporting periods and categories so obligations and receivables map to internal financial calendars and forecast structures, improving precision in budget cycles. The reporting approach supports audit-friendly outputs and structured tracking so different departments can pull the slices of contract and cost data they need without rework.
Compliance and domain modules: The platform facilitates IFRS 16 lease accounting with automation and audit trails, enabling organizations to configure lease calculations and documentation to their accounting policies and audit requirements. It supports third-party risk management under the DORA framework through structured reporting and clear audit trails, which can be adapted to operational resilience governance practices. Security and compliance are reinforced by ISO 27001 certification and ISAE 3402 Type 2 attestation, allowing custom access controls and incident processes to align with internal ITIL/ISO 27000-based policies.
Use-case breadth: Common agreement types—employment, sales, lease, purchase, licensing, and consulting—are supported out of the box, and organizations can prioritize which categories to onboard first, tailoring metadata and reminders to each type’s lifecycle. Customer stories indicate the system scales to large portfolios and can be embedded into procurement and sales planning processes, suggesting flexibility in how teams stage adoption and governance. The combination of centralized storage, configurable search, and lifecycle alerts supports different departmental goals, from savings initiatives to revenue assurance and timely index- or price-adjustments.
Training
Complete Control offers a full lifecycle of onboarding, training, and customer support designed to ensure smooth implementation and sustained adoption across finance, procurement, and legal teams.
Onboarding and Implementation: Every new client receives a dedicated Customer Success Manager (CSM) who oversees the setup process and ensures users gain proficiency in the system quickly. The CSM works closely with key stakeholders to align the platform’s configuration to business processes, such as approval chains, contract categories, and reporting structures. Implementation includes structured data import, integration with ERP or CRM systems (like Microsoft Dynamics 365, Visma.net, and Tripletex), and user access setup following internal governance rules.
User Training Programs: Full onboarding and training sessions are included at no additional cost. These cover the end-to-end use of the platform, including contract upload procedures, lifecycle management, digital signing, role-based access settings, financial tracking, and compliance reporting. Training is designed for both administrative and operational users, ensuring that all departments—from CFOs to project managers—understand how to use the system effectively for their roles. Additional workshops help teams establish best practices for document control, supplier visibility, and deadline monitoring.
Support Services:Complete Control offers continuous customer support beyond the initial setup, ensuring assistance whenever operational questions or issues arise. Support includes system optimization sessions upon request, where the CSM reviews workflow performance, reporting accuracy, and integration health. Customers can also access help documentation, performance metrics, and minor configuration adjustments through direct communication with House of Control’s technical and compliance teams.
Long-Term Partnership Model: House of Control positions itself as a long-term partner rather than a simple software vendor. The customer success structure ensures ongoing engagement through periodic reviews, user training refreshers, and updates on new compliance features such as IFRS 16 lease accounting and DORA operational resilience frameworks. This approach keeps client organizations aligned with evolving regulatory and financial best practices over time.
Security Measures
Complete Control employs a multi-layered, compliance-driven security framework grounded in international standards and the Visma Cloud Delivery Model (VCDM) to ensure protection of customer data at every level of system architecture and operation.
Governance and Certifications: House of Control operates under the Visma Cloud Delivery Model (VCDM), which mandates strict compliance with ISO 27001 and ISAE 3402 Type 2 standards. These certifications confirm that Complete Control’s information security and operational controls are independently audited, focusing on risk management, policy enforcement, and data reliability. ISO 27001 ensures continuous improvement through regular risk assessments and security control updates, while ISAE 3402 Type 2 verifies the design and effectiveness of internal security processes over time.
Data Protection and Encryption: The platform enforces encryption across multiple layers, including file storage, databases, and network communications. By using industry-standard cryptographic protocols, confidential contract and financial data remain secure both in transit and at rest. Access to all sensitive areas follows the least privilege principle, meaning users and internal systems are granted access only to the specific data necessary for their tasks, minimizing internal exposure risks.
Access Controls and Authentication: Complete Control integrates role-based access controls (RBAC) for user management, ensuring permissions are tightly aligned with organizational roles like CFOs, managers, or legal staff. The system also supports two-factor authentication (2FA) for all users, significantly reducing the risk of unauthorized account access. These measures comply with ISO 27000-series controls covering personnel security, access management, and continuous authentication.
Monitoring and Incident Prevention: House of Control practices a proactive cybersecurity approach under Visma’s continuous monitoring infrastructure. The platform conducts real-time threat detection, vulnerability scanning, and preventive risk assessments to shield against data breaches, ransomware, and other cyber threats. The company adheres to the principle that “the best security incident is the one that never happens,” focusing on early detection and automation for mitigation before an event can impact clients.
Compliance and Privacy Oversight: Data protection within Complete Control follows GDPR and broader EU/EEA privacy regulations, supported by a dedicated Chief Information Security Officer (CISO) and Data Protection Officer (DPO) responsible for compliance operations. Both roles oversee adherence to ITIL and ISO 27000 control suites across areas such as access management, incident response, and business continuity planning. The system’s governance model ensures full transparency and traceability through secure audit logs, facilitating alignment with legal and client contractual requirements.
Business Continuity and Reliability: Through the Visma Cloud Delivery Model, Complete Control is engineered for near 100% uptime and operational resilience. The infrastructure integrates automated redundancy, geographically distributed data centers, and disaster recovery measures to minimize service interruptions. Agile and DevOps methodologies provide continuous improvement, fast deployment of security patches, and the ability to respond quickly to client and regulatory changes.
Continuous Security Commitment: House of Control invests continuously in evolving cybersecurity capabilities and regularly collaborates with Visma’s broader security teams to strengthen data protection strategies. This includes adapting to emerging threats, running regular penetration tests, and updating controls in line with the most recent versions of ISO and ISAE standards. Customers benefit from a robust, transparent protection ecosystem certified by external auditors and maintained through ongoing internal security training and review cycles.
Updates
Complete Control follows Visma’s Cloud Delivery Model (VCDM), which ensures structured, continuous updates managed under DevOps and agile methodologies for high-frequency, low-impact software improvement cycles.
Update Frequency: Updates and enhancements are released continuously using a rolling deployment model, meaning software improvements, bug fixes, and new features are deployed incrementally throughout the year rather than in large annual releases. This approach shortens feedback loops and ensures customers benefit quickly from new functionality, particularly compliance, performance, and integration improvements tied to evolving regulatory and operational needs.
Update Management Framework: Under the Visma Cloud Delivery Model (VCDM), all updates go through strict protocols for quality control, regression testing, and security validation before release. Each update is automatically deployed through cloud-based orchestration to minimize disruption and ensure continuous availability. Customers experience near-zero downtime thanks to automated failover processes and real-time monitoring throughout update cycles.
VCDM uses continuous delivery pipelines, meaning updates pass through staging layers for testing and automated verification before promotion to live environments. This model allows rapid deployment but maintains enterprise-grade stability through version control, rollback mechanisms, and post-deployment auditing.
Customer Communication and Change Visibility: Complete Control provides transparent communication regarding version changes through release notes and update notifications within the customer portal. Clients are informed of functional updates, new compliance modules (e.g., IFRS 16 adjustments or DORA risk management upgrades), and integration enhancements in advance. The process is fully managed by House of Control’s Customer Success Managers, who ensure organizations understand the impact of new features and can adjust workflows as needed.
Data Ownership and Portability
Complete Control, operated by House of Control, defines a clear policy on data ownership and portability within its contractual, privacy, and data processing frameworks. The terms ensure that customers retain ownership of their own data, while House of Control acts as a data processor responsible for secure storage, processing, and access management according to GDPR and ISO 27001 standards.
Data Ownership Policy
According to House of Control’s General Terms & Conditions, all intellectual property and proprietary rights to the Complete Control software remain with the supplier, but customers retain ownership of all data entered or uploaded into the system.
The supplier (House of Control) only holds rights to use customer data for statistical or system-improvement purposes and strictly within limitations that preserve confidentiality and compliance with data protection laws.
This ensures that while House of Control manages infrastructure and service availability, it cannot claim ownership or reuse contractual, financial, or personal data for external commercial purposes.
Data Processing Structure
The company’s Data Processing Agreement (DPA) confirms that Complete Control processes data exclusively on behalf of the customer, who functions as the data controller under GDPR Article 4.
The DPA specifies processing only for purposes such as contract management functions, system testing, customer support, and agreed data storage. Processing continues only until the agreement is terminated or canceled, after which data must be deleted or returned per the contract’s closure process.
Categories of processed data include user job details, login credentials, and optional business fields defined by the customer. No ownership transfer or extended processing rights are implied.
Rights to Data and Portability
Under GDPR Article 20 and the platform’s privacy policy, customers and users can invoke their right to data portability, allowing them to receive their personal or business data in a structured, commonly used, and machine-readable format.
House of Control supports such requests by enabling structured export into formats like Excel or CSV, aligning with the service’s built-in “easy export to Excel” function cited in product documentation.
Customers can also request that their data be transmitted directly to another compatible system, to the extent technically feasible, ensuring vendor compliance with portability standards under GDPR and the Visma Cloud Delivery Model (VCDM).
Data Retention and Deletion
Data processing continues only as long as the contract is active. When terminated, the data is either deleted from the system or returned to the customer, depending on contractual preference and regulatory requirements.
Any backups or archived copies are securely destroyed following restoration verification, ensuring compliance with ISO 27001-based retention and destruction protocols.
Security and Custodial Responsibilities
House of Control, as part of the Visma Group, guarantees that data hosting complies with GDPR, ISO 27001, and ISAE 3402 Type 2 certifications, ensuring that ownership rights are protected by internationally recognized security and audit frameworks.
Strict access control, encryption, and incident management policies secure customer-owned data across all environments.
Customers may contact the dedicated Data Protection Officer (DPO) via [email protected] to exercise ownership, portability, deletion, or access control rights.
The terms & conditions for contract renewal and cancellation
Complete Control’scontract renewal and cancellation terms are governed by House of Control’s official General Terms & Conditions, which outline subscription lifecycle rules, renewal intervals, termination notice periods, and billing procedures.
Contract Duration
Each subscription agreement is valid for an initial fixed term of 36 months (3 years), starting from the date specified in the signed contract.
The agreement defines the subscription as continuous access to Complete Control’s licensed software, including updates, maintenance, and support under the same terms.
Renewal Terms
If the customer does not formally terminate the subscription at least three months (90 days) before the expiration of the current period, the contract automatically renews for an additional 12-month term at a time.
Automatic renewals ensure uninterrupted access to Complete Control’s services, data, and integrations without requiring new agreements.
At renewal, subscription fees may be adjusted based on the applicable price index defined in the company’s Indexes In Use publication. This annual price adjustment may occur without prior notice, and the fee will never decrease from the previous year’s rate.
When a start-up discount has been applied during the initial term, the renewal price will revert to the current rate from the House of Control price list.
Cancellation Terms
Written notice of cancellation must be submitted no later than 3 months before the end of the current subscription period to avoid automatic renewal.
Upon termination, all access to Complete Control services, data exports, and functionalities ends on the final day of the active term.
If the customer fails to meet payment obligations, House of Control may pause or suspend the subscription until outstanding invoices are cleared, rather than immediately contract termination.
Cancellation does not entitle customers to prorated refunds; prepaid annual fees remain non-refundable.
Invoicing and Payment Policies
Subscriptions are billed yearly in advance, with an initial invoice sent on the 1st of the month following contract signing.
Implementation or “establishment” costs are invoiced either on the start-up meeting date or 60 days after contract signing, whichever comes first.
Payment terms are net 14 days. Failure to pay may result in service suspension and late fees, with interest calculated at government-specified rates.
Ownership and Usage Rights
Customers are granted a non-exclusive, non-transferable license for the subscription period to use Complete Control within the scope defined in the contract.
All intellectual property and product rights, including enhancements and modifications, remain with House of Control unless expressly agreed otherwise. Customer data, while retained under GDPR data processing rules, cannot be used beyond statistical purposes by the supplier.
Support Continuity During the Contract
Technical support, updates, and standard upgrades are automatically included in the subscription fee throughout the contract term and renewals.
Terms for support can be updated by House of Control without requiring separate customer approval, as long as support coverage remains active.
Compliance
Complete Control complies with several internationally recognized information security, financial reporting, and operational resilience standards, ensuring it meets strict governance and regulatory expectations for enterprise-grade contract management software.
Information Security Standards: Complete Control is certified under ISO 27001, the global benchmark for Information Security Management Systems (ISMS). This standard regulates how information assets are secured through structured policies, risk management, incident response, encryption, and access controls. Certification ensures that House of Control continuously monitors, audits, and improves its information security practices through scheduled internal and external audits.
In addition, the platform maintains ISAE 3402 Type 2 attestation, demonstrating the effectiveness and operational reliability of internal control systems for data processing and financial reporting. This third-party audit verifies the design and consistent operation of key controls over an extended period, offering additional assurance to customers and auditors regarding data integrity and service reliability.
Data Protection and Privacy: Complete Control fully adheres to the EU General Data Protection Regulation (GDPR), supported by dedicated Data Protection Officer (DPO) oversight within House of Control and across the Visma Group. The compliance framework enforces accountability, lawful processing, and data minimization, alongside features allowing organizations to maintain clear audit trails and execute data subject requests.
The solution is built and operated in accordance with the Visma Cloud Delivery Model (VCDM), which incorporates privacy-by-design, encryption standards, and continuous vulnerability assessments into all hosted services.
Financial Reporting Compliance: The software includes features designed to meet IFRS 16 lease accounting standards, automating lease calculations, payment schedules, and reporting controls for accurate recognition and forecasting. Built-in audit trails and structured reports simplify compliance with both statutory accounting and internal audit requirements. This makes it suitable for organizations managing complex multi-entity lease portfolios and financial commitments.
Operational Resilience Standards: Complete Control also aligns with the EU’s Digital Operational Resilience Act (DORA), applicable to financial institutions and third-party service providers. The platform supports organizations in documenting contracts, monitoring third-party risk, maintaining governance records, and strengthening continuity practices in line with DORA’s ICT risk management, incident reporting, and resilience testing principles.
Through integration with Visma’s managed infrastructure, Complete Control benefits from data center redundancy, cybersecurity monitoring, and perpetual operational resilience testing — core factors under DORA compliance.
IT Service Management Controls: House of Control operates under ITIL and ISO 27000 control frameworks covering access provisioning, incident management, and business continuity. These frameworks govern service quality and ensure that updates, maintenance, and recovery protocols adhere to industry-standard service management and information security practices.