Controls map Workflows

Compliance & Legal Workflows

EvidenceFlows workflows owned by or involving Compliance & Legal. Review the steps, responsibilities and evidence, then run them in your browser or download templates for your AssureSwarm instance.

All workflows 212 IT 92 HR 11 Finance 27 Internal Audit 45 Risk Management 32 Compliance & Legal 32 Privacy 11 Procurement 15 Executive 20 AI Governance 11 Facilities 7 Business Operations 9
  • AI Transparency & Value-Chain Communications — AI Governance; with Compliance & Legal · 6 steps
    Run the recurring AI-transparency cycle: keep each AI system's user and deployer documentation, AI-interaction disclosures, and AI-generated-content marking (including deepfakes) current with system changes, and retain distribution evidence. Evaluate AI suppliers against the organization's responsible-AI requirements and review customer needs and communications so customers have what they need to use the systems responsibly.
  • Annual Policy Review — Compliance & Legal · 2 steps
    Obtain substantive owner and policy-team review, route material revisions separately and approve the next review date.
  • Code of Conduct & Workforce Accountability Cycle — HR; with Compliance & Legal · 6 steps
    Adopt the code of conduct and its performance, incentive and disciplinary expectations; communicate it, gate access on acknowledgments, assess violations and verify timely disciplinary and remediation outcomes.
  • Compliance Monitoring & Attestation — Compliance & Legal · 2 steps
    Refresh evidence for an obligation on its review cycle, test continued conformance, and record the owner attestation with any exceptions.
  • Control Responsibility Communications & Ethics Hotline — Compliance & Legal; with HR · 6 steps
    Approve tailored control-responsibility communications, assess acknowledgment coverage and verify concern-raising channels; test anonymous intake routing, review real matters and retain quarterly evidence with owned exceptions.
  • EU AI Act Obligation Impact Analysis — AI Governance; with Compliance & Legal · 10 steps
    Parse EU AI Act obligations, map affected AI use cases, crosswalk controls, flag conformity gaps, and hand high-risk items to AIMS.
  • Framework Adoption & Cross-Mapping — Compliance & Legal; with Risk Management · 5 steps
    Set obligation- and appetite-based framework targets, assess current evidence and crosswalk coverage, and govern risk-ranked gaps; deliver approved policy/control work with a maintained mapping table and versioned adoption record.
  • Fraud & Forensic Investigation Engagement — Internal Audit; with Compliance & Legal · 13 steps
    Run a predication-gated fraud and forensic investigation from allegation intake through evidence preservation, forensic procedures, interviews, loss quantification, audit-committee reporting, and referral and remediation handoffs.
  • GPAI Model Provider Compliance Cycle — AI Governance; with Compliance & Legal · 8 steps
    Run the recurring compliance cycle owned by providers of general-purpose AI models: maintain model technical documentation and the downstream-provider information pack, operate the EU copyright reservation-of-rights policy, and publish the training-content summary on every model release and quarterly refresh. For models designated as posing systemic risk, the cycle additionally runs state-of-the-art model evaluations with adversarial testing, assesses and mitigates systemic risks, tracks and reports serious incidents to the AI Office, and verifies cybersecurity protection of the model and its infrastructure.
  • Incident Management Lifecycle — Business Operations; with IT, Compliance & Legal · 7 steps
    Assess and govern an incident from its detection clock through verified recovery and approved notifications; determine corrective actions or risk acceptance and retain the evidence, reporting handoff and follow-up schedule.
  • Incident Reporting Channels & Spillage Response — IT; with Compliance & Legal · 7 steps
    Operate the standing incident-reporting capability: run the monitored mailbox, hotline, and service portal with full acknowledgment and triage routing, execute the information-spillage response procedure end to end, and maintain reviewed contacts with authorities and special-interest groups.
  • ISO 27001 SoA Review & Controls Assessment — IT; with Compliance & Legal · 8 steps
    Review Statement of Applicability decisions, verify implementation evidence, assess controls, remediate gaps, and publish the approved SoA version.
  • Legal & Regulatory Compliance Register Evaluation — Compliance & Legal · 6 steps
    Run the compliance office's recurring register-evaluation cycle as a per-cycle compliance-review Audit item: maintain the register of applicable legal, regulatory, and contractual requirements — including intellectual-property and software-licensing obligations — with named owners, evaluate compliance with each requirement on its defined cadence through documented reviews, drive remediation of non-compliance as Issues linked to the cycle Audit with status reported to management, and retain the register and evaluation results as evidence.
  • NIST RMF System Authorization (ATO) Cycle — IT; with Compliance & Legal · 9 steps
    Move a single information system through the seven RMF phases — prepare, categorize, select, implement, assess, authorize, and monitor — to reach and sustain an authorization-to-operate, producing the FIPS 199 categorization, SSP, SAR, POA&M, and signed ATO letter as one authorization package.
  • Obligation Implementation & Adoption — Compliance & Legal · 2 steps
    Deliver the control, policy and process changes an obligation requires, validate readiness evidence, and approve the adoption record.
  • Policy Change — Compliance & Legal · 2 steps
    Review a policy redline and its obligation impact, obtain authorized approval, publish the approved version and retain the change record.
  • Policy Exception & Risk Acceptance — Risk Management; with Compliance & Legal · 6 steps
    Manage policy exceptions end-to-end: justify, risk-assess, compensate, approve time-bound, register with expiry, and re-review.
  • Policy Lifecycle Management — Compliance & Legal; with Executive · 8 steps
    Run a Policy item through its full lifecycle — drafting and control/authority linkage, stakeholder review, approval, publication, workforce attestation, monitoring, and scheduled refresh.
  • Public Content & External Sharing Authorization — IT; with Compliance & Legal · 5 steps
    Operate the standing publication-authorization capability: verify only trained, designated individuals post to public-facing systems, confirm external information shares carry information-owner authorization consistent with classification and sharing agreements, and run the quarterly sweep that re-verifies the documented no-authentication actions and inspects public content for nonpublic exposure.
  • Regulatory Change Intake & Impact Assessment — Compliance & Legal · 2 steps
    Validate a new or amended external obligation against its authoritative source, determine applicability, and assess the impact on controls, policies, processes and systems.
  • Regulatory Compliance Attestation Cycle — Compliance & Legal; with Executive · 10 steps
    Compile evidence for a regulation or obligation set, resolve gaps, route officer certification, and archive the attestation package.
  • Regulatory Exam & External Audit Management — Compliance & Legal · 10 steps
    Manage a live regulator exam or external audit from notification intake through request fulfillment, QC'd evidence release, fieldwork support, findings response, and commitment closure.
  • Regulatory Horizon Scanning & Triage — Compliance & Legal · 5 steps
    Ingest regulator publications, classify applicability, assign owners, and route relevant changes into impact analysis.
  • Regulatory Impact Analysis & Obligation Mapping — Compliance & Legal · 9 steps
    Parse regulatory changes into obligations, map them to policies and controls, identify gaps, and hand confirmed gaps to implementation.
  • Regulatory Obligation Implementation — Compliance & Legal · 7 steps
    Implement a new or changed regulatory obligation from gap analysis through policy update, control design, process operationalization, and coverage validation.
  • Requirement Applicability & Control Mapping — Compliance & Legal · 2 steps
    Interpret a requirement, determine supported applicability, map obligations to controls and evidence, and approve the mapping record.
  • Security Control Assessment & POA&M Remediation — IT; with Compliance & Legal · 7 steps
    Enrich the engagement Audit item: assess a system's controls with 800-53A methods, record determinations, open a POA&M Issue per gap, re-validate remediation, and issue the Security Assessment Report (SAR).
  • Security Policy Suite Review — IT; with Compliance & Legal · 6 steps
    Operate the annual (and change-triggered) review cycle for the full security policy suite across eight policy families: secure acquisition, development, configuration-management, and maintenance; asset, media, and physical protection; access control, identification, and personnel security; communications protection and cryptography; security awareness and cyber-hygiene; audit-logging, monitoring, and system integrity; contingency planning and disruption mitigation; and incident response. Each policy is reviewed against current risk and threat inputs, updated, reapproved, and disseminated with communication and acknowledgment tracking captured as one evidence set.
  • SOC 2 Readiness & Evidence Collection — IT; with Compliance & Legal · 5 steps
    Get an already-opened SOC examination Audit engagement audit-ready for SOC 2/SOC 1: map the Control library to each in-scope Trust Services Criterion, close readiness gaps, run the PBC evidence request list with QA, and coordinate the CPA firm — producing the criteria-to-control mapping matrix and gap matrix, the owned PBC request list, the QA'd evidence set, and the cross-referenced PBC response package.
  • SOC 2 Reporting and Management Assertion — Compliance & Legal; with Executive · 2 steps
    Prepare the SOC 2 description and management assertion, reconcile subservice reliance, and approve the auditee report package.
  • System Categorization, Security Planning & Authorization — IT; with Compliance & Legal · 7 steps
    Operate the per-system control — anchored on the existing NIST 800-53 system-authorization Control in the library, one workflow instance per system per authorization cycle — that categorizes each system and its information by confidentiality, integrity, and availability impact with criticality analysis and accountable-official approval, develops and maintains the approved system security and privacy plan (PL-2), authorizes and documents internal system connections (CA-9), and secures the formal authorization-to-operate decision before production use, with reauthorization tracked on frequency and significant change (CA-6). Named deliverables: the security categorization summary and criticality analysis, the system security and privacy plan, the internal-connection authorization register, and the signed authorization-to-operate decision with its plan of action and milestones.
  • Third-Party ICT Vendor Regulatory Assurance — Procurement; with Compliance & Legal · 5 steps
    Assess third-party and ICT vendor regulatory obligations, gaps, remediation, and register updates for DORA, FFIEC, and related regimes.
About EvidenceFlows Privacy Terms