SOPs · Compliance

Compliance: SOPs

Five procedures covering obligation mapping, continuous monitoring, the attestation cycle, gap remediation and audit preparation.

Markdown. No sign-up, no email.

SOP 1: Obligation mapping#

Run: quarterly, and whenever a regulation changes or we enter a new market.

  1. List every obligation that applies, with its source.
  2. Name the control that satisfies each.
  3. Anything unmapped is a gap, recorded today rather than at the next audit.
  4. Anything mapped to a control that does not actually address it is also a gap, and this is the subtler failure: a mapping table that looks complete and is not.

SOP 2: Continuous monitoring#

Run: continuously.

Each control reports one of three states, never two:

StateMeaning
OperatingEvidenced this period
FailingEvidenced as not operating
UnevidencedWe do not know, which is a distinct answer and is reported as such

Unevidenced is never rolled into operating. The whole value of continuous monitoring collapses the moment "no failure signal" is treated as a pass.

SOP 3: The attestation cycle#

Run: quarterly, by a person.

The agent presents evidence. A named human reads it and attests that each control was effective, or records why they cannot.

Attestation is separate from monitoring by design. A system that both watches a control and declares it passing has no independent element in it, and independence is the only thing an attestation is worth.

SOP 4: Gap remediation#

Run: on every identified gap.

FieldRule
OwnerA name, not a team
Remediation dateSet when the gap is found, not when it is convenient
Interim controlWhat reduces the risk meanwhile, or explicitly none
If it cannot be fixedIt becomes an accepted risk, with an accepter and an expiry date

A gap older than 30 days without an escalation is a process failure regardless of the underlying risk, because it means the register is being read and not acted on.

SOP 5: Audit preparation#

Run: continuously, which is the point.

Preparing for an audit should be gathering existing evidence rather than producing it. If audit preparation is a project, the monitoring is not working.

  1. Evidence exists already, dated, from when the control operated.
  2. Gaps are already known and already have owners. Disclose them. An auditor who finds a gap you knew about and did not mention has learned something worse than the gap.
  3. Previous findings are closed in the control, not on paper. A repeated finding is a statement about the organisation, not about the control.

Escalation#

SituationGoes to
An obligation with no controlLegal and the CEO, the same week
A control failing for more than 30 daysCEO, with a remediation plan
An accepted risk past expiryThe original accepter, then their chief
A repeated audit findingCEO. This is a governance issue, not a compliance one
Any request to attest without evidenceRefuse. Record the refusal

Back to Compliance

Get new material when it is published

Everything here is free and stays free. There is no form in front of any document. If you want to know when new guides and templates go up, leave an email.

Roughly monthly. Unsubscribe in one click. We do not share your address, and we will not call you.