Compliance: SOPs
Five procedures covering obligation mapping, continuous monitoring, the attestation cycle, gap remediation and audit preparation.
Markdown. No sign-up, no email.
SOP 1: Obligation mapping#
Run: quarterly, and whenever a regulation changes or we enter a new market.
- List every obligation that applies, with its source.
- Name the control that satisfies each.
- Anything unmapped is a gap, recorded today rather than at the next audit.
- Anything mapped to a control that does not actually address it is also a gap, and this is the subtler failure: a mapping table that looks complete and is not.
SOP 2: Continuous monitoring#
Run: continuously.
Each control reports one of three states, never two:
| State | Meaning |
|---|---|
| Operating | Evidenced this period |
| Failing | Evidenced as not operating |
| Unevidenced | We do not know, which is a distinct answer and is reported as such |
Unevidenced is never rolled into operating. The whole value of continuous monitoring collapses the moment "no failure signal" is treated as a pass.
SOP 3: The attestation cycle#
Run: quarterly, by a person.
The agent presents evidence. A named human reads it and attests that each control was effective, or records why they cannot.
Attestation is separate from monitoring by design. A system that both watches a control and declares it passing has no independent element in it, and independence is the only thing an attestation is worth.
SOP 4: Gap remediation#
Run: on every identified gap.
| Field | Rule |
|---|---|
| Owner | A name, not a team |
| Remediation date | Set when the gap is found, not when it is convenient |
| Interim control | What reduces the risk meanwhile, or explicitly none |
| If it cannot be fixed | It becomes an accepted risk, with an accepter and an expiry date |
A gap older than 30 days without an escalation is a process failure regardless of the underlying risk, because it means the register is being read and not acted on.
SOP 5: Audit preparation#
Run: continuously, which is the point.
Preparing for an audit should be gathering existing evidence rather than producing it. If audit preparation is a project, the monitoring is not working.
- Evidence exists already, dated, from when the control operated.
- Gaps are already known and already have owners. Disclose them. An auditor who finds a gap you knew about and did not mention has learned something worse than the gap.
- Previous findings are closed in the control, not on paper. A repeated finding is a statement about the organisation, not about the control.
Escalation#
| Situation | Goes to |
|---|---|
| An obligation with no control | Legal and the CEO, the same week |
| A control failing for more than 30 days | CEO, with a remediation plan |
| An accepted risk past expiry | The original accepter, then their chief |
| A repeated audit finding | CEO. This is a governance issue, not a compliance one |
| Any request to attest without evidence | Refuse. Record the refusal |