Workflows · Compliance

Compliance: Workflows

How obligations become controls, controls become evidence, and evidence becomes an attestation, plus the handoffs with Legal, Security, Engineering and Audit.

Markdown. No sign-up, no email.

Compliance is a translation function. Obligations arrive as prose written by lawmakers and have to leave as things a system does and records.

What arrives#

FromWhatBecomes
LegalObligations that apply to usControls, or gaps
SecurityControl state, incidentsEvidence, and sometimes findings
Engineering and DevOpsChange and access recordsEvidence, collected as work happens
HRTraining, joiners and leaversAccess and awareness evidence
CustomersSecurity questionnaires and DPAsCommitments that become obligations of our own
AuditorsFindingsRemediation with owners and dates

Customer commitments are obligations too, and the row most often forgotten. A security questionnaire answered optimistically in a sales cycle is a promise that lands here.

What leaves#

ToWhat
Every functionThe controls they own, and the evidence expected
CEOGap register, expired acceptances, anything needing a decision
AuditorsEvidence, and a disclosed gap list
SalesWhat we can honestly claim about our posture
LegalWhere an obligation cannot be met with a control

The chain#

Obligation to attestation Translate: Obligation () → Control () → Owner named (). Operate: Control runs () → Evidence captured () → State reported (). Assert: Person reads evidence () → Attests, or says why not (). Translate Obligation Control Owner named Operate Control runs Evidence captured State reported Assert Person reads evidence Attests, or says why not
Evidence is collected as work happens rather than reconstructed. Reconstructed evidence is the source of most audit pain and is indistinguishable from fabrication even when honest.

The last lane is the one that cannot be automated. Everything before it can.

Handoff contracts#

With Legal. They decide what applies; compliance decides how it is controlled and evidenced. A regulation without a control is escalated jointly, because the answer is sometimes a control and sometimes a decision to exit an activity.

With Security. Overlapping and not identical. Security stops bad things happening; compliance proves the mechanism exists and operated. A company can be secure and unable to demonstrate it, which fails an audit and loses enterprise deals.

With Engineering. Controls are built into how work happens, not added as a review step. A control that depends on someone remembering is a control that fails during a busy week.

With Sales. What we can honestly claim. Answering a security questionnaire optimistically creates an obligation and a future finding at the same moment.

Cadence#

ContinuousMonitoring and evidence capture
MonthlyGap register, unevidenced controls, expired acceptances
QuarterlyObligation mapping, human attestation
AnnuallyExternal audit if in scope

The failure this design is built against#

An organisation that passes its audit and has a control which stopped operating in March. Nobody lied. The control was tested on audit day, evidence was reconstructed for the rest, and the state in between was never actually known.

Continuous monitoring with a separate unevidenced category is the specific answer to that, and keeping attestation in human hands is what stops the monitoring quietly becoming the assertion.

Back to Compliance

Get new material when it is published

Everything here is free and stays free. There is no form in front of any document. If you want to know when new guides and templates go up, leave an email.

Roughly monthly. Unsubscribe in one click. We do not share your address, and we will not call you.