workflow
Regulatory Obligation Implementation
Implement a new or changed regulatory obligation end to end on the Audit item created for this implementation (audit_type = compliance or readiness): its scope names the obligation and authority, its period_end holds the effective (compliance-by) date, and the workflow instance attaches to it. There is no native Regulation type, so the regulator, region, and obligation summary live in the anchor Audit.description with the operative source text uploaded to the gap-analysis step. The work — gap analysis, policy updates (Policy items), control design (Control items), process operationalization (a Process item), and coverage validation — enriches that Audit rather than creating a parallel record. In scope are the legal entities, products, systems, and vendor relationships (Vendor items) the obligation touches; entities and processing below the regulation's applicability thresholds are out of scope. This workflow consumes the obligation map handed off from Regulatory Impact Analysis & Obligation Mapping and hands its named deliverable — a validated coverage package (the gap list, the drafted policies and controls, the operationalized process, and the validation run) — to the Regulatory Compliance Attestation Cycle.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- reg
- department
- compliance-legal
- lineOfDefense
- operate
Details
- teams
- compliance-legal
- domains
- reg
- standards
- gdpr
- dora
- nydfs-500
- eu-ai-act
- nis2
- pci-dss
- hipaa
- ccpa
- sourceTemplateId
- workflow-library:reg-obligation-implementation
- releaseId
- sha256:1d07282aea30741e1be3a50057f444f6ebc5e5cadefc69e1e45d54f762f47f4b
- canonicalUrl
- https://workflow-library.com/all/?w=reg-obligation-implementation
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-GOV-03
- UC-GOV-14
- UC-GOV-16
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:1d07282aea30741e1be3a50057f444f6ebc5e5cadefc69e1e45d54f762f47f4b
Connections
- Regulatory Obligation Implementation operates UC-GOV-16 — Select and tailor a risk-based control baseline
- Regulatory Obligation Implementation operates UC-GOV-14 — Establish and maintain approved security policies and procedures
- Regulatory Obligation Implementation operates UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations