{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:f66b649a8d2dd843ce3e4056421808ddaf88d95e9299e98194e32b19a040db10","slug":"reg-legal-regulatory-compliance-register-evaluation","url":"/assets/agent_workflow-reg-legal-regulatory-compliance-register-evaluation-592eb844.9af14e0d78f372a0.json"},"kind":"record","record":{"attributes":{"department":"compliance-legal","domain":"reg","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=reg-legal-regulatory-compliance-register-evaluation","description":"Runs the compliance office's recurring register-evaluation cycle as a compliance-review engagement: the workflow instance attaches to an Audit item created per cycle (audit_type: compliance, period_start/period_end bounding the evaluation period, lead_auditor = the compliance officer), and every gap, management directive, and result produced this cycle links back to that Audit. A decision-aware cycle that refreshes the register of applicable legal, regulatory, and contractual requirements — including intellectual-property and software-licensing obligations — confirms ownership, schedules and performs documented compliance evaluations on each requirement's defined cadence, remediates non-compliance, reports status to management, and retains the register and results as evidence. Consumes upstream: between-cycle regulatory change flows in as a data feed from the Regulatory Horizon Scanning & Triage workflow, swept at the register-refresh entry point (a feed, not a formal handoff package). Named deliverables: the dated register of record, the period evaluation schedule, the evaluation results register, the compliance determination, the exposure-ranked remediation set (Issues linked to the cycle Audit), the compliance status report and dashboard, and the retained cycle evidence set. Hands off downstream: obligations that need standing up route to the Regulatory Obligation Implementation workflow — named in prose at close-and-archive, with no handoff package produced here. In scope: the legal, regulatory, and contractual requirements already in the compliance register that fall due for evaluation this period — cadence-due, overdue, or event-triggered. Out of scope: standing up brand-new obligations. The cycle scope — register population, the due subset including overdue catch-ups, and the period boundaries — is set at the register-refresh entry point.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=reg-legal-regulatory-compliance-register-evaluation","capabilities":[],"controls":["UC-AUDIT-24"],"domains":["reg"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:f66b649a8d2dd843ce3e4056421808ddaf88d95e9299e98194e32b19a040db10","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:reg-legal-regulatory-compliance-register-evaluation","standards":["cobit-2019","iso-27001"],"teams":["compliance-legal"]},"id":"wf:R12","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AR12","slug":"reg-legal-regulatory-compliance-register-evaluation","sourceIds":["cobit-2019","iso-27001"],"sourceUrl":null,"title":"Legal & Regulatory Compliance Register Evaluation","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9e28b66a7684366e1c248bd4903cd2b5019e949e0e054ccb938deb48999e50c1","properties":{},"sourceDetailPath":"/data/v1/records/wf-r12-f55631e7.json","sourceId":"wf:R12","targetDetailPath":"/data/v1/records/uc-uc-audit-24-fa96fe18.json","targetId":"uc:UC-AUDIT-24","type":"operates"}],"schemaVersion":1}
