{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:1d07282aea30741e1be3a50057f444f6ebc5e5cadefc69e1e45d54f762f47f4b","slug":"reg-obligation-implementation","url":"/assets/agent_workflow-reg-obligation-implementation-4684a566.7441251a21168dcb.json"},"kind":"record","record":{"attributes":{"department":"compliance-legal","domain":"reg","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=reg-obligation-implementation","description":"Implement a new or changed regulatory obligation end to end on the Audit item created for this implementation (audit_type = compliance or readiness): its scope names the obligation and authority, its period_end holds the effective (compliance-by) date, and the workflow instance attaches to it. There is no native Regulation type, so the regulator, region, and obligation summary live in the anchor Audit.description with the operative source text uploaded to the gap-analysis step. The work — gap analysis, policy updates (Policy items), control design (Control items), process operationalization (a Process item), and coverage validation — enriches that Audit rather than creating a parallel record. In scope are the legal entities, products, systems, and vendor relationships (Vendor items) the obligation touches; entities and processing below the regulation's applicability thresholds are out of scope. This workflow consumes the obligation map handed off from Regulatory Impact Analysis & Obligation Mapping and hands its named deliverable — a validated coverage package (the gap list, the drafted policies and controls, the operationalized process, and the validation run) — to the Regulatory Compliance Attestation Cycle.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=reg-obligation-implementation","capabilities":[],"controls":["UC-GOV-03","UC-GOV-14","UC-GOV-16"],"domains":["reg"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:1d07282aea30741e1be3a50057f444f6ebc5e5cadefc69e1e45d54f762f47f4b","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:reg-obligation-implementation","standards":["gdpr","dora","nydfs-500","eu-ai-act","nis2","pci-dss","hipaa","ccpa"],"teams":["compliance-legal"]},"id":"wf:R5","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AR5","slug":"reg-obligation-implementation","sourceIds":["hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Regulatory Obligation Implementation","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:127c3cb86d6ded7bdc55d0fc4200e4848b276cb0fcab40f9825b1c35445d4e8a","properties":{},"sourceDetailPath":"/data/v1/records/wf-r5-c423cac7.json","sourceId":"wf:R5","targetDetailPath":"/data/v1/records/uc-uc-gov-16-694834ac.json","targetId":"uc:UC-GOV-16","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:242639094cff3d814b708b23b6a26846f3357325e2e8b12ff07bb70f5bf8b641","properties":{},"sourceDetailPath":"/data/v1/records/wf-r5-c423cac7.json","sourceId":"wf:R5","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:26ed8e93a5dfeb9e340fec7008dd29e51f3c65168d3baf3a169af9ad4da42460","properties":{},"sourceDetailPath":"/data/v1/records/wf-r5-c423cac7.json","sourceId":"wf:R5","targetDetailPath":"/data/v1/records/uc-uc-gov-03-9e248eb3.json","targetId":"uc:UC-GOV-03","type":"operates"}],"schemaVersion":1}
