Compliance & Legal Workflows

Open-source workflows owned by or involving Compliance & Legal. Review the steps, responsibilities and evidence, then download templates for your AssureSwarm instance.

All workflows 212 IT 92 HR 11 Finance 27 Internal Audit 45 Risk Management 32 Compliance & Legal 32 Privacy 11 Procurement 15 Executive 20 AI Governance 11 Facilities 7 Business Operations 9
  • AI Transparency & Value-Chain Communications — AI Governance; with Compliance & Legal · 6 steps
    Run the recurring AI-transparency cycle: keep each AI system's user and deployer documentation, AI-interaction disclosures, and AI-generated-content marking (including deepfakes) current with system changes, and retain distribution evidence. Evaluate AI suppliers against the organization's responsible-AI requirements and review customer needs and communications so customers have what they need to use the systems responsibly.
  • Annual Policy Review — Compliance & Legal · 2 steps
    Obtain substantive owner and policy-team review, route material revisions separately and approve the next review date.
  • Code of Conduct & Workforce Accountability Cycle — HR; with Compliance & Legal · 6 steps
    Adopt the code of conduct and its performance, incentive and disciplinary expectations; communicate it, gate access on acknowledgments, assess violations and verify timely disciplinary and remediation outcomes.
  • Compliance Monitoring & Attestation — Compliance & Legal · 2 steps
    Refresh evidence for an obligation on its review cycle, test continued conformance, and record the owner attestation with any exceptions.
  • Control Responsibility Communications & Ethics Hotline — Compliance & Legal; with HR · 6 steps
    Approve tailored control-responsibility communications, assess acknowledgment coverage and verify concern-raising channels; test anonymous intake routing, review real matters and retain quarterly evidence with owned exceptions.
  • EU AI Act Obligation Impact Analysis — AI Governance; with Compliance & Legal · 10 steps
    Parse EU AI Act obligations, map affected AI use cases, crosswalk controls, flag conformity gaps, and hand high-risk items to AIMS.
  • Framework Adoption & Cross-Mapping — Compliance & Legal; with Risk Management · 5 steps
    Set obligation- and appetite-based framework targets, assess current evidence and crosswalk coverage, and govern risk-ranked gaps; deliver approved policy/control work with a maintained mapping table and versioned adoption record.
  • Fraud & Forensic Investigation Engagement — Internal Audit; with Compliance & Legal · 13 steps
    Run a predication-gated fraud and forensic investigation from allegation intake through evidence preservation, forensic procedures, interviews, loss quantification, audit-committee reporting, and referral and remediation handoffs.
  • GPAI Model Provider Compliance Cycle — AI Governance; with Compliance & Legal · 8 steps
    Run the recurring compliance cycle owned by providers of general-purpose AI models: maintain model technical documentation and the downstream-provider information pack, operate the EU copyright reservation-of-rights policy, and publish the training-content summary on every model release and quarterly refresh. For models designated as posing systemic risk, the cycle additionally runs state-of-the-art model evaluations with adversarial testing, assesses and mitigates systemic risks, tracks and reports serious incidents to the AI Office, and verifies cybersecurity protection of the model and its infrastructure.
  • Incident Management Lifecycle — Business Operations; with IT, Compliance & Legal · 7 steps
    Assess and govern an incident from its detection clock through verified recovery and approved notifications; determine corrective actions or risk acceptance and retain the evidence, reporting handoff and follow-up schedule.
  • Incident Reporting Channels & Spillage Response — IT; with Compliance & Legal · 7 steps
    Operate the standing incident-reporting capability: run the monitored mailbox, hotline, and service portal with full acknowledgment and triage routing, execute the information-spillage response procedure end to end, and maintain reviewed contacts with authorities and special-interest groups.
  • ISO 27001 SoA Review & Controls Assessment — IT; with Compliance & Legal · 8 steps
    Review Statement of Applicability decisions, verify implementation evidence, assess controls, remediate gaps, and publish the approved SoA version.
  • Legal & Regulatory Compliance Register Evaluation — Compliance & Legal · 6 steps
    Run the compliance office's recurring register-evaluation cycle as a per-cycle compliance-review Audit item: maintain the register of applicable legal, regulatory, and contractual requirements — including intellectual-property and software-licensing obligations — with named owners, evaluate compliance with each requirement on its defined cadence through documented reviews, drive remediation of non-compliance as Issues linked to the cycle Audit with status reported to management, and retain the register and evaluation results as evidence.
  • NIST RMF System Authorization (ATO) Cycle — IT; with Compliance & Legal · 9 steps
    Move a single information system through the seven RMF phases — prepare, categorize, select, implement, assess, authorize, and monitor — to reach and sustain an authorization-to-operate, producing the FIPS 199 categorization, SSP, SAR, POA&M, and signed ATO letter as one authorization package.
  • Obligation Implementation & Adoption — Compliance & Legal · 2 steps
    Deliver the control, policy and process changes an obligation requires, validate readiness evidence, and approve the adoption record.
  • Policy Change — Compliance & Legal · 2 steps
    Review a policy redline and its obligation impact, obtain authorized approval, publish the approved version and retain the change record.
  • Policy Exception & Risk Acceptance — Risk Management; with Compliance & Legal · 6 steps
    Manage policy exceptions end-to-end: justify, risk-assess, compensate, approve time-bound, register with expiry, and re-review.
  • Policy Lifecycle Management — Compliance & Legal; with Executive · 8 steps
    Run a Policy item through its full lifecycle — drafting and control/authority linkage, stakeholder review, approval, publication, workforce attestation, monitoring, and scheduled refresh.
  • Public Content & External Sharing Authorization — IT; with Compliance & Legal · 5 steps
    Operate the standing publication-authorization capability: verify only trained, designated individuals post to public-facing systems, confirm external information shares carry information-owner authorization consistent with classification and sharing agreements, and run the quarterly sweep that re-verifies the documented no-authentication actions and inspects public content for nonpublic exposure.
  • Regulatory Change Intake & Impact Assessment — Compliance & Legal · 2 steps
    Validate a new or amended external obligation against its authoritative source, determine applicability, and assess the impact on controls, policies, processes and systems.
  • Regulatory Compliance Attestation Cycle — Compliance & Legal; with Executive · 10 steps
    Compile evidence for a regulation or obligation set, resolve gaps, route officer certification, and archive the attestation package.
  • Regulatory Exam & External Audit Management — Compliance & Legal · 10 steps
    Manage a live regulator exam or external audit from notification intake through request fulfillment, QC'd evidence release, fieldwork support, findings response, and commitment closure.
  • Regulatory Horizon Scanning & Triage — Compliance & Legal · 5 steps
    Ingest regulator publications, classify applicability, assign owners, and route relevant changes into impact analysis.
  • Regulatory Impact Analysis & Obligation Mapping — Compliance & Legal · 9 steps
    Parse regulatory changes into obligations, map them to policies and controls, identify gaps, and hand confirmed gaps to implementation.
  • Regulatory Obligation Implementation — Compliance & Legal · 7 steps
    Implement a new or changed regulatory obligation from gap analysis through policy update, control design, process operationalization, and coverage validation.
  • Requirement Applicability & Control Mapping — Compliance & Legal · 2 steps
    Interpret a requirement, determine supported applicability, map obligations to controls and evidence, and approve the mapping record.
  • Security Control Assessment & POA&M Remediation — IT; with Compliance & Legal · 7 steps
    Enrich the engagement Audit item: assess a system's controls with 800-53A methods, record determinations, open a POA&M Issue per gap, re-validate remediation, and issue the Security Assessment Report (SAR).
  • Security Policy Suite Review — IT; with Compliance & Legal · 6 steps
    Operate the annual (and change-triggered) review cycle for the full security policy suite across eight policy families: secure acquisition, development, configuration-management, and maintenance; asset, media, and physical protection; access control, identification, and personnel security; communications protection and cryptography; security awareness and cyber-hygiene; audit-logging, monitoring, and system integrity; contingency planning and disruption mitigation; and incident response. Each policy is reviewed against current risk and threat inputs, updated, reapproved, and disseminated with communication and acknowledgment tracking captured as one evidence set.
  • SOC 2 Readiness & Evidence Collection — IT; with Compliance & Legal · 5 steps
    Get an already-opened SOC examination Audit engagement audit-ready for SOC 2/SOC 1: map the Control library to each in-scope Trust Services Criterion, close readiness gaps, run the PBC evidence request list with QA, and coordinate the CPA firm — producing the criteria-to-control mapping matrix and gap matrix, the owned PBC request list, the QA'd evidence set, and the cross-referenced PBC response package.
  • SOC 2 Reporting and Management Assertion — Compliance & Legal; with Executive · 2 steps
    Prepare the SOC 2 description and management assertion, reconcile subservice reliance, and approve the auditee report package.
  • System Categorization, Security Planning & Authorization — IT; with Compliance & Legal · 7 steps
    Operate the per-system control — anchored on the existing NIST 800-53 system-authorization Control in the library, one workflow instance per system per authorization cycle — that categorizes each system and its information by confidentiality, integrity, and availability impact with criticality analysis and accountable-official approval, develops and maintains the approved system security and privacy plan (PL-2), authorizes and documents internal system connections (CA-9), and secures the formal authorization-to-operate decision before production use, with reauthorization tracked on frequency and significant change (CA-6). Named deliverables: the security categorization summary and criticality analysis, the system security and privacy plan, the internal-connection authorization register, and the signed authorization-to-operate decision with its plan of action and milestones.
  • Third-Party ICT Vendor Regulatory Assurance — Procurement; with Compliance & Legal · 5 steps
    Assess third-party and ICT vendor regulatory obligations, gaps, remediation, and register updates for DORA, FFIEC, and related regimes.
Privacy Terms