← Back to catalogue
Published

Regulatory Compliance Process

vr.wm-act-051 · wm-act-051-regulatory-compliance-process

Represent a governed compliance cycle so agents can connect authoritative sources, bounded applicability, obligations, controls, evidence, findings and remediation without treating a process status, attestation or submission as timeless proof of compliance.

World Models Activities and processes ACT.REG

Bundle → Layer → Finding → Questions Filled

6 bundles · 12 layers · 24 findings · 72 questions

Programme identity, scope, authority and regulatory context Groups governed compliance context for programme identity, scope, authority and regulatory context.

Programme profile, identifiers, subject, scope and governance

Groups source-qualified compliance context for programme profile, identifiers, subject, scope and governance.

Compliance programme profile, root identity, subject and boundary

Records compliance programme profile, root identity, subject and boundary as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish compliance programme profile, root identity, subject and boundary? identity
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by compliance programme profile, root identity, subject and boundary, with which authority, independence and limits? composition
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to compliance programme profile, root identity, subject and boundary, and how is it corrected? privacy

Owner, governing body, steward, responsible functions, resources and independence

Records owner, governing body, steward, responsible functions, resources and independence as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish owner, governing body, steward, responsible functions, resources and independence? ownership
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by owner, governing body, steward, responsible functions, resources and independence, with which authority, independence and limits? evidence
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to owner, governing body, steward, responsible functions, resources and independence, and how is it corrected? lifecycle

Regulatory sources, jurisdiction, effective period and change

Groups source-qualified compliance context for regulatory sources, jurisdiction, effective period and change.

Authority, source instrument, provision, version, jurisdiction and language

Records authority, source instrument, provision, version, jurisdiction and language as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish authority, source instrument, provision, version, jurisdiction and language? provenance
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by authority, source instrument, provision, version, jurisdiction and language, with which authority, independence and limits? ownership
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to authority, source instrument, provision, version, jurisdiction and language, and how is it corrected? quality

Publication, effective, transition, repeal, supersession, change impact and watch

Records publication, effective, transition, repeal, supersession, change impact and watch as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish publication, effective, transition, repeal, supersession, change impact and watch? temporal
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by publication, effective, transition, repeal, supersession, change impact and watch, with which authority, independence and limits? measurement
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to publication, effective, transition, repeal, supersession, change impact and watch, and how is it corrected? security
Obligations, applicability, risk and control mapping Groups governed compliance context for obligations, applicability, risk and control mapping.

Requirements, obligations, applicability and interpretation

Groups source-qualified compliance context for requirements, obligations, applicability and interpretation.

Requirement, obligation, prohibition, duty, right and authoritative-text reference

Records requirement, obligation, prohibition, duty, right and authoritative-text reference as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish requirement, obligation, prohibition, duty, right and authoritative-text reference? requirement
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by requirement, obligation, prohibition, duty, right and authoritative-text reference, with which authority, independence and limits? exception
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to requirement, obligation, prohibition, duty, right and authoritative-text reference, and how is it corrected? retention

Applicability, subject, activity, threshold, exemption, interpretation and rationale

Records applicability, subject, activity, threshold, exemption, interpretation and rationale as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish applicability, subject, activity, threshold, exemption, interpretation and rationale? decision
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by applicability, subject, activity, threshold, exemption, interpretation and rationale, with which authority, independence and limits? provenance
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to applicability, subject, activity, threshold, exemption, interpretation and rationale, and how is it corrected? interoperability

Risk, controls, objectives, ownership and traceability

Groups source-qualified compliance context for risk, controls, objectives, ownership and traceability.

Compliance risk, cause, event, consequence, likelihood, impact and tolerance reference

Records compliance risk, cause, event, consequence, likelihood, impact and tolerance reference as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish compliance risk, cause, event, consequence, likelihood, impact and tolerance reference? relationship
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by compliance risk, cause, event, consequence, likelihood, impact and tolerance reference, with which authority, independence and limits? process
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to compliance risk, cause, event, consequence, likelihood, impact and tolerance reference, and how is it corrected? decision

Control objective, definition, owner, type, frequency, mapping and coverage

Records control objective, definition, owner, type, frequency, mapping and coverage as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish control objective, definition, owner, type, frequency, mapping and coverage? composition
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by control objective, definition, owner, type, frequency, mapping and coverage, with which authority, independence and limits? validation
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to control objective, definition, owner, type, frequency, mapping and coverage, and how is it corrected? state
Implementation, evidence, monitoring and control assurance Groups governed compliance context for implementation, evidence, monitoring and control assurance.

Control implementation, design, operation and responsibility

Groups source-qualified compliance context for control implementation, design, operation and responsibility.

Implementation description, component, owner, operator, scope and dependency

Records implementation description, component, owner, operator, scope and dependency as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish implementation description, component, owner, operator, scope and dependency? definition
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by implementation description, component, owner, operator, scope and dependency, with which authority, independence and limits? privacy
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to implementation description, component, owner, operator, scope and dependency, and how is it corrected? identity

Design effectiveness, operating effectiveness, frequency, execution and failure

Records design effectiveness, operating effectiveness, frequency, execution and failure as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish design effectiveness, operating effectiveness, frequency, execution and failure? validation
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by design effectiveness, operating effectiveness, frequency, execution and failure, with which authority, independence and limits? lifecycle
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to design effectiveness, operating effectiveness, frequency, execution and failure, and how is it corrected? classification

Evidence collection, quality, freshness and continuous monitoring

Groups source-qualified compliance context for evidence collection, quality, freshness and continuous monitoring.

Evidence identity, source, method, coverage period, integrity, access and lineage

Records evidence identity, source, method, coverage period, integrity, access and lineage as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish evidence identity, source, method, coverage period, integrity, access and lineage? evidence
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by evidence identity, source, method, coverage period, integrity, access and lineage, with which authority, independence and limits? quality
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to evidence identity, source, method, coverage period, integrity, access and lineage, and how is it corrected? relationship

Monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap

Records monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap? measurement
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap, with which authority, independence and limits? security
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap, and how is it corrected? authority
Assessment, findings, nonconformities, exceptions and waivers Groups governed compliance context for assessment, findings, nonconformities, exceptions and waivers.

Assessment, audit, test, scope, method, results and review

Groups source-qualified compliance context for assessment, audit, test, scope, method, results and review.

Assessment engagement, plan, criteria, procedure, sample, assessor and independence

Records assessment engagement, plan, criteria, procedure, sample, assessor and independence as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish assessment engagement, plan, criteria, procedure, sample, assessor and independence? process
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by assessment engagement, plan, criteria, procedure, sample, assessor and independence, with which authority, independence and limits? retention
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to assessment engagement, plan, criteria, procedure, sample, assessor and independence, and how is it corrected? requirement

Test result, observation, conclusion, confidence, limit and contradiction

Records test result, observation, conclusion, confidence, limit and contradiction as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish test result, observation, conclusion, confidence, limit and contradiction? quality
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by test result, observation, conclusion, confidence, limit and contradiction, with which authority, independence and limits? interoperability
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to test result, observation, conclusion, confidence, limit and contradiction, and how is it corrected? constraint

Finding disposition, root cause, exception and waiver

Groups source-qualified compliance context for finding disposition, root cause, exception and waiver.

Finding, nonconformity, severity, affected scope, source, status and dispute

Records finding, nonconformity, severity, affected scope, source, status and dispute as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish finding, nonconformity, severity, affected scope, source, status and dispute? state
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by finding, nonconformity, severity, affected scope, source, status and dispute, with which authority, independence and limits? decision
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to finding, nonconformity, severity, affected scope, source, status and dispute, and how is it corrected? event

Exception, waiver, authority, rationale, scope, compensating control, expiry and review

Records exception, waiver, authority, rationale, scope, compensating control, expiry and review as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish exception, waiver, authority, rationale, scope, compensating control, expiry and review? exception
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by exception, waiver, authority, rationale, scope, compensating control, expiry and review, with which authority, independence and limits? state
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to exception, waiver, authority, rationale, scope, compensating control, expiry and review, and how is it corrected? temporal
Remediation, verification, attestation, reporting and regulator interface Groups governed compliance context for remediation, verification, attestation, reporting and regulator interface.

Remediation planning, execution, verification and closure

Groups source-qualified compliance context for remediation planning, execution, verification and closure.

Remediation action, owner, priority, due date, resource, dependency and progress

Records remediation action, owner, priority, due date, resource, dependency and progress as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish remediation action, owner, priority, due date, resource, dependency and progress? lifecycle
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by remediation action, owner, priority, due date, resource, dependency and progress, with which authority, independence and limits? identity
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to remediation action, owner, priority, due date, resource, dependency and progress, and how is it corrected? composition

Acceptance criteria, independent verification, residual risk, reopen and closure

Records acceptance criteria, independent verification, residual risk, reopen and closure as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish acceptance criteria, independent verification, residual risk, reopen and closure? validation
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by acceptance criteria, independent verification, residual risk, reopen and closure, with which authority, independence and limits? classification
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to acceptance criteria, independent verification, residual risk, reopen and closure, and how is it corrected? evidence

Attestation, disclosure, reporting, submission and response

Groups source-qualified compliance context for attestation, disclosure, reporting, submission and response.

Compliance-status claim, scope, basis, qualifier, signer, authority and assurance

Records compliance-status claim, scope, basis, qualifier, signer, authority and assurance as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish compliance-status claim, scope, basis, qualifier, signer, authority and assurance? authority
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by compliance-status claim, scope, basis, qualifier, signer, authority and assurance, with which authority, independence and limits? relationship
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to compliance-status claim, scope, basis, qualifier, signer, authority and assurance, and how is it corrected? ownership

Report, notification, submission, recipient, deadline, receipt, acceptance and follow-up

Records report, notification, submission, recipient, deadline, receipt, acceptance and follow-up as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish report, notification, submission, recipient, deadline, receipt, acceptance and follow-up? event
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by report, notification, submission, recipient, deadline, receipt, acceptance and follow-up, with which authority, independence and limits? authority
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to report, notification, submission, recipient, deadline, receipt, acceptance and follow-up, and how is it corrected? measurement
Lifecycle, governance, correction, retention and interoperability Groups governed compliance context for lifecycle, governance, correction, retention and interoperability.

Programme cycle status, review, change, correction and supersession

Groups source-qualified compliance context for programme cycle status, review, change, correction and supersession.

Cycle status, review period, trigger, material change and continuous improvement

Records cycle status, review period, trigger, material change and continuous improvement as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish cycle status, review period, trigger, material change and continuous improvement? lifecycle
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by cycle status, review period, trigger, material change and continuous improvement, with which authority, independence and limits? requirement
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to cycle status, review period, trigger, material change and continuous improvement, and how is it corrected? exception

Correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage

Records correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage? provenance
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage, with which authority, independence and limits? constraint
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage, and how is it corrected? provenance

Access, retention, assurance, projection and agent controls

Groups source-qualified compliance context for access, retention, assurance, projection and agent controls.

Purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition

Records purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition? privacy
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition, with which authority, independence and limits? event
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition, and how is it corrected? process

OSCAL, BPMN, SACM, SARIF, ODRL and PROV projection, version, scope, loss and round trip

Records oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.

  1. Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip? interoperability
  2. Who owns, interprets, performs, reviews, approves, disputes or is affected by oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip, with which authority, independence and limits? temporal
  3. Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip, and how is it corrected? validation

Classifiers Filled

Family
World Models
Category
Activities and processes
Entry kind
aggregate
Navigation path
NAV.ACT.REG
Domain
ACT.REG
Industry
Cross-industry
Tags
regulatorycomplianceprocessact.reg

What it is Filled

Owns one compliance-cycle identity and bounded subject, jurisdiction, scope and period; source-revision watch; attributable applicability decisions; obligation-risk-control mappings; implementation, evidence and monitoring context; assessment result intake; finding, exception, remediation, verification, attestation and reporting links; and correction lineage. Law, regulation, obligation, policy, risk, control, organization, asset, audit, assessment, evidence, incident, task, attestation, regulator submission, provenance, access audit and record masters remain external.

In scope

  • Programme identity, subject and scope, source versions and changes, applicability interpretations, obligation-risk-control traceability, implementation and monitoring assertions
  • Assessment result intake, findings and exceptions, remediation and verification coordination, bounded status claims, attestations, reporting, correction, privacy, retention and loss-aware projections

Out of scope

  • Creating or changing law, authoritative obligations, generic policies, risks, control definitions, organizations, assets, audit engagements, assessments, evidence items, incidents, work tasks, regulator submissions or records
  • Treating compliance as a universal binary fact or equating action completion, finding closure, attestation, submission, certification, acceptance and continuing compliance
  • Providing legal advice, certification, enforcement, exception approval, regulator filing or destructive evidence handling

Why it exists Filled

Represent a governed compliance cycle so agents can connect authoritative sources, bounded applicability, obligations, controls, evidence, findings and remediation without treating a process status, attestation or submission as timeless proof of compliance.

Distinguishing features Filled

  • Tracks one bounded compliance cycle for a subject, jurisdiction and period, not compliance as a permanent state.
  • Connects sources, applicability, obligations, controls and evidence, while the obligation, risk and control models keep their own records.
  • Differs from an audit or assessment, which produces findings that this process takes in and acts upon.
  • Differs from a certification, which is an external attestation and not a running process.

What robots and AI may and may not do Filled

Must not

  • Issue a legal interpretation or a binding applicability decision.
  • Certify or attest compliance.
  • Approve exceptions or risk acceptances.
  • File submissions with a regulator.
  • Mark a finding closed without verification evidence.

Only with a human decision

  • Deciding applicability of a regulation to the organization.
  • Approving an exception, a risk acceptance or a remediation closure.
  • Signing an attestation or a regulator submission.

May

  • Watch authoritative regulatory sources and register changes for review.
  • Draft applicability analyses and obligation-to-control mappings as proposals.
  • Collect and index implementation and monitoring evidence.
  • Track remediation actions and their due dates.

Moral aspects Filled

  • Compliance failures can harm customers, workers or the public that the regulation protects, not only the organization.
  • Evidence collection may involve monitoring of employees and must stay proportionate.
  • Overstated compliance claims mislead regulators and the public.

Who is affected

  • People the regulation protects
  • Employees whose work is monitored as evidence
  • Regulators and auditors relying on the record

Owners Filled

Steward

Dimension owner and compliance-governance mandate

Roles

Compliance programme owner
Own programme purpose, scope, resources, governance and accountable status claims.
Legal or regulatory interpreter
Own attributable applicability interpretation and uncertainty within professional authority.
Control owner and operator
Own control mapping, implementation and operating evidence within scope.
Independent assessor or auditor
Own assessment criteria, method, evidence use, result, limitations and independence declaration.
Finding and remediation owner
Own response, action coordination, due dates, escalation and closure evidence.
Attestor or reporting officer
Own bounded declarations, disclosures and submissions within signing authority.
Interoperability steward
Own versioned projections with jurisdiction, profile, maturity and loss declarations.
Privacy, privilege, records and assurance steward
Own protected views, privilege handling, disclosures, holds, retention and auditability.

Links to other meta-models Filled

references

  • WM-XCT-029 Obligation / Commitment, law, regulation and policy models - Resolve authoritative requirements and obligations while keeping applicability interpretation attributable and local to the cycle.
  • WM-KNW-015 Risk / Opportunity and WM-XCT-027 Risk / Control - Bind versioned risk and control masters to compliance-specific coverage, implementation and gap assertions.
  • WM-ACT-033 Review / Inspection / Audit, WM-ACT-034 Assessment / Evaluation and WM-ECO-035 Audit / Assurance Engagement - Bind assessment and assurance work without owning its execution, independence or evidence-gathering lifecycle.
  • Evidence, incident, task, work-order, attestation, regulator-submission, provenance, access-audit and record models - Resolve evidence, remediation execution, declarations, external interactions and records without copying their lifecycles.

aligned

  • OSCAL 1.2.3, BPMN 2.0.2, SACM 2.3, SARIF 2.1.0, ODRL 2.2 and PROV-O - Project version-pinned control, process, assurance, tool-result, policy and provenance views with scope and information-loss declarations.

neighbor

  • Law, regulation and WM-XCT-029 Obligation / Commitment - Authoritative sources and obligations remain external. The aggregate stores versioned references and attributable applicability and mapping decisions without rewriting authoritative text.
  • WM-KNW-015 Risk / Opportunity and WM-XCT-027 Risk / Control - Risk and control masters own their definitions and lifecycles. The aggregate owns compliance-specific mappings, implementation assertions, coverage and gaps.
  • WM-ACT-033 Review / Inspection / Audit, WM-ACT-034 Assessment / Evaluation and WM-ECO-035 Audit / Assurance Engagement - Specialist models own engagement, method, evidence gathering, testing, results and assurance. This aggregate records commissioning, result intake, response and closure context.
  • Evidence, incident, task and work-order models - External masters own evidence content, incidents and remediation work. The aggregate keeps integrity-qualified references, compliance disposition, acceptance criteria and verification status.
  • Attestation, certification, submission and regulator response - A status claim, signed declaration, independent certification, filing receipt and regulator decision each retain independent authority and state. None proves continuing compliance by itself.
  • BPMN, OSCAL, SACM, SARIF, ODRL and PROV - These are versioned process, control-assessment, assurance, tool-result, policy and provenance projections with different scopes. No mapping is assumed lossless or universally applicable.

parent

  • WM-ACT-003

What else AI and robots need to interact with it Filled

Identity and identifiers required Filled

  • Authoritative master-system identifier for each compliance programme, applicability decision, mapping, evidence item, finding, exception, remediation, attestation or submission, qualified by owning organization and record kind.
  • Governed globally resolvable compliance-record IRI.
  • Dimension UUID when neither preceding identifier exists.

Direct properties not applicable Not applicable

Not applicable

Institutional or informational subject: no invented physical properties.

Recognition optional Filled

  • A compliance cycle names a subject, a regulatory source, a jurisdiction, a period and a set of obligations with controls and evidence.
  • Often confused with an audit engagement, a policy document, a risk register or a certificate.

Capabilities and actions required Filled

  • Register compliance cycle: Governed operation to register compliance cycle without hidden legal interpretation, enforcement or mutation of external masters.
  • Register regulatory source change: Governed operation to register regulatory source change without hidden legal interpretation, enforcement or mutation of external masters.
  • Assess applicability: Governed operation to assess applicability without hidden legal interpretation, enforcement or mutation of external masters.
  • Map obligations, risks and controls: Governed operation to map obligations, risks and controls without hidden legal interpretation, enforcement or mutation of external masters.
  • Record implementation and monitoring evidence: Governed operation to record implementation and monitoring evidence without hidden legal interpretation, enforcement or mutation of external masters.
  • Commission or link assessment: Governed operation to commission or link assessment without hidden legal interpretation, enforcement or mutation of external masters.
  • Record finding or exception: Governed operation to record finding or exception without hidden legal interpretation, enforcement or mutation of external masters.
  • Plan, track and verify remediation: Governed operation to plan, track and verify remediation without hidden legal interpretation, enforcement or mutation of external masters.
  • Attest, report, submit and record response: Governed operation to attest, report, submit and record response without hidden legal interpretation, enforcement or mutation of external masters.
  • Correct, project, retain, disclose and audit: Governed operation to correct, project, retain, disclose and audit without hidden legal interpretation, enforcement or mutation of external masters.

Hazards and failure modes required Filled

  • Missed regulatory change leaving obligations unmapped.
  • Stale evidence presented as current compliance.
  • Paper compliance where controls exist on record but do not operate.

Standards and interfaces required Filled

  • NIST OSCAL for control catalogues, assessment plans and results.
  • ISO 37301 compliance management systems.
  • ISO 31000 risk management guidelines.
  • OMG BPMN 2.0 (ISO/IEC 19510) for process models.
  • OASIS SARIF for static analysis findings.
  • W3C PROV-O for evidence provenance.

Context of use required Filled

  • Legal effect, applicability, professional privilege, regulator authority, reporting, certification, retention and disclosure depend on jurisdiction, sector and facts.
  • DOJ and USSC are United States profiles, GDPR is European Union law and OECD or UNODC guidance is not itself binding law.
  • Local control libraries, regulatory taxonomies, severity scales, assurance levels, evidence rules and exception authorities require versioned profiles.

Sources Filled

  1. Compliance management systems - Requirements with guidance for use - International Organization for Standardization
  2. Risk management - Guidelines - International Organization for Standardization
  3. Guidelines for auditing management systems - International Organization for Standardization
  4. Security and Privacy Controls for Information Systems and Organizations - National Institute of Standards and Technology
  5. Assessing Security and Privacy Controls in Information Systems and Organizations - National Institute of Standards and Technology
  6. Open Security Controls Assessment Language - National Institute of Standards and Technology
  7. Evaluation of Corporate Compliance Programs - United States Department of Justice
  8. Annotated 2025 Chapter 8, section 8B2.1 Effective Compliance and Ethics Program - United States Sentencing Commission
  9. Recommendation of the Council on Public Integrity - Organisation for Economic Co-operation and Development
  10. An Anti-Corruption Ethics and Compliance Programme for Business: A Practical Guide - United Nations Office on Drugs and Crime
  11. Business Process Model and Notation - Object Management Group
  12. Structured Assurance Case Metamodel - Object Management Group
  13. Static Analysis Results Interchange Format - OASIS Open
  14. ODRL Information Model 2.2 - World Wide Web Consortium
  15. PROV-O: The PROV Ontology - World Wide Web Consortium
  16. Regulation (EU) 2016/679 General Data Protection Regulation - European Union
  17. Date and Time on the Internet: Timestamps - Internet Engineering Task Force

Open questions

  • Approve or reject registry relations to obligation, risk/control, audit, assessment, assurance, evidence, incident, task, attestation, submission and record models.
  • Create jurisdiction and sector profiles for financial services, healthcare, product safety, environment, labor, tax, privacy, anti-corruption, competition, export control and AI regimes.
  • Perform licensed clause-level review of ISO 37301, ISO 31000 and ISO 19011 before any conformance claim.
  • Test release-pinned OSCAL, BPMN, SACM, SARIF, ODRL and PROV mappings with round-trip and information-loss evidence.
  • Obtain supplemental independent external review and resolve any material challenge before canonical promotion.
  • Claude and Grok each timed out on one bounded attempt; no independent external result was admitted.
  • No relation-ledger edge is registered for WM-ACT-051, so links to obligation, risk/control, audit, assessment, assurance, incident, task, attestation and record models remain candidate boundary notes.
  • Financial services, healthcare, product safety, environment, labor, tax, privacy, anti-corruption, competition, export control, AI and other regimes require jurisdiction and sector profiles.
  • ISO normative clauses are access-restricted; NIST, DOJ, USSC, OECD, UNODC, GDPR, OSCAL and SARIF each have sectoral, jurisdictional or technical scope and require release-pinned validation.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-act-051-regulatory-compliance-process/spec.yaml, ver-cy/world-models/card-supplements/wm-act-051-regulatory-compliance-process.json