Regulatory Compliance Process
Represent a governed compliance cycle so agents can connect authoritative sources, bounded applicability, obligations, controls, evidence, findings and remediation without treating a process status, attestation or submission as timeless proof of compliance.
Bundle → Layer → Finding → Questions Filled
6 bundles · 12 layers · 24 findings · 72 questions
Programme identity, scope, authority and regulatory context Groups governed compliance context for programme identity, scope, authority and regulatory context.
Programme profile, identifiers, subject, scope and governance
Groups source-qualified compliance context for programme profile, identifiers, subject, scope and governance.
Compliance programme profile, root identity, subject and boundary
Records compliance programme profile, root identity, subject and boundary as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish compliance programme profile, root identity, subject and boundary? identity
- Who owns, interprets, performs, reviews, approves, disputes or is affected by compliance programme profile, root identity, subject and boundary, with which authority, independence and limits? composition
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to compliance programme profile, root identity, subject and boundary, and how is it corrected? privacy
Owner, governing body, steward, responsible functions, resources and independence
Records owner, governing body, steward, responsible functions, resources and independence as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish owner, governing body, steward, responsible functions, resources and independence? ownership
- Who owns, interprets, performs, reviews, approves, disputes or is affected by owner, governing body, steward, responsible functions, resources and independence, with which authority, independence and limits? evidence
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to owner, governing body, steward, responsible functions, resources and independence, and how is it corrected? lifecycle
Regulatory sources, jurisdiction, effective period and change
Groups source-qualified compliance context for regulatory sources, jurisdiction, effective period and change.
Authority, source instrument, provision, version, jurisdiction and language
Records authority, source instrument, provision, version, jurisdiction and language as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish authority, source instrument, provision, version, jurisdiction and language? provenance
- Who owns, interprets, performs, reviews, approves, disputes or is affected by authority, source instrument, provision, version, jurisdiction and language, with which authority, independence and limits? ownership
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to authority, source instrument, provision, version, jurisdiction and language, and how is it corrected? quality
Publication, effective, transition, repeal, supersession, change impact and watch
Records publication, effective, transition, repeal, supersession, change impact and watch as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish publication, effective, transition, repeal, supersession, change impact and watch? temporal
- Who owns, interprets, performs, reviews, approves, disputes or is affected by publication, effective, transition, repeal, supersession, change impact and watch, with which authority, independence and limits? measurement
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to publication, effective, transition, repeal, supersession, change impact and watch, and how is it corrected? security
Obligations, applicability, risk and control mapping Groups governed compliance context for obligations, applicability, risk and control mapping.
Requirements, obligations, applicability and interpretation
Groups source-qualified compliance context for requirements, obligations, applicability and interpretation.
Requirement, obligation, prohibition, duty, right and authoritative-text reference
Records requirement, obligation, prohibition, duty, right and authoritative-text reference as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish requirement, obligation, prohibition, duty, right and authoritative-text reference? requirement
- Who owns, interprets, performs, reviews, approves, disputes or is affected by requirement, obligation, prohibition, duty, right and authoritative-text reference, with which authority, independence and limits? exception
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to requirement, obligation, prohibition, duty, right and authoritative-text reference, and how is it corrected? retention
Applicability, subject, activity, threshold, exemption, interpretation and rationale
Records applicability, subject, activity, threshold, exemption, interpretation and rationale as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish applicability, subject, activity, threshold, exemption, interpretation and rationale? decision
- Who owns, interprets, performs, reviews, approves, disputes or is affected by applicability, subject, activity, threshold, exemption, interpretation and rationale, with which authority, independence and limits? provenance
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to applicability, subject, activity, threshold, exemption, interpretation and rationale, and how is it corrected? interoperability
Risk, controls, objectives, ownership and traceability
Groups source-qualified compliance context for risk, controls, objectives, ownership and traceability.
Compliance risk, cause, event, consequence, likelihood, impact and tolerance reference
Records compliance risk, cause, event, consequence, likelihood, impact and tolerance reference as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish compliance risk, cause, event, consequence, likelihood, impact and tolerance reference? relationship
- Who owns, interprets, performs, reviews, approves, disputes or is affected by compliance risk, cause, event, consequence, likelihood, impact and tolerance reference, with which authority, independence and limits? process
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to compliance risk, cause, event, consequence, likelihood, impact and tolerance reference, and how is it corrected? decision
Control objective, definition, owner, type, frequency, mapping and coverage
Records control objective, definition, owner, type, frequency, mapping and coverage as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish control objective, definition, owner, type, frequency, mapping and coverage? composition
- Who owns, interprets, performs, reviews, approves, disputes or is affected by control objective, definition, owner, type, frequency, mapping and coverage, with which authority, independence and limits? validation
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to control objective, definition, owner, type, frequency, mapping and coverage, and how is it corrected? state
Implementation, evidence, monitoring and control assurance Groups governed compliance context for implementation, evidence, monitoring and control assurance.
Control implementation, design, operation and responsibility
Groups source-qualified compliance context for control implementation, design, operation and responsibility.
Implementation description, component, owner, operator, scope and dependency
Records implementation description, component, owner, operator, scope and dependency as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish implementation description, component, owner, operator, scope and dependency? definition
- Who owns, interprets, performs, reviews, approves, disputes or is affected by implementation description, component, owner, operator, scope and dependency, with which authority, independence and limits? privacy
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to implementation description, component, owner, operator, scope and dependency, and how is it corrected? identity
Design effectiveness, operating effectiveness, frequency, execution and failure
Records design effectiveness, operating effectiveness, frequency, execution and failure as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish design effectiveness, operating effectiveness, frequency, execution and failure? validation
- Who owns, interprets, performs, reviews, approves, disputes or is affected by design effectiveness, operating effectiveness, frequency, execution and failure, with which authority, independence and limits? lifecycle
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to design effectiveness, operating effectiveness, frequency, execution and failure, and how is it corrected? classification
Evidence collection, quality, freshness and continuous monitoring
Groups source-qualified compliance context for evidence collection, quality, freshness and continuous monitoring.
Evidence identity, source, method, coverage period, integrity, access and lineage
Records evidence identity, source, method, coverage period, integrity, access and lineage as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish evidence identity, source, method, coverage period, integrity, access and lineage? evidence
- Who owns, interprets, performs, reviews, approves, disputes or is affected by evidence identity, source, method, coverage period, integrity, access and lineage, with which authority, independence and limits? quality
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to evidence identity, source, method, coverage period, integrity, access and lineage, and how is it corrected? relationship
Monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap
Records monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap? measurement
- Who owns, interprets, performs, reviews, approves, disputes or is affected by monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap, with which authority, independence and limits? security
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap, and how is it corrected? authority
Assessment, findings, nonconformities, exceptions and waivers Groups governed compliance context for assessment, findings, nonconformities, exceptions and waivers.
Assessment, audit, test, scope, method, results and review
Groups source-qualified compliance context for assessment, audit, test, scope, method, results and review.
Assessment engagement, plan, criteria, procedure, sample, assessor and independence
Records assessment engagement, plan, criteria, procedure, sample, assessor and independence as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish assessment engagement, plan, criteria, procedure, sample, assessor and independence? process
- Who owns, interprets, performs, reviews, approves, disputes or is affected by assessment engagement, plan, criteria, procedure, sample, assessor and independence, with which authority, independence and limits? retention
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to assessment engagement, plan, criteria, procedure, sample, assessor and independence, and how is it corrected? requirement
Test result, observation, conclusion, confidence, limit and contradiction
Records test result, observation, conclusion, confidence, limit and contradiction as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish test result, observation, conclusion, confidence, limit and contradiction? quality
- Who owns, interprets, performs, reviews, approves, disputes or is affected by test result, observation, conclusion, confidence, limit and contradiction, with which authority, independence and limits? interoperability
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to test result, observation, conclusion, confidence, limit and contradiction, and how is it corrected? constraint
Finding disposition, root cause, exception and waiver
Groups source-qualified compliance context for finding disposition, root cause, exception and waiver.
Finding, nonconformity, severity, affected scope, source, status and dispute
Records finding, nonconformity, severity, affected scope, source, status and dispute as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish finding, nonconformity, severity, affected scope, source, status and dispute? state
- Who owns, interprets, performs, reviews, approves, disputes or is affected by finding, nonconformity, severity, affected scope, source, status and dispute, with which authority, independence and limits? decision
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to finding, nonconformity, severity, affected scope, source, status and dispute, and how is it corrected? event
Exception, waiver, authority, rationale, scope, compensating control, expiry and review
Records exception, waiver, authority, rationale, scope, compensating control, expiry and review as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish exception, waiver, authority, rationale, scope, compensating control, expiry and review? exception
- Who owns, interprets, performs, reviews, approves, disputes or is affected by exception, waiver, authority, rationale, scope, compensating control, expiry and review, with which authority, independence and limits? state
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to exception, waiver, authority, rationale, scope, compensating control, expiry and review, and how is it corrected? temporal
Remediation, verification, attestation, reporting and regulator interface Groups governed compliance context for remediation, verification, attestation, reporting and regulator interface.
Remediation planning, execution, verification and closure
Groups source-qualified compliance context for remediation planning, execution, verification and closure.
Remediation action, owner, priority, due date, resource, dependency and progress
Records remediation action, owner, priority, due date, resource, dependency and progress as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish remediation action, owner, priority, due date, resource, dependency and progress? lifecycle
- Who owns, interprets, performs, reviews, approves, disputes or is affected by remediation action, owner, priority, due date, resource, dependency and progress, with which authority, independence and limits? identity
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to remediation action, owner, priority, due date, resource, dependency and progress, and how is it corrected? composition
Acceptance criteria, independent verification, residual risk, reopen and closure
Records acceptance criteria, independent verification, residual risk, reopen and closure as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish acceptance criteria, independent verification, residual risk, reopen and closure? validation
- Who owns, interprets, performs, reviews, approves, disputes or is affected by acceptance criteria, independent verification, residual risk, reopen and closure, with which authority, independence and limits? classification
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to acceptance criteria, independent verification, residual risk, reopen and closure, and how is it corrected? evidence
Attestation, disclosure, reporting, submission and response
Groups source-qualified compliance context for attestation, disclosure, reporting, submission and response.
Compliance-status claim, scope, basis, qualifier, signer, authority and assurance
Records compliance-status claim, scope, basis, qualifier, signer, authority and assurance as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish compliance-status claim, scope, basis, qualifier, signer, authority and assurance? authority
- Who owns, interprets, performs, reviews, approves, disputes or is affected by compliance-status claim, scope, basis, qualifier, signer, authority and assurance, with which authority, independence and limits? relationship
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to compliance-status claim, scope, basis, qualifier, signer, authority and assurance, and how is it corrected? ownership
Report, notification, submission, recipient, deadline, receipt, acceptance and follow-up
Records report, notification, submission, recipient, deadline, receipt, acceptance and follow-up as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish report, notification, submission, recipient, deadline, receipt, acceptance and follow-up? event
- Who owns, interprets, performs, reviews, approves, disputes or is affected by report, notification, submission, recipient, deadline, receipt, acceptance and follow-up, with which authority, independence and limits? authority
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to report, notification, submission, recipient, deadline, receipt, acceptance and follow-up, and how is it corrected? measurement
Lifecycle, governance, correction, retention and interoperability Groups governed compliance context for lifecycle, governance, correction, retention and interoperability.
Programme cycle status, review, change, correction and supersession
Groups source-qualified compliance context for programme cycle status, review, change, correction and supersession.
Cycle status, review period, trigger, material change and continuous improvement
Records cycle status, review period, trigger, material change and continuous improvement as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish cycle status, review period, trigger, material change and continuous improvement? lifecycle
- Who owns, interprets, performs, reviews, approves, disputes or is affected by cycle status, review period, trigger, material change and continuous improvement, with which authority, independence and limits? requirement
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to cycle status, review period, trigger, material change and continuous improvement, and how is it corrected? exception
Correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage
Records correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage? provenance
- Who owns, interprets, performs, reviews, approves, disputes or is affected by correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage, with which authority, independence and limits? constraint
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage, and how is it corrected? provenance
Access, retention, assurance, projection and agent controls
Groups source-qualified compliance context for access, retention, assurance, projection and agent controls.
Purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition
Records purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition? privacy
- Who owns, interprets, performs, reviews, approves, disputes or is affected by purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition, with which authority, independence and limits? event
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition, and how is it corrected? process
OSCAL, BPMN, SACM, SARIF, ODRL and PROV projection, version, scope, loss and round trip
Records oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.
- Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip? interoperability
- Who owns, interprets, performs, reviews, approves, disputes or is affected by oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip, with which authority, independence and limits? temporal
- Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip, and how is it corrected? validation
Classifiers Filled
- Family
- World Models
- Category
- Activities and processes
- Entry kind
- aggregate
- Navigation path
- NAV.ACT.REG
- Domain
- ACT.REG
- Industry
- Cross-industry
- Tags
- regulatorycomplianceprocessact.reg
What it is Filled
Owns one compliance-cycle identity and bounded subject, jurisdiction, scope and period; source-revision watch; attributable applicability decisions; obligation-risk-control mappings; implementation, evidence and monitoring context; assessment result intake; finding, exception, remediation, verification, attestation and reporting links; and correction lineage. Law, regulation, obligation, policy, risk, control, organization, asset, audit, assessment, evidence, incident, task, attestation, regulator submission, provenance, access audit and record masters remain external.
In scope
- Programme identity, subject and scope, source versions and changes, applicability interpretations, obligation-risk-control traceability, implementation and monitoring assertions
- Assessment result intake, findings and exceptions, remediation and verification coordination, bounded status claims, attestations, reporting, correction, privacy, retention and loss-aware projections
Out of scope
- Creating or changing law, authoritative obligations, generic policies, risks, control definitions, organizations, assets, audit engagements, assessments, evidence items, incidents, work tasks, regulator submissions or records
- Treating compliance as a universal binary fact or equating action completion, finding closure, attestation, submission, certification, acceptance and continuing compliance
- Providing legal advice, certification, enforcement, exception approval, regulator filing or destructive evidence handling
Why it exists Filled
Represent a governed compliance cycle so agents can connect authoritative sources, bounded applicability, obligations, controls, evidence, findings and remediation without treating a process status, attestation or submission as timeless proof of compliance.
Distinguishing features Filled
- Tracks one bounded compliance cycle for a subject, jurisdiction and period, not compliance as a permanent state.
- Connects sources, applicability, obligations, controls and evidence, while the obligation, risk and control models keep their own records.
- Differs from an audit or assessment, which produces findings that this process takes in and acts upon.
- Differs from a certification, which is an external attestation and not a running process.
What robots and AI may and may not do Filled
Must not
- Issue a legal interpretation or a binding applicability decision.
- Certify or attest compliance.
- Approve exceptions or risk acceptances.
- File submissions with a regulator.
- Mark a finding closed without verification evidence.
Only with a human decision
- Deciding applicability of a regulation to the organization.
- Approving an exception, a risk acceptance or a remediation closure.
- Signing an attestation or a regulator submission.
May
- Watch authoritative regulatory sources and register changes for review.
- Draft applicability analyses and obligation-to-control mappings as proposals.
- Collect and index implementation and monitoring evidence.
- Track remediation actions and their due dates.
Moral aspects Filled
- Compliance failures can harm customers, workers or the public that the regulation protects, not only the organization.
- Evidence collection may involve monitoring of employees and must stay proportionate.
- Overstated compliance claims mislead regulators and the public.
Who is affected
- People the regulation protects
- Employees whose work is monitored as evidence
- Regulators and auditors relying on the record
Owners Filled
Steward
Dimension owner and compliance-governance mandate
Roles
- Compliance programme owner
- Own programme purpose, scope, resources, governance and accountable status claims.
- Legal or regulatory interpreter
- Own attributable applicability interpretation and uncertainty within professional authority.
- Control owner and operator
- Own control mapping, implementation and operating evidence within scope.
- Independent assessor or auditor
- Own assessment criteria, method, evidence use, result, limitations and independence declaration.
- Finding and remediation owner
- Own response, action coordination, due dates, escalation and closure evidence.
- Attestor or reporting officer
- Own bounded declarations, disclosures and submissions within signing authority.
- Interoperability steward
- Own versioned projections with jurisdiction, profile, maturity and loss declarations.
- Privacy, privilege, records and assurance steward
- Own protected views, privilege handling, disclosures, holds, retention and auditability.
Links to other meta-models Filled
references
- WM-XCT-029 Obligation / Commitment, law, regulation and policy models - Resolve authoritative requirements and obligations while keeping applicability interpretation attributable and local to the cycle.
- WM-KNW-015 Risk / Opportunity and WM-XCT-027 Risk / Control - Bind versioned risk and control masters to compliance-specific coverage, implementation and gap assertions.
- WM-ACT-033 Review / Inspection / Audit, WM-ACT-034 Assessment / Evaluation and WM-ECO-035 Audit / Assurance Engagement - Bind assessment and assurance work without owning its execution, independence or evidence-gathering lifecycle.
- Evidence, incident, task, work-order, attestation, regulator-submission, provenance, access-audit and record models - Resolve evidence, remediation execution, declarations, external interactions and records without copying their lifecycles.
aligned
- OSCAL 1.2.3, BPMN 2.0.2, SACM 2.3, SARIF 2.1.0, ODRL 2.2 and PROV-O - Project version-pinned control, process, assurance, tool-result, policy and provenance views with scope and information-loss declarations.
neighbor
- Law, regulation and WM-XCT-029 Obligation / Commitment - Authoritative sources and obligations remain external. The aggregate stores versioned references and attributable applicability and mapping decisions without rewriting authoritative text.
- WM-KNW-015 Risk / Opportunity and WM-XCT-027 Risk / Control - Risk and control masters own their definitions and lifecycles. The aggregate owns compliance-specific mappings, implementation assertions, coverage and gaps.
- WM-ACT-033 Review / Inspection / Audit, WM-ACT-034 Assessment / Evaluation and WM-ECO-035 Audit / Assurance Engagement - Specialist models own engagement, method, evidence gathering, testing, results and assurance. This aggregate records commissioning, result intake, response and closure context.
- Evidence, incident, task and work-order models - External masters own evidence content, incidents and remediation work. The aggregate keeps integrity-qualified references, compliance disposition, acceptance criteria and verification status.
- Attestation, certification, submission and regulator response - A status claim, signed declaration, independent certification, filing receipt and regulator decision each retain independent authority and state. None proves continuing compliance by itself.
- BPMN, OSCAL, SACM, SARIF, ODRL and PROV - These are versioned process, control-assessment, assurance, tool-result, policy and provenance projections with different scopes. No mapping is assumed lossless or universally applicable.
parent
- WM-ACT-003
What else AI and robots need to interact with it Filled
Identity and identifiers required Filled
- Authoritative master-system identifier for each compliance programme, applicability decision, mapping, evidence item, finding, exception, remediation, attestation or submission, qualified by owning organization and record kind.
- Governed globally resolvable compliance-record IRI.
- Dimension UUID when neither preceding identifier exists.
Direct properties not applicable Not applicable
Not applicable
Institutional or informational subject: no invented physical properties.
Recognition optional Filled
- A compliance cycle names a subject, a regulatory source, a jurisdiction, a period and a set of obligations with controls and evidence.
- Often confused with an audit engagement, a policy document, a risk register or a certificate.
Capabilities and actions required Filled
- Register compliance cycle: Governed operation to register compliance cycle without hidden legal interpretation, enforcement or mutation of external masters.
- Register regulatory source change: Governed operation to register regulatory source change without hidden legal interpretation, enforcement or mutation of external masters.
- Assess applicability: Governed operation to assess applicability without hidden legal interpretation, enforcement or mutation of external masters.
- Map obligations, risks and controls: Governed operation to map obligations, risks and controls without hidden legal interpretation, enforcement or mutation of external masters.
- Record implementation and monitoring evidence: Governed operation to record implementation and monitoring evidence without hidden legal interpretation, enforcement or mutation of external masters.
- Commission or link assessment: Governed operation to commission or link assessment without hidden legal interpretation, enforcement or mutation of external masters.
- Record finding or exception: Governed operation to record finding or exception without hidden legal interpretation, enforcement or mutation of external masters.
- Plan, track and verify remediation: Governed operation to plan, track and verify remediation without hidden legal interpretation, enforcement or mutation of external masters.
- Attest, report, submit and record response: Governed operation to attest, report, submit and record response without hidden legal interpretation, enforcement or mutation of external masters.
- Correct, project, retain, disclose and audit: Governed operation to correct, project, retain, disclose and audit without hidden legal interpretation, enforcement or mutation of external masters.
Hazards and failure modes required Filled
- Missed regulatory change leaving obligations unmapped.
- Stale evidence presented as current compliance.
- Paper compliance where controls exist on record but do not operate.
Standards and interfaces required Filled
- NIST OSCAL for control catalogues, assessment plans and results.
- ISO 37301 compliance management systems.
- ISO 31000 risk management guidelines.
- OMG BPMN 2.0 (ISO/IEC 19510) for process models.
- OASIS SARIF for static analysis findings.
- W3C PROV-O for evidence provenance.
Context of use required Filled
- Legal effect, applicability, professional privilege, regulator authority, reporting, certification, retention and disclosure depend on jurisdiction, sector and facts.
- DOJ and USSC are United States profiles, GDPR is European Union law and OECD or UNODC guidance is not itself binding law.
- Local control libraries, regulatory taxonomies, severity scales, assurance levels, evidence rules and exception authorities require versioned profiles.
Sources Filled
- Compliance management systems - Requirements with guidance for use - International Organization for Standardization
- Risk management - Guidelines - International Organization for Standardization
- Guidelines for auditing management systems - International Organization for Standardization
- Security and Privacy Controls for Information Systems and Organizations - National Institute of Standards and Technology
- Assessing Security and Privacy Controls in Information Systems and Organizations - National Institute of Standards and Technology
- Open Security Controls Assessment Language - National Institute of Standards and Technology
- Evaluation of Corporate Compliance Programs - United States Department of Justice
- Annotated 2025 Chapter 8, section 8B2.1 Effective Compliance and Ethics Program - United States Sentencing Commission
- Recommendation of the Council on Public Integrity - Organisation for Economic Co-operation and Development
- An Anti-Corruption Ethics and Compliance Programme for Business: A Practical Guide - United Nations Office on Drugs and Crime
- Business Process Model and Notation - Object Management Group
- Structured Assurance Case Metamodel - Object Management Group
- Static Analysis Results Interchange Format - OASIS Open
- ODRL Information Model 2.2 - World Wide Web Consortium
- PROV-O: The PROV Ontology - World Wide Web Consortium
- Regulation (EU) 2016/679 General Data Protection Regulation - European Union
- Date and Time on the Internet: Timestamps - Internet Engineering Task Force
Open questions
- Approve or reject registry relations to obligation, risk/control, audit, assessment, assurance, evidence, incident, task, attestation, submission and record models.
- Create jurisdiction and sector profiles for financial services, healthcare, product safety, environment, labor, tax, privacy, anti-corruption, competition, export control and AI regimes.
- Perform licensed clause-level review of ISO 37301, ISO 31000 and ISO 19011 before any conformance claim.
- Test release-pinned OSCAL, BPMN, SACM, SARIF, ODRL and PROV mappings with round-trip and information-loss evidence.
- Obtain supplemental independent external review and resolve any material challenge before canonical promotion.
- Claude and Grok each timed out on one bounded attempt; no independent external result was admitted.
- No relation-ledger edge is registered for WM-ACT-051, so links to obligation, risk/control, audit, assessment, assurance, incident, task, attestation and record models remain candidate boundary notes.
- Financial services, healthcare, product safety, environment, labor, tax, privacy, anti-corruption, competition, export control, AI and other regimes require jurisdiction and sector profiles.
- ISO normative clauses are access-restricted; NIST, DOJ, USSC, OECD, UNODC, GDPR, OSCAL and SARIF each have sectoral, jurisdictional or technical scope and require release-pinned validation.
Machine files
Provenance
world-models research · reviewable-draft
Built from: models/wm-act-051-regulatory-compliance-process/spec.yaml, ver-cy/world-models/card-supplements/wm-act-051-regulatory-compliance-process.json