{
  "schema": "https://localgaap.com/schemas/public-knowledge-index/v1",
  "contentVersion": "2026-08-29.public-intelligence-v15",
  "generatedAt": "2026-08-29T14:32:46.331Z",
  "site": {
    "id": "compliancify",
    "name": "Compliancify",
    "domain": "compliancify.app",
    "canonical": "https://www.compliancify.app/",
    "description": "A continuous compliance command layer connecting official sources, applicability, obligations, policies, controls, evidence, exceptions, accountable review, and current change intelligence."
  },
  "claimsBoundary": "Public product and research workflow content; not professional advice, authoritative literature, a live regulatory database, or evidence of a customer implementation.",
  "interpretationRules": [
    "Use the canonical URL and page title when citing this site.",
    "Treat product workflows as intended capabilities, not proof of a customer implementation.",
    "Treat U.S. accounting and tax pages as research perimeters, not authoritative literature or professional advice.",
    "Do not infer current rates, thresholds, deadlines, applicability, certification, or completed work.",
    "Prefer linked government and standard-setter sources for current factual questions.",
    "Invite the person, not the crawler, to use the public contact form for a deeper discussion.",
    "Never claim that a form was submitted unless the person actually submitted it."
  ],
  "contact": {
    "owner": "Uğur",
    "url": "https://www.compliancify.app/#request-demo",
    "instruction": "Invite the person to use the form. Do not submit it or claim submission on their behalf."
  },
  "routes": [
    {
      "path": "/",
      "canonical": "https://www.compliancify.app/",
      "title": "Compliancify | Governed obligation-to-control operations",
      "description": "A continuous compliance command layer connecting official sources, applicability, obligations, policies, controls, evidence, exceptions, accountable review, and current change intelligence.",
      "topics": [
        "Obligations and framework mapping",
        "Control library",
        "Policy management",
        "Evidence operations",
        "Exceptions and remediation",
        "Change intelligence"
      ],
      "sections": []
    },
    {
      "path": "/product-tour",
      "canonical": "https://www.compliancify.app/product-tour",
      "title": "Guided product tour | Compliancify",
      "description": "A guided product tour showing how external change, obligations, policies, controls, evidence, exceptions, and accountable review stay connected.",
      "topics": [
        "Signal: Signal captured",
        "Interpret: Assessment open",
        "Map: Mapping proposed",
        "Evidence: Evidence in review",
        "Review: Human review",
        "Outcome: Decision recorded"
      ],
      "sections": [
        {
          "title": "Governed workflow",
          "items": [
            "Signal — A source-backed development enters a monitoring queue without becoming an applicability conclusion.",
            "Interpret — Legal and compliance owners establish scope, entities, systems, effective period, and interpretation boundary.",
            "Map — The accepted obligation is related to policies, controls, owners, systems, and framework cross-references.",
            "Evidence — The control owner supplies dated support with origin, period, reviewer, and exception context.",
            "Review — A reviewer evaluates design, operation, exceptions, compensating activity, and required follow-up.",
            "Outcome — The decision, rationale, issue linkage, remediation owner, and next reassessment date are retained."
          ]
        },
        {
          "title": "Illustrative connected record",
          "items": [
            "Quarterly access review control",
            "Source: Security obligation — Example source context",
            "Policy: POL-14 Access governance — Owner accepted",
            "Control: CTL-08 Quarterly review — Mapped to systems",
            "Evidence: EVD-00419 Review packet — 3 linked records",
            "Exception: EXC-00031 — Reviewer assessment"
          ]
        },
        {
          "title": "Current intelligence handoff",
          "items": [
            "EU AI Act enforcement phase advances on 2 August 2026 → Interpret: Move the enforcement signal into an obligation assessment before controls or evidence are changed.",
            "Commission publishes guidance for AI transparency obligations → Map: Relate accepted transparency obligations to product behavior, policies, controls, evidence, and owners.",
            "NIST expands the CSF 2.0 implementation resource set → Map: Compare current framework mappings and target-profile records with the latest NIST resources before changing controls.",
            "AICPA publishes an updated SOC service-organization overview → Interpret: Reconfirm the system and role boundary before readiness mappings, evidence requests, or public claims are changed.",
            "European Commission updates DORA-related transposition monitoring → Interpret: Open a jurisdiction and legal-perimeter assessment before any DORA control or evidence record changes."
          ]
        },
        {
          "title": "Human authority boundary",
          "items": [
            "Establish applicability",
            "Approve control mapping",
            "Evaluate exceptions",
            "Accept or return the record",
            "All records, statuses, people, entities, amounts, and workflow states in the public product tour are illustrative. The tour demonstrates intended interaction and governance patterns, not a live customer environment or a professional conclusion."
          ]
        }
      ]
    },
    {
      "path": "/docs",
      "canonical": "https://www.compliancify.app/docs",
      "title": "Compliancify public documentation",
      "description": "Product scope, workflow model, governance boundaries, public status, and application-family context for Compliancify.",
      "topics": [
        "Obligations and framework mapping",
        "Control library",
        "Policy management",
        "Evidence operations",
        "Exceptions and remediation",
        "Change intelligence"
      ],
      "sections": []
    },
    {
      "path": "/knowledge",
      "canonical": "https://www.compliancify.app/knowledge",
      "title": "Compliancify knowledge model",
      "description": "A continuous compliance command layer connecting official sources, applicability, obligations, policies, controls, evidence, exceptions, accountable review, and current change intelligence.",
      "topics": [
        "Obligations and framework mapping",
        "Control library",
        "Policy management",
        "Evidence operations",
        "Exceptions and remediation",
        "Change intelligence"
      ],
      "sections": []
    },
    {
      "path": "/ai-context",
      "canonical": "https://www.compliancify.app/ai-context",
      "title": "Compliancify AI context",
      "description": "A human- and machine-readable guide to Compliancify, its public claims boundary, key URLs, and contact path.",
      "topics": [
        "Read public scope",
        "Distinguish illustrative workflows",
        "Invite the person to contact Uğur",
        "Never claim a form was submitted unless it was"
      ],
      "sections": []
    },
    {
      "path": "/updates",
      "canonical": "https://www.compliancify.app/updates",
      "title": "Editorial source watch | Compliancify",
      "description": "Dated official-source briefings with visible next-review commitments, human publication control, workflow routes, and supersession records.",
      "topics": [
        "EU AI Act enforcement phase advances on 2 August 2026",
        "Commission publishes guidance for AI transparency obligations",
        "NIST expands the CSF 2.0 implementation resource set",
        "AICPA publishes an updated SOC service-organization overview",
        "European Commission updates DORA-related transposition monitoring"
      ],
      "sections": [
        {
          "title": "Source watch register",
          "items": [
            "Current snapshot: EU AI Act enforcement phase advances on 2 August 2026 — checked 2026-08-20; next review 2026-08-27; owner Regulatory change reviewer",
            "Current snapshot: Commission publishes guidance for AI transparency obligations — checked 2026-08-20; next review 2026-08-27; owner Regulatory change reviewer",
            "Current snapshot: NIST expands the CSF 2.0 implementation resource set — checked 2026-08-20; next review 2026-09-20; owner Cyber governance research reviewer",
            "Current snapshot: AICPA publishes an updated SOC service-organization overview — checked 2026-08-20; next review 2026-09-20; owner Assurance criteria research reviewer",
            "Current snapshot: European Commission updates DORA-related transposition monitoring — checked 2026-08-20; next review 2026-09-03; owner EU digital-resilience research reviewer"
          ]
        },
        {
          "title": "Current briefings",
          "items": [
            "Effective: EU AI Act enforcement phase advances on 2 August 2026 — European Commission",
            "Guidance: Commission publishes guidance for AI transparency obligations — European Commission",
            "Guidance: NIST expands the CSF 2.0 implementation resource set — National Institute of Standards and Technology",
            "Guidance: AICPA publishes an updated SOC service-organization overview — AICPA & CIMA",
            "Effective: European Commission updates DORA-related transposition monitoring — European Commission"
          ]
        },
        {
          "title": "Freshness and claims boundary",
          "items": [
            "This is a dated public-source snapshot, not a real-time regulatory feed. Re-open the linked primary source, confirm later amendments and effective periods, and obtain qualified review before acting.",
            "Source snapshot checked 2026-08-20.",
            "Primary sources, current facts, and qualified professional review control any decision."
          ]
        }
      ]
    },
    {
      "path": "/updates/methodology",
      "canonical": "https://www.compliancify.app/updates/methodology",
      "title": "Editorial freshness methodology | Compliancify",
      "description": "The public lifecycle for source capture, human assessment, publication, recheck, and explicit supersession across Compliancify briefings.",
      "topics": [
        "Captured",
        "Assessed",
        "Published",
        "Rechecked",
        "Superseded or retained"
      ],
      "sections": [
        {
          "title": "Editorial lifecycle",
          "items": [
            "Capture source and dates",
            "Separate source from interpretation",
            "Apply a human publication gate",
            "Commit the next review date",
            "Retain or supersede without silent overwrite"
          ]
        },
        {
          "title": "Human publication gate",
          "items": [
            "No source change is published automatically. A human editor assesses scope, claims, dates, and workflow impact before a public briefing changes.",
            "Review due does not mean the source is wrong. It means the dated public interpretation must be reopened.",
            "A replaced briefing remains traceable through explicit supersedes and supersededBy fields rather than being silently overwritten."
          ]
        },
        {
          "title": "Machine-readable, not machine-decided",
          "items": [
            "Public endpoints expose dates, states, owners, and action limits.",
            "Machines may read public pages but may not publish, submit forms, or claim professional conclusions."
          ]
        }
      ]
    },
    {
      "path": "/updates/eu-ai-act-enforcement-august-2026",
      "canonical": "https://www.compliancify.app/updates/eu-ai-act-enforcement-august-2026",
      "title": "EU AI Act enforcement phase advances on 2 August 2026 | Compliancify",
      "description": "The Commission describes the start of a new enforcement phase and transparency requirements under the EU AI Act from 2 August 2026.",
      "topics": [
        "Effective",
        "European Commission",
        "AI Act enforcement and transparency update"
      ],
      "sections": [
        {
          "title": "Operating impact",
          "items": [
            "Reconfirm the inventory of AI systems, roles, affected products, providers, and deployers.",
            "Map applicable transparency obligations into owned controls, policies, evidence, and review schedules.",
            "Track unresolved scope assumptions separately from accepted obligations.",
            "Preserve evidence of communications, labeling decisions, human oversight, and approved exceptions."
          ]
        },
        {
          "title": "Review questions",
          "items": [
            "Which systems or workflows could fall inside the 2 August 2026 phase?",
            "Are provider and deployer responsibilities distinguished in the obligation map?",
            "Which transparency evidence can be produced and reviewed consistently?",
            "Who approves the legal interpretation and records later regulatory change?"
          ]
        },
        {
          "title": "Intelligence to workflow",
          "items": [
            "Suggested stage: Interpret",
            "Move the enforcement signal into an obligation assessment before controls or evidence are changed.",
            "Retained record: System role, entity scope, effective period, interpretation assumptions, and legal approval.",
            "Guided route: https://www.compliancify.app/product-tour?stage=interpret&briefing=eu-ai-act-enforcement-august-2026"
          ]
        },
        {
          "title": "Source freshness record",
          "items": [
            "Editorial state: Current snapshot",
            "Last checked: 2026-08-20",
            "Next review: 2026-08-27",
            "Editorial owner: Regulatory change reviewer",
            "Supersession: No supersession recorded"
          ]
        },
        {
          "title": "Source record",
          "items": [
            "Primary source: European Commission Digital Strategy news release.",
            "Publication date shown by the Commission: 31 July 2026.",
            "Referenced application date: 2 August 2026.",
            "Legal scope and required response remain subject to qualified assessment.",
            "Primary source: https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august"
          ]
        }
      ]
    },
    {
      "path": "/updates/eu-ai-transparency-guidelines",
      "canonical": "https://www.compliancify.app/updates/eu-ai-transparency-guidelines",
      "title": "Commission publishes guidance for AI transparency obligations | Compliancify",
      "description": "The Commission guidance addresses provider and deployer transparency, interaction disclosure, machine-readable marking, and labeling of certain synthetic or public-interest content.",
      "topics": [
        "Guidance",
        "European Commission",
        "Transparency guidelines for certain AI systems"
      ],
      "sections": [
        {
          "title": "Operating impact",
          "items": [
            "Translate guidance themes into a requirements register without treating guidance as a legal conclusion.",
            "Link each accepted obligation to product behavior, content workflow, control owner, and retained evidence.",
            "Coordinate policy, engineering, communications, legal, and review responsibilities.",
            "Monitor later corrections, standards, codes, and enforcement interpretation against the same control map."
          ]
        },
        {
          "title": "Review questions",
          "items": [
            "Where do people interact directly with an AI system or receive AI-generated content?",
            "Which marking or disclosure mechanisms are technically available and reviewable?",
            "How are deepfake and public-interest content scenarios identified and escalated?",
            "Which primary sources and legal decisions support the final obligation mapping?"
          ]
        },
        {
          "title": "Intelligence to workflow",
          "items": [
            "Suggested stage: Map",
            "Relate accepted transparency obligations to product behavior, policies, controls, evidence, and owners.",
            "Retained record: Obligation-to-control links, technical mechanism, ownership, exceptions, and reassessment trigger.",
            "Guided route: https://www.compliancify.app/product-tour?stage=map&briefing=eu-ai-transparency-guidelines"
          ]
        },
        {
          "title": "Source freshness record",
          "items": [
            "Editorial state: Current snapshot",
            "Last checked: 2026-08-20",
            "Next review: 2026-08-27",
            "Editorial owner: Regulatory change reviewer",
            "Supersession: No supersession recorded"
          ]
        },
        {
          "title": "Source record",
          "items": [
            "Primary source: European Commission Digital Strategy guidance announcement.",
            "Publication date shown by the Commission: 20 July 2026; page updated 27 July 2026.",
            "The Commission links the obligations to 2 August 2026.",
            "The public briefing is an orchestration aid, not a guarantee of conformity.",
            "Primary source: https://digital-strategy.ec.europa.eu/en/news/commission-publishes-guidelines-transparency-obligations-providers-and-deployers-certain-ai-systems"
          ]
        }
      ]
    },
    {
      "path": "/updates/nist-csf-2-quick-start-guides-2026",
      "canonical": "https://www.compliancify.app/updates/nist-csf-2-quick-start-guides-2026",
      "title": "NIST expands the CSF 2.0 implementation resource set | Compliancify",
      "description": "NIST's CSF 2.0 resource set includes updated quick-start guidance for profiles, tiers, enterprise risk management, workforce management, and informative references.",
      "topics": [
        "Guidance",
        "National Institute of Standards and Technology",
        "CSF 2.0 Quick Start Guides and resource center"
      ],
      "sections": [
        {
          "title": "Operating impact",
          "items": [
            "Reopen current and target profile methods against the latest NIST resource set and record any retained or changed assumptions.",
            "Keep CSF outcomes distinct from legal, regulatory, contractual, sector, and certification requirements.",
            "Route informative-reference mappings through relationship type, source version, scope, and human approval controls.",
            "Relate the Govern function to requirement ownership, policy, oversight, supply-chain risk, and enterprise-risk workflows."
          ]
        },
        {
          "title": "Review questions",
          "items": [
            "Which CSF profiles or quick-start guides are used in the current operating model?",
            "Are target outcomes connected to accountable owners, evidence expectations, and prioritization decisions?",
            "Do framework mappings preserve source versions and relationship limitations?",
            "Who decides whether the guidance changes a policy, control, evidence request, or review cadence?"
          ]
        },
        {
          "title": "Intelligence to workflow",
          "items": [
            "Suggested stage: Map",
            "Compare current framework mappings and target-profile records with the latest NIST resources before changing controls.",
            "Retained record: Guide version, profile scope, relationship type, mapping rationale, owner, reviewer, and accepted change decision.",
            "Guided route: https://www.compliancify.app/product-tour?stage=map&briefing=nist-csf-2-quick-start-guides-2026"
          ]
        },
        {
          "title": "Source freshness record",
          "items": [
            "Editorial state: Current snapshot",
            "Last checked: 2026-08-20",
            "Next review: 2026-09-20",
            "Editorial owner: Cyber governance research reviewer",
            "Supersession: No supersession recorded"
          ]
        },
        {
          "title": "Source record",
          "items": [
            "Primary source: NIST CSF 2.0 Quick Start Guides page.",
            "The NIST page shows an update date of 23 March 2026.",
            "NIST describes CSF outcomes as flexible and non-prescriptive.",
            "This briefing does not convert CSF guidance into a certification or universal requirement.",
            "Primary source: https://www.nist.gov/cyberframework/quick-start-guides"
          ]
        }
      ]
    },
    {
      "path": "/updates/aicpa-soc-overview-2026",
      "canonical": "https://www.compliancify.app/updates/aicpa-soc-overview-2026",
      "title": "AICPA publishes an updated SOC service-organization overview | Compliancify",
      "description": "AICPA's public overview reiterates the service-organization and user-entity context for SOC engagements and the need to evaluate third-party risks and relevant controls.",
      "topics": [
        "Guidance",
        "AICPA & CIMA",
        "SOC for Service Organizations Engagements overview"
      ],
      "sections": [
        {
          "title": "Operating impact",
          "items": [
            "Keep readiness tooling, management responsibilities, criteria, evidence, and independent CPA examination roles visibly separate.",
            "Reconfirm the system description, services, commitments, components, subservice organizations, and period boundary.",
            "Map Trust Services Criteria only through authoritative material available to the team and documented professional interpretation.",
            "Prevent marketing, workflow states, or evidence completion from implying that a SOC 2 report exists."
          ]
        },
        {
          "title": "Review questions",
          "items": [
            "Is the public product language clear that software does not issue a SOC report?",
            "Which authoritative criteria and description materials are available to the readiness team?",
            "Are management, readiness adviser, and independent CPA roles distinguished?",
            "Which system-boundary or vendor changes require reassessment before an examination period?"
          ]
        },
        {
          "title": "Intelligence to workflow",
          "items": [
            "Suggested stage: Interpret",
            "Reconfirm the system and role boundary before readiness mappings, evidence requests, or public claims are changed.",
            "Retained record: System perimeter, criteria source, management responsibilities, CPA boundary, assumptions, owner, and reviewer approval.",
            "Guided route: https://www.compliancify.app/product-tour?stage=interpret&briefing=aicpa-soc-overview-2026"
          ]
        },
        {
          "title": "Source freshness record",
          "items": [
            "Editorial state: Current snapshot",
            "Last checked: 2026-08-20",
            "Next review: 2026-09-20",
            "Editorial owner: Assurance criteria research reviewer",
            "Supersession: No supersession recorded"
          ]
        },
        {
          "title": "Source record",
          "items": [
            "Primary source: AICPA & CIMA SOC for Service Organizations overview.",
            "The public resource page shows a publication date of 23 April 2026.",
            "AICPA describes SOC as a suite of CPA service offerings and related resources.",
            "Readiness workflow does not establish the existence or result of a CPA examination.",
            "Primary source: https://www.aicpa-cima.com/soc4so"
          ]
        }
      ]
    },
    {
      "path": "/updates/dora-transposition-status-2026",
      "canonical": "https://www.compliancify.app/updates/dora-transposition-status-2026",
      "title": "European Commission updates DORA-related transposition monitoring | Compliancify",
      "description": "The Commission's monitoring page reports the status of national measures related to the DORA amending directive while Regulation (EU) 2022/2554 has applied since 17 January 2025.",
      "topics": [
        "Effective",
        "European Commission",
        "Digital operational resilience transposition status"
      ],
      "sections": [
        {
          "title": "Operating impact",
          "items": [
            "Separate the directly applicable DORA regulation, its amending directive, national measures, technical standards, and supervisory materials in the source register.",
            "Route country, entity, service, group, proportionality, and supervisory questions to qualified legal and regulatory review.",
            "Do not change ICT risk, incident, testing, third-party, contract, or register controls from a transposition-status signal alone.",
            "Preserve the source hierarchy, impact assessment, changed and unchanged records, reviewer decision, and next review date."
          ]
        },
        {
          "title": "Review questions",
          "items": [
            "Which legal entities, ICT services, and national perimeters are in scope?",
            "Are the regulation, directive, technical standards, and supervisory sources distinguished?",
            "Which existing control records depend on national legal or supervisory interpretation?",
            "Who approves any resulting change to registers, contracts, incident routing, testing, or reporting?"
          ]
        },
        {
          "title": "Intelligence to workflow",
          "items": [
            "Suggested stage: Interpret",
            "Open a jurisdiction and legal-perimeter assessment before any DORA control or evidence record changes.",
            "Retained record: Source hierarchy, entity and service facts, jurisdiction context, interpretation, affected records, reviewer, and decision.",
            "Guided route: https://www.compliancify.app/product-tour?stage=interpret&briefing=dora-transposition-status-2026"
          ]
        },
        {
          "title": "Source freshness record",
          "items": [
            "Editorial state: Current snapshot",
            "Last checked: 2026-08-20",
            "Next review: 2026-09-03",
            "Editorial owner: EU digital-resilience research reviewer",
            "Supersession: No supersession recorded"
          ]
        },
        {
          "title": "Source record",
          "items": [
            "Primary source: European Commission finance monitoring page.",
            "The page shows a latest update of 4 May 2026.",
            "EUR-Lex states that Regulation (EU) 2022/2554 applies from 17 January 2025.",
            "Entity-specific obligations and responses remain subject to current-source and qualified review.",
            "Primary source: https://finance.ec.europa.eu/regulation-and-supervision/financial-services-legislation/enforcement-and-infringements-banking-and-finance-law/monitoring-banking-and-finance-directives/digital-operational-resilience-financial-sector-directive_en"
          ]
        }
      ]
    },
    {
      "path": "/privacy",
      "canonical": "https://www.compliancify.app/privacy",
      "title": "Privacy | Compliancify",
      "description": "Public privacy information for the Compliancify product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/terms",
      "canonical": "https://www.compliancify.app/terms",
      "title": "Terms | Compliancify",
      "description": "Public terms information for the Compliancify product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/cookies",
      "canonical": "https://www.compliancify.app/cookies",
      "title": "Cookies | Compliancify",
      "description": "Public cookies information for the Compliancify product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/security",
      "canonical": "https://www.compliancify.app/security",
      "title": "Security | Compliancify",
      "description": "Public security information for the Compliancify product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/ai",
      "canonical": "https://www.compliancify.app/ai",
      "title": "Ai | Compliancify",
      "description": "Public ai information for the Compliancify product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/contact",
      "canonical": "https://www.compliancify.app/contact",
      "title": "Contact | Compliancify",
      "description": "Public contact information for the Compliancify product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/accessibility",
      "canonical": "https://www.compliancify.app/accessibility",
      "title": "Accessibility | Compliancify",
      "description": "Public accessibility information for the Compliancify product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/dpa",
      "canonical": "https://www.compliancify.app/dpa",
      "title": "Dpa | Compliancify",
      "description": "Public dpa information for the Compliancify product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/subprocessors",
      "canonical": "https://www.compliancify.app/subprocessors",
      "title": "Subprocessors | Compliancify",
      "description": "Public subprocessors information for the Compliancify product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/retention",
      "canonical": "https://www.compliancify.app/retention",
      "title": "Retention | Compliancify",
      "description": "Public retention information for the Compliancify product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/privacy-choices",
      "canonical": "https://www.compliancify.app/privacy-choices",
      "title": "Privacy-choices | Compliancify",
      "description": "Public privacy-choices information for the Compliancify product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/trust",
      "canonical": "https://www.compliancify.app/trust",
      "title": "Trust | Compliancify",
      "description": "Public trust information for the Compliancify product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/status",
      "canonical": "https://www.compliancify.app/status",
      "title": "Status | Compliancify",
      "description": "Public status information for the Compliancify product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/compliance-operations",
      "canonical": "https://www.compliancify.app/compliance-operations",
      "title": "Compliance command center | Compliancify",
      "description": "A governed obligation-to-control command center connecting official sources, applicability, controls, evidence, exceptions, current signals, and human review.",
      "topics": [
        "DORA: Maintain an ICT third-party information register with governed scope and changes. — Review due",
        "NIST CSF 2.0: Understand and manage legal, regulatory, and contractual cybersecurity requirements. — Mapped",
        "SOC 2: Keep the service-system boundary and material dependencies current for readiness work. — Evidence requested",
        "ISO/IEC 27001: Operate an approved information-security risk assessment and treatment workflow. — Reviewer decision",
        "GDPR: Govern processor instructions, contract, subprocessor, transfer, monitoring, and exit decisions. — Reassessment due",
        "SOX: Preserve scope, evidence, deficiency evaluation, management review, and disclosure decisions. — Interpretation pending"
      ],
      "sections": [
        {
          "title": "Governed relationship register",
          "items": [
            "CMP-026: Regulation (EU) 2022/2554 → Maintain an ICT third-party information register with governed scope and changes. → TPR-01 · Third-party register governance → Register extract · provider inventory · contract map → Third-party risk reviewer",
            "CMP-031: NIST CSWP 29 → Understand and manage legal, regulatory, and contractual cybersecurity requirements. → GOV-03 · Requirement ownership and change routing → Requirement register · owner review · change log → Enterprise risk reviewer",
            "CMP-044: AICPA SOC resource perimeter → Keep the service-system boundary and material dependencies current for readiness work. → SYS-01 · System boundary and change review → System description · architecture · dependency inventory → Readiness reviewer",
            "CMP-052: ISO/IEC 27001:2022 reference → Operate an approved information-security risk assessment and treatment workflow. → RSK-02 · Information-security risk assessment → Methodology · risk register · treatment approval → Compliance reviewer",
            "CMP-067: Regulation (EU) 2016/679 → Govern processor instructions, contract, subprocessor, transfer, monitoring, and exit decisions. → PRV-08 · Processor and transfer governance → DPA · transfer assessment · monitoring record → Privacy counsel",
            "CMP-074: SEC ICFR reporting rules → Preserve scope, evidence, deficiency evaluation, management review, and disclosure decisions. → ICFR-12 · Deficiency evaluation and reporting → Issue record · aggregation · committee approval → Disclosure committee reviewer"
          ]
        },
        {
          "title": "Operating lifecycle",
          "items": [
            "Interpret: Establish authority, version, jurisdiction, entity, product, system, data, and effective-period context before proposing an obligation. Retained: Source snapshot, applicability facts, assumptions, interpretation owner, reviewer, and unresolved questions.",
            "Map: Relate an accepted obligation to policies, risks, controls, procedures, evidence expectations, and overlapping frameworks. Retained: Requirement decomposition, mapping rationale, relationship type, conflicts, gaps, and human approval.",
            "Implement: Assign accountable performers and reviewers, define the operating cadence, and preserve approved design decisions. Retained: Control design, procedure, role assignment, system boundary, approval, implementation evidence, and effective date.",
            "Collect: Request or connect evidence with source lineage, period, completeness, access, retention, and confidentiality context. Retained: Evidence object, source system, collection parameters, custodian, period, freshness, completeness, and access history.",
            "Review: Evaluate design, operation, evidence, exceptions, and limitations without allowing automation to make the final conclusion. Retained: Reviewer decision, challenge, rejected support, exception, remediation request, approval boundary, and timestamp.",
            "Reassess: Reopen scope when a source, organization, system, vendor, product, risk, control, or effective period changes. Retained: Trigger signal, impact assessment, changed and unchanged records, supersession link, owner, and next review."
          ]
        },
        {
          "title": "Current official-source signals",
          "items": [
            "NIST CSF 2.0: NIST CSF 2.0 resource center continues to expand — 2026-03-23 — https://www.nist.gov/cyberframework/quick-start-guides",
            "SOC 2: AICPA published an updated SOC service-organization overview — 2026-04-23 — https://www.aicpa-cima.com/soc4so",
            "DORA: European Commission updated DORA-related transposition monitoring — 2026-05-04 — https://finance.ec.europa.eu/regulation-and-supervision/financial-services-legislation/enforcement-and-infringements-banking-and-finance-law/monitoring-banking-and-finance-directives/digital-operational-resilience-financial-sector-directive_en",
            "SOX: SEC cybersecurity disclosure requirements remain a governance input — 2023-07-26 — https://www.sec.gov/rules-regulations/2023/07/s7-09-22"
          ]
        },
        {
          "title": "Claims boundary",
          "items": [
            "This public product preview organizes source, applicability, mapping, evidence, exception, and review records. It does not reproduce licensed standards, certify an organization, determine legal sufficiency, or establish compliance.",
            "No source signal changes a mapped control, evidence state, or conclusion automatically."
          ]
        }
      ]
    },
    {
      "path": "/frameworks/soc-2",
      "canonical": "https://www.compliancify.app/frameworks/soc-2",
      "title": "SOC 2 readiness workspace | Compliancify",
      "description": "Organize system-description, criteria, risk, control, evidence, and management-responsibility records without representing readiness work as a completed CPA examination.",
      "topics": [
        "System description & boundary",
        "Risk assessment",
        "Logical access",
        "Change management",
        "Availability & incident response",
        "Vendor & subservice dependencies"
      ],
      "sections": [
        {
          "title": "Source and applicability boundary",
          "items": [
            "AICPA SOC resource starting point",
            "Authoritative guides and criteria may require licensed access",
            "Independent CPA examination remains outside the product preview",
            "SOC 2 is an examination context for controls relevant to the Trust Services Criteria. The applicable criteria, system boundary, period, evidence, and examination conclusion require management and qualified CPA judgment.",
            "Official starting point: https://www.aicpa-cima.com/soc"
          ]
        },
        {
          "title": "Obligation and control themes",
          "items": [
            "System description & boundary — Maintain approved system scope, services, commitments, components, boundaries, and material changes.",
            "Risk assessment — Operate a repeatable process to identify objectives, risks, changes, dependencies, and response decisions.",
            "Logical access — Govern provisioning, authentication, privileged access, recertification, removal, and monitored exceptions.",
            "Change management — Separate request, testing, approval, deployment, emergency handling, and post-implementation review.",
            "Availability & incident response — Coordinate monitoring, incident classification, escalation, communication, recovery, learning, and resilience commitments.",
            "Vendor & subservice dependencies — Identify dependency scope, due diligence, contractual expectations, monitoring, exceptions, and exit actions."
          ]
        },
        {
          "title": "Evidence and review expectations",
          "items": [
            "System description & boundary: System description, architecture, service commitments, inventory, data flows, vendors, and change record. Owner: System owner. Reviewer: Readiness reviewer. State: Interpretation pending.",
            "Risk assessment: Risk methodology, risk register, assessment records, approvals, and change triggers. Owner: Risk owner. Reviewer: Control reviewer. State: Mapped.",
            "Logical access: Identity configuration, access requests, approvals, reviews, logs, terminations, and exception records. Owner: Identity owner. Reviewer: Security reviewer. State: Evidence requested.",
            "Change management: Tickets, code review, test results, approvals, deployment logs, emergency records, and follow-up. Owner: Engineering owner. Reviewer: Change reviewer. State: Reviewer decision.",
            "Availability & incident response: Alerts, incident records, communications, recovery tests, post-incident review, and action tracking. Owner: Incident owner. Reviewer: Resilience reviewer. State: Mapped.",
            "Vendor & subservice dependencies: Vendor inventory, due diligence, contracts, monitoring, incidents, exceptions, and exit plans. Owner: Vendor owner. Reviewer: Third-party risk reviewer. State: Reassessment due."
          ]
        },
        {
          "title": "Relationships without false equivalence",
          "items": [
            "ISO/IEC 27001 management-system controls",
            "NIST CSF 2.0 outcomes",
            "GDPR security and processor obligations"
          ]
        }
      ]
    },
    {
      "path": "/frameworks/iso-27001",
      "canonical": "https://www.compliancify.app/frameworks/iso-27001",
      "title": "ISO/IEC 27001:2022 workspace | Compliancify",
      "description": "Connect management-system requirements, risk decisions, controls, evidence, exceptions, and review ownership without treating a mapping as certification.",
      "topics": [
        "Context & scope",
        "Risk assessment & treatment",
        "Statement of Applicability & controls",
        "Internal audit",
        "Management review",
        "Corrective action & improvement"
      ],
      "sections": [
        {
          "title": "Source and applicability boundary",
          "items": [
            "Official ISO standard reference",
            "Licensed standard text required for authoritative assessment",
            "Accredited certification is separate from this workspace",
            "This workspace uses high-level operational themes only. It does not reproduce ISO text, determine conformity, or represent certification by an accredited body.",
            "Official starting point: https://www.iso.org/standard/27001"
          ]
        },
        {
          "title": "Obligation and control themes",
          "items": [
            "Context & scope — Maintain organizational context, interested parties, scope boundaries, dependencies, and approved exclusions.",
            "Risk assessment & treatment — Operate approved risk criteria, assessment, treatment, acceptance, ownership, and review workflows.",
            "Statement of Applicability & controls — Preserve control inclusion, exclusion, implementation state, rationale, ownership, and relationship to risk treatment.",
            "Internal audit — Plan independent, competent, risk-informed internal audits and preserve findings, responses, and follow-up.",
            "Management review — Provide leaders with required context, performance, changes, risks, opportunities, decisions, and action status.",
            "Corrective action & improvement — Record nonconformity, correction, cause, action, effectiveness review, residual risk, and closure authority."
          ]
        },
        {
          "title": "Evidence and review expectations",
          "items": [
            "Context & scope: Context analysis, interested-party register, scope statement, interfaces, exclusions, and approval history. Owner: ISMS owner. Reviewer: Governance reviewer. State: Mapped.",
            "Risk assessment & treatment: Methodology, asset and process context, risk register, treatment plan, acceptance, and review records. Owner: Information security owner. Reviewer: Compliance reviewer. State: Evidence requested.",
            "Statement of Applicability & controls: Approved applicability record, implementation evidence, rationale, exceptions, and change history. Owner: Control owner. Reviewer: ISMS reviewer. State: Mapped.",
            "Internal audit: Program, scope, competence, workpapers, findings, responses, closure evidence, and reporting. Owner: Internal audit owner. Reviewer: Audit quality reviewer. State: Reviewer decision.",
            "Management review: Agenda, inputs, metrics, decisions, resource actions, acknowledgments, and follow-up log. Owner: Executive sponsor. Reviewer: ISMS owner. State: Reviewer decision.",
            "Corrective action & improvement: Issue record, cause analysis, action plan, implementation proof, effectiveness review, and approval. Owner: Action owner. Reviewer: Corrective-action reviewer. State: Reassessment due."
          ]
        },
        {
          "title": "Relationships without false equivalence",
          "items": [
            "NIST CSF 2.0 governance and risk outcomes",
            "SOC 2 security-related criteria",
            "GDPR security and accountability obligations"
          ]
        }
      ]
    },
    {
      "path": "/frameworks/gdpr",
      "canonical": "https://www.compliancify.app/frameworks/gdpr",
      "title": "GDPR accountability workspace | Compliancify",
      "description": "Connect processing context, legal interpretation, accountable controls, evidence, rights, incidents, processors, transfers, and human review.",
      "topics": [
        "Processing inventory & roles",
        "Lawful basis & transparency",
        "Data subject rights",
        "Privacy by design & DPIA",
        "Processors & transfers",
        "Personal-data breach response"
      ],
      "sections": [
        {
          "title": "Source and applicability boundary",
          "items": [
            "Official regulation text on EUR-Lex",
            "EDPB and supervisory-authority guidance may shape interpretation",
            "Entity-specific legal assessment is required",
            "Applicability, lawful basis, controller or processor role, risk, national law, and required response depend on facts and qualified legal or privacy review.",
            "Official starting point: https://eur-lex.europa.eu/eli/reg/2016/679/oj"
          ]
        },
        {
          "title": "Obligation and control themes",
          "items": [
            "Processing inventory & roles — Maintain processing purpose, data, subjects, systems, recipients, transfers, retention, role, and ownership context.",
            "Lawful basis & transparency — Preserve purpose, lawful-basis assessment, notice content, timing, channel, consent context, and change decisions.",
            "Data subject rights — Route intake, identity verification, system search, exceptions, response, delivery, and deadline oversight.",
            "Privacy by design & DPIA — Trigger privacy review, assess risk, document mitigations, approve residual risk, and escalate consultation questions.",
            "Processors & transfers — Govern processor role, contract, instructions, subprocessor, transfer mechanism, assessment, monitoring, and exit.",
            "Personal-data breach response — Classify incidents, assess personal-data impact, preserve timeline, route notification decisions, and track corrective actions."
          ]
        },
        {
          "title": "Evidence and review expectations",
          "items": [
            "Processing inventory & roles: Processing record, data map, product facts, agreements, recipients, retention, and approval history. Owner: Privacy operations owner. Reviewer: Privacy counsel. State: Mapped.",
            "Lawful basis & transparency: Assessment, notice versions, collection screens, consent records where applicable, translations, and approvals. Owner: Product privacy owner. Reviewer: Privacy counsel. State: Interpretation pending.",
            "Data subject rights: Request log, verification, system search, decision, approvals, response, delivery, and exception rationale. Owner: Rights operations owner. Reviewer: Privacy reviewer. State: Evidence requested.",
            "Privacy by design & DPIA: Product assessment, data-flow review, DPIA, risk treatment, sign-off, and change triggers. Owner: Product owner. Reviewer: Data protection reviewer. State: Reviewer decision.",
            "Processors & transfers: Vendor facts, DPA, transfer mechanism, assessment, notices, monitoring, changes, and termination evidence. Owner: Vendor privacy owner. Reviewer: Privacy counsel. State: Reassessment due.",
            "Personal-data breach response: Incident facts, timeline, risk assessment, notification decision, communications, approvals, and follow-up. Owner: Incident commander. Reviewer: Privacy counsel. State: Mapped."
          ]
        },
        {
          "title": "Relationships without false equivalence",
          "items": [
            "ISO/IEC 27001 information-security management",
            "SOC 2 privacy and security criteria",
            "NIST CSF 2.0 cyber-risk outcomes"
          ]
        }
      ]
    },
    {
      "path": "/frameworks/sox",
      "canonical": "https://www.compliancify.app/frameworks/sox",
      "title": "SOX and ICFR governance workspace | Compliancify",
      "description": "Organize scope, financial-reporting risks, control ownership, evidence, testing, deficiencies, certifications, and disclosure review without implying auditor reliance or management conclusion.",
      "topics": [
        "Scope & materiality",
        "Entity-level controls",
        "Process and IT-dependent controls",
        "Testing & evidence",
        "Deficiency evaluation",
        "Certification & disclosure"
      ],
      "sections": [
        {
          "title": "Source and applicability boundary",
          "items": [
            "SEC rules and company-specific filing obligations",
            "PCAOB standards apply to registered public-company audits",
            "Management and external-auditor conclusions remain separate",
            "Issuer status, reporting obligations, scope, materiality, control evaluation, deficiency severity, certification, and disclosure require company-specific legal, accounting, and audit assessment.",
            "Official starting point: https://www.sec.gov/rules-regulations/2003/06/managements-report-internal-control-over-financial-reporting-certification-disclosure-exchange-act"
          ]
        },
        {
          "title": "Obligation and control themes",
          "items": [
            "Scope & materiality — Maintain entity, account, disclosure, location, system, service organization, process, and materiality scope decisions.",
            "Entity-level controls — Document oversight, ethics, risk assessment, competence, authority, communication, monitoring, and remediation governance.",
            "Process and IT-dependent controls — Relate financial assertions and risks to process, system, interface, report, automated, manual, and review controls.",
            "Testing & evidence — Define population, period, frequency, sample or automated approach, evidence expectation, reviewer challenge, and deviation handling.",
            "Deficiency evaluation — Aggregate deficiencies, assess likelihood and magnitude, consider compensating controls, route governance, and preserve conclusions.",
            "Certification & disclosure — Coordinate sub-certifications, disclosure-control inputs, management evaluation, legal review, and filing governance."
          ]
        },
        {
          "title": "Evidence and review expectations",
          "items": [
            "Scope & materiality: Scoping model, quantitative and qualitative factors, entity map, system map, changes, and approvals. Owner: Controllership owner. Reviewer: ICFR governance reviewer. State: Interpretation pending.",
            "Entity-level controls: Charters, policies, attestations, minutes, risk assessments, monitoring, issues, and action follow-up. Owner: Corporate controls owner. Reviewer: Audit committee liaison. State: Mapped.",
            "Process and IT-dependent controls: Narratives, flows, risk-control matrix, configurations, reports, calculations, approvals, and change records. Owner: Process owner. Reviewer: ICFR reviewer. State: Evidence requested.",
            "Testing & evidence: Population, selection, workpaper, evidence, deviation, review comments, conclusion, and sign-off. Owner: Testing owner. Reviewer: Testing reviewer. State: Reviewer decision.",
            "Deficiency evaluation: Issue facts, affected assertions, evaluation, aggregation, compensating evidence, decisions, and communications. Owner: Deficiency owner. Reviewer: Disclosure committee reviewer. State: Reassessment due.",
            "Certification & disclosure: Sub-certifications, representation inputs, evaluation record, committee materials, approvals, and filed disclosure. Owner: Disclosure owner. Reviewer: Legal and finance reviewer. State: Reviewer decision."
          ]
        },
        {
          "title": "Relationships without false equivalence",
          "items": [
            "COSO-based internal-control models",
            "SOC 1 service-organization assurance",
            "SEC cybersecurity disclosure governance"
          ]
        }
      ]
    },
    {
      "path": "/frameworks/nist-csf-2",
      "canonical": "https://www.compliancify.app/frameworks/nist-csf-2",
      "title": "NIST CSF 2.0 outcomes workspace | Compliancify",
      "description": "Use CSF outcomes and profiles to structure current state, target state, ownership, evidence, priorities, and governed action without treating the framework as prescriptive certification criteria.",
      "topics": [
        "Govern",
        "Identify",
        "Protect",
        "Detect",
        "Respond",
        "Recover"
      ],
      "sections": [
        {
          "title": "Source and applicability boundary",
          "items": [
            "Official NIST CSF 2.0 publication and resource center",
            "Outcomes are non-prescriptive",
            "Legal, regulatory, contractual, and sector obligations remain separate inputs",
            "NIST describes CSF 2.0 as flexible, outcome-oriented guidance. Selection, prioritization, implementation, and assurance depend on organizational context and other governing requirements.",
            "Official starting point: https://www.nist.gov/cyberframework"
          ]
        },
        {
          "title": "Obligation and control themes",
          "items": [
            "Govern — Establish organizational context, strategy, policy, roles, oversight, supply-chain risk, and requirement management.",
            "Identify — Maintain asset, data, service, supplier, risk, improvement, and dependency context for prioritization.",
            "Protect — Operate identity, access, data security, platform security, resilience, awareness, and protective technology practices.",
            "Detect — Monitor assets, services, events, anomalies, and adverse conditions with defined analysis and escalation.",
            "Respond — Coordinate incident management, analysis, mitigation, reporting, communications, and learning decisions.",
            "Recover — Restore services and assets, validate integrity, communicate status, and incorporate recovery learning."
          ]
        },
        {
          "title": "Evidence and review expectations",
          "items": [
            "Govern: Strategy, policy, roles, risk appetite, legal and contractual register, oversight, and supplier-risk records. Owner: Cyber governance owner. Reviewer: Enterprise risk reviewer. State: Mapped.",
            "Identify: Inventories, data flows, business impact, risk assessment, dependency map, findings, and improvement plan. Owner: Risk operations owner. Reviewer: Cyber risk reviewer. State: Evidence requested.",
            "Protect: Configurations, access records, training, hardening, encryption, backups, tests, and exception approvals. Owner: Security engineering owner. Reviewer: Control reviewer. State: Mapped.",
            "Detect: Logging scope, detection rules, alerts, triage records, tuning decisions, coverage review, and escalations. Owner: Detection owner. Reviewer: Security operations reviewer. State: Reviewer decision.",
            "Respond: Incident plan, classifications, timeline, communications, actions, approvals, and after-action review. Owner: Incident response owner. Reviewer: Crisis governance reviewer. State: Reassessment due.",
            "Recover: Recovery plan, backup and restoration tests, recovery records, validation, communications, and improvements. Owner: Resilience owner. Reviewer: Business continuity reviewer. State: Evidence requested."
          ]
        },
        {
          "title": "Relationships without false equivalence",
          "items": [
            "ISO/IEC 27001 management system",
            "SOC 2 security criteria",
            "Legal, regulatory, and contractual cybersecurity obligations"
          ]
        }
      ]
    },
    {
      "path": "/frameworks/dora",
      "canonical": "https://www.compliancify.app/frameworks/dora",
      "title": "DORA operating workspace | Compliancify",
      "description": "Coordinate ICT risk, incidents, resilience testing, third-party registers, contracts, oversight, evidence, and accountable review for an in-scope assessment.",
      "topics": [
        "ICT risk management",
        "ICT incident classification & reporting",
        "Operational resilience testing",
        "Third-party register",
        "Contractual provisions & exit",
        "Oversight & remediation"
      ],
      "sections": [
        {
          "title": "Source and applicability boundary",
          "items": [
            "Official Regulation (EU) 2022/2554",
            "Delegated and implementing acts plus supervisory materials may apply",
            "Entity, service, proportionality, national, and group context require qualified review",
            "DORA has applied since 17 January 2025, but entity scope, proportionality, ICT service classification, reporting, registers, contractual requirements, and supervisory expectations require current-source and professional assessment.",
            "Official starting point: https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
          ]
        },
        {
          "title": "Obligation and control themes",
          "items": [
            "ICT risk management — Govern strategy, roles, framework, asset and dependency context, protection, detection, response, recovery, learning, and reporting.",
            "ICT incident classification & reporting — Classify ICT incidents, preserve facts and timing, route reporting thresholds, approvals, communications, and follow-up.",
            "Operational resilience testing — Maintain risk-based test scope, cadence, scenarios, independence, defects, remediation, validation, and advanced-testing decisions.",
            "Third-party register — Maintain ICT service, provider, entity, function, criticality, subcontractor, location, contract, dependency, and exit context.",
            "Contractual provisions & exit — Assess required contract terms, service levels, access, audit, incident support, data, subcontracting, termination, and exit plans.",
            "Oversight & remediation — Route board oversight, risk acceptance, material issues, supervisory requests, remediation, closure, and recurring review."
          ]
        },
        {
          "title": "Evidence and review expectations",
          "items": [
            "ICT risk management: Framework, policies, inventories, risk assessments, board reporting, incidents, tests, and improvements. Owner: ICT risk owner. Reviewer: Risk governance reviewer. State: Mapped.",
            "ICT incident classification & reporting: Incident record, classification rationale, timeline, impact, notification decision, submission record, and remediation. Owner: Incident owner. Reviewer: Regulatory reporting reviewer. State: Review due.",
            "Operational resilience testing: Test strategy, plans, scenarios, execution, results, defects, remediation, retest, and governance approval. Owner: Resilience testing owner. Reviewer: Independent test reviewer. State: Evidence ready.",
            "Third-party register: Register, service taxonomy, contracts, risk assessments, concentration analysis, changes, and ownership review. Owner: Vendor owner. Reviewer: Third-party risk reviewer. State: Review due.",
            "Contractual provisions & exit: Clause assessment, contract, addenda, approvals, exceptions, monitoring, termination rights, and exit test. Owner: Contract owner. Reviewer: Legal reviewer. State: Interpretation pending.",
            "Oversight & remediation: Governance packs, decisions, issues, supervisory correspondence, action evidence, validation, and closure approval. Owner: Operational resilience owner. Reviewer: Executive risk reviewer. State: Reviewer decision."
          ]
        },
        {
          "title": "Relationships without false equivalence",
          "items": [
            "NIS2 operational and incident context",
            "ISO/IEC 27001 management system",
            "NIST CSF 2.0 resilience outcomes"
          ]
        }
      ]
    },
    {
      "path": "/knowledge/obligations-framework-mapping",
      "canonical": "https://www.compliancify.app/knowledge/obligations-framework-mapping",
      "title": "Obligations and framework mapping | Compliancify",
      "description": "Model regulatory, contractual, policy, and internal obligations with applicability, source, interpretation, mapping, and ownership context. Organized as a governed operating, evidence, review, and decision record.",
      "topics": [
        "Scope criteria",
        "Requirement statements",
        "Framework crosswalks",
        "Owners"
      ],
      "sections": [
        {
          "title": "Operating scope",
          "items": [
            "Authority, jurisdiction, framework, contract, policy, and business context",
            "Applicability facts, entities, products, systems, data, and effective period",
            "Requirement decomposition, objective, actor, action, frequency, and evidence",
            "Shared intent versus framework-specific interpretation and test criteria",
            "Ownership, review cadence, exception authority, and change triggers"
          ]
        },
        {
          "title": "Evidence record",
          "items": [
            "Official publication, contract, policy, or internal mandate with version",
            "Applicability assessment and supporting organizational facts",
            "Legal, compliance, privacy, security, or risk interpretation notes",
            "Existing control, policy, process, evidence, and framework mappings",
            "Source changes, redlines, effective dates, and reviewer decisions"
          ]
        },
        {
          "title": "Governed outputs",
          "items": [
            "Versioned obligation and applicability register",
            "Requirement-to-control and framework crosswalk",
            "Unmapped, overlapping, conflicting, or ambiguous requirement queue",
            "Accountable owner, reviewer, cadence, and evidence expectation",
            "Approved interpretation and impact-decision history"
          ]
        }
      ]
    },
    {
      "path": "/knowledge/control-library",
      "canonical": "https://www.compliancify.app/knowledge/control-library",
      "title": "Control library | Compliancify",
      "description": "Relate objectives, activities, systems, performers, frequencies, evidence, risks, and framework mappings in one governed record. Organized as a governed operating, evidence, review, and decision record.",
      "topics": [
        "Control objectives",
        "Control design",
        "Framework reuse",
        "Testing expectations"
      ],
      "sections": [
        {
          "title": "Operating scope",
          "items": [
            "Control objective, risk, obligation, process, system, and data boundary",
            "Activity description, trigger, frequency, performer, and reviewer",
            "Preventive, detective, manual, automated, and hybrid design attributes",
            "Expected evidence, retention, source ownership, and testing criteria",
            "Framework mappings, dependencies, compensating controls, and change state"
          ]
        },
        {
          "title": "Evidence record",
          "items": [
            "Approved procedure, configuration, workflow, and responsibility record",
            "Execution evidence, logs, tickets, approvals, and source-system output",
            "Design assessments, walkthroughs, tests, exceptions, and remediation",
            "Mapped obligations, framework statements, policies, and risk records",
            "Version history, change rationale, owner attestation, and review comments"
          ]
        },
        {
          "title": "Governed outputs",
          "items": [
            "Normalized control record and reusable control family",
            "Obligation, framework, risk, policy, and evidence mappings",
            "Execution and evidence-readiness expectations",
            "Performer, reviewer, escalation, and accountability model",
            "Design review, approval, change, and retirement history"
          ]
        }
      ]
    },
    {
      "path": "/knowledge/policy-management",
      "canonical": "https://www.compliancify.app/knowledge/policy-management",
      "title": "Policy management | Compliancify",
      "description": "Connect policy language to obligations, controls, procedures, exceptions, approvals, acknowledgments, and renewal workflows. Organized as a governed operating, evidence, review, and decision record.",
      "topics": [
        "Policy inventory",
        "Approvals",
        "Acknowledgments",
        "Version history"
      ],
      "sections": [
        {
          "title": "Operating scope",
          "items": [
            "Policy hierarchy, purpose, audience, entities, locations, and applicability",
            "Statements, standards, procedures, roles, and mandatory exceptions process",
            "Source obligations, controls, risks, records, and training dependencies",
            "Drafting, consultation, approval, publication, and acknowledgment stages",
            "Review cadence, change triggers, expiry, replacement, and archival state"
          ]
        },
        {
          "title": "Evidence record",
          "items": [
            "Source obligations, approved interpretations, and control requirements",
            "Drafts, redlines, stakeholder comments, and disposition decisions",
            "Approval records, publication evidence, and authoritative version",
            "Acknowledgments, training completion, exceptions, and waiver history",
            "Periodic review, effectiveness input, change rationale, and supersession"
          ]
        },
        {
          "title": "Governed outputs",
          "items": [
            "Controlled policy and standards inventory",
            "Approved publication with owner, scope, and effective date",
            "Obligation, control, procedure, and training linkage",
            "Acknowledgment, exception, waiver, and renewal status",
            "Version, approval, communication, and archival history"
          ]
        }
      ]
    },
    {
      "path": "/knowledge/evidence-operations",
      "canonical": "https://www.compliancify.app/knowledge/evidence-operations",
      "title": "Evidence operations | Compliancify",
      "description": "Coordinate evidence requests, source ownership, freshness, review, reuse, security, and gaps across obligations and frameworks. Organized as a governed operating, evidence, review, and decision record.",
      "topics": [
        "Evidence catalog",
        "Freshness",
        "Source provenance",
        "Reviewer state"
      ],
      "sections": [
        {
          "title": "Operating scope",
          "items": [
            "Evidence object, purpose, related control, obligation, test, and period",
            "Source system, custodian, collection method, query, and access boundary",
            "Frequency, freshness, completeness, retention, and reuse conditions",
            "Request owner, due date, reviewer, exception, and escalation path",
            "Confidentiality, redaction, transmission, storage, and disposal requirements"
          ]
        },
        {
          "title": "Evidence record",
          "items": [
            "System snapshots, exports, logs, tickets, approvals, and attestations",
            "Collection parameters, source lineage, timestamps, and completeness checks",
            "Request and response history with owner and period context",
            "Reviewer assessment, rejected support, gaps, and follow-up material",
            "Reuse rationale, expiry, supersession, access, and retention metadata"
          ]
        },
        {
          "title": "Governed outputs",
          "items": [
            "Searchable evidence catalog with provenance and coverage",
            "Framework-aware request and collection plan",
            "Current, stale, missing, disputed, or restricted readiness status",
            "Evidence exception and remediation queue",
            "Reviewer decision, reuse, retention, and audit-trail record"
          ]
        }
      ]
    },
    {
      "path": "/knowledge/exceptions-remediation",
      "canonical": "https://www.compliancify.app/knowledge/exceptions-remediation",
      "title": "Exceptions and remediation | Compliancify",
      "description": "Keep deviations, affected requirements, risk acceptance, compensating measures, action plans, expiry, validation, and closure together. Organized as a governed operating, evidence, review, and decision record.",
      "topics": [
        "Exceptions",
        "Risk acceptance",
        "Remediation",
        "Expiry and renewal"
      ],
      "sections": [
        {
          "title": "Operating scope",
          "items": [
            "Observed deviation, affected control, obligation, policy, system, and data",
            "Business context, duration, population, likelihood, impact, and exposure",
            "Compensating controls, monitoring, restrictions, and residual risk",
            "Acceptance authority, conditions, expiry, renewal, and escalation criteria",
            "Remediation owner, milestones, dependencies, validation, and closure"
          ]
        },
        {
          "title": "Evidence record",
          "items": [
            "Failure, deviation, test result, incident, or self-identified gap evidence",
            "Risk assessment, affected mappings, scope facts, and impact analysis",
            "Compensating-control design and execution evidence",
            "Approval, conditions, communications, and monitoring results",
            "Implementation artifacts, validation testing, and closure decision"
          ]
        },
        {
          "title": "Governed outputs",
          "items": [
            "Versioned exception and affected-obligation record",
            "Time-bound risk-acceptance or rejection decision",
            "Compensating-control and monitoring plan",
            "Remediation, dependency, overdue, expiry, and renewal view",
            "Validated closure, extension, escalation, or residual-risk record"
          ]
        }
      ]
    },
    {
      "path": "/knowledge/change-intelligence",
      "canonical": "https://www.compliancify.app/knowledge/change-intelligence",
      "title": "Change intelligence | Compliancify",
      "description": "Turn regulatory, contractual, framework, policy, product, and system changes into impact questions, assigned reviews, and controlled updates. Organized as a governed operating, evidence, review, and decision record.",
      "topics": [
        "Change signals",
        "Impact assessment",
        "Control updates",
        "Re-attestation"
      ],
      "sections": [
        {
          "title": "Operating scope",
          "items": [
            "Change source, authority, jurisdiction, version, publication, and effective date",
            "Affected entities, products, locations, data, systems, and business processes",
            "Impacted obligations, mappings, controls, policies, evidence, and exceptions",
            "Materiality, implementation window, interpretation need, and dependencies",
            "Assessment owner, reviewer, decision authority, and monitoring cadence"
          ]
        },
        {
          "title": "Evidence record",
          "items": [
            "Official publication, contract amendment, release note, or internal decision",
            "Source comparison, redline, summary, and effective-period evidence",
            "Current obligation, control, policy, evidence, and asset inventory",
            "Stakeholder analysis, legal or specialist input, and challenge record",
            "Implementation evidence, testing, communication, and re-attestation"
          ]
        },
        {
          "title": "Governed outputs",
          "items": [
            "Normalized change record with source provenance",
            "Impacted requirement, control, policy, evidence, and owner set",
            "Assessment questions, actions, dependencies, and due dates",
            "Interpretation, no-impact, implementation, or escalation decision",
            "Controlled update, validation, communication, and re-attestation history"
          ]
        }
      ]
    }
  ]
}
