COMPLY
How it works

A continuous lifecycle for evidence-driven compliance.

COMPLY turns control design, operation, evidence, review, and improvement into a repeatable governance cadence.

Compliance lifecycle wheel

Assess
Design
Implement
Operate
Review
Improve

Continuous Compliance

Governed. Evidenced. Improved.

Lifecycle operating principle

Each phase produces governance decisions, control actions, and evidence that feed the next phase. The result is a compliance program that can be operated, reviewed, improved, and defended continuously.

Step 1

Assess

Establish the compliance baseline by understanding risk exposure, obligations, control coverage, and available evidence.

RisksCompliance obligationsExisting controlsCurrent evidence

Key activities

  • Identify applicable frameworks, standards, regulations, and customer obligations.
  • Review existing control inventory, policies, procedures, and ownership.
  • Evaluate current evidence for completeness, freshness, and audit usability.
  • Document gaps between required outcomes and current operating reality.

Outputs

  • Compliance baseline assessment
  • Risk and obligation map
  • Current-state evidence review
  • Prioritized gap register

Governance outcome

Leadership understands the starting point, major compliance risks, and the evidence gaps that could weaken audit conclusions.

Step 2

Design

Translate obligations into a practical operating model with governance, control design, evidence expectations, and accountability.

GovernancePoliciesStandardsProceduresControls

Key activities

  • Define the governance model, decision cadence, and management review structure.
  • Map requirements to unified controls and supporting policies or standards.
  • Clarify control owners, performers, reviewers, and evidence expectations.
  • Design procedures and monitoring routines that can actually operate.

Outputs

  • Unified control framework
  • Policy and standards architecture
  • RACI and ownership model
  • Evidence requirements matrix

Governance outcome

The organization has a defensible design that links requirements to controls, owners, evidence, and review cycles.

Step 3

Implement

Put the designed controls and governance routines into operation with clear ownership and repeatable execution.

ControlsProcessesMonitoringAccountability

Key activities

  • Launch or update control procedures, workflows, and review routines.
  • Assign accountable owners and define expected operating frequency.
  • Set up monitoring signals, evidence capture points, and escalation paths.
  • Train control owners on execution, documentation, and evidence quality.

Outputs

  • Implemented control procedures
  • Owner accountability register
  • Monitoring and escalation model
  • Operational evidence templates

Governance outcome

Controls move from documented intent to assigned, repeatable processes that can produce audit-ready evidence.

Step 4

Operate

Execute controls in the normal course of business and collect evidence while the work is happening.

Execute controlsCollect evidenceMonitor performance

Key activities

  • Perform controls according to defined frequency and ownership.
  • Collect evidence tied to control objectives and framework requirements.
  • Monitor exceptions, overdue reviews, missing evidence, and control drift.
  • Maintain records that show who did what, when, and with what result.

Outputs

  • Control execution records
  • Validated evidence repository
  • Exception and issue log
  • Operational performance dashboard

Governance outcome

Evidence is created continuously, reducing audit scramble and improving confidence that controls are operating effectively.

Step 5

Review

Evaluate whether controls are operating effectively and whether evidence supports defensible compliance conclusions.

Internal auditManagement reviewKPI analysisGap identification

Key activities

  • Perform internal audit, control testing, and evidence sufficiency reviews.
  • Analyze compliance KPIs, trends, exceptions, and unresolved remediation.
  • Conduct management review to confirm accountability and oversight.
  • Identify emerging gaps caused by business, technology, or regulatory change.

Outputs

  • Internal audit results
  • Management review package
  • KPI and exception analysis
  • Control effectiveness findings

Governance outcome

Management gains visibility into control effectiveness, audit readiness, and areas requiring corrective action.

Step 6

Improve

Use findings, risk changes, and audit feedback to strengthen the program and reduce recurring compliance effort.

Corrective actionsOptimizationContinuous improvement

Key activities

  • Prioritize corrective actions based on risk, audit impact, and operational value.
  • Optimize controls, evidence requests, and framework mappings to reduce duplication.
  • Update policies, procedures, and governance routines as the business changes.
  • Track remediation through closure and confirm improvements are operating.

Outputs

  • Corrective action plan
  • Optimization backlog
  • Updated control and evidence mappings
  • Continuous improvement report

Governance outcome

The compliance program becomes more efficient, better governed, and more resilient across future audits and framework changes.