Compliance checklists and registry
Manage enterprise compliance obligations, browse the registry, add custom requirements, and score applications against checklist items.
This page covers day-to-day use. To seed the standard GDPR / HIPAA / SOC 2 / internal pack, see Loading standard compliance checklists.
Who this is for
Compliance, risk, and architecture owners who track regulatory and internal controls against the application portfolio.
Two related catalogs
PlexArch stores the same obligation in two places when you load the standard pack:
| Store | Used for |
|---|---|
| Compliance checklist | Named items with category, guidance, and critical flags. Application checklist scoring. |
| Compliance registry | Requirements with severity, regulatory body, description, and policy mapping. Application requirement assessments. |
Create → Compliance Checklist in the navigation opens the Compliance Registry (requirements list). Tools → Compliance Checklists is the seed tool, not the registry.
Compliance registry
Open Create → Compliance Checklist.
The header shows how many entries exist. KPI cards show:
- Total requirements
- Critical / High count
- Distinct regulators
- Distinct categories
Filter and search
- Search name, regulatory body, or description
- Filter by category
- Filter by severity
- Apply or Clear all
- Pagination and page size
Export
Use the download icon to export the current filter as CSV (ExportComplianceRegistryCsv).
Add from the registry
Add Compliance opens New Compliance in a new tab.
Add a compliance requirement
Open Create → New Compliance, or Add Compliance from the registry.
| Field | Required | Notes |
|---|---|---|
| Compliance name | Yes | Up to 200 characters. Example: GDPR Article 32 — Security of processing. |
| Category | No | Technical, Process, Architecture, GDPR, HIPAA, SOC2, Data, Security, Policy Compliance. |
| Severity level | No | Mission Critical, Critical, High, Medium, Low. Default on the form is Medium. |
| Regulatory body | No | For example ICO, SEC, internal audit. |
| Description | No | Scope, applicability, evidence expectations. |
| Policy mapping | No | Internal policy IDs, document links, or control mappings. |
Save compliance writes the requirement for the current enterprise and returns you to the registry with a success message.
Use this for obligations that are not in the standard seed, or for extra controls after you load the catalog. Avoid duplicating seeded names in the same category unless you intend two rows.
Application compliance tracking
After checklists and/or registry items exist, open Application compliance tracking (linked from the seed success page, or via the application compliance screens).
- Select an application.
- Optionally filter by category.
- Record assessment status and notes per requirement for that application.
If no applications exist, register or onboard applications first.
Suggested setup order
- Register the enterprise and sign in.
- Onboard applications (and the rest of the landscape).
- Load standard checklists.
- Add custom requirements here if needed.
- Score applications in compliance tracking.
- Optionally run surveys for owner-attested evidence.
Related screens
Category-specific compliance views (for example GDPR, HIPAA, security, process, architecture) under compliance show portfolio-level checklist posture after items exist and applications have been scored.