Documentation

Compliance checklists and registry

Browse requirements, add custom obligations, and track application compliance.

Compliance checklists and registry

Manage enterprise compliance obligations, browse the registry, add custom requirements, and score applications against checklist items.

This page covers day-to-day use. To seed the standard GDPR / HIPAA / SOC 2 / internal pack, see Loading standard compliance checklists.

Who this is for

Compliance, risk, and architecture owners who track regulatory and internal controls against the application portfolio.

PlexArch stores the same obligation in two places when you load the standard pack:

StoreUsed for
Compliance checklistNamed items with category, guidance, and critical flags. Application checklist scoring.
Compliance registryRequirements with severity, regulatory body, description, and policy mapping. Application requirement assessments.

Create → Compliance Checklist in the navigation opens the Compliance Registry (requirements list). Tools → Compliance Checklists is the seed tool, not the registry.

Compliance registry

Open Create → Compliance Checklist.

The header shows how many entries exist. KPI cards show:

  • Total requirements
  • Critical / High count
  • Distinct regulators
  • Distinct categories
  • Search name, regulatory body, or description
  • Filter by category
  • Filter by severity
  • Apply or Clear all
  • Pagination and page size

Export

Use the download icon to export the current filter as CSV (ExportComplianceRegistryCsv).

Add from the registry

Add Compliance opens New Compliance in a new tab.

Add a compliance requirement

Open Create → New Compliance, or Add Compliance from the registry.

FieldRequiredNotes
Compliance nameYesUp to 200 characters. Example: GDPR Article 32 — Security of processing.
CategoryNoTechnical, Process, Architecture, GDPR, HIPAA, SOC2, Data, Security, Policy Compliance.
Severity levelNoMission Critical, Critical, High, Medium, Low. Default on the form is Medium.
Regulatory bodyNoFor example ICO, SEC, internal audit.
DescriptionNoScope, applicability, evidence expectations.
Policy mappingNoInternal policy IDs, document links, or control mappings.

Save compliance writes the requirement for the current enterprise and returns you to the registry with a success message.

Use this for obligations that are not in the standard seed, or for extra controls after you load the catalog. Avoid duplicating seeded names in the same category unless you intend two rows.

Application compliance tracking

After checklists and/or registry items exist, open Application compliance tracking (linked from the seed success page, or via the application compliance screens).

  1. Select an application.
  2. Optionally filter by category.
  3. Record assessment status and notes per requirement for that application.

If no applications exist, register or onboard applications first.

Suggested setup order

  1. Register the enterprise and sign in.
  2. Onboard applications (and the rest of the landscape).
  3. Load standard checklists.
  4. Add custom requirements here if needed.
  5. Score applications in compliance tracking.
  6. Optionally run surveys for owner-attested evidence.

Category-specific compliance views (for example GDPR, HIPAA, security, process, architecture) under compliance show portfolio-level checklist posture after items exist and applications have been scored.