Documentation

Load compliance checklists

Seed standard GDPR, HIPAA, SOC 2, and internal checklist items for your enterprise.

Loading standard compliance checklists

Seed the eight built-in compliance categories into your enterprise: checklist items with guidance, plus matching entries in the compliance registry.

Who this is for

Administrators setting up compliance tracking for a new tenant, or resetting the standard catalog after a demo or trial.

How to open it

In the workspace, go to Tools → Compliance Checklists.

The page title is Standard Compliance Checklists.

What gets loaded

The catalog currently contains 71 items across these categories:

CategoryTypical focus
GDPRLawful basis, notices, data subject rights, DPIAs, transfers, breach reporting
HIPAAPHI inventory, BAAs, access, encryption, training, contingency
SOC2Trust boundaries, access, patching, availability, change management
ArchitectureRepository, patterns, NFRs, environment separation, technology sunset
DataCatalog, classification, quality, lineage, masking, retention
SecurityMFA, vulnerability management, secrets, PAM, supply chain, pentest
ProcessSOPs, CAB, incident/problem, SLAs, BCP, access certification
Policy CompliancePolicy inventory, annual review, acknowledgements, exceptions, audit

Each item has a name, guidance (what to do to achieve compliance), and an optional Critical flag.

The same items are also written as compliance requirements in the registry:

  • Severity: Critical if flagged, otherwise High
  • Description: the guidance text
  • Policy mapping: Checklist:{category}

Preview before you load

The Tools page shows a sample of six items and the count of remaining items. Review categories there before you commit.

Load checklists

  1. Read the warning: this replaces existing checklist and registry entries in the eight standard categories for your enterprise.
  2. Confirm the dialog: Replace standard compliance checklists for this enterprise?
  3. Choose Load Compliance Checklists.

On success you see:

  • Number of checklist items created
  • Number of registry requirements created
  • Counts by category
  • Links to App compliance tracking and Compliance registry

If the seed fails, the error message is shown on the same page.

What is replaced

Reload deletes, for this company and enterprise, records in those eight categories:

  • Application-level assessments tied to the old requirements
  • Application checklist scores tied to the old checklist items
  • The checklist items themselves
  • The registry requirements themselves

Custom requirements you created in other category names are left alone. Requirements in the eight standard category names are removed and recreated.

After loading

  1. Open Compliance registry to browse names, categories, and severity.
  2. Open Application → Application compliance tracking to score applications against the items.
  3. Add extra obligations with New Compliance if the catalog is not enough.

Do not use this Tools action as a daily update. Use it for initial setup or a deliberate reset of the standard pack.