Loading standard compliance checklists
Seed the eight built-in compliance categories into your enterprise: checklist items with guidance, plus matching entries in the compliance registry.
Who this is for
Administrators setting up compliance tracking for a new tenant, or resetting the standard catalog after a demo or trial.
How to open it
In the workspace, go to Tools → Compliance Checklists.
The page title is Standard Compliance Checklists.
What gets loaded
The catalog currently contains 71 items across these categories:
| Category | Typical focus |
|---|---|
| GDPR | Lawful basis, notices, data subject rights, DPIAs, transfers, breach reporting |
| HIPAA | PHI inventory, BAAs, access, encryption, training, contingency |
| SOC2 | Trust boundaries, access, patching, availability, change management |
| Architecture | Repository, patterns, NFRs, environment separation, technology sunset |
| Data | Catalog, classification, quality, lineage, masking, retention |
| Security | MFA, vulnerability management, secrets, PAM, supply chain, pentest |
| Process | SOPs, CAB, incident/problem, SLAs, BCP, access certification |
| Policy Compliance | Policy inventory, annual review, acknowledgements, exceptions, audit |
Each item has a name, guidance (what to do to achieve compliance), and an optional Critical flag.
The same items are also written as compliance requirements in the registry:
- Severity: Critical if flagged, otherwise High
- Description: the guidance text
- Policy mapping:
Checklist:{category}
Preview before you load
The Tools page shows a sample of six items and the count of remaining items. Review categories there before you commit.
Load checklists
- Read the warning: this replaces existing checklist and registry entries in the eight standard categories for your enterprise.
- Confirm the dialog: Replace standard compliance checklists for this enterprise?
- Choose Load Compliance Checklists.
On success you see:
- Number of checklist items created
- Number of registry requirements created
- Counts by category
- Links to App compliance tracking and Compliance registry
If the seed fails, the error message is shown on the same page.
What is replaced
Reload deletes, for this company and enterprise, records in those eight categories:
- Application-level assessments tied to the old requirements
- Application checklist scores tied to the old checklist items
- The checklist items themselves
- The registry requirements themselves
Custom requirements you created in other category names are left alone. Requirements in the eight standard category names are removed and recreated.
After loading
- Open Compliance registry to browse names, categories, and severity.
- Open Application → Application compliance tracking to score applications against the items.
- Add extra obligations with New Compliance if the catalog is not enough.
Do not use this Tools action as a daily update. Use it for initial setup or a deliberate reset of the standard pack.