Business Core · Compliance · Module
Regulatory mapping
Establishing which rules actually apply — by jurisdiction, sector and activity — before deciding how to meet them.
The idea
How it works
Obligations arrive from jurisdiction, from sector, from activity and from contract, and organisations usually track the ones with a dedicated regulator while missing the rest. Employment, data protection and consumer rules apply to nearly everyone and are owned by nobody in particular.
The map is only useful once obligations are translated into requirements someone can act on. A citation is not an instruction, and leaving the translation undone is how an obligation becomes a finding.
Working with it
In practice
- 01
Map by activity, not by department
Obligations follow what the organisation does, wherever it is done.
- 02
Cover every jurisdiction you operate in
Including where staff are, where data sits, and where customers are.
- 03
Translate into requirements
Each obligation becomes something a named person must do or evidence.
- 04
Watch for change
Rules change. An obligation register with no review date describes a past state.
One level in
The components of regulatory mapping
A component is something that exists afterwards which did not exist before — a deliverable or a mechanism, not an intention.
Employment, data and consumer obligations apply to nearly everyone and are the ones most often unowned.
The other modules in compliance
Controls
The mechanisms that make compliance happen — built into how work is done, rather than checked afterwards.
LearnMonitoring
Checking that controls are actually operating, independently of the people who operate them.
LearnIncident response
What happens when something goes wrong — containment, notification and correction — decided in advance rather than during.
Learn