Skip to content

Compliance management

The compliance engine evaluates configured policy against organization records and selected operational actions.

Compliance frameworks page in FlaskTrack
Frameworks organize the policies and checklists used to evaluate controlled operations.

Configuration model

Component Purpose
Framework Groups requirements under a regulation, standard, or internal policy.
Compliance level Represents severity or operational significance.
Regulatory tag Classifies an entity or procedure.
Mapping Connects a tag to a framework and level.
Authorization rule Makes an action allowed, approval-required, or blocked for a level.
Applicability scope Limits where a rule or checklist applies.
Checklist Defines confirmations and evidence to collect.

Evaluation

When a controlled action occurs, FlaskTrack resolves the regulatory surface inherited from the entity and related records, evaluates active framework mappings, determines the effective level, applies authorization rules, and identifies applicable checklists.

The current policy result should be tested with representative records before production use. The policy matrix helps explain the effective result across frameworks.

Approval-required actions

When policy requires approval, the original action should remain pending until an authorized reviewer approves or rejects it. The decision, reviewer, timestamp, and related evidence should remain associated with the request.

Administration practices

  • Keep frameworks focused and named clearly.
  • Avoid duplicate tags with overlapping meanings.
  • Use the smallest effective scope.
  • Require evidence only when it is useful and reviewable.
  • Test conflicts across multiple active frameworks.
  • Record the configuration version included in each validation cycle.