Compliance management
The compliance engine evaluates configured policy against organization records and selected operational actions.
Configuration model
| Component | Purpose |
|---|---|
| Framework | Groups requirements under a regulation, standard, or internal policy. |
| Compliance level | Represents severity or operational significance. |
| Regulatory tag | Classifies an entity or procedure. |
| Mapping | Connects a tag to a framework and level. |
| Authorization rule | Makes an action allowed, approval-required, or blocked for a level. |
| Applicability scope | Limits where a rule or checklist applies. |
| Checklist | Defines confirmations and evidence to collect. |
Evaluation
When a controlled action occurs, FlaskTrack resolves the regulatory surface inherited from the entity and related records, evaluates active framework mappings, determines the effective level, applies authorization rules, and identifies applicable checklists.
The current policy result should be tested with representative records before production use. The policy matrix helps explain the effective result across frameworks.
Approval-required actions
When policy requires approval, the original action should remain pending until an authorized reviewer approves or rejects it. The decision, reviewer, timestamp, and related evidence should remain associated with the request.
Administration practices
- Keep frameworks focused and named clearly.
- Avoid duplicate tags with overlapping meanings.
- Use the smallest effective scope.
- Require evidence only when it is useful and reviewable.
- Test conflicts across multiple active frameworks.
- Record the configuration version included in each validation cycle.