Version 1 · 13 July 2026

A taxonomy for incoming compliance requests.

The category describes what the requester is trying to establish—not which team happens to receive the spreadsheet. A request may belong to more than one category.

Organisation and governance

Requester objectiveHow accountability, oversight and decisions are structured.
Likely ownersManagement, operations
Common evidencePolicies, approvals, meeting records
Recurring ambiguityTerms such as oversight and regular review vary.
Related categoriesPolicies and training; certifications

Information security

Requester objectiveHow security risks and safeguards are managed.
Likely ownersSecurity, engineering, management
Common evidenceRisk records, policies, configurations, test records
Recurring ambiguityScope may mean company, service or environment.
Related categoriesIdentity and access; secure development

Identity and access

Requester objectiveWhether access is authorized, limited, reviewed and removed.
Likely ownersSystem owners, IT, security
Common evidenceAccess exports, approvals, review records, logs
Recurring ambiguityAccount, user, role and privileged access are often conflated.
Related categoriesEmployee lifecycle; audit logs

Employee lifecycle

Requester objectiveHow joiners, movers and leavers receive and lose access.
Likely ownersPeople, IT, managers
Common evidenceHR events, task records, access logs
Recurring ambiguityWorkers, contractors and timing scope vary.
Related categoriesIdentity and access; policies and training

Secure software development

Requester objectiveHow software changes and vulnerabilities are managed.
Likely ownersEngineering, security
Common evidenceChange records, reviews, scans, test summaries
Recurring ambiguityProduct, repository and environment scope can differ.
Related categoriesInformation security; independent assessments

Incident response

Requester objectiveHow incidents are detected, escalated, handled and learned from.
Likely ownersSecurity, engineering, management
Common evidencePlans, exercises, incident records, action closure
Recurring ambiguitySecurity incident, privacy breach and service outage differ.
Related categoriesBusiness continuity; privacy

Business continuity and backups

Requester objectiveHow critical services and data are restored after disruption.
Likely ownersEngineering, operations, management
Common evidencePlans, exercises, restore tests, follow-up actions
Recurring ambiguityBackup success is not restoration or business recovery.
Related categoriesIncident response; governance

Privacy and data processing

Requester objectiveHow personal data roles, use, disclosure and rights are handled.
Likely ownersPrivacy or legal adviser, operations
Common evidenceRecords, notices, contracts, supplier registers
Recurring ambiguityRole and jurisdiction require context-specific interpretation.
Related categoriesThird-party risk; governance

Third-party risk

Requester objectiveHow suppliers are selected, assessed and monitored.
Likely ownersProcurement, security, privacy
Common evidenceVendor inventory, assessments, approvals, monitoring
Recurring ambiguityVendor, supplier, processor and subprocessor are not synonyms.
Related categoriesPrivacy; information security

Physical security

Requester objectiveHow premises, devices and physical access are protected.
Likely ownersFacilities, operations, IT
Common evidenceAccess lists, visitor records, device records
Recurring ambiguityRemote companies may have different scope and reliance.
Related categoriesEmployee lifecycle; information security

Finance and statutory evidence

Requester objectiveWhether financial, insurance or statutory claims are supported.
Likely ownersFinance, management, professional advisers
Common evidenceFiled records, policies, confirmations
Recurring ambiguityJurisdiction and reporting entity matter.
Related categoriesGovernance; independent assessments

Policies and training

Requester objectiveWhether expectations are documented, communicated and understood.
Likely ownersPolicy owner, People, security
Common evidenceApproved policies, acknowledgements, completion reports
Recurring ambiguityA policy or completion record does not prove operation or behavior.
Related categoriesEmployee lifecycle; governance

Certifications and independent assessments

Requester objectiveWhether an external party assessed a defined scope.
Likely ownersManagement, security, professional adviser
Common evidenceCertificates, scope statements, independent reports
Recurring ambiguityCertificate, attestation, audit and alignment are distinct.
Related categoriesInformation security; governance