Version 1 · 13 July 2026
A taxonomy for incoming compliance requests.
The category describes what the requester is trying to establish—not which team happens to receive the spreadsheet. A request may belong to more than one category.
Organisation and governance
| Requester objective | How accountability, oversight and decisions are structured. |
|---|---|
| Likely owners | Management, operations |
| Common evidence | Policies, approvals, meeting records |
| Recurring ambiguity | Terms such as oversight and regular review vary. |
| Related categories | Policies and training; certifications |
Information security
| Requester objective | How security risks and safeguards are managed. |
|---|---|
| Likely owners | Security, engineering, management |
| Common evidence | Risk records, policies, configurations, test records |
| Recurring ambiguity | Scope may mean company, service or environment. |
| Related categories | Identity and access; secure development |
Identity and access
| Requester objective | Whether access is authorized, limited, reviewed and removed. |
|---|---|
| Likely owners | System owners, IT, security |
| Common evidence | Access exports, approvals, review records, logs |
| Recurring ambiguity | Account, user, role and privileged access are often conflated. |
| Related categories | Employee lifecycle; audit logs |
Employee lifecycle
| Requester objective | How joiners, movers and leavers receive and lose access. |
|---|---|
| Likely owners | People, IT, managers |
| Common evidence | HR events, task records, access logs |
| Recurring ambiguity | Workers, contractors and timing scope vary. |
| Related categories | Identity and access; policies and training |
Secure software development
| Requester objective | How software changes and vulnerabilities are managed. |
|---|---|
| Likely owners | Engineering, security |
| Common evidence | Change records, reviews, scans, test summaries |
| Recurring ambiguity | Product, repository and environment scope can differ. |
| Related categories | Information security; independent assessments |
Incident response
| Requester objective | How incidents are detected, escalated, handled and learned from. |
|---|---|
| Likely owners | Security, engineering, management |
| Common evidence | Plans, exercises, incident records, action closure |
| Recurring ambiguity | Security incident, privacy breach and service outage differ. |
| Related categories | Business continuity; privacy |
Business continuity and backups
| Requester objective | How critical services and data are restored after disruption. |
|---|---|
| Likely owners | Engineering, operations, management |
| Common evidence | Plans, exercises, restore tests, follow-up actions |
| Recurring ambiguity | Backup success is not restoration or business recovery. |
| Related categories | Incident response; governance |
Privacy and data processing
| Requester objective | How personal data roles, use, disclosure and rights are handled. |
|---|---|
| Likely owners | Privacy or legal adviser, operations |
| Common evidence | Records, notices, contracts, supplier registers |
| Recurring ambiguity | Role and jurisdiction require context-specific interpretation. |
| Related categories | Third-party risk; governance |
Third-party risk
| Requester objective | How suppliers are selected, assessed and monitored. |
|---|---|
| Likely owners | Procurement, security, privacy |
| Common evidence | Vendor inventory, assessments, approvals, monitoring |
| Recurring ambiguity | Vendor, supplier, processor and subprocessor are not synonyms. |
| Related categories | Privacy; information security |
Physical security
| Requester objective | How premises, devices and physical access are protected. |
|---|---|
| Likely owners | Facilities, operations, IT |
| Common evidence | Access lists, visitor records, device records |
| Recurring ambiguity | Remote companies may have different scope and reliance. |
| Related categories | Employee lifecycle; information security |
Finance and statutory evidence
| Requester objective | Whether financial, insurance or statutory claims are supported. |
|---|---|
| Likely owners | Finance, management, professional advisers |
| Common evidence | Filed records, policies, confirmations |
| Recurring ambiguity | Jurisdiction and reporting entity matter. |
| Related categories | Governance; independent assessments |
Policies and training
| Requester objective | Whether expectations are documented, communicated and understood. |
|---|---|
| Likely owners | Policy owner, People, security |
| Common evidence | Approved policies, acknowledgements, completion reports |
| Recurring ambiguity | A policy or completion record does not prove operation or behavior. |
| Related categories | Employee lifecycle; governance |
Certifications and independent assessments
| Requester objective | Whether an external party assessed a defined scope. |
|---|---|
| Likely owners | Management, security, professional adviser |
| Common evidence | Certificates, scope statements, independent reports |
| Recurring ambiguity | Certificate, attestation, audit and alignment are distinct. |
| Related categories | Information security; governance |