Appearance
Compliance Activities
Where to find it: Regulatory Compliance, then Compliance Activities (/activities).
A requirement states what the regulator wants. An activity is a piece of work a named person can actually do about it.
Why activities exist
Consider a clause reading: "The institution shall maintain a documented access control policy, review privileged access at least quarterly, and retain evidence of each review for five years."
That is one requirement and three duties. They belong to three functions — Policy, IT Security Operations, and Records Management — with three different cadences. Assigning the whole clause to one person guarantees that at least two of the three duties will be under-served.
Decomposing the requirement into activities makes each duty ownable, schedulable and individually evidenced.
What an activity carries
| Field | Purpose |
|---|---|
| Parent requirement | The obligation it serves |
| Description | The specific duty |
| Owner | The accountable person or team |
| Department | The owning function |
| Due date | Where the duty is time-bound |
| Status | Progress through the work and review chain |
| Response | The owner's recorded position and narrative |
| Evidence | Attached supporting artefacts |
Activities and requirements
The requirement's compliance position reflects its activities, but the relationship is not arithmetic. Two completed activities out of three is not "67% compliant" — the requirement's position depends on which duty is outstanding and what the assurance evidence shows.
Working an activity
- Receive it. Assigned activities appear in your Workbench.
- Do the work. The actual compliance activity happens in your business systems.
- Record the response. Describe what was done and what the position is.
- Attach evidence. Link supporting artefacts from the Evidence Register.
- Submit. The activity enters the review chain.
- Respond to returns. A reviewer may return it with comments; it comes back to your Workbench.
The review chain
Activities and their parent requirements move through a governed chain configured for your tenant. The default requirement chain is:
Work then Department Review then Compliance Review then Management Approval then Closed
Lighter chains are available and can be bound by tenant and routing tier. Every review stage enforces segregation of duties: the person who did the work cannot be the person who reviews it.
See Workflow Templates and Segregation of Duties.
Assignment
Activities can be assigned to an individual or to a team. As with requirements, assignment is an offer the recipient accepts.
Requires obligations.assign or work.assign. Accepting requires ownership.accept.
Deadlines
Where an activity carries a due date, it appears on the GRC Calendar and drives reminder and escalation behaviour through your tenant's SLA policy.
Setting requirement and framework compliance deadlines requires deadline.configure. SLA policy is configured under Administration and requires sla.configure.
Permissions
| Action | Permission |
|---|---|
| View activities | obligations.read |
| Update responses | obligations.update |
| Assign owners and split obligations | obligations.assign or work.assign |
| Review submissions | obligations.review |
| Act on assigned work | work.act |
| Participate in the review chain | work.review |
| Escalate within the chain | work.escalate |
Example
An outsourcing requirement reads: "Institutions shall notify the supervisor at least 30 days before entering a material outsourcing arrangement and shall maintain a register of all such arrangements."
Two activities:
| Activity | Owner | Cadence |
|---|---|---|
| Pre-notification process for material outsourcing | Procurement | Per arrangement |
| Maintain and reconcile the material outsourcing register | Third-Party Risk | Quarterly |
The Procurement activity is evidenced by notification records for each arrangement entered in the period. The Third-Party Risk activity is evidenced by the quarterly reconciliation between the register and the TPRM engagement register.
When the reconciliation finds three arrangements missing from the register, that is a genuine gap. The activity is submitted with an honest response, a finding is raised, and the requirement's compliance position moves to Partially Complied — not Complied because the notification duty was met.
Troubleshooting
"I cannot submit an activity." Check that a response is recorded and required evidence is attached. Chains can require both.
"An activity came back to me." It was returned by a reviewer. The return reason is on the activity timeline.
"I cannot review an activity I worked on." That is segregation of duties operating as designed. A different reviewer is required.
"An activity has no due date and no reminders." Due dates are set deliberately, not derived. A missing date means no deadline was captured — never a fabricated one.