A common compliance problem
The same control is tested again because the mapping is missing
Obligations, policies, controls and evidence are often maintained in separate repositories. A control that supports several requirements may be copied into each framework, assessed several times and reported with different owners.
The platform provides regulatory compliance software capability within the connected risk platform, allowing obligations and evidence to remain related to reusable controls. When a gap appears, the issue and remediation can stay linked to the requirement and the risks it affects.
- Obligations linked to policies
- Reusable control catalogs
- Assessment evidence
- Issues and remediation
An illustrative change
Map a new obligation to work that already exists
When a new obligation is added, the first question should be which policies and controls already address it. Reusing those records avoids creating another compliance checklist with another owner and another evidence request.
If the existing control is not sufficient, the compliance owner can record the gap, assign corrective work and keep the reason for the action visible.
- Review existing controls first
- Record where coverage is partial
- Assign the gap to an accountable owner
- Report unresolved obligations and actions
Traceability
Move in either direction
A reviewer should be able to start with the obligation or the evidence and still understand the chain.
Traceability
From obligation
See the policy, control, owner, evidence, assessment and open issue connected to a requirement.
Traceability
From control
See every obligation and risk that relies on the control before changing or retiring it.
Traceability
From issue
Return to the failed requirement, control evidence and decision that created the remediation work.
Questions answered
Frequently asked questions
Can one control support several obligations?
Yes. Reusable control records can be related to multiple obligations or risks, reducing duplicate descriptions and assessments.
Are control catalogs and policy templates chargeable?
No. Governance templates, including control catalogs, risk catalogs, policies and procedures, are not charged.
How does Parapet connect compliance risk to action?
Compliance risk can remain related to the relevant obligation, policy, control, evidence, issue and remediation decision.
Can evidence and compliance issues have restricted access?
Yes. Parapet applies role-based permissions, groups and specific-user rules at the item level.