Phase 1
Obligations map
We identify and classify the applicable obligations: national and sector legislation, regulator requirements, contractual obligations and voluntary commitments taken on.
Compliance and integrity
Compliance is not signing a declaration: it is knowing which obligations apply, who answers for each one, how they are controlled and what evidence is left behind. ISO 37301 turns that into an auditable system.
We build the map of compliance obligations —legal, regulatory, contractual and voluntary— assess the risks associated with each, define controls and owners, and establish the monitoring, reporting and improvement cycle. The outcome is that the Board can answer, with evidence, what obligations the organisation has and how it is managing them.
Phase 1
We identify and classify the applicable obligations: national and sector legislation, regulator requirements, contractual obligations and voluntary commitments taken on.
Phase 2
We assess the likelihood and consequence of breaching each obligation, taking into account penalties, reputational impact and business continuity.
Phase 3
We assign an owner and a control to each material obligation, and document the evidence that must be generated in each case.
Phase 4
We establish indicators, the reporting cycle to the governing body, internal audit and the handling of breaches.
With the obligations map. It is the deliverable that creates the most immediate value and, in many organisations, the first time everything that must be complied with is consolidated in one place.
Uruguay’s Law 18.331 and the rules issued by the data protection authority are obligations that go into the map. The compliance system manages them like any other obligation, drawing on the ISMS controls where one exists.
Yes, and the incremental effort is smaller. They share structure, compliance function, whistleblowing channel and internal audit; what is added is the breadth of the obligations universe.
your business partner