Workflow Template
Compliance Incident Management Workflow
Manages compliance breach incidents end-to-end: intake from reporter, AI-assisted severity classification, owner assignment and investigation, corrective action approval, management escalation for high-severity cases, notification confirmation, and incident closure.
It's Friday afternoon and someone just reported a possible data breach — now what? This workflow takes it from that first report all the way through AI-assisted severity classification, owner assignment, investigation, corrective action approval, and closure, automatically escalating anything serious to management. Your team gets a consistent, auditable process instead of scattered emails and spreadsheets, and nothing falls through the cracks because every step, decision, and sign-off is tracked in one place.
Business Outcomes
- Cut incident acknowledgement time from days to minutes
- Ensure 100% of high-severity incidents are automatically escalated to management
- Create a full audit trail for every compliance breach for regulators or auditors
- Reduce manual chasing for approvals and corrective action sign-off
- Standardise severity classification across every reported incident
Workflow Steps
Steps
- 1Create Incident Recordcreate record
Registers the reported incident as a compliance_incident record.
- 2Set Status to Openupdate record
Marks the incident as Open on creation.
- 3Acknowledge Receipt to Reportersend email
Confirms the incident report has been received.
- 4AI Severity Classificationai classification
Uses AI to classify the incident severity based on the reported details.
- 5Check Classification Confidence
Routes low-confidence classifications to human review.
_ai_clf_classify_severity_needs_human_review: "true"→Compliance Reviews SeverityDefault→Record AI-Classified Severity - 6Compliance Reviews Severitycreate task
Compliance team manually determines severity when AI confidence is low.
- 7Record Manually Set Severityupdate record
Persists the compliance team's manual severity decision to the record.
- 8Record AI-Classified Severityupdate record
Persists the AI-determined severity to the record.
- 9Assign Investigation Ownerassign user
Assigns a compliance owner to investigate the incident.
- 10Set Status to Under Investigationupdate record
Updates status as investigation begins.
- 11Check for High Severity Escalation
Escalates high-severity incidents to management for awareness while investigation proceeds.
severity: "high"→Escalate to ManagementDefault→Owner Investigates and Records Findings - 12Escalate to Managementcreate task
Notifies management of the high-severity incident and marks it escalated.
- 13Set Status to Escalatedupdate record
Marks the incident as escalated to management.
- 14Owner Investigates and Records Findingscreate task
The assigned owner investigates and records findings, required notifications and proposed corrective actions.
- 15Persist Investigation Detailsupdate record
Saves findings, notifications and corrective actions to the record and sets status to Pending Approval.
- 16Request Approval of Corrective Actionsrequest approval
Compliance lead reviews findings and corrective actions for approval before closure.
- 17Route on Approval Outcome
Routes based on whether the corrective actions were approved or rejected.
approval_status: "approved"→Record Approved Corrective Actionsapproval_status: "rejected"→Return to Owner for RevisionDefault→End - 18Return to Owner for Revisionrestart from step
Corrective actions were rejected; owner must revise findings and resubmit.
- 19Record Approved Corrective Actionsupdate record
Confirms the corrective actions are approved and finalised on the record.
- 20Confirm Required Notifications Sentcreate task
Compliance confirms that any required regulatory or customer notifications have been sent.
- 21Persist Notification Confirmationupdate record
Saves the notification confirmation status to the record.
- 22Close Incidentupdate record
Marks the incident as closed.
- 23Notify Reporter of Closuresend email
Informs the reporter that the incident has been resolved and closed.
Fields
- Reporter Name*
- Reporter Email*
- Reporter Phone
- Incident Details*
- Affected Area / Department*
- Immediate Containment Actions Taken
- +7 more fields
Forms
Compliance Incident Report
7 fields
Data Views
All Compliance Incidents
compliance_incident_ref, affected_area, severity, incident_status +1 more
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Workflows
Similar Categories
FAQs
Do I need to install anything to use this workflow?
No, everything runs directly inside assess.one. You just publish the template and your team starts using it immediately — there's no software to install or IT project to run.
Can my team customise the severity classification logic?
Yes, you can adjust how the AI classification confidence threshold triggers a compliance review, and you can edit the criteria compliance reviewers check manually. All of this is configured directly in the workflow builder without needing developer support.
Who needs access to this workflow?
Typically you'll want reporters (anyone who can log an incident), a compliance reviewer, investigation owners, and management for escalations. You can set roles and permissions for each step inside assess.one so people only see the parts of the process relevant to them.
What happens if the AI severity classification isn't confident?
The workflow includes a confidence check step — if the AI isn't confident enough, the incident routes to a compliance reviewer to manually set the severity instead. This keeps low-confidence classifications from slipping through unchecked.
How does high-severity escalation work?
After severity is set, the workflow checks whether the incident meets your escalation threshold. If it does, it's automatically routed to management, the status is updated to 'Escalated', and management is notified so they can act without waiting on a manual handoff.
Can corrective actions be sent back for revision?
Yes, when corrective actions are submitted for approval, the approver can approve them or send them back to the owner for revision. The workflow tracks this routing automatically so nothing gets lost between rounds of review.
Is this suitable for regulated industries with strict compliance requirements?
Yes, the workflow is built to give you a documented trail from intake to closure, including severity classification, investigation notes, approvals, and notification confirmation. This structure supports the kind of evidence auditors and regulators typically ask for.
How long does implementation take?
There's no lengthy implementation project — you publish the template and it's live in seconds. Your team can start logging and managing incidents through the workflow right away.
Can we confirm notifications were actually sent before closing an incident?
Yes, there's a dedicated step to confirm required notifications have been sent before the incident can move to closure. This stops incidents being closed prematurely without stakeholders or regulators being informed.
What if the investigation reveals a different severity than originally assigned?
The owner records their findings during the investigation, and the workflow keeps a record of both the AI-classified and any manually set severity. This means you always have visibility into how the severity assessment evolved as more information came in.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
