Governance & Compliance
Governance and compliance workflows for declarations, reviews, approvals, controlled documents, obligations, and accountable decision-making.
Governance & Compliance Templates(18)
Policy Review and Approval Workflow
Governance workflow for reviewing and approving policy drafts or revisions. The policy owner submits the policy, reason for review, and draft. Stakeholders review it, with legal/compliance review where required, then the approval authority signs off. Approved policies are published, prior versions superseded, and the next review date set. Requested changes are routed back to the owner for revision.
Regulatory Change Management Workflow
Manages the end-to-end lifecycle of a regulatory change: intake of a new/changed requirement, applicability assessment, gap analysis and implementation planning, policy/control updates and communications, reviewer sign-off, and closure with stakeholder notification.
Compliance Incident Management Workflow
Manages compliance breach incidents end-to-end: intake from reporter, AI-assisted severity classification, owner assignment and investigation, corrective action approval, management escalation for high-severity cases, notification confirmation, and incident closure.
Gifts and Hospitality Declaration Workflow
Enables declarers to submit gift and hospitality declarations with details on the other party, value, and business context. The workflow automatically routes declarations below the policy threshold straight into the compliance register, while higher-value declarations are sent to compliance for formal approval. Approved and auto-recorded declarations are added to the register and the declarer is notified; rejected declarations are closed out with the declarer notified of the reason.
Whistleblower Reporting Workflow
Confidential intake of misconduct reports (with optional anonymity), compliance triage and investigator assignment, recording of findings and recommended outcome, approval of the outcome, remediation tracking, and closure with optional reporter notification when contact details were provided.
Policy Acknowledgement Workflow
Allows a policy owner to submit a policy, assign it to a staff recipient, and track acknowledgement. The recipient is assigned a task to review the policy and confirm they have read it. A due date is set for follow-up on outstanding acknowledgements. Once acknowledged, the record is marked complete and the owner is notified.
Contractor Onboarding Workflow
Coordinator submits contractor company, worker, services, licence, insurance and safety document details. Compliance runs due diligence on the documents; if any are missing or deficient, they are requested from the contractor and rechecked until complete. The contractor then completes a site induction acknowledgement, site access is routed for approval, granted and recorded with a due date for expiring documents, and the coordinator is notified when onboarding completes or access is declined.
Supplier Risk Assessment Workflow
Captures a supplier risk assessment request, triages inherent risk with AI, runs due diligence, adds a security/privacy review when sensitive data or critical systems are accessed, has a reviewer record the risk treatment plan, gates residual risk acceptance through formal approval, sets a reassessment date, and notifies the requester of the outcome.
Marketing Content Approval Workflow
Manages review and approval of marketing content (blogs, emails, social posts) from submission through editorial review, brand sign-off, optional compliance review, revision loops, and final publishing handoff with owner notification.
Internal Audit Workflow
Plans, executes, and closes internal audits: lead auditor defines scope and schedule, auditor performs fieldwork and records findings, the audited area supplies management responses and corrective actions, the report is approved, corrective actions are followed up and verified, and stakeholders are notified on closure.
Privacy Impact Assessment Workflow
Enables a privacy team to intake initiatives involving personal information, screen them for privacy risk, conduct a full privacy impact assessment where required, obtain reviewer sign-off, record residual risk acceptance and treatment actions, close the assessment, and schedule a future reassessment.
Data Subject Access Request Workflow
Handles individuals' requests to access their personal information: captures identity details, request scope and contact preference; verifies identity; collects and redacts relevant records; routes the response through privacy review; delivers it securely; tracks the statutory deadline; and closes the request.
Data Breach Response Workflow
Manages the end-to-end privacy incident response process: intake of a suspected data breach report, responder investigation and impact assessment, legal/privacy review with a notification decision, remediation and required communications, and formal incident closure with corrective actions recorded.
Contract Renewal Workflow
Manages expiring contracts from intake through review, renewal decision, and either commercial/legal approval leading to signature-ready renewal, or termination handoff. Notifies the contract owner of the final decision.
Contract Review and Approval Workflow
Captures a contract submission from an owner, routes it through legal review (with redlines), triggers finance approval for higher-value contracts, has the owner address redlines, then routes for final approval — marking approved contracts ready for signature or returning rejected ones to the owner for revision.
Workplace Complaint and Investigation Workflow
Enables employees to confidentially report workplace concerns (bullying, harassment, conduct). HR triages the complaint, assigns an investigator who records findings and a recommended outcome, and management approves the outcome. Approved cases have agreed actions recorded and closure confirmed with the reporter; unsubstantiated complaints are closed with a documented reason.
Document Review and Approval Workflow
End-to-end controlled document lifecycle: draft submission, multi-reviewer comments and revisions, management approval, version tracking, publication/distribution, optional acknowledgement collection, and scheduled review date setting.
Conflict of Interest Declaration Workflow
Allows employees, contractors, board members, and other relevant persons to disclose actual, potential, or perceived conflicts of interest. Covers initial disclosure, risk assessment, management action planning, approval, declarant acknowledgement, periodic review, and closure.
