assess.one – AI-powered business operations platform

Workflow Template

Regulatory Change Management Workflow

Manages the end-to-end lifecycle of a regulatory change: intake of a new/changed requirement, applicability assessment, gap analysis and implementation planning, policy/control updates and communications, reviewer sign-off, and closure with stakeholder notification.

This workflow is designed for compliance, risk, and legal teams responsible for tracking and responding to new or amended regulatory requirements. It automates the full lifecycle — applicability assessment, gap analysis, implementation planning, policy updates, and reviewer sign-off — so nothing falls through the cracks between identification and closure. The result is a defensible, auditable trail showing exactly how each regulatory change was assessed, actioned, and communicated to stakeholders.

Business Outcomes

  • Reduce time-to-closure on regulatory changes by standardising assessment and sign-off steps
  • Eliminate missed deadlines through automated due-date tracking on implementation plans
  • Create a full audit trail for every regulatory change decision, supporting regulator and auditor reviews
  • Cut manual follow-up effort by automating owner and stakeholder notifications at each stage
  • Improve consistency in applicability and gap analysis across teams and regulatory domains

Workflow Steps

Steps

  1. 1
    Create Regulatory Change Recordcreate record

    Registers the new or changed requirement as a record.

  2. 2
    Set Status: Openupdate record

    Marks the change record as newly opened.

  3. 3
    Assess Applicabilitycreate task

    Owner assesses whether the requirement applies to the organisation.

  4. 4
    Set Status: Under Assessmentupdate record

    Updates the record to reflect applicability assessment has occurred.

  5. 5
    Route on Applicability

    Branches based on whether the requirement applies.

    applies: "Yes"Set Status: Gap Analysis In Progress
    applies: "No"Close as Not Applicable
    DefaultClose as Not Applicable
  6. 6
    Close as Not Applicableupdate record

    Records the non-applicability reason and closes the change.

  7. 7
    Notify Owner - Not Applicablesend email

    Informs the requirement owner that the change was assessed as not applicable and closed.

  8. 8
    Set Status: Gap Analysis In Progressupdate record

    Updates the record as gap analysis begins.

  9. 9
    Perform Gap Analysis & Implementation Plancreate task

    Owner conducts a gap analysis and records an implementation plan with a due date.

  10. 10
    Persist Gap Analysis & Set Due Dateupdate record

    Saves the gap analysis, implementation plan, and sets the record due date for SLA tracking.

  11. 11
    Set Implementation Due Dateset due date

    Applies a default SLA-based due date to the record for tracking (fixed offset; not bound to the captured implementation date).

  12. 12
    Complete Policy/Control Updates & Communicationscreate task

    Owner completes the policy or control updates and any required communications.

  13. 13
    Persist Update Summaryupdate record

    Saves the summary of completed updates and communications to the record.

  14. 14
    Reviewer Sign-Offrequest approval

    A reviewer signs off on the completed implementation before the change is closed.

  15. 15
    Route on Reviewer Sign-Off

    Branches based on whether the reviewer approves the implementation.

    approval_status: "approved"Close Change as Implemented
    approval_status: "rejected"Restart Implementation for Rework
    DefaultEnd
  16. 16
    Restart Implementation for Reworkrestart from step

    Sends the change back to the implementation step for rework after reviewer rejection.

  17. 17
    Close Change as Implementedupdate record

    Marks the change as implemented and closed following sign-off.

  18. 18
    Notify Stakeholders of Closuresend email

    Notifies the requirement owner that the regulatory change has been implemented and closed.

Fields

  • New/Changed Requirement*
  • Description of Requirement*
  • Regulatory Source / Reference
  • Areas Affected*
  • Requirement Owner Email*
  • Requirement Owner Name*
  • +9 more fields

Forms

Regulatory Change Intake

7 fields

Data Views

All Regulatory Changes

requirement_title, affected_areas, change_status, implementation_due_date +1 more

Dashboard Widgets

Changes by StatusRegulatory Change OverviewRegulatory Change Pipeline

Recommended integrations

Setup the following integrations to extend workflow capability.

  • Send email in the workflow

    AWS SES logoAWS SES
regulatory change managementregulatory updatecompliance changelegal changeobligation management

Similar Workflows

Similar Categories

FAQs

Why should we replace our spreadsheet or email-based regulatory change process with this workflow?

Spreadsheets and email threads make it difficult to prove who assessed a change, when, and with what outcome — a common gap in regulator and audit reviews. This workflow captures every status change, assessment, sign-off, and notification automatically inside assess.one, giving you a complete, timestamped record without manual log-keeping. It also removes the risk of changes being forgotten between inboxes.

What is the ROI of automating regulatory change management?

The main returns come from reduced compliance risk exposure, faster turnaround on applicability decisions, and significant time savings from eliminating manual status chasing and notification emails. Teams also avoid the cost of missed implementation deadlines, which can lead to regulatory findings or penalties. Because the template is published instantly, there is no implementation project cost to offset before these gains begin.

How long does it take to get this workflow live?

Publishing the template takes minutes — there is no lengthy setup or IT project required. Once published, your team can immediately start creating regulatory change records and running the process live, with the ability to refine steps as you learn from real cases.

Can we customise the applicability assessment and gap analysis steps?

Yes. All steps, including the applicability assessment, gap analysis, and implementation planning stages, can be edited directly in assess.one to match your organisation's specific criteria and terminology. You can also adjust field requirements, due-date logic, and routing rules without needing developer support.

Who should have access to this workflow?

Typically, compliance officers or regulatory change owners initiate and manage records, policy and control owners contribute to implementation, and designated reviewers perform sign-off. Access and permissions for each role can be configured directly in assess.one, ensuring only authorised users can approve or close a change.

What happens if a regulatory change is deemed not applicable?

The workflow routes the record to a 'Close as Not Applicable' step, automatically notifying the owner and closing the record without further action. This decision point is still logged in the record history, preserving the rationale for future audit or regulator queries.

What happens if the reviewer rejects the sign-off?

If reviewer sign-off is not approved, the workflow automatically routes the record back to the implementation stage for rework rather than closing it. This ensures policy and control updates meet review standards before the change can be marked as implemented and closed.

How does this workflow support compliance and audit requirements?

Every stage — from applicability assessment through gap analysis, implementation, and sign-off — is recorded with status changes, due dates, and notifications, creating a complete audit trail. This structure supports internal audit, external regulator reviews, and demonstrates due diligence in managing regulatory obligations.

Can notifications and integrations be configured to match our existing tools?

Yes, notifications such as owner alerts and stakeholder closure updates are configured directly inside assess.one, including email and Slack integrations. No third-party development work is required to connect these notifications to your team's existing communication channels.

How does this compare to building a custom regulatory change tracker?

A custom-built tracker typically requires a development project, ongoing maintenance, and delays before your team can use it. This template is ready to publish immediately, already structured around a proven regulatory change lifecycle, and can be customised within assess.one as your requirements evolve, avoiding both the build time and long-term maintenance overhead.

Ready to use this workflow?

Create a free account and customise this workflow for your business.

Regulatory Change Management Workflow | assess.one