Workflow Template
Regulatory Change Management Workflow
Manages the end-to-end lifecycle of a regulatory change: intake of a new/changed requirement, applicability assessment, gap analysis and implementation planning, policy/control updates and communications, reviewer sign-off, and closure with stakeholder notification.
This workflow is designed for compliance, risk, and legal teams responsible for tracking and responding to new or amended regulatory requirements. It automates the full lifecycle — applicability assessment, gap analysis, implementation planning, policy updates, and reviewer sign-off — so nothing falls through the cracks between identification and closure. The result is a defensible, auditable trail showing exactly how each regulatory change was assessed, actioned, and communicated to stakeholders.
Business Outcomes
- Reduce time-to-closure on regulatory changes by standardising assessment and sign-off steps
- Eliminate missed deadlines through automated due-date tracking on implementation plans
- Create a full audit trail for every regulatory change decision, supporting regulator and auditor reviews
- Cut manual follow-up effort by automating owner and stakeholder notifications at each stage
- Improve consistency in applicability and gap analysis across teams and regulatory domains
Workflow Steps
Steps
- 1Create Regulatory Change Recordcreate record
Registers the new or changed requirement as a record.
- 2Set Status: Openupdate record
Marks the change record as newly opened.
- 3Assess Applicabilitycreate task
Owner assesses whether the requirement applies to the organisation.
- 4Set Status: Under Assessmentupdate record
Updates the record to reflect applicability assessment has occurred.
- 5Route on Applicability
Branches based on whether the requirement applies.
applies: "Yes"→Set Status: Gap Analysis In Progressapplies: "No"→Close as Not ApplicableDefault→Close as Not Applicable - 6Close as Not Applicableupdate record
Records the non-applicability reason and closes the change.
- 7Notify Owner - Not Applicablesend email
Informs the requirement owner that the change was assessed as not applicable and closed.
- 8Set Status: Gap Analysis In Progressupdate record
Updates the record as gap analysis begins.
- 9Perform Gap Analysis & Implementation Plancreate task
Owner conducts a gap analysis and records an implementation plan with a due date.
- 10Persist Gap Analysis & Set Due Dateupdate record
Saves the gap analysis, implementation plan, and sets the record due date for SLA tracking.
- 11Set Implementation Due Dateset due date
Applies a default SLA-based due date to the record for tracking (fixed offset; not bound to the captured implementation date).
- 12Complete Policy/Control Updates & Communicationscreate task
Owner completes the policy or control updates and any required communications.
- 13Persist Update Summaryupdate record
Saves the summary of completed updates and communications to the record.
- 14Reviewer Sign-Offrequest approval
A reviewer signs off on the completed implementation before the change is closed.
- 15Route on Reviewer Sign-Off
Branches based on whether the reviewer approves the implementation.
approval_status: "approved"→Close Change as Implementedapproval_status: "rejected"→Restart Implementation for ReworkDefault→End - 16Restart Implementation for Reworkrestart from step
Sends the change back to the implementation step for rework after reviewer rejection.
- 17Close Change as Implementedupdate record
Marks the change as implemented and closed following sign-off.
- 18Notify Stakeholders of Closuresend email
Notifies the requirement owner that the regulatory change has been implemented and closed.
Fields
- New/Changed Requirement*
- Description of Requirement*
- Regulatory Source / Reference
- Areas Affected*
- Requirement Owner Email*
- Requirement Owner Name*
- +9 more fields
Forms
Regulatory Change Intake
7 fields
Data Views
All Regulatory Changes
requirement_title, affected_areas, change_status, implementation_due_date +1 more
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Workflows
Similar Categories
FAQs
Why should we replace our spreadsheet or email-based regulatory change process with this workflow?
Spreadsheets and email threads make it difficult to prove who assessed a change, when, and with what outcome — a common gap in regulator and audit reviews. This workflow captures every status change, assessment, sign-off, and notification automatically inside assess.one, giving you a complete, timestamped record without manual log-keeping. It also removes the risk of changes being forgotten between inboxes.
What is the ROI of automating regulatory change management?
The main returns come from reduced compliance risk exposure, faster turnaround on applicability decisions, and significant time savings from eliminating manual status chasing and notification emails. Teams also avoid the cost of missed implementation deadlines, which can lead to regulatory findings or penalties. Because the template is published instantly, there is no implementation project cost to offset before these gains begin.
How long does it take to get this workflow live?
Publishing the template takes minutes — there is no lengthy setup or IT project required. Once published, your team can immediately start creating regulatory change records and running the process live, with the ability to refine steps as you learn from real cases.
Can we customise the applicability assessment and gap analysis steps?
Yes. All steps, including the applicability assessment, gap analysis, and implementation planning stages, can be edited directly in assess.one to match your organisation's specific criteria and terminology. You can also adjust field requirements, due-date logic, and routing rules without needing developer support.
Who should have access to this workflow?
Typically, compliance officers or regulatory change owners initiate and manage records, policy and control owners contribute to implementation, and designated reviewers perform sign-off. Access and permissions for each role can be configured directly in assess.one, ensuring only authorised users can approve or close a change.
What happens if a regulatory change is deemed not applicable?
The workflow routes the record to a 'Close as Not Applicable' step, automatically notifying the owner and closing the record without further action. This decision point is still logged in the record history, preserving the rationale for future audit or regulator queries.
What happens if the reviewer rejects the sign-off?
If reviewer sign-off is not approved, the workflow automatically routes the record back to the implementation stage for rework rather than closing it. This ensures policy and control updates meet review standards before the change can be marked as implemented and closed.
How does this workflow support compliance and audit requirements?
Every stage — from applicability assessment through gap analysis, implementation, and sign-off — is recorded with status changes, due dates, and notifications, creating a complete audit trail. This structure supports internal audit, external regulator reviews, and demonstrates due diligence in managing regulatory obligations.
Can notifications and integrations be configured to match our existing tools?
Yes, notifications such as owner alerts and stakeholder closure updates are configured directly inside assess.one, including email and Slack integrations. No third-party development work is required to connect these notifications to your team's existing communication channels.
How does this compare to building a custom regulatory change tracker?
A custom-built tracker typically requires a development project, ongoing maintenance, and delays before your team can use it. This template is ready to publish immediately, already structured around a proven regulatory change lifecycle, and can be customised within assess.one as your requirements evolve, avoiding both the build time and long-term maintenance overhead.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
