Take the requirement

OrderTabContent in the tab
1Source & ApplicabilityQuestion: Where did this requirement come from, and why does it apply to this company? → Identify source: law, regulation, framework, contract, customer, industry standard, or internal policy. → Explain why it applies to LondonBuild.
2RequirementRecord the exact requirement. Example: ISO 27001 A.5.15 — Access Control.
3Requirement InterpretationExplain in simple business language what the requirement is asking LondonBuild to do.
4ScopeDetermine what parts of the company the requirement applies to: departments, systems, locations, employees, contractors, data, processes, etc.
5ApplicabilityConfirm whether the requirement is Applicable, Not Applicable, or Partially Applicable, with justification.
6Control IdentificationIdentify the control(s) LondonBuild uses to satisfy the requirement.
7Control OwnerIdentify who is responsible for operating the control. Example: IT Manager.
8Evidence RequestDefine what evidence you need to prove the control exists and operates.
9Control TestingTest the evidence: Is it current? Complete? Approved? Relevant? Operating effectively?
10Assessment ResultRecord Pass / Partial / Fail and document your testing result.
11GapIf the requirement/control isn’t adequately satisfied, document exactly what is missing.
12RiskDetermine the risk created by the identified gap.
13RemediationDefine what LondonBuild needs to do to fix the gap. Assign owner and target date.
14ReportingReport the overall status to management: compliance status, gaps, risks, remediation and outstanding actions.

The complete flow

1. Where did the requirement come from, and why does it apply?

2. What exactly is the requirement?

3. What does it mean?

4. What is in scope?

5. Does it apply?

6. What control satisfies it?

7. Who owns the control?

8. What evidence proves it?

9. Test the evidence

10. Pass / Partial / Fail

11. Identify the gap

12. Assess the risk

13. Remediate

14. Report

This is a good master workflow to learn because you can apply it to ISO 27001, NIST, SOC 2, PCI DSS, NIS2, DORA, GDPR, etc.