| Order | Tab | Content in the tab |
|---|---|---|
| 1 | Source & Applicability | Question: Where did this requirement come from, and why does it apply to this company? → Identify source: law, regulation, framework, contract, customer, industry standard, or internal policy. → Explain why it applies to LondonBuild. |
| 2 | Requirement | Record the exact requirement. Example: ISO 27001 A.5.15 — Access Control. |
| 3 | Requirement Interpretation | Explain in simple business language what the requirement is asking LondonBuild to do. |
| 4 | Scope | Determine what parts of the company the requirement applies to: departments, systems, locations, employees, contractors, data, processes, etc. |
| 5 | Applicability | Confirm whether the requirement is Applicable, Not Applicable, or Partially Applicable, with justification. |
| 6 | Control Identification | Identify the control(s) LondonBuild uses to satisfy the requirement. |
| 7 | Control Owner | Identify who is responsible for operating the control. Example: IT Manager. |
| 8 | Evidence Request | Define what evidence you need to prove the control exists and operates. |
| 9 | Control Testing | Test the evidence: Is it current? Complete? Approved? Relevant? Operating effectively? |
| 10 | Assessment Result | Record Pass / Partial / Fail and document your testing result. |
| 11 | Gap | If the requirement/control isn’t adequately satisfied, document exactly what is missing. |
| 12 | Risk | Determine the risk created by the identified gap. |
| 13 | Remediation | Define what LondonBuild needs to do to fix the gap. Assign owner and target date. |
| 14 | Reporting | Report the overall status to management: compliance status, gaps, risks, remediation and outstanding actions. |
The complete flow
1. Where did the requirement come from, and why does it apply?
↓
2. What exactly is the requirement?
↓
3. What does it mean?
↓
4. What is in scope?
↓
5. Does it apply?
↓
6. What control satisfies it?
↓
7. Who owns the control?
↓
8. What evidence proves it?
↓
9. Test the evidence
↓
10. Pass / Partial / Fail
↓
11. Identify the gap
↓
12. Assess the risk
↓
13. Remediate
↓
14. Report
This is a good master workflow to learn because you can apply it to ISO 27001, NIST, SOC 2, PCI DSS, NIS2, DORA, GDPR, etc.