Risk and compliance management guide

Design the operating model before choosing compliance software

Turn a vague request for “one GRC system” into concrete records, roles, decisions, evidence, exception paths, measures, and a pilot the business can evaluate.

Use this guide to define requirements and product boundaries. It is not a legal interpretation or a substitute for your risk and compliance professionals.

Start with Jodoo’s Free plan for up to five users. No credit card required.

  • A record map from obligation and risk to evidence and verified action
  • Distinct lifecycles for risk, compliance, findings, and decisions
  • A difficult-state pilot that exposes weak handoffs and misleading dashboards
  1. 01Define scope
  2. 02Map records
  3. 03Separate lifecycles
  4. 04Assign roles
  5. 05Design exceptions
  6. 06Choose measures
  7. 07Pilot and improve
Requirements map

Begin with decisions and evidence, not product modules

Write each requirement as a trigger, managed record, accountable decision, evidence, and finish condition.

Business trigger

A new obligation, risk signal, failed test, expired evidence, finding, exception request, or completed action starts work.

Managed record

Give obligation, risk, control, test, evidence, finding, action, and decision their own identity and lifecycle.

Accountable decision

Name who can accept exposure, return weak work, verify completion, retire a control, or close a risk.

Finish condition

Define the evidence that proves the control, action, decision, or closure is complete.

Lifecycle design

Do not force four kinds of work into one status list

Risk, obligations, findings, and decisions change for different reasons.

01

Risk lifecycle

Identified, assessed, treated, monitored, accepted, controlled, closed, or reopened.

02

Compliance lifecycle

Applicable, owned, controlled, evidence due, tested, action open, current, or retired.

03

Finding lifecycle

Open, triaged, remediating, blocked, ready for verification, verified, or reopened.

04

Decision lifecycle

Draft, submitted, returned, approved, rejected, expired, renewed, or closed.

Roles and permissions

Put judgment and execution in the right hands

A single “compliance owner” field hides the real handoffs.

Business owner

Owns the operating risk, treatment, and current context.

Control owner

Performs the control and maintains usable evidence.

Tester or reviewer

Challenges evidence and records an independent conclusion where required.

Decision owner

Accepts, returns, rejects, expires, or closes within defined authority.

Measures

Measure whether evidence, remediation, and decisions are healthy

Completion counts alone reward activity without showing whether risk changed.

Evidence currency

Current, due soon, overdue, expired, or unusable evidence by obligation and owner.

Can we demonstrate it?

Control outcome

Effective, partial, ineffective, not tested, and the finding path behind the result.

Did the control work?

Remediation health

Open, due, blocked, waiting, ready to verify, verified, and reopened actions.

Is exposure changing?

Decisions waiting for action

Residual-risk and exception decisions awaiting review, returned, expiring, or overdue.

Who must decide?
Pilot plan

Prove the difficult states before scaling

A happy-path demo can approve almost any platform.

01

Choose one real process

Use one business area with named owners and meaningful evidence.

02

Load representative states

Include current, due, overdue, failed, blocked, returned, accepted, verified, and retired records.

03

Run every handoff

Test submission, ownership, challenge, correction, the native Risk Decision route, operational verification, and reopen.

04

Change one rule

Ask an administrator to add a field, threshold, route, role view, or dashboard.

05

Review the source evidence

Open records behind every dashboard signal and document remaining gaps.

Architecture boundary

Decide what Jodoo owns and what specialist products supply

A coherent architecture is often stronger than asking one platform to pretend it does everything.

Jodoo owns

Tailored business records, cross-functional handoffs, the Risk Decision workflow, remediation tracking, dashboards, and rapid adaptation.

Specialist products own

Regulatory content, technical collectors, quantitative risk, assurance methodology, or regulated validation.

Source systems own

The transactions, identities, assets, security telemetry, contracts, suppliers, or incidents that generate facts.

Integration owns

Stable identity, timing, permissions, error recovery, and traceability between systems.

How to use this guide

Treat the reference App as a requirements test, not a compliance opinion

The guide uses the configured Jodoo App to frame questions about records, roles, evidence, decisions, and system boundaries. Your legal, risk, security, audit, and regulatory specialists still decide what applies and what evidence is sufficient.

  • The working example contains 42 linked records across normal and exception states.
  • The native approval evidence is limited to residual-risk and exception decisions.
  • Last reviewed September 19, 2026 against the App shown on this page.
Practical questions

Risk and compliance management guide · Practical questions

How do I write risk and compliance software requirements?+

Define triggers, records, fields, relationships, lifecycles, roles, permissions, exceptions, decisions, evidence, views, measures, integrations, retention, and finish conditions.

Should risk and compliance share one system?+

They can share relationships and reporting while retaining different lifecycles. The deciding factor is whether shared data and action outweigh specialist methods and controls.

What sample data should a pilot include?+

Include normal, due-soon, overdue, failed, blocked, waiting, returned, approved, expiring, verified, reopened, and retired states where they apply.

How should Jodoo be evaluated?+

Test whether the App matches the required records and decisions, users can complete the work, dashboards open the evidence, and administrators can make and retest a controlled change quickly.

What should happen after the pilot?+

Document accepted scope, gaps, ownership, permissions, integrations, migration, training, monitoring, change control, and the specialist capabilities that remain outside Jodoo.

Try the complete workflow

Use a populated model to challenge the requirements

Inspect the reference App, test difficult states, and turn each gap into a clear configuration, integration, or specialist-product decision.

Explore the reference App