Business Flows
Compliance
The regulations that shape process design — each broken into clause-level obligations with their risk, penalties and the controls that satisfy them, linked to the processes they govern.
EU Artificial Intelligence Act
Official source →EU/2024/1689 · European Union · effective 2024-08-01
Max penalty: EUR 35,000,000 or 7% of global annual turnover (prohibited practices)
5 obligations mapped to processes
Obligations of deployers of high-risk AI systems
Prohibited AI practices
Transparency obligations for certain AI systems
High-risk AI system classification
Obligations for high-risk AI systems
General Data Protection Regulation (GDPR)
Official source →EU/2016/679 · European Union · effective 2018-05-25
Max penalty: EUR 20,000,000 or 4% of global annual turnover
9 obligations mapped to processes
Information to be provided to data subjects
Automated individual decision-making, including profiling
Data protection by design and by default
Processor obligations and Data Processing Agreements
Security of processing
Data Protection Impact Assessment (DPIA)
Principles relating to processing of personal data
Lawfulness of processing
General conditions for imposing administrative fines
GxP — EU Annex 11: Computerised Systems
Official source →EU/Annex11/2011 · EU + USA (FDA) · effective 2011-06-30
Max penalty: Manufacturing licence revocation; product recall; criminal prosecution
4 obligations mapped to processes
Data integrity — ALCOA+ principles
Validation of computerised systems
Audit trail and electronic records integrity
Deviation management and CAPA
ISO/IEC 27001:2022 Information Security Management
Official source →ISO/IEC 27001:2022 · International · effective 2022-10-25
3 obligations mapped to processes
Supplier relationships and cloud service security
Organisational, people, physical and technological controls
Information security risk assessment and treatment
Sarbanes-Oxley Act (SOX)
Official source →US/107-204 · USA (applies to all SEC-listed companies globally) · effective 2002-07-30
Max penalty: Up to USD 5M fine + 20 years imprisonment for wilful violation (CEO/CFO)
3 obligations mapped to processes
Segregation of duties in financial processes
CEO and CFO certification of financial statements
Internal controls over financial reporting (ICFR)
See how each obligation maps to specific processes — with the key controls and BPM/AI relevance — with the Business Flows Assistant.
Open the Business Flows Assistant