Compliance, SoA and controls# Compliance, SoA and controls ## Purpose and tabs **Compliance** brings together **Assessments**, **Repositories** and **SoA & controls**. Administrators manage standards/requirements; the evaluators provide the authorized results. ## References and evaluations A repository contains active requirements. Create an assessment with baseline, scope, evaluator and date: RiskPilot generates one result per requirement. Enter maturity 0–5, status compliant/partial/non-compliant/not applicable/not assessed, proof and corrective action. ## SoA and testing The applicability statement links requirements, controls, risks, actions and evidence. The admin approver is different from the manager. An approved version is immutable; **Review** creates the next one. Tests describe design or effectiveness, procedure, frequency, tester, sample, result, evidence and next review. ## Correspondence and exports Mappings between requirements reuse a proof with provenance and coverage. Assessments and SoA