Every material change must be formally requested.
Governance
Reference pack demo
Generalizes strongest governance concepts from SOX-controlled technology environments without claiming SOX certification.
Requirements (25)
- The requestor of the change must be identified.
- The affected system must be identified.
- Business and technical impact must be assessed.
- Financial-reporting impact must be classified when applicable.
- Security impact must be assessed.
- Privacy impact must be assessed.
- AI or model impact must be assessed when change category is model.
- Data impact must be assessed.
- At least one independent approver must be recorded.
- Requestor cannot also be the sole approver.
- Testing evidence must be attached before production.
- Approval must occur before production deployment.
- Emergency changes must be explicitly designated.
- Emergency changes require retrospective review scheduling.
- Rollback procedures must be documented.
- Production implementation must be verified.
- Deviations from standard process must be recorded.
- Related controls must be identified.
- Evidence must remain available for review.
- Change lifecycle state must be beyond draft for reporting.
- Failed controls must have remediation tracked.
- Material changes must have an assigned steward.
- Downstream effects must be tracked via relationships.
- Actual outcomes must be compared with expected outcomes.