Primary sources
Source register · reviewed 24 September 2026. Use the linked publications to verify framework scope and applicability.
Inspect the exact schema ↗
ABDULLAH AL OWASIGovernance / Linked records, review criteria & decision outputs
Connect versioned policies, approval responsibilities, attestations and justified exceptions to accountable decisions.
Connect versioned policies, approval responsibilities, attestations and justified exceptions to accountable decisions.
Connect versioned policies, approval responsibilities, attestations and justified exceptions to accountable decisions.
Use the shared policy register. Fields: id, title, owner, status, reviewDate, notes, version, approver, approvalDate, attested, requiredAttestations, exceptionRationale. Records link by ID to related entities. Validate inputs, assign an owner and set a review date.
Related workflows: regulatory-obligations, executive-risk, continuous-assurance. Reuse linked records in suite views rather than duplicating facts. The suite and specialist workspace use distinct import formats; export and reconcile records explicitly when crossing between them.
Review required fields, supporting evidence, relationships and decision rationale. Export the suite JSON dataset for handover. This workflow organizes oversight metadata; external collection, recovery testing and regulatory interpretation require separately verified evidence.
Source register · reviewed 24 September 2026. Use the linked publications to verify framework scope and applicability.
Inspect the exact schema ↗Adapt this pattern
Bring the real decision boundary, authorized metadata, evidence available, accountable reviewers and target date. The workflow can then be scoped around explicit outputs and acceptance criteria.
Use the linked source records and assessment dates to review the scenario basis.