Implementing a compliance strategy
From the boardroom decision to daily operations — a practical playbook with models and templates.
Compliance becomes durable only when it is built into how a company decides, staffs, structures its data and operates day-to-day — buying a tool alone does not fix it. This practical playbook walks through the five stages of implementation (leadership, business, people, data and operations), grounded in the ISO 37301 compliance-management-system model and the IIA Three Lines Model. It includes models to copy and templates to fill in — a governance model, a compliance data model, a continuous-compliance loop, a maturity model, a 90-day roadmap, a RACI matrix, a KPI scorecard and more.
- The five-stage implementation arc: leadership → business → people → data → operations
- Governance with the IIA Three Lines Model and ISO 37301
- A compliance data model and a continuous-compliance (PDCA) loop
- Ready-to-use templates: policy, business case, RACI, product data, supplier request, roadmap, KPIs, register
Grounded in ISO 37301:2021, the IIA Three Lines Model (2020), GPSR and ESPR.
Companion toolkit — every template from this paper as a ready-to-use Excel workbook (fill manually or auto-sync from Conphora).