Operational controls
Specific controls for the identified noncompliance risks, built into everyday processes.
Third-party due diligence
Assessing the compliance risk of business partners, suppliers and other relevant third parties.
Delegation of authority
Clear authority and approval limits for decisions carrying compliance risk.
What an auditor usually asks for
- Documented compliance controls by risk
- A due diligence assessment for relevant third parties
- An authority delegation matrix for critical decisions
- An approval log for risk-bearing operations
How to cover operation in Kimobox
- 1Document compliance controls directly on the process map.
- 2Log due diligence for every relevant third party from the supplier portal.
- 3Set up the authority delegation matrix in the system.
Every third party's due diligence stays linked to their record, with the re-evaluation scheduled.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO 37301:2021 — Compliance management systems. Requirements with guidance for use ISO · April 2021
- Ley 2/2023 on the protection of persons who report regulatory breaches BOE-A-2023-4513 · 21 February 2023
- ISO 37001:2016 — Anti-bribery management systems ISO · 2016 ed.