Our own servers in Europe · GDPR · Support in your language

Module 3 of 7 · ISO 37301 · Clause 6

Planning

Planning in compliance means identifying where compliance could fail and setting concrete objectives to reduce that risk.

Content reviewed on

Compliance risk assessment

Identifying and assessing noncompliance risks by area, with their likelihood and impact.

Compliance objectives

Measurable objectives, consistent with the policy, with an action plan and an assigned owner.

Planning of changes

Assessing the compliance impact of any relevant change in the organization or its activity.

What an auditor usually asks for

  • A compliance risk matrix by area
  • Compliance objectives with an indicator, an owner and a date
  • An action plan per objective with tracking
  • A compliance impact assessment for relevant changes

How to cover planning in Kimobox

  1. 1Log the compliance risk matrix with its owner and linked action.
  2. 2Define compliance objectives with an indicator and let the system track them.
  3. 3Document the impact assessment for every relevant change.

The compliance risk map stays linked to the actions that mitigate it, not a static document.

See how objectives and indicators work in Kimobox

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO 37301:2021 — Compliance management systems. Requirements with guidance for use ISO · April 2021
  2. Ley 2/2023 on the protection of persons who report regulatory breaches BOE-A-2023-4513 · 21 February 2023
  3. ISO 37001:2016 — Anti-bribery management systems ISO · 2016 ed.