Compliance cartography
Compliance
Scope DERIVES from the map (golden sources + flows carrying sensitive objects); the DPO confirms or excludes each application, with a note. DORA: the exportable ICT third-party register.
0apps in scope0sensitive objects0to confirm0vendors
GDPR — personal-data processing7
- CRM 360master of Personprovides Person to Customer Web Portalprovides Person to Data Warehouse & BI
- Claims Managementmaster of Claimprovides Claim to Fraud Detectionprovides Claim to Data Warehouse & BI
- Fraud Detectionconsumer of Claimcontributor of Risk scorereceives Claim from Claims Management
- Customer Web Portalcontributor of Personreceives Person from CRM 360
- Third-Party Master Datacontributor of Personprovides Person to CRM 360
- Pricing Enginemaster of Risk score
- Data Warehouse & BIexcluded despite evidence — reviewconsumer of Personconsumer of Claimreceives Person from CRM 360
DORA — ICT third-party register6Generate the auditable report →
Vendor
Jurisdiction
Contract criticality
Applications fed
Flows
Max cadence
VendorReinsurance Platform
JurisdictionUS
Contract criticalityCritical
Applications fed—
Flows1
Max cadence—
VendorCRM 360
JurisdictionUE
Contract criticality—
Applications fedCustomer Web Portal, Data Warehouse & BI
Flows3
Max cadenceReal-time
Jurisdiction—
Contract criticality—
Applications fed—
Flows0
Max cadence—
VendorAccounting (ERP)
Jurisdiction—
Contract criticality—
Applications fedData Warehouse & BI, Reinsurance Platform
Flows3
Max cadenceDaily