Compliance cartography
Compliance
Scope DERIVES from the map (golden sources + flows carrying sensitive objects); the DPO confirms or excludes each application, with a note. DORA: the exportable ICT third-party register.
Health
0apps in scope0sensitive objects0to confirm0vendors
GDPR — personal-data processing7
- CRM 360master of Personprovides Person to Customer Web Portalprovides Person to Data Warehouse & BI
- Claims Managementmaster of Claimprovides Claim to Fraud Detectionprovides Claim to Data Warehouse & BI
- Fraud Detectionconsumer of Claimcontributor of Risk scorereceives Claim from Claims Management
- Customer Web Portalcontributor of Personreceives Person from CRM 360
- Third-Party Master Datacontributor of Personprovides Person to CRM 360
- Pricing Enginemaster of Risk score
- Data Warehouse & BIexcluded despite evidence — reviewconsumer of Personconsumer of Claimreceives Person from CRM 360
DORA — ICT third-party register6Generate the auditable report →
Vendor
Jurisdiction
Contract criticality
Applications fed
Flows
Max cadence
Vendor
Jurisdiction
US
Contract criticality
Critical
Applications fed
—
Flows
1
Max cadence
—
Vendor
Jurisdiction
UE
Contract criticality
—
Applications fed
Customer Web Portal, Data Warehouse & BI
Flows
3
Max cadence
Real-time
Jurisdiction
—
Contract criticality
—
Applications fed
—
Flows
0
Max cadence
—
Vendor
Jurisdiction
—
Contract criticality
—
Applications fed
Data Warehouse & BI, Reinsurance Platform
Flows
3
Max cadence
Daily