Skip to Content
Welcome to the Novantra documentation.
GuidesGovernanceModulesRegulatory Register

Regulatory Register

The Regulatory Register module is where an organization keeps a governed view of the rules, circulars, standards, source updates, applicability decisions, obligations, posture, review work, and export requests that matter to a compliance program.

It is not a control library. Controls live in the controls module. The regulatory register is the traceability surface that explains which source applies, why it applies, what it maps to, what needs review, and what can be exported for auditors or regulators.

When to use it

Use the regulatory register when you need to maintain:

  • A legal register for applicable laws, circulars, and standards.
  • A statement of applicability for a framework or internal governance profile.
  • A source-change review queue after a new circular, standard, or catalog package arrives.
  • A register matrix that links source records to framework nodes, applicability decisions, obligations, controls, evidence requirements, responsibilities, and posture.
  • Review cycles for recurring or event-driven regulatory review.
  • Export requests for Legal Register or SoA evidence through Audit Packages.

The profile family is tenant-managed. You can create profiles such as legal_register, statement_of_applicability, circular_register, or another internal family without Novantra hardcoding sector or framework behavior.

Profiles and source sets can also be adopted from reviewed catalog packages. When a package decision is applied, Regulatory Register creates or reuses local profile/source-set records, stores safe source rows and policy snapshots for local setup, and keeps catalog lineage evidence. Catalog content remains the source package; the local register remains the operational truth.

What you see in the product

Regulatory Register lives under Governance -> Regulatory Register.

The console has these tabs:

  • Profiles: tenant-owned register definitions such as Legal Register or SoA.
  • Source sets: governed-source selections that feed a profile.
  • Triage: source-change, import, or impact-review items that need a decision.
  • Register matrix: projections over source, framework, applicability, obligation, implementation, and posture references.
  • Review cycles: planned or event-driven review work.
  • Exports: register export requests routed through Audit Packages.

Every write requires a reason and is recorded in the workspace audit trail.

How it fits with other modules

Regulatory Register consumes other foundations instead of replacing them:

  • Governed Source owns source truth and imported source versions.
  • Frameworks own framework versions and nodes.
  • Applicability owns applicability decisions.
  • Obligations own obligation records and obligation links.
  • Controls, Evidence, Responsibilities, Findings, and Exceptions own their respective governance records.
  • Compliance Posture owns posture models and posture projections.
  • Work Management owns reusable task, due-date, and expiry descriptors.
  • Audit Packages owns export fields, templates, packages, and generation requests.

The register may keep snapshots for review and export history, but the underlying records remain owned by their modules.

Regulatory Register publishes safe export-field descriptors for profiles, source sets, triage, projections, review cycles, and export requests. It also publishes work descriptors for source triage and register reviews, plus an expiry descriptor for source-driven register projections.

Typical workflow

  1. Create a profile such as Legal Register or SoA.
  2. Link the profile to governed-source records through source sets.
  3. Review triage items created from source changes or imports.
  4. Record or rebuild register projections after source, framework, applicability, obligation, implementation, or posture signals change.
  5. Run review cycles for periodic or event-driven regulatory review.
  6. Request an export when the register is ready for an audit package or regulator-facing bundle.
Last updated on