Scenario: responding to a new regulation

A supervisory authority publishes a decision, it lands in your feed overnight, and you need to judge whether it touches your programme — and be able to show that you reviewed it the week it was published, not the week the auditor asked.

A directive amendment, a data-protection authority's decision, or an updated technical standard can unsettle a control mapping that took months to build. This scenario follows one such publication from the moment it appears in the feed to the point where a policy has been revised because of it. Two people do the work: Contributor Daniel, who watches the feed and prepares the ground, and Manager Ruth, who records the formal review decision. The journey crosses Regulatory changes, Compliance frameworks and Policies, and leaves a dated, attributed trail in each.

Settle one thing up front: Aegis pulls regulatory developments automatically. A background worker polls the feeds registered for your tenant on each feed's own cadence, writes every new publication in as a regulatory change (a record of something an authority has published), and scores it for relevance against the frameworks and topics you track. Out of the box that means ENISA and NIST Cybersecurity, plus GDPRhub DPA Decisions where the licence allows it. An Admin can register further RSS or Atom feeds — another supervisory authority, say — in Settings, giving each one an identifier, a name, a URL, a region and a polling frequency. Nothing on this screen lets you type a change in by hand. What needs a person is the judgement.

Before you start

Two gates stand in front of this screen, both carrying the same name. The REGULATORY_INTELLIGENCE module has to be switched on for your tenant, or the menu entry never appears; and your licence has to include the matching feature, which ships from the Professional tier upwards. Without it the page reads "Regulatory change tracking is not available on your current plan." Above that gate, the split is between reading and deciding:

Role What they can do with a regulatory change
Viewer Contributor Read the feed, open any item's detail dialog, follow the source link, and run Relevance Triage (AI) and Suggested actions
Manager All of the above, plus Mark as Reviewed, Analyze impact, Dismiss and Restore to queue
Admin All of the above, plus registering the feeds that are polled and switching on the daily regulatory digest email in Settings

The write actions sit behind the regulatory:write permission. Where a role lacks it, those buttons are not rendered at all — so Daniel opens the same dialog Ruth does and sees fewer buttons on it. Anyone can keep watch; signing off that a change has been reviewed rests with a named, accountable person.

What's on this screen

/regulatory-changes is a single feed of incoming items — one table, no folders, no create button. In the left menu, Regulatory Changes sits at the foot of the Compliance group. Across the top runs the global bar: the environment name, global search, the language picker, the light/dark toggle, a help icon, the notification bell, and the signed-in user's name with Sign out beside it.

The page header reads Regulatory Changes over the line "Track incoming regulatory updates and assess their impact on your compliance posture", with a single action on the right: Relevance Triage (AI). Below it sits the filter bar — a Search regulatory changes... box with its own Search button, an All Sources dropdown built from the sources actually present in your data plus the feeds in your registry, and a View dropdown set to Active that you can switch to Dismissed. The table carries five columns: Title, Source, Relevance as a coloured percentage, Published, and Status. There are no per-row buttons — clicking anywhere on a row opens its detail dialog. In the capture below, every visible row comes from GDPRhub DPA Decisions, all published on the same day, and every one reads Pending Review in grey: a fresh queue nobody has worked through yet. Scroll past the table, below the fold of this capture, and two more panels follow — the AI insights saved from a triage run, and the action items raised against them.

Step 1 — Daniel opens the feed and works out what to read first

The change arrives on its own. Daniel's job is not to find it but to decide which items in the queue deserve his afternoon.

  1. Open the module. Expand the Compliance group in the left menu and select Regulatory Changes. The feed loads twenty items to a page, newest first.
  2. Ask for a reading order. Select Relevance Triage (AI) at the top right, then Run Relevance Triage in the panel that opens. Aegis ranks your open — that is, non-dismissed — changes by stored relevance, review state and recency, then drafts a plan naming a next step for each: review it, assess its impact, or dismiss it. The ranking is computed, not written by the AI. Save as record keeps the plan in the saved-insights panel below the table.
  3. Narrow the feed. Type into Search regulatory changes.... The table filters as you type — the match runs over both the title and the summary text — and the Search button beside the box submits the same term. Or pick one authority from All Sources. Daniel filters to the issuing authority and finds the row he wants, still Pending Review.
  4. Check the guide if a column is unfamiliar. The help icon in the top bar opens this User Guide inside Aegis, at the chapter for the screen you are on.
  5. Confirm whose account you are in. The name at the top right is the account every action from here on is attributed to — and, for Daniel, the cue that the write actions will not be available to him.
The regulatory changes feed: the Relevance Triage (AI) action, the search and source filters, and rows showing computed relevance and Pending Review status — /regulatory-changes.
The regulatory changes feed: the Relevance Triage (AI) action, the search and source filters, and rows showing computed relevance and Pending Review status — /regulatory-changes.
The relevance score is a hint, not a verdict

On arrival the percentage is computed by keyword match against the frameworks your tenant tracks, your sectors, and how recently the item was published: green below 40, amber from 40 to 69, red at 70 and above. Where an impact analysis has since run, the figure you see is that analysis's own overall relevance instead. Either way it helps you triage — read the red rows first — but it decides nothing. A low score on an item that turns out to matter is exactly why a person still reads each change.

Step 2 — Read the change and draft the actions it implies

Clicking a row opens a dialog headed Regulatory Change. Daniel reads it in full before anyone records a decision.

  1. Open the change. Click anywhere on the row. The dialog opens with the relevance figure and its band across the top — for example 95% — High Relevance.
  2. Read the record. Details holds the Source, Identifier, Publication Date and Relevance Score. Summary carries the publication's own text, tidied of feed markup; Categories shows the feed's own tags, plus the key of any framework a later impact analysis flagged; and Source Link offers View original document, which opens the authority's page in a new tab. Read the original — the summary is an extract, not the decision.
  3. Ask for a draft checklist. Select Suggested actions. Aegis turns this change, plus any impact analysis already on record, into a prioritised list of concrete compliance actions with an owner hint for the top items. Saving it keeps the checklist on this change, in the insights and action items panels at the foot of the dialog. This needs only read access, so Daniel can prepare the ground before handing over.
  4. Hand it to a Manager. Daniel sees no Mark as Reviewed, Analyze impact or Dismiss button — they are not rendered for his role. He confirms the change looks relevant and passes it to Ruth.

Step 3 — Ruth analyses the impact and records the review

Ruth opens the same item. As a Manager she holds regulatory:write, so three further buttons appear along the top of the dialog.

  1. Look at what is already there. Where your licence includes the AI assistant, newly ingested changes are queued for impact analysis on arrival — twenty-five per scan run at most, so a large ingestion leaves the remainder unanalysed. The Impact Analysis section may therefore already be filled in. If it reads No impact analysis yet, select Analyze impact. Aegis queues a background job and confirms "Impact analysis queued — results appear here when ready".
  2. Reopen the change once the worker has run. The section then shows a written summary, an Overall relevance figure, when it was Analyzed, and a list of Affected frameworks, each with its own percentage.
  3. Judge the reading. The analysis is a draft opinion. Ruth weighs it against what she knows of the programme and decides whether she agrees. Running it rewrites this change's own relevance score and adds the flagged framework keys to its categories, so the row's percentage may move — but no control, policy or review state has changed.
  4. Mark it reviewed. Select Mark as Reviewed. The button is replaced by a green Reviewed badge, a Review section appears with Reviewed At and Reviewed By, and the row's Status in the feed turns green. That dated, attributed record is the point of the whole step.
  5. Or set it aside honestly. If the change does not touch you, select Dismiss instead. The item leaves the Active view and stays reachable under ViewDismissed, where its row carries an amber Dismissed badge; the dialog gains a Dismissed section with Dismissed At and Dismissed By. The button asks no question first, so nothing records why — the Reason line appears only where one was supplied through the API. Restore to queue reverses it. Dismissing is a recorded decision, not a delete.

The AI assist

Three AI reads appear in this journey: the triage plan on the list, the suggested actions in the dialog, and the impact analysis. All three produce text for a person to weigh. None of them marks anything reviewed, dismisses an item, or edits a control, a policy or a framework mapping. The triage plan and the suggested actions write nothing at all until you save them; the impact analysis is the one exception to watch — it stores its findings on the change and, in doing so, overwrites that change's relevance score and adds the flagged framework keys to its categories. All three reason only over your own records — they never fetch outside data and never invent a change that is not in your feed. Each run is metered against your tenant's AI credits; see the AI assistant chapter for how that budget works.

Step 4 — Carry the change into your frameworks and policies

Marking a change reviewed records that you saw it. Acting on it happens in the modules it touches, starting from the Affected frameworks list.

  1. Open the affected framework and update its controls. Go to Compliance frameworks, open the framework the analysis flagged, and filter its controls by status, domain or owner group. Where the change tightens an expectation, update the control's implementation status and re-check its mappings — because one control can satisfy more than one framework, a single update may close a gap in several at once. See Control mapping for that view.
  2. Revise the policies. In Policies, edit each policy the change touches. Every revision runs through its own draft, review and approval lifecycle, so the update is itself approved by a person — another dated, attributed record.
  3. Refresh the evidence behind the affected controls. Where a control's proof no longer matches the new expectation, attach a current artefact in Evidence. An auditor will ask what changed as well as when you noticed.
  4. Close the loop on the action items. Work through the checklist saved on the change. The change record itself has no "addressed" status, so the action items are what tell you the response is finished.
The process is the evidence

Frameworks such as ISO 27001 (clause 6.1.3), NIS2 (a European cybersecurity law) and DORA (a European financial-sector resilience regulation) expect a documented way of monitoring and responding to regulatory change. An auditor examines the trail as much as the source — the feed, the dated review, who reviewed it, and what changed downstream. Marking each relevant change Reviewed in the week you see it is what builds that trail; the audit log keeps its own immutable copy.

Tips and limits

Where this connects

Each module in this journey has its own chapter: Regulatory changes for the feed and the detail dialog in depth, Regulatory alerts for the wider intelligence view, Compliance frameworks for the control mappings, Policies for the revisions, and Action items for the follow-up. When the auditor comes asking for that trail, Scenario: preparing for an external audit picks the story up. See also What each role can do and Settings, where the polled feeds and the digest are configured.