Skip to main content
Bring your team and maximize your impact at Dreamforce. Register three or more to unlock $999 passes.

Track Regulations and Policies

Learning Objectives

After completing this unit, you’ll be able to:

  • Describe how to define and track regulations, their versions, and clauses.
  • Explain how to track and publish internal policies.
  • Identify how business operations processes connect to regulations and policies.

Share Compliance Knowledge

Process Compliance Navigator manages both the external and internal rules that your organization follows. Compliance officers capture these rules in different sets of objects.

Track details about external rules in the Regulation object and related objects. These objects help you manage the lifecycle of a regulation and its clauses. With this information, compliance officers and others can easily plan and execute regulatory updates, reviews, and retirements.

Store details about your internal rules in the Policy object and its related objects. Storing this information in Salesforce makes it easy to see gaps in compliance policy coverage and quickly inform control and business process owners about updates.

You connect regulations and policies to the Business Operations Process object, which stores the details about predefined activities to compliantly complete a task. Think of your business operations processes as a checklist of methods that help you run your daily operations.

In this unit, you learn how to map business processes, regulations, and policies. Start with business processes.

Map Business Processes

Your compliance officers don’t own business processes, but knowing how your operations relate to regulations, policies, and controls is essential.

The Business Operations Process object stores the details of an organization's processes. This information includes a process description, process owner, control manager, and a reference to where and how a process is implemented. Processes can include tasks performed in Salesforce and external systems, such as a core banking system for financial services.

Business operations processes relate to regulation clause versions, policy clause versions, and other business operations processes. These connections serve as junction objects to relate business operations processes to compliance controls, regulation clauses, and policy clauses, as shown in the screenshot here. You explore all of these objects later in this badge.

Related records connecting a business operations process to a compliance control, two regulation clauses, and two policy clauses.

This screenshot shows the Actionable Relationship Center (ARC) component configured to show compliance record relationships in an easy-to-navigate graph. Read ARC for Process Compliance Navigator for a list of available ARC templates.

Here are a few examples of business processes for different industries.

  • Order fulfillment and management for communications
  • Know your customer (KYC) verification for financial services
  • Patient intake and information processing for healthcare

Now that you understand how to track your business processes, learn how to create and manage the regulations and policies that you relate to business operations processes.

Track Regulations

Regulations are the third-party rules and laws that your organization follows.

To track regulations, first create a record for the organization that issues and enforces those regulations, such as a government agency that defines rules and issues permits. Compliance officers use the Regulatory Authority object to track an authority’s name, description, legal jurisdiction, and type of authority. For example, this screenshot shows a regulatory authority record that tracks the US Consumer Financial Protection Bureau.

The record includes a description of the authority, its jurisdiction, and internal comments.

After you create a regulatory authority, define the regulations it enforces. Compliance officers use the Regulation object to track details about the topics covered by a regulation, the work that’s impacted, and links to official regulatory documents for quick reference. Also connect regulations to a regulation manager responsible for ensuring compliance with the regulation. This screenshot shows a regulation record for a home mortgage disclosure law.

Corresponding image of information.

The Regulation object works with a system of other objects to completely understand a regulation. Here are the objects.

  • Regulation Version relates directly to a regulation and tracks its changes and effective dates. The system automatically creates a regulation version when you create a regulation.
  • Regulation Clause relates to a regulation and stores its specific provisions or sections.
  • Regulation Clause Version relates to regulation clauses and regulation versions, and tracks the granular details of a regulation clause and its changes over time. These records store clause text and valid dates. The system automatically creates a regulation clause version when you create a regulation clause. Regulation clause versions also relate to compliance control versions, which you learn about in the next unit.
  • Business Operations Process relates to regulation clause versions to help process owners understand regulations that relate to their work.

After you set up regulation clauses and regulation clause versions, set the regulation version to Published status. The system automatically publishes the related regulation clause version, as well. When the regulation’s effective date arrives, a compliance officer sets the status of the regulation version and its related clause versions to Active.

Later, when a regulatory authority modifies a regulation, a compliance officer clones their existing regulation versions and regulation clause versions. Your team uses these new records to track updates, then sets the previous versions to Retired status.

Publish Internal Policies

Not all compliance rules come from regulatory authorities; some are your internal policies and procedures.

For those rules, use the Compliance Policy object, such as this compliance policy record for a Know Your Customer (KYC) policy.

The compliance policy mentioned in the preceding content.

As with the Regulation object, the Compliance Policy works with a system of other objects to track details about a policy. Here are the details.

  • Compliance Policy Version relates to a compliance policy and specifies policy effective dates, details, change summaries, and reference documents. The system automatically creates a compliance policy version when you create a compliance policy.
  • Compliance Policy Clause relates to a compliance policy, compliance policy clause version, and other compliance policy clauses. Compliance policy clauses store a policy’s clause names and descriptions.
  • Compliance Policy Clause Version relates to a compliance policy version and compliance policy clause to track the granular details of a compliance policy clause and its changes over time. These records store clause text and valid dates, plus they relate to regulation clause versions and business operations processes. Compliance policy clause versions also relate to compliance control versions, which you learn about in the next unit. The system automatically creates a compliance policy clause version when you create a compliance policy clause.
  • Business Operations Process connects to compliance policy clause versions to help process owners quickly understand the impact of policy changes on their work.

After a compliance officer defines a policy and its clauses, the officer publishes the records to make them accessible to control managers, business process representatives, and other stakeholders. On a policy’s effective date, the compliance officer then sets the policy version and policy clause version to Active status.

To update an existing policy, a compliance officer clones the active compliance policy version to create a new version, incorporates changes in a cloned compliance policy clause version, publishes the new records, then retires the previous version and activates the new one.

What’s Next?

In this unit you learned how compliance officers use Process Compliance Navigator to track business processes, regulations, and policies. The officers then pass the baton to a few very important teammates: control managers and IT admins.

In the next unit, you learn how these roles work to enforce regulations and policies in Salesforce using controls.

Resources

Salesforce 도움말에서 Trailhead 피드백을 공유하세요.

Trailhead에 관한 여러분의 의견에 귀 기울이겠습니다. 이제 Salesforce 도움말 사이트에서 언제든지 새로운 피드백 양식을 작성할 수 있습니다.

자세히 알아보기 의견 공유하기