Files
govoplan-risk-compliance/README.md

2.5 KiB

GovOPlaN Risk Compliance

Repository type: module (domain).

govoplan-risk-compliance owns risk and compliance workflows for data protection incidents, DPIAs, compliance controls, audit measures, risk registers, internal-control evidence, and legal screening decisions.

Its runtime module ID is risk_compliance; the repository and Python distribution retain the hyphenated govoplan-risk-compliance name.

The first complete vertical is sanctions screening. Connectors acquires immutable source evidence; Risk Compliance imports and normalizes exact list versions, runs deterministic version-pinned screening, and presents potential matches to an independent reviewer. Fuzzy matching only creates review candidates and never confirms a legal match.

The module includes database migrations, tenant-isolated APIs, an operational WebUI, append-only dispositions, time-bounded false-positive exceptions, and audit events. Queue and audit summaries deliberately retain only the minimum subject data needed for the workflow.

Initial Ownership

  • risk registers
  • compliance controls
  • DPIA records
  • data protection incident records
  • audit measures
  • internal-control evidence
  • immutable sanctions list catalogues
  • sanctions screening and reviewer dispositions

Boundaries

This module does not own:

  • immutable audit log storage
  • records retention engine
  • inspection fieldwork

Detailed boundary notes are in docs/RISK_COMPLIANCE_DOMAIN_BOUNDARY.md.

Integrations

Expected optional integrations:

  • audit
  • policy
  • records
  • inspections
  • files
  • tasks
  • notifications
  • connectors

Development Install

From the core checkout:

cd /mnt/DATA/git/govoplan-core
./.venv/bin/python -m pip install -e ../govoplan-risk-compliance

Focused manifest verification:

cd /mnt/DATA/git/govoplan-risk-compliance
PYTHONPATH=src:/mnt/DATA/git/govoplan-core/src /mnt/DATA/git/govoplan-core/.venv/bin/python -m unittest discover -s tests

Gitea Workflow

Issue templates are installed under .gitea/, and the shared label taxonomy is copied to docs/gitea-labels.json with the module label module/risk-compliance.

From the core checkout, labels can be synced once a local GITEA_TOKEN is available:

cd /mnt/DATA/git/govoplan-core
/mnt/DATA/git/govoplan/tools/gitea/gitea-sync-labels.py --root /mnt/DATA/git/govoplan-risk-compliance --apply