GLEMAD GOVERNANCE FRAMEWORK
CONTROL → EVIDENCE → REVIEWGovernance is the chain from a requirement to a reviewable decision.
The Compliance and Governance framework maps institutional requirements to runtime controls, role boundaries, decision records, and retained evidence. It supports audit and review without transferring legal responsibility from the institution to the system.
THE GOVERNANCE PATH
Compliance starts before evidence is requested.
The framework begins with the requirement an institution has accepted. Each following step preserves the connection between policy, operation, responsibility, and review.
- 01
Requirement intake
Record the source, jurisdiction, scope, version, effective date, and institutional owner of each accepted requirement.
OUTPUTGoverned requirement - 02
Control mapping
Translate the accepted requirement into a technical or procedural control with a defined test and review condition.
OUTPUTControl definition - 03
Role and access
Name who may configure, approve, execute, review, revoke, or change the control. Access follows the role, not convenience.
OUTPUTAuthority record - 04
Decision record
Connect observed state, evidence, reasoning, policy, approval, action, and outcome in one reviewable sequence.
OUTPUTEvidence chain - 05
Audit support
Prepare the relevant control state and decision evidence for internal review, an auditor, or a regulator.
OUTPUTReview package - 06
Drift and review
Detect changes between the declared control and live operation, then route the gap to the responsible owner.
OUTPUTReview decision - 07
Retention
Keep or dispose of records according to the institution's retention, residency, privacy, and legal requirements.
OUTPUTRetention state
THE DECISION LEDGER
Every control should answer five review questions.
What obligation has the institution accepted?
Source, version, scope, ownerHow is that obligation represented in operation?
Rule, test, exception, review dateWho may decide, change, or revoke it?
Role, grant, approval, access historyWhat occurred, and why was this response permitted?
State, reasoning, policy result, actionDid the control produce the intended operating state?
Result, residual risk, rollback, follow-upA review package can organize this record for an audit or investigation. It does not declare that the institution is compliant. That determination belongs to the institution and its appointed reviewers.
DRIFT AND REVIEW
A control is governed only while its operating state remains visible.
Review is triggered by time, change, or evidence. A gap is routed to the owner with the affected control, observed state, and required decision intact.
- 01
A requirement, regulation, or internal policy changes
- 02
The live system no longer matches the declared control
- 03
A role or access grant no longer reflects responsibility
- 04
Evidence is incomplete, contradictory, or outside retention policy
- 05
An incident reveals that a control behaved differently from its design
The system can preserve a record. It cannot assume legal responsibility.
The institution determines which laws, regulations, standards, contracts, and internal policies apply. It approves the resulting controls, assigns accountable roles, resolves exceptions, and decides whether the evidence meets its obligations.
Glemad's framework defines the technical chain needed to make those decisions inspectable. It does not replace legal, regulatory, or audit judgment.
FROM POLICY TO DEPLOYMENT
