About Us Contact Blog
Governance DocsGovernance Docs
Which Toolkit?SoA GeneratorFree TemplatesAboutBlogContactMy AccountCart
FOX v.2.4.9
Browse Toolkits
Governance Docs
  • Browse All Toolkits
  • Information Security & Cybersecurity
  • Data Privacy & Protection
  • Governance, Risk & Compliance
  • Quality Management
  • Health, Safety & Environment
  • AI Governance

My Account

CART

No products in the cart.

Category: Articles

When a data protection officer is mandatory under GDPR Article 37

Data Protection Officer: When Article 37 Makes One Mandatory

Governance Docs16th August 2026

A DPO is mandatory in three cases, and all of them turn on core activities. What Article 38…
Read More
The GDPR Chapter V routes for international data transfers

International Data Transfers: Chapter V in Priority Order

Governance Docs16th August 2026

GDPR Chapter V has a strict order: adequacy, then safeguards, then situational derogations. Why the last route is…
Read More
What GDPR Article 15 requires in response to a data subject access request

Data Subject Access Request: The Copy Is Only Half of It

Governance Docs16th August 2026

Article 15 asks for the data plus eight further items. The extension you must claim inside month one,…
Read More
GDPR breach notification thresholds, audiences and timing

Breach Notification: Two Thresholds, Two Clocks

Governance Docs16th August 2026

GDPR breach notification is not one 72-hour rule. Two thresholds, two audiences, phased notification, and the log you…
Read More
The legitimate interests assessment test under GDPR Article 6(1)(f)

Legitimate Interests Assessment: The Test and the Trap

Governance Docs16th August 2026

A legitimate interests assessment has three parts, one hard exclusion, and an Article 21 consequence most teams miss…
Read More
GDPR Article 30 records of processing for controllers and processors

Records of Processing: Why the 250-Employee Exemption Fails

Governance Docs15th August 2026

GDPR Article 30 records of processing: the exemption almost never applies, controllers and processors keep different records, and…
Read More
What GDPR Article 35 requires in a DPIA

DPIA: What GDPR Article 35 Actually Requires

Governance Docs15th August 2026

A DPIA has four mandatory elements and two of them get skipped. What Article 35 requires, when Article…
Read More
TISAX Exchange steps and the active and passive participant roles

TISAX Exchange: The Half of TISAX Suppliers Never Use

Governance Docs15th August 2026

TISAX is an exchange mechanism, not a certificate. The four steps, why scope decides what customers receive, and…
Read More
The SWIFT CSCF customer security controls framework and assessment routes

SWIFT CSCF: Your Independent Assessment Can Be Internal

Governance Docs15th August 2026

The SWIFT CSCF independent assessment can be performed by your own second or third line of defence, not…
Read More
SOX 404 filer status and the auditor attestation requirement

SOX 404: Who Needs the Auditor Attestation

Governance Docs15th August 2026

SOX 404(a) applies to every issuer; 404(b) only to some. The public float and revenue tests that decide…
Read More
PCI DSS validation, scope and the assessor roles

PCI DSS Validation: Who Requires It, and What to Do First

Governance Docs15th August 2026

PCI SSC does not require PCI DSS validation — your acquirer or payment brand does. How scope really…
Read More
The NIST AI RMF four functions for AI risk management

NIST AI RMF: The Four Functions, and the Revision Underway

Governance Docs15th August 2026

The NIST AI RMF is voluntary, widely referenced, and version 1.0 is being revised under the White House…
Read More
    ←
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • …
  • 21
  • →

Recent Posts

ISO 27001 risk treatment plan diagram showing the six steps of clause 6.1.3
ISO 27001 Risk Treatment Plan: The Complete 2026 Guide

August 23, 2026

ISO 27001 nonconformity classification chart comparing major and minor audit findings
ISO 27001 Nonconformity: The Complete 2026 Guide to Major vs Minor Findings

August 22, 2026

ISO 27001 recertification audit timeline showing the three-year certification cycle from Stage 1 and Stage 2 through surveillance audits to year three reassessment
ISO 27001 Recertification Audit: The Complete 2026 Guide

August 21, 2026

Phishing-resistant MFA methods compared against NIST SP 800-63B-4 assurance levels
Phishing-Resistant MFA: The Complete 2026 Guide

August 20, 2026

Cybersecurity governance obligations under NIS2, DORA, ISO 27001 and NIST CSF 2.0
Cybersecurity Governance: The Definitive 2026 Board Guide

August 20, 2026

Categories

  • Articles
  • DORA
  • GDPR
  • HIPAA
  • ISO 27001
  • ISO 42001 & AI governance
  • ISO 9001
  • Management systems
  • NIS2
  • Security frameworks
  • SOC 2
Governance DocsGovernance Docs

Reliable ISO & compliance documentation toolkits that help your business meet regulatory standards with ease.

Governance Docs LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110, USA
info@governancedocs.com
+1 812 227 5662

Toolkits

  • ISO 27001:2022
  • GDPR
  • SOC 2
  • PCI-DSS v4.0
  • HIPAA
  • ISO 42001
  • All toolkits →

Company

  • About Us
  • Blog
  • Contact
  • FAQ
  • Which toolkit do I need?
  • Free templates
  • SoA generator
  • RSS feeds

Policies

  • Privacy Policy
  • Terms & Conditions
  • Refund & Return Policy
  • Delivery Policy
Browse by topicISO 27001ISO 42001 & AI governanceGDPRSOC 2HIPAANIS2DORAISO 9001Management systemsSecurity frameworks
© 2026 Governance Docs LLC. All rights reserved.
Secure checkoutstripeVISA