Appearance
Implement Phase
Implement is where governance becomes real: Controls move to executed status, Evidence becomes traceable, and readiness changes are reviewable.
ScopeDefine the system and governance scope
ImplementExecute Controls and attach Evidence
MonitorKeep governance continuously current
AuditPrepare internal review and exports
Outcome
You leave this phase with:
- prioritized Requirements and Controls with assigned owners
- Evidence attached to the Controls that matter most
- execution and fulfillment statuses that match what Evidence supports
Time to first value: 60–120 minutes
Prerequisites: the project is scoped and frameworks are attached
Path at a glance
1
Prioritize the backlog
Start from the biggest gaps and highest exposure
2
Execute Controls
Implement the Control and record how it was done
3
Attach Evidence
Link artifacts that prove execution
4
Complete and review
Log Control status changes; review at the Requirement level
Step 1: Prioritize what matters first
Goal: work on the Controls that move readiness the most.
Where in Modulos
Project → RequirementsProject → Controls
Do this
- Identify Requirements that are not fulfilled and map them to their key Controls.
- Prioritize Controls that are high impact for your current scope and risk posture.
- Assign Owners for execution and use the Viewer role for oversight.
You’re done when
- the next set of Controls to implement is clear, owned, and reviewable
Step 2: Execute Controls and document implementation
Goal: implement the Control in reality and capture the operational truth.
Where in Modulos
Project → Controls → select a control
Do this
- Follow the Control intent and guidance.
- Use the Control report fields to document what was implemented and where it lives.
You’re done when
- the Control implementation is described clearly enough to be reviewed
Step 3: Attach Evidence to prove execution
Goal: make the work auditable by linking artifacts.
Where in Modulos
Project → Controls → select a control → Control tab
Do this
- Attach the strongest, most specific Evidence you have to the Control's Control tab.
- Prefer Evidence that is durable (policy, ticket, design doc, audit log extract) and tied to the Control.
You’re done when
- a reviewer can verify execution from the linked Evidence without backchannels
Step 4: Complete Controls, then review Requirements
Goal: turn progress into an auditable record.
Where in Modulos
Project → Controlsfor Control execution statusesProject → Controls → select a Control → Comments and Logsfor status-change commentsProject → Requirementsfor Requirement review and fulfillment
Do this
- Move Controls to Executed only when Evidence supports it; each status change is confirmed with a comment that lands in the Control's Comments and Logs.
- Watch for Requirements becoming ready for review as their mapped Controls reach a final status.
- As Requirement Owner, review the completed Controls and mark the Requirement as Fulfilled. Reviews happen at the Requirement level, not per Control.
You’re done when
- statuses match reality and can be defended via Evidence, the Comments and Logs record, and the Requirements' reviews
Next
Monitor phase
Add signals and schedules so governance stays continuously current
Compliance Lead path
A role-based walkthrough for driving readiness end-to-end