Business Catalog
The layer that makes everything else mean something
Domain, capability, service, and process, with objectives above them and an exhaustive link web below, so a control failure can be traced to the business service it affects.
- Domain, capability, service, and process hierarchy
- Business objectives linked to capabilities, services, and processes
- Typed links to risks, controls, policies, findings, and assessments
- Business dependencies modelled explicitly
- PaymentsDomain
- Card acquiringCapability3 risks2 policies
- Merchant settlementService4 controls2 assets
- Daily reconciliationProcess1 risk2 controls1 finding
Every level links out to risks, controls, policies, findings, assessments, and assets
Linkage
Impact answered structurally
Because each level carries typed links, questions like which objectives depend on this process, or which services this asset supports, are queries rather than investigations.
- Objective links to capabilities, services, processes, and org entities
- Process and service links to assets, risks, controls, and findings
- Capability links to risks, policies, controls, and assessments
- Governance events recorded against the catalog
Control
Privileged access is reviewed each quarter by the system owner
PPTDF applicability
One owner · one procedure · one evidence trail
Framework alignment
Works with your control frameworks
This module shares the platform control library. Map national frameworks and global standards alongside jurisdiction-specific authorities.
Solutions by role
Built for your team
See the business catalog in your environment
A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.