Scoped practices
What we commit to addressing in the written scope.
- Data map Identify the data categories, systems, transfers, and people involved in the proposed workflow.
- Minimum access Request only the access needed for the agreed work and revisit it when the scope changes.
- Approved systems Document the tools and service providers proposed for the engagement before sensitive data is introduced.
- Retention and deletion Agree how working data and project artifacts are retained, returned, or deleted.
- Human responsibility Define where review, approval, exception handling, and escalation remain with people.
- Closeout Document access removal, handoff material, and any continuing operational responsibilities.
Important boundary
No universal control claim.
Specific controls depend on the client, jurisdiction, data, vendors, and deployment model. This page does not claim a certification, a standard vendor agreement, dedicated inference, a particular hosting model, or a control that has not been included in a signed scope.
Where legal, regulatory, contractual, or professional obligations apply, those requirements must be identified and confirmed for that engagement. GRC does not present this page as legal or compliance advice.
Questions to include
Useful details for a written intake.
- Which systems and data categories the workflow touches.
- Which jurisdictions, client commitments, or internal policies apply.
- Who can approve access, vendors, and production changes.
- What must remain human-reviewed and what evidence must be retained.