Guide

Compliance matrix

From every active standard and every binding Authority constraint, quality and technical requirement down to the records that carry it, their acceptance criteria, the tests that prove them, the latest result and any exemption. It answers "do we comply with KVKK, BDDK or our security standards" with evidence.

For: Security & compliance, Project lead, Tester, Admin

Reading a row

  • Proven: every criterion has a passing test (within the period, when one is chosen). Partly proven: some are.
  • Failing: a covering test failed or is blocked. Not run: tests exist but have no passing run (in the period).
  • No test, No criterion: the requirement cannot be proven yet. No requirement carries it: the standard is not linked to any record (use Applies to on the standard).
  • Exempt / Exemption proposed: an accepted or proposed decision waives the standard for this project, with who decided and when. A MUST standard cannot be waived.

For an audit

Choose from and to: each test's result is its last run before the end of the period, and only runs within the period prove a criterion. Only gaps keeps what needs attention; Export CSV gives one row per criterion. The card on the right shows the last code conformance review (get_conformance_checklist and report_conformance). Coding agents ask the same with get_compliance_matrix.