Business Requirements · Process Documentation
Compliance Document Intake: Requirements (excerpt)
- Audience
- IT, compliance, leadership
- Project
- SharePoint intake redesign
- Doc ID
- BRD-CDI-002
- Status
- Approved
1.0Problem statement
Compliance documents currently arrive by email to a shared inbox and are filed manually. Intake takes an average of 6 business days, roughly 8% of submissions are misfiled, and there is no audit trail showing who reviewed a document or when. The organization cannot demonstrate a consistent review process during audits.
2.0Objective and success measures
Replace the shared-inbox process with a SharePoint intake workflow that routes, tracks, and archives every submission automatically.
| Measure | Current | Target (90 days post-launch) |
|---|---|---|
| Average intake-to-filed time | 6 business days | ≤ 2 business days |
| Misfiled submissions | ~8% | ≤ 1% |
| Submissions with complete audit trail | 0% | 100% |
3.0Process flow (to-be)
The redesigned intake follows five states. Every state change is timestamped and attributed automatically.
SUBMITTED ──▶ TRIAGE ──▶ IN REVIEW ──▶ APPROVED ──▶ ARCHIVED
│ │
└──▶ RETURNED ◀──────────┘
(missing info — returns to submitter
with required-fields checklist)
| State | Owner | SLA | Exit condition |
|---|---|---|---|
| Submitted | System | Instant | Form passes required-field validation. |
| Triage | Compliance coordinator | 4 business hours | Document type assigned; routed to the correct reviewer queue. |
| In review | Assigned reviewer | 1 business day | Reviewer approves, or returns with a reason code. |
| Approved | System | Instant | Retention label applied; submitter notified. |
| Archived | System | Instant | Stored to the records library with metadata; read-only. |
4.0Requirements (excerpt)
Requirements use MoSCoW prioritization. "Must" items are launch-blocking.
| ID | Requirement | Priority | Rationale |
|---|---|---|---|
FR-01 | The intake form must reject submissions missing any required metadata field and tell the submitter exactly which fields are missing. | Must | Eliminates the #1 cause of triage delay. |
FR-02 | The system must record user, timestamp, and action for every state change, viewable by compliance without IT assistance. | Must | Core audit finding from the prior year. |
FR-03 | Reviewers must receive a queue digest at 8:00 a.m. local time listing items approaching SLA breach. | Should | Keeps review SLAs visible without dashboard-checking. |
FR-04 | Submitters should be able to check their submission's state without contacting the coordinator. | Should | Removes ~30 status-inquiry emails per week. |
FR-05 | The archive could expose a read-only search page for external auditors. | Could | Nice-to-have; auditors currently accept exported reports. |
5.0Open decisions
| # | Decision needed | Owner | Needed by |
|---|---|---|---|
| D-1 | Retention period for returned-and-abandoned submissions (30 vs. 90 days). | Compliance director | Design sign-off |
| D-2 | Whether triage may reassign document type after review has begun. | Process owner | Build start |