← All samples

Business Requirements · Process Documentation

Compliance Document Intake: Requirements (excerpt)

Audience
IT, compliance, leadership
Project
SharePoint intake redesign
Doc ID
BRD-CDI-002
Status
Approved

Demonstration sample created for this portfolio. The organization is fictional; the format reflects requirements and workflow documentation I've produced for IT support and compliance teams.

1.0Problem statement

Compliance documents currently arrive by email to a shared inbox and are filed manually. Intake takes an average of 6 business days, roughly 8% of submissions are misfiled, and there is no audit trail showing who reviewed a document or when. The organization cannot demonstrate a consistent review process during audits.

2.0Objective and success measures

Replace the shared-inbox process with a SharePoint intake workflow that routes, tracks, and archives every submission automatically.

MeasureCurrentTarget (90 days post-launch)
Average intake-to-filed time6 business days≤ 2 business days
Misfiled submissions~8%≤ 1%
Submissions with complete audit trail0%100%

3.0Process flow (to-be)

The redesigned intake follows five states. Every state change is timestamped and attributed automatically.

SUBMITTED ──▶ TRIAGE ──▶ IN REVIEW ──▶ APPROVED ──▶ ARCHIVED
                 │                        │
                 └──▶ RETURNED ◀──────────┘
                      (missing info — returns to submitter
                       with required-fields checklist)
StateOwnerSLAExit condition
SubmittedSystemInstantForm passes required-field validation.
TriageCompliance coordinator4 business hoursDocument type assigned; routed to the correct reviewer queue.
In reviewAssigned reviewer1 business dayReviewer approves, or returns with a reason code.
ApprovedSystemInstantRetention label applied; submitter notified.
ArchivedSystemInstantStored to the records library with metadata; read-only.

4.0Requirements (excerpt)

Requirements use MoSCoW prioritization. "Must" items are launch-blocking.

IDRequirementPriorityRationale
FR-01The intake form must reject submissions missing any required metadata field and tell the submitter exactly which fields are missing.MustEliminates the #1 cause of triage delay.
FR-02The system must record user, timestamp, and action for every state change, viewable by compliance without IT assistance.MustCore audit finding from the prior year.
FR-03Reviewers must receive a queue digest at 8:00 a.m. local time listing items approaching SLA breach.ShouldKeeps review SLAs visible without dashboard-checking.
FR-04Submitters should be able to check their submission's state without contacting the coordinator.ShouldRemoves ~30 status-inquiry emails per week.
FR-05The archive could expose a read-only search page for external auditors.CouldNice-to-have; auditors currently accept exported reports.
Out of scope Migration of pre-2024 records, contract-negotiation workflows, and integration with the finance ERP. Each is captured in the project backlog for future phases.

5.0Open decisions

#Decision neededOwnerNeeded by
D-1Retention period for returned-and-abandoned submissions (30 vs. 90 days).Compliance directorDesign sign-off
D-2Whether triage may reassign document type after review has begun.Process ownerBuild start