Skip to main content
Documentation

Execution Workflows

Compliance Roadmaps — Gantt Plans & Corrective Actions

Don't just track compliance failures — project-manage the fix. EuroCompliant's Compliance Roadmaps turn every unfulfilled cross-framework obligation and every open high-severity scan finding into trackable CompliancePlanItem tasks, laid out on an interactive Gantt chart with dependencies, milestones and target dates. The loop only closes when a verified Evidence Vault file is linked or a rescan passes — a bar turns green only when the proof is real.

Transcript

Don't just track your compliance failures — project-manage the fix. EuroCompliant's Compliance Roadmaps take your regulatory gaps and instantly lay out an interactive Gantt chart with task dependencies and milestones.

Go to Dashboard. Notice a red compliance gap — a framework score below fifty, an urgent alert. Click Auto-Generate from Obligations. The platform pulls every unfulfilled obligation and open high-severity scan finding into trackable remediation tasks, grouped by framework and chapter, with deadlines spread to your target date.

Click Auto-Generate, name the plan Q1 2026 Compliance Roadmap, select obligations, and generate. The new plan appears grouped by framework and chapter, deadlines spread to your target date, ready to assign without manual transcription.

Switch to the Compliance Plans Gantt view at slash plans. Every task is a bar on a shared timeline, with dependency arrows, milestone diamonds for phases like Foundation Complete, and the critical path highlighted in red — the longest chain that determines your earliest possible completion date. Drag a bar to reschedule; the path recalculates live.

Click to resolve a corrective action task. Pick a file from the Evidence Vault to satisfy the loop-closure rule — a verified Document or EvidenceFile dated and linked to the obligation — and watch the Gantt bar turn green. Without a verified file link or a passing rescan, the backend rejects the transition: done means evidenced, not just claimed.

Hover the critical path. Any delay on a red bar pushes the whole plan's earliest completion date. Tasks off the path have slack. Milestones track phase completion at a glance, and every deadline feeds the compliance calendar alongside breach, DSAR and monitoring clocks.

Assign each task to a team member. Their My Compliance page now shows assigned to me and overdue counts. Notifications fire on assignment and deadline approach via Slack, email or webhook — so nothing falls through the cracks between your plans and your broader compliance programme.

Why this is required

GDPR Article 5(2) accountability and the AI Act's documentation duties are not satisfied by knowing what is missing; they are satisfied by showing a plan to fix it, who owns it, and when it will be done. A regulator's second question after 'what is non-compliant?' is always 'what are you doing about it, and how will you prove it is done?'

Article 9's risk-management system is explicitly continuous and iterative across the entire lifecycle, and Article 72's post-market monitoring must be systematic. A static checklist with no timeline cannot evidence that continuity. A Gantt-tracked plan with dated tasks, dependencies and milestones is what turns a point-in-time gap analysis into a defensible programme of work.

Scan findings make the gap analysis dynamic. A new high-severity prowler_cspm or trivy_vuln finding is not just a separate finding; it is a corrective action that must be tracked to closure with the same rigour as a missed Article 10 bias test. Without auto-generation, that translation is manual and therefore late.

Loop-closure is where programmes usually fail: a task is marked done because someone says so, not because evidence was produced. The validation rule requiring a verified Evidence Vault file link or a passing rescan to move a corrective action to resolved is what prevents that — it makes 'done' mean 'evidenced'.

What EuroCompliant does

Auto-generation — From Dashboard → Auto-Generate from Obligations, the platform pulls every unfulfilled obligation (obligation_meta n_a excluded, applies_when filtered) and every open high/critical ScanFinding, groups them by framework and chapter (e.g. EU AI Act Art. 9-15, GDPR Art. 32, DORA Art. 11), spreads deadlines evenly between now and the plan's target_date, and sets priority from expiry urgency and severity. The result is a set of CompliancePlanItem rows (title, description, framework, article_reference, priority, target_date, status todo) plus linked EnterpriseRisk where applicable, ready to assign without manual transcription.

Gantt timeline & critical path — The Gantt view (frontend/src/components/plans/GanttChart.tsx) renders every task as a bar on a shared timeline, with dependency arrows (depends_on_id), milestone diamonds (CompliancePlanMilestone), and the critical path highlighted in red. The critical path is the longest chain of dependent tasks that determines the earliest possible completion date; dragging a task reschedules it and recalculates the path in real time. Zoom from days to months. Milestones group tasks into phases like Foundation Complete or First Audit Ready, with completion percentages per phase.

Loop-closure evidence enforcement — Moving a corrective action from in_progress to resolved is not a free-form status change. The backend validates that the task either has a verified evidence_file_id link into the Evidence Vault (a Document or EvidenceFile that is dated, attributable and linked to the obligation) or a linked passing rescan (ScanJob status=completed with no open high/critical ScanFinding for that framework). Without one, the transition is rejected with 400 'Evidence required to close'. The Gantt bar only turns green when that proof exists, so green means evidenced, not just claimed.

Calendar and ownership — Every task deadline feeds the compliance calendar (obligations-calendar) alongside breach, DSAR and monitoring deadlines, so plan deadlines never fall through the cracks. Assign an owner (TeamMember) per task; My Compliance surfaces 'assigned to me' and overdue views per person. Notifications fire on assignment and deadline approach via the tenant's NotificationChannels (Slack/email/webhook).

Deadlines

Per task target_dateEvenly spread between now and the plan's target completion date on auto-generation; adjustable per task by dragging the Gantt bar.
Continuous (Art. 9/72)Re-generate after any material change, model retrain or new high finding — the loop-closure rule ensures the new task cannot be closed without fresh evidence.

Walking through it

1

Notice the red gap on the Dashboard

A framework score is red or an urgent alert fires. The gap analysis names the system, the obligation and the severity. Click Auto-Generate from Obligations.

Open /dashboard
2

Auto-generate the remediation plan

In Compliance Plans → New Plan, choose target_date, then Auto-Generate. The platform pulls pending obligations and open high findings, groups by framework/chapter, spreads deadlines, sets priority, and creates the tasks. No manual transcription.

Open /plans
3

Work the Gantt — dependencies, milestones, target dates

Switch to Gantt view. See dependency arrows, critical path in red, milestone diamonds. Drag a bar to reschedule; the critical path recalculates live. Create a milestone (e.g. Phase One Complete), link tasks to it, and watch phase completion.

Open /plans
4

Assign owners and track overdue

Assign each task to a team member. Their My Compliance page now shows 'assigned to me' and overdue counts. The compliance calendar shows plan deadlines alongside regulatory clocks.

Open /plans
5

Close the loop with verified evidence — watch the bar turn green

Click a task → Resolve → pick a file from the Evidence Vault (or link a passing rescan). Without a verified file link or passing rescan, the backend rejects the transition. When linked, the Gantt bar turns green: done means evidenced.

Open /evidence

The law

Penalties for non-compliance

Article 99 sets fines up to €15M or 3% for breaching Articles 9–15; GDPR Article 83 up to €20M or 4% for processing without appropriate technical measures. A plan that is tracked but not evidenced is, in enforcement terms, an admission that the control was not operating.

Frequently asked

What does Auto-Generate actually create?

One CompliancePlan and one CompliancePlanItem per pending obligation + one per open high/critical ScanFinding, grouped by framework and chapter, with priorities from expiry urgency/severity and deadlines spread evenly to the target date. Milestones are not auto-created; you add them to group phases as needed.

Why does resolving a task require an evidence file?

To prevent 'done by declaration.' The backend rejects a status change to resolved (or done) unless the task carries a verified evidence_file_id linked to the Evidence Vault or a passing rescan for that framework. That is the loop-closure enforcement: green on the Gantt means evidenced, not just claimed.

Can scan findings automatically close tasks?

Yes — the passing-rescan path. If a task was created from a trivy_vuln finding and a later trivy_vuln scan for that system/framework completes with no open high/critical findings, that satisfies the evidence rule without an explicit file upload. The platform links the passing scan result as the proof.

What if a task blocks many others — how do I see it?

The critical path is highlighted in red on the Gantt. Any delay on a red bar pushes the whole plan's earliest completion date. Tasks not on the critical path have slack and can slip without moving the milestone.

Do plan deadlines appear in the compliance calendar?

Yes. Every task with a target_date appears as a calendar event alongside breach, DSAR and monitoring deadlines, so plan work and regulatory clocks are visible in one view.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial