Phase 4: Monitor
Maintain compliance posture through continuous monitoring, regulatory change tracking, renewal management, and compliance reporting.
Purpose
The Monitor phase maintains compliance posture after initial certification. Compliance is not a one-time event — regulations change, controls drift, and certifications expire. This phase establishes continuous monitoring, tracks regulatory changes, manages renewal calendars, and produces compliance reports.
Skills
Continuous Monitoring
/compliance:continuous-monitoring <topic>Designs a continuous compliance monitoring strategy. Defines automated control testing procedures, compliance metrics and KPIs, drift detection mechanisms, and alerting thresholds for compliance degradation.
Output: Continuous monitoring strategy with metrics and alerting → .metapowers/compliance/<topic>/04-monitor.md
Regulatory Watch
/compliance:regulatory-watch <topic>Establishes a regulatory change management process. Identifies regulatory bodies and information sources to monitor, defines impact assessment procedures for new or amended regulations, and creates update workflows.
Output: Regulatory watch process with change management procedures → .metapowers/compliance/<topic>/04-monitor.md
Renewal Calendar
/compliance:renewal-calendar <topic>Manages certification renewal timelines and recertification requirements. Tracks validity periods, renewal preparation milestones, surveillance audit schedules, and re-assessment triggers across all active certifications.
Output: Renewal calendar with preparation milestones → .metapowers/compliance/<topic>/04-monitor.md
Compliance Reporting
/compliance:compliance-reporting <topic>Designs compliance reporting for internal stakeholders, boards, and regulators. Defines report formats, frequency, audience-specific content, and automated data collection for compliance dashboards.
Output: Compliance reporting framework with templates → .metapowers/compliance/<topic>/04-monitor.md