Approval workflow (RACI)

Understand the draft - submission - review - approval cycle that applies to your ROPA registers, PIAs, and official documents, plus the conditions that can block an approval.

3 min read

Why an approval workflow?

Law 25 requires organizations to demonstrate due diligence: who documented what, who validated, and when. Conformaze's approval workflow (RACI model: Responsible, Accountable, Consulted, Informed) materializes this traceability. Each strategic document — ROPA register, PIA, security measure, processor contract — goes through a structured cycle before being considered official.

Cycle statuses

A document evolves through five statuses: (1) Draft — being written, freely editable by the contributor. (2) Submitted for review — write-locked, awaiting the approver. (3) Under review — the approver has started reading, can request changes. (4) Approved — official version, exportable as a watermarked PDF, archived with timestamp and approver identity. (5) Rejected — the approver has documented a rejection reason; the contributor resumes from Draft.

Submitting for approval

From the document edit screen, click Submit for approval. Conformaze checks that required fields are filled and that prerequisites are met (for example: a PIA associated with a high residual risk must be approved before its ROPA register can be). If a condition is not met, a detailed message lists the actions to take before submission. Once submitted, the document is write-locked for the entire team except the designated approver.

Important

A PIA with residual risk >= 4x4 (score 16+) blocks approval of the associated ROPA registry. You must add mitigation measures or document a formal risk acceptance by management before the registry can be approved.

Approve, request changes, or reject

The approver receives a notification (email + task in the dashboard) as soon as a document is submitted. From the review screen, they can: Approve — the document becomes official, exportable as a watermarked PDF, and an event is recorded in the audit trail; Request changes — they comment on sections to revise, the document returns to Draft with annotations; Reject — they document the rejection reason, the document returns to Draft. All these actions are timestamped and kept indefinitely in the audit trail.

Who can approve? (RACI matrix)

Approval rights depend on the document type and the application role. By default: the Privacy Officer approves PIAs, DPA contracts, and incident notifications; an organization administrator approves ROPA registers and internal policies; a contributor can submit but not approve. You can customize this matrix from Settings > Application roles. Any matrix change is itself audited.

After approval: export, archiving, and revisions

Once approved, a document is exportable as a watermarked PDF including the version number, approval date, approver identity, and an integrity hash. This export constitutes your evidence in case of a CAI investigation. Any later change creates a new version: the document returns to Draft, keeps its full history, and a new approval cycle is required before the new version becomes official. You can schedule an automatic annual review to prevent an approved document from becoming outdated.

    Approval workflow (RACI) — Conformaze Help Center | Conformaze