The SDLC pipeline
Compliance
Requirements checked against regulatory frameworks, with every gap flagged.
The Compliance step checks the project's requirements against the regulatory frameworks Alara Code ships with, and writes the result up as a Compliance Assessment: which controls the requirements trigger, how severe each one is, what evidence each needs, and the overall risk. It is a report, not a review gate — it runs once the test plan exists and is complete as soon as it is written.
What you get
A Markdown document titled Compliance Assessment. The bridge writes all of it from the agent's structured reply — the agent returns data, not prose — so its layout is fixed:
| Section | Contents |
|---|---|
| Title block | Project, client, version, date. |
| Summary | The assessment mode, the frameworks that produced findings, and the overall risk level. |
| Findings | One row per control a requirement triggered: framework, control, title, triggering requirement, severity, status and required evidence. |
| Gap Analysis | Total controls and the compliant, partial, non-compliant and not-applicable counts, with a pie chart of control status when any of those counts is above zero. |
| Critical Gaps | A bullet list, or "None." |
| Recommendations | The agent's recommendation. |
| Version History | One row per run. |
The frameworks
Every run checks against all eight framework definitions, each a list of controls with keywords, required evidence and a severity:
| Framework code | Framework | Controls |
|---|---|---|
AAOIFI | Accounting and Auditing Organisation for Islamic Financial Institutions — IT governance and Sharia compliance | 10 |
CBUAE-2024 | Central Bank of the UAE — Information Assurance Regulation 2024 | 10 |
GDPR | EU General Data Protection Regulation | 20 |
ISO-27001 | ISO/IEC 27001:2022 Information Security Management System | 20 |
PCI-DSS-4 | Payment Card Industry Data Security Standard 4.0 | 12 |
PPRA-2024 | Public Procurement Regulatory Authority Rules 2024 | 18 |
SAMA-2024 | Saudi Arabian Monetary Authority Cybersecurity Framework 2024 | 20 |
SBP-2024 | State Bank of Pakistan IT Governance Framework 2024 | 25 |
All eight are sent on every call rather than guessed from the project, because missing a critical control is a worse failure than scanning a few extra.
Before you run it
- The STS must exist. It does not need to be approved. Until it exists,
/complianceis locked with "Run /sts first". The assessment itself reads only the requirements; waiting for the STS keeps it in pipeline order, after the core documents. - The project state must hold a non-empty requirement list.
How it works
Compliance makes one skill call, sdlc-compliance-checker, with up to three attempts — the same skill the SRS step uses for its inline flags.
The skill works mechanically, so the result is repeatable:
- For each requirement, it joins the title, description and acceptance criteria into one text.
- For each control in each framework, it checks whether any of the control's keywords appears in that text, ignoring case.
- Each match is a finding, recorded with the framework code, control id and title, the triggering requirement, the matched keyword, the control's severity and required evidence exactly as the framework states them, and status "pending-review".
- It reports each framework, control and requirement combination once.
- It never adds keywords, frameworks or controls that are not in the definitions. Zero findings is a valid result for a project with no regulated scope.
It also returns which frameworks now apply to each flagged requirement, the gap counts, and a summary with the overall risk level: critical if any finding is critical, otherwise high if any is high, otherwise medium if there are any findings, otherwise low.
The reply is validated against the compliance schema, which rejects unknown keys and checks every required field. When it passes, the bridge merges the findings into the project's compliance flags — updating a flag that already exists for the same framework and control, adding new ones — and adds the frameworks to each flagged requirement.
The run panel shows: Checking project state, Assessing frameworks, Persisting to project state, Writing the Markdown document. The completion message gives the mode, the number of flags and how many are critical.
Ids this step owns
None. Findings are identified by the framework's own codes — a framework code such as SBP-2024 and a control id from that framework's definition — and point at the requirement ids (REQ-…) that triggered them.
Reviewing it
There is no approval step, but the report is meant to be read:
- Start with the critical and high findings, and check the SDS addresses each control's required evidence.
- A finding triggered by a keyword that is clearly incidental is worth noting, but the fix is in the requirement wording, not the report.
- Frameworks the project is not subject to will still produce findings if their keywords match. Ignore those, or reword the requirement.
The Proposal names the frameworks found in the project's compliance flags, so running Compliance before the Proposal gives the proposal writer the fuller list.
When it fails
| What you see | Why | What to do |
|---|---|---|
/compliance locked: "Run /sts first" | The STS has not been produced. | Run /sts. |
| "requirements[] is empty — run /srs first." | The project state has no requirements. | Run /srs. |
| "ECC script failed: scripts/validate-json.js" | Three replies in a row failed the compliance schema — usually an extra key such as bySeverity, or a wrong mode value. | Run it again; check sdlc-compliance-checker.md is attached as shipped. |
Under the hood
- The driver is
bridge/src/services/compliancePipeline.service.ts; the message is built bybridge/src/lib/complianceMessage.tsfrom the files inbridge/sdlc-engine/frameworks/. - Written to the project state:
complianceFlags(merged by framework and control), each requirement'scomplianceFrameworks, andartifacts.compliance. The phase moves to compliance unless the project is already further along. - The document is
.sdlc/artifacts/compliance-vN.md. Because Compliance is never approved, every run takes the next version number. - The project's flags are also available from
GET /api/projects/:id/compliance-flags.