Compliance Management

BC-130 Level 1 Cross-Industry 108 providers 233 API surfaces 54 rated strong or better

Ensuring adherence to laws, regulations, and internal policies.

Compliance Management (BC-130) is a level-1 business capability in the Cross-Industry model. The catalog holds 233 API surface(s) from 108 provider(s) that can perform some part of it, 54 of them rated strong or better. Reach is the vendor surface that lands on this capability — it is not a claim about what any particular organisation has deployed.

Where this capability definition comes from. This capability is part of a published business-architecture model that API Evangelist did not author. It is redistributed here under CC-BY-4.0. Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 Changes: Consolidated from 333 per-L1 YAML files into one JSON; English only (upstream i18n/ omitted); descriptions whitespace-normalised. No capability was added, removed, renamed or re-parented. Source repository · NOTICE and third-party framework attributions

Sub-capabilities

Regulatory Compliance Management BC-130.10

Compliance with sector-specific regulations.

36 providers, 74 API surfaces

Policy Management BC-130.20

Policy lifecycle - drafting, approval, attestation, retirement.

5 providers, 8 API surfaces

Ethics & Conduct Management BC-130.30

Code of conduct, ethics, whistle-blowing programmes.

no catalog coverage

Anti-Bribery & Corruption Management BC-130.40

ABC programmes, third-party due diligence, gifts and hospitality.

1 provider, 1 API surface

Privacy & Data Protection Management BC-130.50

GDPR/equivalent compliance, data subject rights, privacy by design.

69 providers, 140 API surfaces

Providers that reach this capability

Ordered by rating band. Reach means a provider publishes an API surface that can perform some part of this capability — it is not a claim that any particular organisation has deployed it.

Exemplar 22 Complete, well-documented, and agent-ready
Strong 32 Solid coverage with minor gaps
Developing 45 Usable, with meaningful gaps to close
Orion Advisor SolutionsCompliance/DisclosePortfolio/OfacChecksPortfolio/OfacFiles3 APIs53.5ObservePointaudits-consent-categoryconsent-categoriescookie-privacy-reporttag-privacy-report4 APIs53.4EverbridgePrivacy Policy1 API53.3YouSignWatchlist Verification1 API52.8JusttData Subjects1 API52.2TranscendConsentData Subject RequestPreferences3 APIs52.2LaterDataSubjectRequest1 API51.6DotfileAML checkCasesCompany Monitoring checkDocument check9 APIs51.1MavrckDataSubjectRequest1 API51.1SocotraCompliance1 API50.9MINEEvidenceSearchPrivacyRightsPublicTickets3 APIs50.6QualioCompliance Intelligence1 API50.0SafelloCompliance1 API50.0InthConsentSubjects2 APIs49.7DiligentCDDName Screening2 APIs49.6American Express Global Business Travelgdpr-controller1 API49.2PimlocMedia1 API49.1Elastic PathPersonal Data Erasure Requests1 API48.9Pendo.ioBulk Deletion (GDPR/CCPA)1 API48.4TRM LabsSanctions Screening1 API48.0WegalvanizeCompliance Maps1 API47.5London Stock Exchange GroupCaseMedia-CheckZfs3 APIs47.3VTEXData Subject Rights1 API47.1DixaAnonymization1 API46.5University of Amsterdamcompliance1 API46.5AghanimGDPR Requests1 API46.3SERTICACertificates1 API46.0Sigma360Monitoring: Entity CreationMonitoring: Entity ManagementOne-Off Screening3 APIs45.8Google Cloud Assured WorkloadsViolations1 API45.6SEONAML1 API45.4SurvicatePersonal Data1 API45.0UsercentricsConsentConsent ModeTCF3 APIs44.9PrewaveEUDR - Customers - DDS1 API44.4DinariKYC1 API44.0SAP Commerce CloudConsents1 API44.0PersonaInquiries1 API43.9SiteJabberPrivacy1 API43.8WishEU Product ComplianceFrance EPR ComplianceGermany EPR Compliance3 APIs43.8Harbor ComplianceLicenses1 API42.8OnfidoReports1 API42.8TikTokData Portability1 API42.5LiveIntentAPI ReferencesLegacy2 APIs42.1Salvmanual-alertsmonitoring-checksscreening-alertsscreening-checks6 APIs42.1CalendlyData Compliance1 API40.7sanctions.ioAdverse MediaBatch ScreeningMonitoringScreening4 APIs40.0
Thin 9 Limited public surface area

Workflows that realise this capability

Arazzo workflows whose own sourceDescriptions call APIs that carry this capability. The link is derived, not asserted: each workflow declares x-realizes-capability-ids with the spec and confidence behind it.

This page carries no rating. Capabilities are not rated. A capability is a description of what a business does, not a thing a company publishes, so a Kin Score would have nothing to measure.
The edge table is a Pro feature. This page shows which providers and tags reach Compliance Management. The underlying tag → capability edges — each with the quoted fragment of the provider's own OpenAPI that evidences it, a calibrated confidence score, and the contract-provenance gate it passed — are available through the API, along with company-level capability maps. Only edges at confidence ≥ 0.7 with evidence found verbatim in the source contract are published at all.

See plans →  ·  How the edges are graded →