Generating controls and risks for entities that are out of the compliance program’s agreed scope floods owners with noise. What should architecture enforce before generation?
Select an answer to reveal the explanation.
Short Explanation
Generation without a fence is a firehose. Scope boundaries decide which entities are in the program before controls and risks spawn. Otherwise owners drown in junk for buildings and apps nobody asked IRM to govern.
Full Explanation
Item generation multiplies content across scoped entities. Architecture must enforce scope boundaries—entity filters, classes, or program scope—before generating controls and risks so out-of-scope objects do not create work for the wrong owners. Unbounded generation degrades adoption and obscures real compliance obligations.