1. Confirm applicability
Identify the regulated entities, current MAS source material, relevant core functions, senior-manager population, material-risk-personnel approach, and local interpretation before encoding requirements into software.
2. Clean the source data
Reconcile organisation charts, HR records, committee structures, job descriptions, delegated authorities, issue registers, and existing responsibility maps before migration. Do not automate contradictions.
3. Define the evidence model
Decide what proves each operating step, who owns it, who reviews it, how long it is retained, and what must be reproducible for audit or supervisory review.
4. Configure workflow and access
Implement maker-checker approvals, role-based access, entity scoping, reminders, escalation, exception handling, and change control around the actual operating model.
5. Test real scenarios
Walk through appointment, departure, interim coverage, reorganisation, material incident, outsourcing change, conduct investigation, and unresolved issue transfer. Verify the audit trail after each scenario.
6. Govern the system itself
Assign product ownership, change approval, access review, integration monitoring, backup, recovery, data quality, retention, and periodic control testing. IAC evidence is only useful if the supporting system is trustworthy.