This fictional example illustrates a system record. Adapt its scope, values and targets to your organisation's approved criteria; it is not a recommended configuration for every CRM service.

Define the boundary

Name the record Customer relationship platform. Describe a hosted service used by the sales and account-management teams to maintain customer contact information and interactions.

State whether the record includes integrations, exported data and identity services. Document separately operated dependencies and shared provider responsibilities in Complementary information, with third-party links where appropriate.

Record context and architecture

AreaExample information
ContextSales and account-management activities; production use; responsible business unit and regions.
CriticalityThe organisation's approved classification, with a rationale tied to the effect of an outage or information loss.
ArchitectureApplication domain; hosted service; externally managed components identified in the scope.
ExposureWhether users or integrations reach the service through the internet.
Third partiesThe provider and other material dependencies represented by existing records.

Select matching workspace catalogue values instead of copying labels that are not configured. Explain important qualifications in prose.

Classify information and recovery needs

Add information types such as customer contact details and commercial interactions. Assess each one's confidentiality, integrity and availability requirements using the agreed CIA scale. Review the resulting summary and record whether personal or health information is processed.

For illustration, the organisation might approve an RTO of four hours and an RPO of fifteen minutes. These are fictional business targets. Verify that the actual service arrangements and recovery evidence support the targets before treating them as achievable.

Assign responsibility and supporting work

Record named operational contacts and assign the accountable workspace owners. Link a completed risk demand that assesses the defined scope and set the next assessment date where appropriate.

Attach relevant evidence or links in the record panel. Configure a separate record-review schedule to keep the inventory information current. Do not mark a review complete merely because a reminder became due.

Save and check

Use Done in section editors, then save the pending record changes. Verify owner, relationship, assessment and evidence actions separately. Read the completed record as another assessor would: the purpose, boundary, responsibility, data, dependencies and assessment basis should be understandable without the original author present.