Enabling Continuous Compliance with Product-Repository Integrated Traceability Management Tool
| dc.contributor.author | Yu, Jinlu | |
| dc.contributor.department | Chalmers tekniska högskola / Institutionen för data och informationsteknik | sv |
| dc.contributor.department | Chalmers University of Technology / Department of Computer Science and Engineering | en |
| dc.contributor.examiner | Horkoff, Jennifer | |
| dc.contributor.supervisor | Knauss, Eric | |
| dc.date.accessioned | 2026-07-09T06:53:32Z | |
| dc.date.issued | 2026 | |
| dc.date.submitted | ||
| dc.description.abstract | Continuous compliance is becoming increasingly important as software-intensive systems are developed in regulated domains, where both systems and regulatory expectations evolve over time. Traditional compliance approaches often rely on manual evidence collection and periodic assessment, making it difficult to maintain compliance during continuous development. This thesis investigates how product repository-integrated traceability management (PRITM) tools can support continuous compliance by managing compliance-relevant artifacts, traceability links and checks within a product repository. The study follows a Design Science Research approach with three iterations. For RQ1, literature review and workshops were used to develop a reference model of continuous compliance. The main finding is that software development activities support continuous compliance by producing and updating artifacts that can serve as evidence of compliance. However, these artifacts only become useful evidence when they are traceable, maintained and connected to compliance requirements and compliance checks. For RQ2, the reference model was instantiated via a TReqs plugin prototype named treqs-compliance. The prototype uses ISO 26262 Part 8 Clauses 7 and 8 as an example to demonstrate how standards, clauses, compliance requirements, and work products can be represented and maintained in a product repository. The prototype implements rule-based structural checks, lifecycle status handling, change-review detection, and compliance report generation. The main finding is that PRITM tools can support continuous compliance by keeping compliance artifacts close to development artifacts, managing traceability, and enabling lightweight automated checks. For RQ3, the prototype and final reference model were used to reflect on where effort could be reduced compared to traditional compliance approaches. The results suggest that PRITM tools can mainly reduce effort for structural and traceability related tasks, such as checking artifact existence, identifying required fields, and locating missing links. However, semantic content evaluation, runtime context checks, and structured compliance argumentation remain outside the implemented scope and still require human judgment or more advanced tool support. This thesis contributes a reference model for understanding continuous compliance across activities and artifacts, with a particular focus on the DevOps lifecycle. It also provides a prototype demonstration showing how selected concepts can be implemented in a PRITM tool. | |
| dc.identifier.uri | https://hdl.handle.net/20.500.12380/311960 | |
| dc.language.iso | eng | |
| dc.setspec.uppsok | Technology | |
| dc.subject | continuous compliance, compliance as code, traceability, Requirements Engineering (RE), ISO 26262 | |
| dc.title | Enabling Continuous Compliance with Product-Repository Integrated Traceability Management Tool | |
| dc.type.degree | Examensarbete för masterexamen | sv |
| dc.type.degree | Master's Thesis | en |
| dc.type.uppsok | H | |
| local.programme | Interaction design and technologies (MPIDE), MSc |
