“…Other works (Ghanavati, Amyot, 2009;Businska et al, 2012;Massey at al 2010;Maxwell, Anton, 2010;Antón, Earp, Carter, 2013 ) propose how to guarantee compliance between business processes and law (Ghanavati, Amyot, 2009;Businska et al, 2012) or between law and software requirements (Massey at al 2010;Maxwell, Anton, 2010;Antón, Earp, Carter, 2013). Since we are dealing with continuous compliance, we also review the works related to goal model and compliance (Yu, Shinpei, Motoshi 2017) (Ghanavati et al,2014), continuous compliance (Flowerday and von Solms 2005;KPMG, 2008;Armellinet al, 2011;Galán et al, 2016), and compliance monitoring (Linh et al, 2015;Namiri and Stojanovic, 2007;Santos et al, 2012;Ingolfo and Souza, 2013;Siegbahn and Engel, 2009). Breaux and Anton (2005) propose a method called Semantic Parametrization that is used together with goal analysis for the derivation of semantic models of Policy Privacy Documents.…”