| Model Focus | Topic Area | Source |
| 1) Interrelationships of COBIT components | IT-Governance | [21] p. 8 |
| 2) Relationships between process modelling and control modelling concepts | Compliance | [22] p. 5 |
| 3) Selected correspondences between business process and risk | Risk management | [23] p. 24 |
| 4) Conceptual model of the compliance management problem | Compliance | [24] p. 5 |
| 5) A basic high level model for regulatory compliance | Compliance | [25] p. 180 |
| 6) Policy ontology | Compliance | [25] p. 187 |
| 7) Rule ontology | Compliance | [25] p. 188 |
| 8) A MOF/UML metamodel of a business protocol model | Compliance | [26] p. 562 |
| 9) A MOF/UML metamodel of an obligation | Compliance | [26] p. 563 |
| 10) A MOF/UML metamodel of a conditional commitment | Compliance | [26] p. 563 |
| 11) Rule ontology (constraints) | Compliance | [27] p. 794 |
| 12) The upper domain model of the internal controls compliance | Compliance | [28] p. 62 |
| 13) Relationship between an application control and a business process | Compliance | [28] p. 62 |
| 14) A semi-formalization of the control implementation | Compliance | [28] p. 63 |
| 15) IT risk reference model | Risk management | [29] p. 4 |
| 16) Meta-reference model for compliance management | Compliance | [30] p. 555 |
| 17) A classification model for automating compliance | Compliance | [31] p. 41 |
| 18) Exemplary excerpt from a corporate rule base | GRC | [4] p. 364 |
| 19) ISO 27001 metamodel | Risk management/Compliance | [9] |
| 20) The oracle corporate analysis flow | Compliance | [32] p. 42 |
| 21) The regulatory mandate and compliance framework control domain relationship | Compliance | [32] p. 43 |