The Compliance Workspace provides a single-pane view for compliance managers and analysts to assess the organization's overall compliance posture. It enables them to track time-sensitive issues, high-risk exceptions, ongoing policy acknowledgments, and new regulatory changes. The workspace also allows them to define and manage the compliance library, test the effectiveness of controls, and continuously monitor control performance through Key Control Indicators (KCIs). Using the centralized issue management capability, they can also define the remediation plans and ensure that the control gaps are addressed promptly.
Highlights of the Next Experience user interface:
- A default home page tailored to each user persona that delivers actionable insights and quick links.
- A well-structured navigation menu that organizes modules based on user roles and needs.
- A redesigned page layout that enhances the user experience for practitioners, business users, and executives.
- A holistic view of record pages with actionable insights specific to what is being viewed.
- A 360° view of relationships for comprehensive visibility.
- Personalized homepage for corporate compliance managers to manage their work effectively.
- Personalized homepage for corporate compliance analysts to manage their work effectively.
- Consolidated task landing page to manage all assigned tasks for the users and their groups.
- Centralized compliance library.
- Policy authoring and redlining integrated with Microsoft 365, Google Drive, and SharePoint.
- Policy acknowledgment management.
- Policy exception management.
- Design and operational effectiveness testing of controls.
- Continuous monitoring of controls through Key Control Indicators (KCIs).
- Issues landing page for triaging, managing, and remediating compliance issues.
- Regulatory change management landing page.
- Security and access features to manage the confidentiality of engagements, audit tasks, issues, remediation tasks, evidence requests, and other related activities.
New
- Policy authoring now supports a hybrid authentication approach for Google Drive and Sharepoint, using both personal and service accounts:
- Actions such as creating, connecting, and uploading documents use personal authentication.
- Actions such as enabling or disabling sync, updating links, and finalizing the playbook use the service account.
- An alternative DOCX-to-HTML conversion API is now available for Policy authoring, resolving overlapping text issues in translated Knowledge articles caused by the current GroupDocs-based API. Note that output formatting may differ from the current API.
- A dashboard landing page is now available on the left panel of the Compliance Workspace.
- Control, entity, and user information is now displayed in control attestation (smart assessment) lists across the Compliance Workspace.
Fixed issues
This release resolves the following issues:
- Translate button not functioning on the Compliance Workspace.
- Workspace View rule not working as expected due to conflicts between the record view and the popup view.
- Control status value briefly appearing and then disappearing after the page finishes loading.
- Policy text losing spacing and formatting when viewed from the Policy Text tab compared to the Details tab.
- Homepage report population job causing out-of-memory issues that require multiple node restarts.
The following GRC applications must be installed and activated:
- GRC: Policy and Compliance Management (com.sn_compliance)
- GRC: Common Workspace Elements (com.sn_grc_workspace)
- Smart Assessment Core (com.sn_smart_asmt))
- sn-smart-assessment-connected
- sn-smart-assessment-designer
- Integrated Risk Management Standard
Permissions and roles:
- Role required to install the app: System Administrator (admin)
To enable Policy Redlining, ensure the following platforms and applications are installed:
- Platform version: San Diego Patch-1 and above
- Multiple Provider Document Services Framework
- Microsoft Azure AD Spoke, version 3.5.0
- Microsoft OneDrive Spoke for Document Service Framework, version 1.0.5
- Microsoft OneDrive Spoke, version 2.1.1
Note: IntegrationHub entitlements included in the Compliance Workspace are restricted to Policy Authoring integration with Microsoft 365. Any other usage requires additional IntegrationHub entitlements.