The Compliance Workspace provides a single-pane view for compliance managers and analysts to assess the organization's overall compliance posture. It enables them to track time-sensitive issues, high-risk exceptions, ongoing policy acknowledgments, and new regulatory changes. The workspace also allows them to define and manage the compliance library, test the effectiveness of controls, and continuously monitor control performance through Key Control Indicators (KCIs). Using the centralized issue management capability, they can also define the remediation plans and ensure that the control gaps are addressed promptly.
Highlights of the Next Experience user interface:
- A default home page tailored to each user persona that delivers actionable insights and quick links.
- A well-structured navigation menu that organizes modules based on user roles and needs.
- A redesigned page layout that enhances the user experience for practitioners, business users, and executives.
- A holistic view of record pages with actionable insights specific to what is being viewed.
- A 360° view of relationships for comprehensive visibility.
- Personalized homepage for corporate compliance managers to manage their work effectively.
- Personalized homepage for corporate compliance analysts to manage their work effectively.
- Consolidated task landing page to manage all assigned tasks for the users and their groups.
- Centralized compliance library.
- Policy authoring and redlining integrated with Microsoft 365, Google Drive, and SharePoint.
- Policy acknowledgment management.
- Policy exception management.
- Design and operational effectiveness testing of controls.
- Continuous monitoring of controls through Key Control Indicators (KCIs).
- Issues landing page for triaging, managing, and remediating compliance issues.
- Regulatory change management landing page.
- Security and access features to manage the confidentiality of engagements, audit tasks, issues, remediation tasks, evidence requests, and other related activities.
New:
Workflow introduced on control objectives:
- Major and minor updates can be done on a separate record instead of the current active record.
- Owners and owning groups added on control objectives.
- Dynamic approvals enabled
- Auto-publish of control objectives based on the Effective date
- Workflows/reports updated to exclude working drafts.
- All control objectives will have a record nature as the current version, and active ones will be published by default.
Changed:
Minor update done on a control objective will not move a control back to draft.
The following GRC applications must be installed and activated:
- GRC: Policy and Compliance Management (com.sn_compliance)
- GRC: Common Workspace Elements (com.sn_grc_workspace)
- Smart Assessment Core (com.sn_smart_asmt))
- sn-smart-assessment-connected
- sn-smart-assessment-designer
Permissions and roles:
- Role required to install the app: System Administrator (admin)
To enable policy redlining capability, ensure you have the following platforms and applications installed:
- Platform version: San Diego Patch-1 and above
- Multiple Provider Document Services Framework
- Microsoft Azure AD Spoke version 3.5.0
- Microsoft OneDrive Spoke for Document Service Framework version 1.0.5
- Microsoft OneDrive Spoke version 2.1.1
Note: IntegrationHub entitlements included in the Compliance Workspace are solely restricted to use for Policy Authoring integration with Microsoft 365. Any other usage requires purchase of additional IntegrationHub entitlements.