Compliance Hub
Run a SOX, SOC 2, ISO 27001, HIPAA or ISO 9001 / 14001 / 45001 program: control register, recurring attestation campaigns, a risk register fed from incidents and inspections, a legal register with compliance status, and auditor-ready evidence packages.
MangoApps
Meet the agent
This app ships with a production AI agent — permission-aware, tenant-scoped, audit-logged, and governed by the Agent Development Lifecycle.
Compliance Hub AI
Control register, attestation campaigns, framework coverage, risk and legal registers, audit-grade trail.
Overview
Compliance Hub is the audit file for the safety, quality, and security work already happening in MangoApps. Seven curated framework catalogs — SOC 2, SOX, ISO 27001, HIPAA, ISO 45001, ISO 9001, and ISO 14001 — import in one click and crosswalk to each other, and every ISO clause names the record that satisfies it: a Safety Hub incident investigation, an inspection, a CAPA action, a toolbox talk, a policy, an SOP. Those records link in as evidence, so the proof is the live operational record rather than a re-keyed copy.
A control register tracks owners, cadence, and effectiveness; recurring campaigns fan out attestations and lock on completion; flagged items become owned, due-dated findings. A risk register rates threats on a 5×5 likelihood × impact matrix with inherent and residual scores and is fed from serious incidents, near misses, failed inspections, and regulator findings. A legal register tracks the laws, permits, and contractual requirements you are bound by, with a compliance status and an evaluation cadence, and suggests employment-law rules for your mapped jurisdictions.
Auditor exports carry the control register, sign-off trails, evidence, and both registers as XLSX or PDF, on a schedule or through a token-gated read-only portal. A built-in AI agent answers posture, coverage, evidence-gap, finding, risk, and obligation questions, and can draft a control or launch a campaign behind a confirmation.
Highlights
Capabilities
Framework Library & Coverage
-
Seven curated catalogs: SOC 2, SOX ITGC, ISO 27001, HIPAA, ISO 45001, ISO 9001, ISO 14001 (122 controls)
-
113 cross-framework crosswalks (exact / partial / related) so one control satisfies several frameworks
-
Every ISO clause names the MangoApps record that satisfies it — incidents, inspections, CAPA, toolbox talks, policies, SOPs
-
One-click import, idempotent "import the gaps," import by category, and pull in crosswalked equivalents
-
Coverage matrix (framework × category, imported vs missing)
Control Register & Effectiveness
-
Define controls with reference code, framework, category, owner, and a review cadence that derives the next due date
-
Effectiveness rating per control (effective / partially effective / deficient / not tested) with a last-tested date
-
Due-soon and overdue tracking on the dashboard, register, and nightly reminders
-
Bulk-import controls from CSV with a downloadable template
-
See a control's full trail — campaigns, evidence, findings, and cross-framework equivalents
Risk Register & Legal Register
-
Risk register on a 5×5 likelihood × impact matrix with inherent and residual ratings, owner, site, treating control, and review cadence
-
Risks suggested from serious incidents, near misses, failed inspections, and regulator visit findings
-
Legal register of laws, permits, and contractual requirements with citation, authority, and applies-to
-
Compliance status per obligation (compliant / partially / non-compliant / not assessed) with an evaluation cadence
-
Obligations suggested from the employment-law catalog for your mapped jurisdictions
-
Both registers on the dashboard, in search, in the auditor export, and with nightly review reminders
Review Campaigns, Attestations & Findings
-
Campaign types: access review, cert review, change review, general
-
Auto fan-out review items (one per user, vendor certification, or documented change)
-
Attest / flag / mark N-A with decision notes and per-item evidence, singly or in bulk
-
Require evidence before an item can be attested (opt-in gate)
-
Personal attestation inbox with assignment, activation, and due-soon reminders
-
Lifecycle draft → active → completed (locked) → archived; admin unlock replaces the prior sign-off
-
Recurring campaigns open themselves when a control's review date arrives
-
A flagged item auto-opens a finding; findings can also be raised by hand against a control
-
Findings carry severity, owner, and due date through open → remediated / accepted / closed, with a stamped resolution
Evidence Registry
-
Link live records as proof — vendor certs, contract obligations, change requests, employee certifications
-
Link safety and quality records as proof — incidents, CAPA actions, toolbox talks, observations, inspections, policies, SOPs
-
Attach uploaded files (up to 25 MB) on controls, campaigns, items, findings, risks, and obligations, each with an optional expiry date
-
Auto-collect evidence from linked records (opt-in)
-
Step-up identity verification to download evidence (opt-in)
Auditor Exports & Portal
-
Point-in-time XLSX workbook — controls, campaigns, sign-off trail, evidence, and on a full export the risk and legal registers
-
PDF package, or an export scoped to one framework
-
Recurring export schedules (monthly / quarterly / annually) and an immutable export history
-
Read-only auditor portal via token link, with optional expiry and revoke; anonymous links can be switched off per tenant
AI, Analytics & Integrations
-
Compliance analytics: coverage, campaign throughput, on-time rate, 6-month trend
-
AI agent answers posture, overdue-control, evidence-gap, coverage, finding, risk-register, and legal-register questions
-
AI agent creates a control or launches a campaign (with confirmation)
-
Native vendor/change register (with CSV import) so cert and change reviews work standalone
-
Composes with Safety Hub, Inspections, Asset Pro / Supplier Hub, Contracts, Service Desk, Policy Hub, SOP Hub, and Skills & Credentials
-
Reviewer surface on mobile — pending items, attest / flag / N-A
Limits & Specs
-
Frameworks: SOC 2, SOX, ISO 27001, HIPAA, ISO 45001, ISO 9001, ISO 14001, custom
-
Risk rating scale: 5 × 5 (score 1–25; low, medium, high, critical)
-
Max evidence file size: 25 MB per file
-
Default due-soon window: 14 days (admin-configurable)
-
Export formats: XLSX, PDF
-
Access: Requires a license — per-tenant opt-in; sold standalone or in the Safety & Compliance Pack
Use cases
FAQ
No. Compliance Hub is a focused compliance layer inside MangoApps — control register, seven prebuilt framework catalogs, review campaigns, findings, a risk register, a legal register, evidence, and auditor export. It has no agentless continuous-monitoring connectors, and it composes with the apps you already run instead of re-modeling them. Management of change and contractor pre-qualification live next door in Safety Hub.
Yes. The catalog ships curated ISO 45001, ISO 9001, and ISO 14001 clause sets alongside SOC 2, SOX, ISO 27001, and HIPAA, crosswalked across the harmonised management-system clauses. Each ISO clause's evidence hint names the record MangoApps already keeps — a Safety Hub incident investigation, an inspection, a CAPA action, a toolbox talk, a policy, an SOP — and those records link in as evidence.
The risk register rates each risk on a 5×5 likelihood × impact matrix with inherent and residual scores, an owner, a site, a treating control, and a review cadence; it suggests risks from serious incidents, near misses, failed inspections, and regulator visit findings. The legal register lists the laws, permits, and contractual requirements you are bound by with a citation, authority, applies-to, compliance status, and evaluation cadence, and suggests employment-law rules for your mapped jurisdictions. Both appear on the dashboard, in search, and on the full auditor export.
Yes. Seven platform-curated catalogs — 122 controls with 113 crosswalks — are authored in the MangoApps Console. A tenant imports a whole framework, one category, or just the gaps in one click, and crosswalks let one control satisfy several frameworks at once. The catalogs are curated starter sets, not the exhaustive official standards.
No. A native vendor/change register makes certification and change reviews work standalone. When Safety Hub, Inspections, Asset Pro / Supplier Hub, Contracts, Service Desk, Policy Hub, or SOP Hub are present, their records link in as evidence or feed the registers, and Compliance Hub dedupes against them.
A completed campaign is locked: its items and evidence become read-only for audit integrity. An admin can explicitly unlock it for re-attestation, which reopens the campaign and replaces the earlier sign-off with the new one. The unlock is logged.
A multi-sheet XLSX workbook (or a PDF) snapshotting controls, campaigns, sign-off trails, and evidence; a full export also carries the Risk Register and Legal Register sheets. Exports run on demand or on a monthly, quarterly, or annual schedule, are never deleted, and can be published as a token-gated read-only portal with an optional expiry — or anonymous links can be switched off for the tenant.
Evidence is either a linked live record — a vendor certification, contract obligation, change request, employee certification, incident, CAPA action, toolbox talk, safety observation, inspection, policy, or SOP — or a file you upload (up to 25 MB). Each evidence record can carry an expiry date. You can require evidence before an item can be attested, auto-collect it from linked records, and gate downloads behind step-up identity verification — each an admin toggle, off by default.
They do the work; Compliance Hub is the audit file. Safety Hub runs incidents, inspections feed CAPA, Policy Hub authors policies with acknowledgments, and SOP Hub tracks procedures. Compliance Hub maps those records to framework clauses, rates the risks they surface, tracks the obligations behind them, runs the attestations, and hands an auditor the package.
The agent answers read questions — controls, posture, your pending attestations, evidence gaps, framework coverage, findings, the risk register, and the legal register — for anyone with app access. People who hold the manage capability can also ask it to create a control or launch a review campaign; those writes route through the same controller as the UI, show a diff preview, and require an explicit Confirm. Who may manage the program is a per-tenant capability setting: app admins only by default, or specific groups.