Compliance Hub
Track software vendors, run recurring access and security review attestation cycles, log required changes, and produce auditor-ready evidence packages for SOX and SOC 2 compliance.
MangoApps
Meet the agent
This app ships with a production AI agent — permission-aware, tenant-scoped, audit-logged, and governed by the Agent Development Lifecycle.
Compliance Hub AI
Control register, attestation campaigns, framework coverage, audit-grade trail.
Overview
Compliance Hub gives compliance owners a single place to run a SOX or SOC 2 program without leaving MangoApps. It adds a control register (the list of controls an auditor walks), recurring review campaigns that fan out attestations to reviewers (review user access, review access roles, review security certifications), an evidence registry that links each control to the records that prove it — vendor SOC 2 certifications, change requests, form submissions, or uploaded files — and one-click auditor exports that snapshot controls, sign-off trails, and evidence as a point-in-time package. It composes with the apps you already use (Asset Pro / Supplier Hub for the software-vendor inventory, Contracts for vendor certifications and obligations, and Service Desk Change Management for the change log) rather than re-modeling them. Built for first-time compliance programs that need structure inside their everyday platform, not a separate GRC tool.
Highlights
Capabilities
Control Register & Effectiveness
-
Define controls with reference code, framework, category, and owner
-
Effectiveness rating per control (effective / partially effective / deficient / not tested)
-
Per-control review frequency with configurable due-soon and overdue tracking
-
Bulk-import controls from CSV with a downloadable template
-
Launch a review campaign straight from a control
-
See a control's full trail — linked campaigns, evidence, findings, and cross-framework equivalents
Framework Library & Coverage
-
Platform-curated catalogs (SOX, SOC 2, ISO 27001, HIPAA)
-
One-click import, idempotent "import the gaps," and import-by-category
-
Pull in crosswalked equivalents from other frameworks
-
Coverage matrix (framework × category, imported vs missing)
Review Campaigns & Attestations
-
Campaign types: access review, cert review, change review, general
-
Auto fan-out review items (one per user, vendor certification, or documented change)
-
Attest / flag / mark N-A with decision notes and per-item evidence
-
Bulk-attest all of your pending items at once
-
Require evidence before an item can be attested (opt-in gate)
-
Reviewer notifications & a personal attestation inbox — assignment, activation, and due-soon reminders
-
Enforced lifecycle draft → active → completed (locked) → archived, with a completion gate
-
Admin unlock for re-attestation (the unlock itself is logged)
Findings & Remediation
-
Auto-open a finding when a review item is flagged
-
Raise findings manually against a control
-
Severity, owner, and due date with an open → remediated / accepted / closed lifecycle
-
Overdue-findings tracking on the dashboard
Evidence Registry
-
Link existing records as proof — vendor certs, change requests, contract obligations, or employee certifications
-
Attach uploaded files (up to 25 MB) as evidence
-
Evidence expiry dates with expiring-soon and expired flags
-
Auto-collect evidence from linked records (opt-in)
-
Step-up identity verification to download evidence (opt-in)
Auditor Exports & Portal
-
Point-in-time export of controls, the sign-off trail, and evidence
-
Multi-sheet XLSX workbook or PDF package, scoped full / framework / campaign
-
Recurring export schedules (monthly / quarterly / annual)
-
Immutable export history — export rows are never deleted
-
Read-only auditor portal via token link, with optional expiry and revoke
AI, Analytics & Integrations
-
Compliance analytics: coverage, campaign throughput, on-time rate, 6-month trend
-
AI agent answers posture, overdue-control, and evidence-gap questions
-
AI agent creates a control or launches a campaign (with confirmation)
-
Native vendor/change register so cert & change reviews work standalone
-
Bulk-import vendors & changes from CSV with a template
-
Composes with Asset Pro / Supplier Hub, Contracts, and Service Desk
Limits & Specs
-
Frameworks: SOX, SOC 2, ISO 27001, HIPAA, custom
-
Max evidence file size: 25 MB per file
-
Default due-soon window: 14 days (admin-configurable)
-
Export formats: XLSX, PDF
-
Access: Requires a license — per-tenant opt-in
Use cases
FAQ
No. Compliance Hub is a focused compliance layer inside MangoApps — control register, prebuilt framework catalogs, review campaigns, findings, evidence, and auditor export. It has no risk register and no agentless continuous-monitoring integrations, and it composes with apps you already run instead of re-modeling them.
Yes. Platform-curated SOX, SOC 2, ISO 27001, and HIPAA catalogs are authored in the MangoApps Console; a tenant imports a whole framework (or just the gaps) in one click, and cross-framework crosswalks let one control satisfy several frameworks at once.
No. A native vendor/change register makes certification and change reviews work standalone. When Asset Pro / Supplier Hub, Contracts, or Service Desk are present, Compliance Hub prefers those canonical records and dedupes against them.
A completed campaign is locked and its items become read-only for audit integrity. An admin can explicitly unlock it for re-attestation; the unlock itself is recorded.
A multi-sheet XLSX workbook (or a PDF) snapshotting controls, sign-off trails, and evidence — scoped full / framework / campaign and generated on demand or on a recurring schedule. Export rows are never deleted, and a read-only token-link portal lets an auditor open the package without a login.
Evidence is either a linked existing record — a vendor certification, a change request, a contract obligation, or an employee certification — or a file you upload (up to 25 MB per file). Each evidence record can carry an expiry date so certs about to lapse are flagged expiring-soon or expired. You can optionally require evidence before a review item can be attested, auto-collect it from linked records, and gate evidence downloads behind step-up identity verification — each is an admin toggle, off by default except where noted.
Flagging a review item auto-opens a finding — a tracked remediation record with a severity, an owner, and a due date. You can also raise findings manually against a control. Findings move through open → remediated / accepted / closed, and overdue ones surface on the dashboard so nothing flagged quietly falls through.
They solve different problems. Policy Hub authors HR policies and employee handbooks and tracks employee acknowledgments; SOP Hub documents step-by-step standard operating procedures with completion and re-certification tracking. Compliance Hub is the audit layer: a control register, recurring review/attestation campaigns, findings, an evidence registry, and auditor exports for SOX / SOC 2 / ISO 27001 / HIPAA. Run them together — but Compliance Hub is what you hand an auditor.
The agent answers read questions — control lists, program posture, your pending attestations, evidence gaps, framework coverage, and open findings — for anyone. Admins and managers can also ask it to create a control or launch a review campaign; those writes route through the same controller as the UI, so they show a diff preview and require an explicit Confirm and never auto-submit. Who may manage controls and campaigns is itself a per-tenant setting (admins only by default, or any user).