Loading...
Compliance Hub
Compliance Hub
Compliance Hub

Compliance Hub

Track software vendors, run recurring access and security review attestation cycles, log required changes, and produce auditor-ready evidence packages for SOX and SOC 2 compliance.

MangoApps

Category
Operations & Safety
Version
1.0.0
Published
Jun 2026
Type
App

Overview

Compliance Hub runs a SOX, SOC 2, ISO 27001, or HIPAA program on records your team keeps in MangoApps. Vendor certifications and change requests tracked in Asset Pro / Supplier Hub, Contracts, and Service Desk feed review campaigns as canonical subjects automatically, and link in as evidence, with a native vendor/change register as fallback.

A control register tracks owners and review cadence; recurring campaigns fan out attestations and lock on completion; flagged items become owned, due-dated findings. Platform-curated SOX / SOC 2 / ISO 27001 / HIPAA catalogs import in one click, crosswalked so one control can satisfy several frameworks, and auditor exports come as XLSX, PDF, or a token-gated read-only link, no login needed.

A built-in AI agent answers posture and evidence-gap questions for anyone; admins can also have it draft a control or launch a campaign, with every write shown as a diff, awaiting confirmation.

Highlights

Maintain a control register with owners, review cadence, and an effectiveness rating an auditor can walk.
Import prebuilt SOX / SOC 2 / ISO 27001 / HIPAA catalogs, then track coverage and cross-framework crosswalks.
Run recurring review campaigns that fan out attestations, then lock on completion for audit integrity.
Turn every flagged item into an owned, due-dated finding and track it through remediation.
Attach proof — linked records or files — with expiry dates, auto-collection, and step-up-gated downloads.
Hand auditors a point-in-time XLSX/PDF package or a token-gated read-only portal, on a schedule.

Capabilities

Control Register & Effectiveness
  • Define controls with reference code, framework, category, and owner
  • Effectiveness rating per control (effective / partially effective / deficient / not tested)
  • Per-control review frequency with configurable due-soon and overdue tracking
  • Bulk-import controls from CSV with a downloadable template
  • Launch a review campaign straight from a control
  • See a control's full trail — linked campaigns, evidence, findings, and cross-framework equivalents
Framework Library & Coverage
  • Platform-curated catalogs (SOX, SOC 2, ISO 27001, HIPAA)
  • One-click import, idempotent "import the gaps," and import-by-category
  • Pull in crosswalked equivalents from other frameworks
  • Coverage matrix (framework × category, imported vs missing)
Review Campaigns & Attestations
  • Campaign types: access review, cert review, change review, general
  • Auto fan-out review items (one per user, vendor certification, or documented change)
  • Attest / flag / mark N-A with decision notes and per-item evidence
  • Bulk-attest all of your pending items at once
  • Require evidence before an item can be attested (opt-in gate)
  • Reviewer notifications & a personal attestation inbox — assignment, activation, and due-soon reminders
  • Enforced lifecycle draft → active → completed (locked) → archived, with a completion gate
  • Admin unlock for re-attestation (the unlock itself is logged)
Findings & Remediation
  • Auto-open a finding when a review item is flagged
  • Raise findings manually against a control
  • Severity, owner, and due date with an open → remediated / accepted / closed lifecycle
  • Overdue-findings tracking on the dashboard
Evidence Registry
  • Link existing records as proof — vendor certs, change requests, contract obligations, or employee certifications
  • Attach uploaded files (up to 25 MB) as evidence
  • Evidence expiry dates with expiring-soon and expired flags
  • Auto-collect evidence from linked records (opt-in)
  • Step-up identity verification to download evidence (opt-in)
Auditor Exports & Portal
  • Point-in-time export of controls, the sign-off trail, and evidence
  • Multi-sheet XLSX workbook or PDF package, scoped full / framework / campaign
  • Recurring export schedules (monthly / quarterly / annual)
  • Immutable export history — export rows are never deleted
  • Read-only auditor portal via token link, with optional expiry and revoke
AI, Analytics & Integrations
  • Compliance analytics: coverage, campaign throughput, on-time rate, 6-month trend
  • AI agent answers posture, overdue-control, and evidence-gap questions
  • AI agent creates a control or launches a campaign (with confirmation)
  • Native vendor/change register so cert & change reviews work standalone
  • Bulk-import vendors & changes from CSV with a template
  • Composes with Asset Pro / Supplier Hub, Contracts, and Service Desk
Limits & Specs
  • Frameworks: SOX, SOC 2, ISO 27001, HIPAA, custom
  • Max evidence file size: 25 MB per file
  • Default due-soon window: 14 days (admin-configurable)
  • Export formats: XLSX, PDF
  • Access: Requires a license — per-tenant opt-in

Screenshots

Use cases

Annual user access review
A compliance lead launches an access-review campaign that fans out one attestation per user; reviewers confirm or flag access, each flag becomes a tracked finding, and the campaign locks when every item is resolved.
SOC 2 readiness from a catalog
A first-time compliance owner imports the SOC 2 catalog, sees coverage by category, and imports just the gaps rather than authoring controls by hand.
Vendor security certification review
A risk manager runs a cert-review campaign over active vendor SOC 2 / COI certifications, attaching each certificate as evidence and surfacing the ones about to expire.
Remediating a flagged control
A control owner picks up an auto-opened finding, sets its severity and due date, records remediation evidence, and resolves it before the dashboard flags it overdue.
Handing an auditor evidence
An admin schedules a quarterly XLSX package and publishes a token-gated portal so an external auditor reviews controls, sign-off trails, and evidence without a login.

FAQ

No. Compliance Hub is a focused compliance layer inside MangoApps — control register, prebuilt framework catalogs, review campaigns, findings, evidence, and auditor export. It has no risk register and no agentless continuous-monitoring integrations, and it composes with apps you already run instead of re-modeling them.

Yes. Platform-curated SOX, SOC 2, ISO 27001, and HIPAA catalogs are authored in the MangoApps Console; a tenant imports a whole framework (or just the gaps) in one click, and cross-framework crosswalks let one control satisfy several frameworks at once.

No. A native vendor/change register makes certification and change reviews work standalone. When Asset Pro / Supplier Hub, Contracts, or Service Desk are present, Compliance Hub prefers those canonical records and dedupes against them.

A completed campaign is locked and its items become read-only for audit integrity. An admin can explicitly unlock it for re-attestation; the unlock itself is recorded.

A multi-sheet XLSX workbook (or a PDF) snapshotting controls, sign-off trails, and evidence — scoped full / framework / campaign and generated on demand or on a recurring schedule. Export rows are never deleted, and a read-only token-link portal lets an auditor open the package without a login.

Evidence is either a linked existing record — a vendor certification, a change request, a contract obligation, or an employee certification — or a file you upload (up to 25 MB per file). Each evidence record can carry an expiry date so certs about to lapse are flagged expiring-soon or expired. You can optionally require evidence before a review item can be attested, auto-collect it from linked records, and gate evidence downloads behind step-up identity verification — each is an admin toggle, off by default.

Flagging a review item auto-opens a finding — a tracked remediation record with a severity, an owner, and a due date. You can also raise findings manually against a control. Findings move through open → remediated / accepted / closed, and overdue ones surface on the dashboard so nothing flagged quietly falls through.

They solve different problems. Policy Hub authors HR policies and employee handbooks and tracks employee acknowledgments; SOP Hub documents step-by-step standard operating procedures with completion and re-certification tracking. Compliance Hub is the audit layer: a control register, recurring review/attestation campaigns, findings, an evidence registry, and auditor exports for SOX / SOC 2 / ISO 27001 / HIPAA. Run them together — but Compliance Hub is what you hand an auditor.

The agent answers read questions — control lists, program posture, your pending attestations, evidence gaps, framework coverage, and open findings — for anyone. Admins can also ask it to create a control or launch a review campaign; those writes route through the same controller as the UI, so they show a diff preview and require an explicit Confirm and never auto-submit. Who may manage controls and campaigns is itself a per-tenant setting (admins only by default, or any user) — the agent honors the same setting.