Compliance Hub
Track software vendors, run recurring access and security review attestation cycles, log required changes, and produce auditor-ready evidence packages for SOX and SOC 2 compliance.
MangoApps
Meet the agent
This app ships with a production AI agent — permission-aware, tenant-scoped, audit-logged, and governed by the Agent Development Lifecycle.
Compliance Hub AI
Control register, attestation campaigns, framework coverage, audit-grade trail.
Overview
Compliance Hub runs a SOX, SOC 2, ISO 27001, or HIPAA program on records your team keeps in MangoApps. Vendor certifications and change requests tracked in Asset Pro / Supplier Hub, Contracts, and Service Desk feed review campaigns as canonical subjects automatically, and link in as evidence, with a native vendor/change register as fallback.
A control register tracks owners and review cadence; recurring campaigns fan out attestations and lock on completion; flagged items become owned, due-dated findings. Platform-curated SOX / SOC 2 / ISO 27001 / HIPAA catalogs import in one click, crosswalked so one control can satisfy several frameworks, and auditor exports come as XLSX, PDF, or a token-gated read-only link, no login needed.
A built-in AI agent answers posture and evidence-gap questions for anyone; admins can also have it draft a control or launch a campaign, with every write shown as a diff, awaiting confirmation.
Highlights
Capabilities
Control Register & Effectiveness
-
Define controls with reference code, framework, category, and owner
-
Effectiveness rating per control (effective / partially effective / deficient / not tested)
-
Per-control review frequency with configurable due-soon and overdue tracking
-
Bulk-import controls from CSV with a downloadable template
-
Launch a review campaign straight from a control
-
See a control's full trail — linked campaigns, evidence, findings, and cross-framework equivalents
Framework Library & Coverage
-
Platform-curated catalogs (SOX, SOC 2, ISO 27001, HIPAA)
-
One-click import, idempotent "import the gaps," and import-by-category
-
Pull in crosswalked equivalents from other frameworks
-
Coverage matrix (framework × category, imported vs missing)
Review Campaigns & Attestations
-
Campaign types: access review, cert review, change review, general
-
Auto fan-out review items (one per user, vendor certification, or documented change)
-
Attest / flag / mark N-A with decision notes and per-item evidence
-
Bulk-attest all of your pending items at once
-
Require evidence before an item can be attested (opt-in gate)
-
Reviewer notifications & a personal attestation inbox — assignment, activation, and due-soon reminders
-
Enforced lifecycle draft → active → completed (locked) → archived, with a completion gate
-
Admin unlock for re-attestation (the unlock itself is logged)
Findings & Remediation
-
Auto-open a finding when a review item is flagged
-
Raise findings manually against a control
-
Severity, owner, and due date with an open → remediated / accepted / closed lifecycle
-
Overdue-findings tracking on the dashboard
Evidence Registry
-
Link existing records as proof — vendor certs, change requests, contract obligations, or employee certifications
-
Attach uploaded files (up to 25 MB) as evidence
-
Evidence expiry dates with expiring-soon and expired flags
-
Auto-collect evidence from linked records (opt-in)
-
Step-up identity verification to download evidence (opt-in)
Auditor Exports & Portal
-
Point-in-time export of controls, the sign-off trail, and evidence
-
Multi-sheet XLSX workbook or PDF package, scoped full / framework / campaign
-
Recurring export schedules (monthly / quarterly / annual)
-
Immutable export history — export rows are never deleted
-
Read-only auditor portal via token link, with optional expiry and revoke
AI, Analytics & Integrations
-
Compliance analytics: coverage, campaign throughput, on-time rate, 6-month trend
-
AI agent answers posture, overdue-control, and evidence-gap questions
-
AI agent creates a control or launches a campaign (with confirmation)
-
Native vendor/change register so cert & change reviews work standalone
-
Bulk-import vendors & changes from CSV with a template
-
Composes with Asset Pro / Supplier Hub, Contracts, and Service Desk
Limits & Specs
-
Frameworks: SOX, SOC 2, ISO 27001, HIPAA, custom
-
Max evidence file size: 25 MB per file
-
Default due-soon window: 14 days (admin-configurable)
-
Export formats: XLSX, PDF
-
Access: Requires a license — per-tenant opt-in
Use cases
FAQ
No. Compliance Hub is a focused compliance layer inside MangoApps — control register, prebuilt framework catalogs, review campaigns, findings, evidence, and auditor export. It has no risk register and no agentless continuous-monitoring integrations, and it composes with apps you already run instead of re-modeling them.
Yes. Platform-curated SOX, SOC 2, ISO 27001, and HIPAA catalogs are authored in the MangoApps Console; a tenant imports a whole framework (or just the gaps) in one click, and cross-framework crosswalks let one control satisfy several frameworks at once.
No. A native vendor/change register makes certification and change reviews work standalone. When Asset Pro / Supplier Hub, Contracts, or Service Desk are present, Compliance Hub prefers those canonical records and dedupes against them.
A completed campaign is locked and its items become read-only for audit integrity. An admin can explicitly unlock it for re-attestation; the unlock itself is recorded.
A multi-sheet XLSX workbook (or a PDF) snapshotting controls, sign-off trails, and evidence — scoped full / framework / campaign and generated on demand or on a recurring schedule. Export rows are never deleted, and a read-only token-link portal lets an auditor open the package without a login.
Evidence is either a linked existing record — a vendor certification, a change request, a contract obligation, or an employee certification — or a file you upload (up to 25 MB per file). Each evidence record can carry an expiry date so certs about to lapse are flagged expiring-soon or expired. You can optionally require evidence before a review item can be attested, auto-collect it from linked records, and gate evidence downloads behind step-up identity verification — each is an admin toggle, off by default.
Flagging a review item auto-opens a finding — a tracked remediation record with a severity, an owner, and a due date. You can also raise findings manually against a control. Findings move through open → remediated / accepted / closed, and overdue ones surface on the dashboard so nothing flagged quietly falls through.
They solve different problems. Policy Hub authors HR policies and employee handbooks and tracks employee acknowledgments; SOP Hub documents step-by-step standard operating procedures with completion and re-certification tracking. Compliance Hub is the audit layer: a control register, recurring review/attestation campaigns, findings, an evidence registry, and auditor exports for SOX / SOC 2 / ISO 27001 / HIPAA. Run them together — but Compliance Hub is what you hand an auditor.
The agent answers read questions — control lists, program posture, your pending attestations, evidence gaps, framework coverage, and open findings — for anyone. Admins can also ask it to create a control or launch a review campaign; those writes route through the same controller as the UI, so they show a diff preview and require an explicit Confirm and never auto-submit. Who may manage controls and campaigns is itself a per-tenant setting (admins only by default, or any user) — the agent honors the same setting.