Compliance Hub
1. What it is
Compliance Hub is where your team runs its own compliance program. You keep a register of controls, run recurring review campaigns that send attestation items to reviewers, track findings through remediation, and hand auditors an evidence package. Seven framework catalogs are available to start from: SOC 2, SOX, ISO 27001, HIPAA, ISO 9001, ISO 14001 and ISO 45001.
Two registers sit alongside the controls. The Risk Register rates hazards on a 5 × 5 likelihood-by-impact scale and reminds owners to review them. The Legal Register lists laws, permits and contract requirements with a compliance status and an evaluation cadence.
- Enablement: Compliance Hub is a licensed app. An admin enables it per tenant from Admin → Apps Marketplace; it is never on by default.
- What it is not: Compliance Hub is not where policies are written or acknowledged — that is Policy Hub. Policies, SOPs, incidents and inspections stay in their own apps and link into Compliance Hub as evidence.
2. Standing it up
- Enable the app from Admin → Apps Marketplace, then open Apps → Compliance Hub. The left rail shows a Program group (Dashboard, My Attestations, Controls, Review Register, Review Campaigns, Findings, Risk Register, Legal Register, Auditor Exports) and a Manage group (Frameworks, Analytics, Guided Setup, Settings) for privileged users.
- Run Manage → Guided Setup (also linked from Settings as Set up your program). Pick a Framework, a Program owner, and tick Import the framework’s starter controls and Create the standard recurring reviews. Setup imports the catalog’s controls and creates three draft campaigns: Annual Access Review, Annual Certification Review and Quarterly Change Review. It is safe to run twice; nothing is duplicated.
- Decide who manages the program. In Settings → Permissions, the Who can manage the compliance program? picker defaults to Business admins and Compliance Hub app administrators only. Choose …and the groups I choose below to name a compliance analyst who is not an admin. This is the platform’s “Who Can Do What” capability picker.
- Connect review sources. Certification reviews pull vendor certifications from Contracts / Supplier Hub. Change reviews pull change requests from Service Desk. Without those apps, add vendors and changes to the Review Register yourself. Settings → Review Sources shows a Connected or Native register badge per source.
- Prepare the registers. Risk suggestions come from Safety Hub and Inspections, so the person authoring risks needs access to those apps. Legal suggestions come from the employment-law catalog through your mapped jurisdictions; the Legal Register shows Map your locations until at least one location is mapped.
- Confirm it worked. The Dashboard shows control, campaign, finding, Risk Register and Legal Register cards. A reviewer sees their queue under My Attestations and on the mobile site at /m/apps/compliance-hub.
Things that silently do nothing until a second thing is configured:
- Build items on a certification or change campaign creates zero items when no source app is connected and the Review Register is empty.
- The Suggested from your jurisdictions panel on the Legal Register is empty until locations are mapped to jurisdictions.
- The Suggested from Safety Hub & Inspections panel is shown only to people who can author risks and can open those apps.
- Publish auditor link is unavailable while Allow anonymous auditor links is off, and turning it off disables links already handed out.
- Guided Setup only imports controls when Enable Framework Library is on and the runner is an admin or app admin.
3. How it fits together
Control vs framework control — A control is a row in your register with an owner, a review cadence, a next review date and an effectiveness rating. A framework control is a catalog entry inside a framework in the library. Importing copies the catalog entry into your register and keeps a link back to it, which powers the Also satisfies crosswalk panel.
Campaign vs item vs subject — A campaign is one review cycle, such as “Annual Access Review 2026”. A subject is the thing being reviewed: a person’s access, a vendor certification, a change request, or a row in the Review Register. An item is one attestation line, one campaign paired with one subject, assigned to a reviewer. Access reviews assign each person’s item to their manager, never to the person themselves.
Finding vs risk vs obligation — A finding is a tracked deficiency with an owner, a severity and a remediation lifecycle; flagging an item opens one automatically. A risk is a rated hazard with a likelihood, an impact and a review cadence. An obligation is a legal, permit or contract requirement with a compliance status and an evaluation cadence. They live in three different registers and are exported on three different sheets.
Inherent vs residual rating — The inherent rating is the risk before treatment. The residual rating is optional and describes the risk after the treatment plan. Both use the same scale: score = likelihood × impact, banded Low (1–4), Medium (5–9), High (10–16) and Critical (17–25).
Worked example. A forklift-pedestrian conflict in Bay 3 is entered with Likelihood 4 and Impact 5. The inherent score is 20, so the badge reads Critical. After a barrier and a marked walkway, the owner records a residual Likelihood 2 and Impact 5. The residual score is 10, which reads High. The Dashboard’s “high or critical” count uses the inherent rating.
Evidence vs linked source — Evidence is the proof entry attached to a control, campaign, item, finding, risk or obligation. It is either an uploaded file or a link to a record another app owns: a vendor certification or contract obligation, a change request, an employee certification, an incident, CAPA action, toolbox talk or safety observation, an inspection, a policy, or an SOP. The picker only offers apps the viewer can open. Evidence can carry a valid-until date and shows expired or expiring badges.
Locked campaign — Completing or archiving a campaign locks it. Decisions, evidence and subject deletion are frozen so the audit trail cannot change. Only a business admin or app admin can Unlock a completed campaign, and the unlock is recorded. Archived campaigns are permanent.
Findings viewer scope — Managers and above, and anyone with the manage capability, see the whole findings register. Everyone else sees only findings they own — on the register, the control page, the Dashboard, in Ask AI and in search.
Narrowed export — An export scoped to one framework includes only that framework’s controls and their evidence. The Risk Register and Legal Register sheets appear only on a full-program XLSX export. PDF exports never include them.
Boundaries with other apps: management of change lives in Safety Hub permits and Service Desk change requests. Supplier pre-qualification lives in Safety Hub. Framework catalogs are authored in the MangoApps Console, not in the tenant.
4. Running it
Running a review campaign
- Go to Review Campaigns and create a campaign, or click Launch Review Campaign on a control’s page. The due date defaults to today plus the Default review lead time.
- Click Build items to fan out one item per subject. General campaigns have no fan-out; add items manually.
- Click Activate. Reviewers are notified and the campaign can no longer return to draft.
- Reviewers choose Attest, Confirm flag (a reason is required) or Mark N/A on each item. Anyone with the manage capability can use Attest all pending for the whole campaign, recorded under their own name.
- When every item is decided, click Complete. The campaign locks and the control’s next review date advances by its cadence.
Managing findings
- Go to Findings. Flagged items already appear here with the reviewer’s note as the description and Medium severity.
- To raise one by hand, add a finding with a title, severity, owner, due date, control and remediation plan.
- The owner or a manager resolves it with Resolve finding and a resolution note, choosing Remediated, Accepted or Closed. Reopening clears the resolution stamp.
Keeping the Risk Register current
- Go to Risk Register. Use the Suggested from Safety Hub & Inspections panel and Add to register to pre-fill a risk from an incident, a failed inspection or a regulator finding.
- Set the Inherent rating (Likelihood, Impact), a Treatment / mitigation plan, an optional Residual rating, an Owner, a Review cadence and optionally a Treating control and Site / location.
- When the review date arrives, the owner opens Record review, sets Next review and clicks Mark reviewed. The nightly sweep reminds the owner when a review is due or overdue.
Evaluating a legal obligation
- Go to Legal Register. Use Suggested from your jurisdictions and Add to register to pre-fill from the employment-law catalog, or add an obligation with its Citation, Regulator / authority, Jurisdiction and What it requires of us.
- Set an Owner, an Evaluation cadence, and optionally an Implementing control.
- On the due date the owner opens Evaluate, picks an Outcome (Compliant, Partially compliant, Non-compliant or Not assessed), sets Next evaluation and clicks Record evaluation. The gaps filter lists everything partially or non-compliant.
Handing an auditor the package
- Go to Auditor Exports, choose a Scope (All — full program or one framework) and a Format (Excel (XLSX) or PDF), then click Generate Export. The page polls until the file is ready.
- Click Download package, or Publish auditor link with an Expires after (days) value (default 90; blank never expires). The auditor opens the link without logging in.
- Click Revoke to disable a link immediately. Export rows are kept permanently.
- For a standing cadence, create an Export Schedule with a Name, Scope, Cadence (monthly, quarterly or annually) and Next run. Schedules can be paused and resumed.
5. Settings
All settings are at Apps → Compliance Hub → Settings (business admin or app admin required). Allowed ranges are in the FAQ.
| Setting | Where | Default | What it changes |
|---|---|---|---|
| Enable Compliance Hub AI Agent | Settings → Compliance Hub AI Agent | On | Makes the Compliance Hub agent available in Ask AI. It has 9 read tools and 2 confirmation-gated write tools (create a control, launch a draft campaign). |
| Who can manage the compliance program? | Settings → Permissions | Business admins and Compliance Hub app administrators only | Who can author controls, campaigns, subjects, findings, risks and obligations, build items, decide other people’s items, run exports and schedules, and use Guided Setup. Admins always can. |
| Enable Certification Review campaigns | Settings → Campaign Types | On | Offers the certification review type, its Guided Setup draft, and its fan-out from Contracts / Supplier Hub and the Review Register. |
| Enable Change Review campaigns | Settings → Campaign Types | On | Offers the change review type, its Guided Setup draft, and its fan-out from Service Desk and the Review Register. |
| Enable Framework Library | Settings → Campaign Types | On | Shows the Frameworks tab, allows Guided Setup to import starter controls, and enables the agent’s framework coverage tool. |
| Require evidence when attesting a review item | Settings → Evidence & Scheduling | Off | Blocks Attest until the item has evidence; bulk attest skips evidence-less items; mobile sends the reviewer to the full site to attach it. |
| Require identity verification to download evidence | Settings → Evidence & Scheduling | Off | Adds a step-up identity check before an evidence file is served, via a short-lived signed link. |
| Auto-collect evidence from linked records | Settings → Evidence & Scheduling | Off | The nightly sweep links vendor certifications and change requests as evidence onto pending items of active certification and change campaigns. |
| Allow anonymous auditor links | Settings → Evidence & Scheduling | On | Allows Publish auditor link; turning it off also disables links already published. |
| Due-soon window (days) | Settings → Evidence & Scheduling | 14 | How far ahead the Dashboard, list filters, nightly reminders and the agent treat something as due soon. |
| Default review lead time (days) | Settings → Evidence & Scheduling | 14 | The default due date for new campaigns, launch-from-control, recurring campaigns and Guided Setup drafts. |
| Notify reviewers when assigned an item | Settings → Notifications | On | One in-app, push and email notice to the reviewer when an item is assigned and when a campaign activates. |
| Send due-soon reminders — reviews, open findings and expiring evidence | Settings → Notifications | On | Weekly email to the campaign owner and pending reviewers; in-app only for findings, risks, obligations and expiring evidence. |
| Send overdue alerts — reviews, findings past their due date and expired evidence | Settings → Notifications | On | Same audiences, re-sent every 3 days and stopping 90 days after the due date. |
Settings also hosts Program Setup (Set up your program) and Demo Data (Load demo data / Delete demo data), which only touch tagged demo records.
6. More help
- Compliance Hub FAQ — specific setup and operating questions, employee complaints, and every limit
- Public framework library at /compliance-library — the catalog controls, evidence hints and crosswalks, readable without a login
- Ask AI — the Compliance Hub agent answers questions about Compliance Hub from these articles.