Loading...
Help Center / Apps & Extensions / Compliance Hub FAQ

Compliance Hub FAQ

Compliance Hub FAQ

Answers to common setup and operating questions about Compliance Hub.
For what the app is and how to set it up from scratch, see the
Compliance Hub Overview.


Setup

Do I need to configure anything before review campaigns work?

Controls, general campaigns, findings and both registers work as soon as the app is enabled. Certification and change reviews need a source: Contracts / Supplier Hub or Service Desk when connected, otherwise vendors and changes you add to the Review Register — with neither, Build items creates nothing. Three features are off by default and need a switch in Settings: Require evidence when attesting a review item, Auto-collect evidence from linked records and Require identity verification to download evidence.

Who can manage the compliance program, and how do I change that?

By default only business admins and Compliance Hub app administrators can create controls, campaigns, subjects, findings, risks and obligations, decide other people’s items, and generate exports. Change it under Settings → Permissions with the Who can manage the compliance program? picker: keep Business admins and Compliance Hub app administrators only, or choose …and the groups I choose below and name the groups. There is deliberately no “everyone” option. Regardless of the setting, every app member can still attest the items assigned to them.

Who can see the Frameworks, Analytics and Guided Setup tabs?

Frameworks appears for business admins and app admins, and only while Enable Framework Library is on. Analytics appears for managers and above, app admins, and anyone with the manage capability. Guided Setup appears for anyone with the manage capability. Everyone with app access sees the Program group: Dashboard, My Attestations, Controls, Review Register, Review Campaigns, Findings, Risk Register, Legal Register and Auditor Exports.

Which frameworks are in the library, and can I add my own?

Seven curated starter catalogs: SOC 2 (20 controls), SOX IT General Controls (15), ISO/IEC 27001 (20), HIPAA Security Rule (14), ISO 45001 (20), ISO 9001 (19) and ISO 14001 (14) — 122 controls with 113 crosswalks between them. They are starter subsets, not the full official standards. Tenant-defined frameworks cannot be created in the app; catalogs are authored in the MangoApps Console. You can still add your own controls to the register with the Custom framework tag.


Permissions and access

Why can’t I see the findings my colleague mentioned?

Findings are viewer-scoped. Managers and above, and anyone with the manage capability, see the whole register. Everyone else sees only the findings they own — on the Findings tab, on a control’s page, on the Dashboard, in search and in Ask AI. If you should own that finding, ask its owner or an admin to reassign it to you.

Generating, downloading, publishing and revoking exports needs the manage capability (business admins and app admins always have it). Publishing also needs Allow anonymous auditor links switched on in Settings → Evidence & Scheduling. Turning that toggle off disables every link already handed out, not just new ones; the export itself stays and can still be downloaded by a logged-in user with the manage capability.

Who can unlock a completed campaign?

Only business admins and Compliance Hub app administrators, regardless of the manage capability. Unlocking returns the campaign to Active, lets reviewers change decisions, and is recorded. Archived campaigns cannot be unlocked at all.


Day-to-day

How does Build items decide who reviews what?

Access reviews create one item per active person and assign it to that person’s manager, never to the person themselves; with no manager, the campaign owner gets it. Certification reviews create one item per vendor certification from Contracts / Supplier Hub plus the Review Register. Change reviews create one item per Service Desk change request inside the campaign’s date window plus the Review Register. General campaigns have no fan-out. Running Build items again is safe — existing subjects are skipped.

I flagged an item — what happens now?

A finding opens automatically, titled “Flagged: “ plus the subject, with your reason as its description and Medium severity. You own it if you are still a member; otherwise the campaign owner does. The finding owner is notified in-app, and the finding shows up on the control’s page and the Dashboard. Flagging the same item again does not create a second finding.

Where do I record that I reviewed my risk?

Open the risk in Risk Register, expand Record review, set Next review and click Mark reviewed. That stamps you and today’s date and moves the next review out by the risk’s Review cadence. Only the risk’s owner or someone with the manage capability can record a review; the nightly sweep reminds the owner when it is due or overdue.

Open it in Legal Register, expand Evaluate, choose an Outcome (Compliant, Partially compliant, Non-compliant or Not assessed), set Next evaluation and click Record evaluation. The Dashboard’s Legal Register card counts active obligations, gaps (partially or non-compliant), not assessed, and evaluation overdue. The owner or a manage-holder can evaluate.

Both panels are shown only to people who can author the register. Suggested from Safety Hub & Inspections lists high or critical incidents and near misses from the last 12 months, failed inspections, and open regulator-visit findings — and only for apps you can open, up to 8 per source. Suggested from your jurisdictions lists active employment-law catalog rules for your mapped jurisdictions and their parents, up to 40, skipping rules already cited. If no location is mapped to a jurisdiction, the panel shows Map your locations instead.

Can I attest all my pending items at once?

Yes. On the campaign page, Attest all my pending attests every pending item assigned to you; someone with the manage capability can use Attest all pending for the whole campaign, recorded under their own name. Each click handles up to 200 items. When Require evidence when attesting a review item is on, items without evidence are skipped and the result says how many.

What notifications does Compliance Hub send, and how often?

Three switches in Settings → Notifications, all on by default. Notify reviewers when assigned an item sends one in-app, push and email notice per assignment and campaign activation. Send due-soon reminders emails the campaign owner and pending reviewers weekly inside the due-soon window; findings, risks, obligations and expiring evidence get in-app notices only. Send overdue alerts repeats every 3 days and stops 90 days after the due date. People can mute Compliance Hub email in their own notification preferences.


When something looks wrong

“I attested an item but it still shows pending”

The campaign is locked because it was completed or archived. A business admin or app admin must open the campaign and click Unlock (archived campaigns cannot be reopened). Once it is Active again, record the decision and the owner can Complete it once more.

“Why can’t I attest from my phone?”

The mobile site can attest, flag and mark items not applicable, but it cannot attach evidence. When Require evidence when attesting a review item is on and the item has none, tapping Attest shows “This attestation requires evidence — please use the full site to attach it.” Attach the file or linked record on the full site, then attest from either surface.

Those two sheets are added only to a full-program Excel export. Choose All — full program as the Scope and Excel (XLSX) as the Format. A framework-scoped export limits evidence to that framework’s controls and omits both registers, and PDF exports never include them.

“I imported a framework but some controls say already present”

The import is idempotent. Controls already copied from the same catalog entry are counted as skipped, not duplicated, so re-importing after a catalog update adds only the new entries. You can import by category, or tick the option to include crosswalked equivalents from other frameworks; imported controls are due in 30 days and owned by the importer.


Licensing and limits

Does Compliance Hub require a licence?

Yes. Compliance Hub requires a licence and is enabled per tenant by an admin through the Apps Marketplace. It is not auto-enabled.

Are there limits I should know about?

What Limit
Evidence file upload under 25 MB per file; label up to 255 characters
Titles / reference code 255 / 64 characters (reference code unique per business, case-insensitive)
Decision note 2,000 characters
Fan-out subjects per campaign 500
Bulk attest 200 items per click
Campaign items per page 100; other lists 25; framework catalog 50
Control page shows 20 campaigns, 50 evidence entries, 20 open findings
CSV imports (controls, subjects) 2,000 rows / 10 MB per file
Framework import imported controls due in 30 days
Due-soon window default 14 days, accepts 1–120
Default review lead time default 14 days, accepts 1–365
Reminder cadence assignment once; due-soon weekly; overdue every 3 days, stopping 90 days past due
Evidence expiring-soon badge 30 days before the valid-until date
Auditor link expiry 1–365 days or never (form default 90)
Auditor portal throttle 1,000 page views and 30 downloads per hour per IP address
Identity-verified download link valid 15 minutes
Export build polls for about 5 minutes; export rows are never deleted
Risk scale 5 × 5; Low 1–4, Medium 5–9, High 10–16, Critical 17–25
Risk suggestions 8 per source (24 max), 12-month lookback
Legal suggestions up to 40
Crosswalk confidence 0–100
XLSX cell 32,767 characters, truncated with a marker
Agent list tools default 25, max 100; coverage gaps default 50, max 200

More help

  • Compliance Hub Overview
  • Public framework library at /compliance-library — catalog controls, evidence hints and crosswalks, readable without a login
  • Ask AI — the Compliance Hub agent answers Compliance Hub questions from these articles.