Compliance Hub FAQ
Answers to common setup and operating questions about Compliance Hub.
For what the app is and how to set it up from scratch, see the
Compliance Hub Overview.
Setup
Do I need to configure anything before review campaigns work?
No — controls, campaigns, and findings work as soon as the app is enabled and licensed. Three optional features are off by default and require a toggle in Settings before they take effect: Require Evidence When Attesting a Review Item, Auto-Collect Evidence from Linked Records, and Require Identity Verification to Download Evidence. The Framework Library (SOX / SOC 2 / ISO 27001 / HIPAA catalog import) and both specialized campaign types (certification review and change review) default to on and can be turned off in Settings if you don’t need them.
Who can manage controls and campaigns, and how do I change that?
By default, only admins and app admins can create, edit, or retire controls, and can create, activate, complete, or archive campaigns. The “Who Can Manage Controls & Campaigns?” setting in Compliance Hub Settings has two choices: Admins only (default) and Any user. When set to Any user, every member with app access can manage controls and campaigns. Regardless of this setting, any user can view controls, campaigns, and findings — and an assigned reviewer can always record a decision on their own items.
Who can see the Frameworks tab?
Only admins and app admins. The Frameworks tab is also hidden entirely when the Enable Framework Library toggle is off. Managers see Analytics but not Frameworks; all users see the program tabs (Dashboard, Controls, Review Register, Campaigns, Findings, Auditor Exports).
Permissions and access
Why can’t a user create or edit controls?
The “Who Can Manage Controls & Campaigns?” setting is set to Admins only (the default). Either change it to Any user in Settings, or make the person an admin or a Compliance Hub app admin.
Who can unlock a completed campaign for re-attestation?
Only admins and app admins, regardless of the “Who Can Manage” setting. The Any user option extends create/edit/complete privileges but not unlock — re-opening a locked audit trail is always an admin act, and the unlock itself is logged.
Day-to-day
How does the fan-out work when I activate a campaign?
When you click Build items on a draft campaign, the app creates one review item per subject based on the campaign type:
- Access review — one item per active user in the business.
- Certification review — one item per active vendor certification (from Contracts / Supplier Hub when present, plus the native vendor register), deduplicated so the same vendor isn’t reviewed twice.
- Change review — one item per change request (from Service Desk when present, plus the native change register), scoped to the campaign’s date range when set.
- General — no automatic fan-out; you add items manually.
The subject list is capped at 500. If the list exceeds 500, the app warns you and adds the first 500; you can add the rest manually or run additional campaigns. Re-running Build items is safe — subjects already on the campaign are skipped.
What happens when a reviewer flags an item?
Flagging automatically opens a finding — a tracked remediation record linked to the flagged item and its control. The finding defaults to Medium severity and Open status, owned by the reviewer (or the campaign owner if no reviewer is assigned). If the same item is re-flagged, a duplicate finding is not created. You can also raise findings manually against any control.
What are the finding severity levels and lifecycle states?
Severity: Low, Medium, High, Critical. Status lifecycle: Open → In progress → Remediated / Accepted / Closed. Overdue findings (past their due date and still open or in progress) surface on the dashboard. Findings stop sending overdue reminders after 90 days past due — the finding still shows overdue on the dashboard, but the email stops so abandoned findings don’t nag forever.
Can I attest all my pending items at once?
Yes. The Bulk attest button on the campaign page attests every pending item you can act on in a single operation. If you’re a manager or admin, it covers all pending items; otherwise only items assigned to you. If the Require Evidence setting is on, any item without evidence is skipped (not attested), and the result tells you how many were skipped.
What does “Require Evidence When Attesting” actually do?
When this toggle is on, a reviewer cannot attest a review item until at least one piece of evidence is attached to it — either a linked record or an uploaded file. Items without evidence are blocked from single attestation and skipped during bulk attest. The gate does not apply to flagging or marking an item N/A — only to attesting.
What notifications does Compliance Hub send?
Three notification types, each controlled by its own toggle in Settings (all on by default):
- Assignment — when a review item is assigned or a campaign is activated, each assigned reviewer gets an in-app Inbox action and an email.
- Due-soon reminders — for open campaigns and findings within the due-soon window (default 14 days, configurable). Sent to the campaign owner and pending reviewers.
- Overdue alerts — for open campaigns and findings past their due date. Same recipients as due-soon.
Evidence with an expiry date also triggers expiring-soon and expired notifications to the person who captured it, using the same due-soon and overdue toggles.
When something looks wrong
“I attested an item but it still shows pending”
The campaign is locked. A completed campaign locks all items so decisions can’t be changed. An admin must unlock the campaign first (Review Campaigns → the campaign → Unlock), which returns it to Active status and clears the lock. After the re-attestation, the campaign can be completed and locked again.
“I can’t download evidence — it asks me to verify my identity”
The Require Identity Verification to Download Evidence setting is on. This requires a step-up (“sudo”) session before any evidence file can be served. The setting is off by default; your admin turned it on intentionally. Complete the identity verification prompt and the download proceeds.
“The framework library shows no frameworks”
Framework catalogs are authored in the MangoApps Console (system administration). If no catalogs have been published there, the tenant’s Frameworks tab is empty. Tenant-defined custom frameworks are not yet supported — only system-curated catalogs (SOX, SOC 2, ISO 27001, HIPAA) appear.
“I imported a framework but some controls say ‘already present’”
The import is idempotent. Controls that were already imported from the same catalog entry are counted as skipped rather than duplicated. When you re-import after the catalog has been updated, only new catalog entries are added. You can also import by category (checkboxes on the framework page) or pull in crosswalked equivalents from other frameworks.
Licensing and limits
Does Compliance Hub require a licence?
Yes. Compliance Hub requires a licence and is enabled per tenant by an admin through the Apps Marketplace. It is not auto-enabled.
Are there limits I should know about?
| What | Limit |
|---|---|
| Fan-out subjects per campaign | 500 (warns if exceeded) |
| Evidence file upload size | 25 MB per file |
| CSV import rows (controls) | 2,000 rows per file |
| Control title length | 255 characters |
| Reference code length | 64 characters (unique per business, case-insensitive) |
| Review items per page | 100 |
| Default due-soon window | 14 days (configurable in Settings) |
| Evidence expiring-soon window | 30 days |
| Overdue notification cutoff | 90 days past due (notifications stop; dashboard still shows overdue) |
| Export formats | XLSX and PDF |
| Export scopes | Full program, by framework, or by campaign |
| Recurring export cadences | Monthly, Quarterly, Annually |
| Auditor portal link | Token-based, optional expiry, revocable |
More help
- Compliance Hub Overview
- Ask AI — the assistant answers Compliance Hub questions from these articles.