Loading...
Help Center / Apps & Extensions / Compliance Hub Overview

Compliance Hub Overview

Compliance Hub

1. What it is

Compliance Hub runs a SOX, SOC 2, ISO 27001, or HIPAA compliance program on records your team already keeps in MangoApps. You maintain a register of controls, run recurring review campaigns that fan out attestation items to reviewers, track findings through remediation, and produce auditor-ready evidence packages — all in one place.

  • Enablement: Compliance Hub is a licensed app. An admin enables it from the Apps Marketplace, and it requires an active licence.
  • What it is not: Compliance Hub is not the platform’s audit log viewer or the labor-law rule engine. The audit log viewer lives at Admin → Compliance Audit Logs, and labor-law rules are managed through Admin → Compliance Explorer. Compliance Hub is the app where your team runs its own control-attestation program.

2. Standing it up

  1. Go to Apps → Compliance Hub. If the app is not yet enabled, enable it from Admin → Apps Marketplace.
  2. Open Set Up Program (visible the first time, before any controls exist). Choose a framework to import (SOX, SOC 2, ISO 27001, or HIPAA), pick a program owner, and decide whether to import the framework’s starter controls and create the standard review campaigns as drafts.
  3. The setup imports controls into your register and creates up to three draft campaigns: Annual Access Review, Annual Certification Review, and Quarterly Change Review. Review each draft, add review items, and activate them when ready.
  4. If your organisation uses Supplier Hub / Contracts for vendor certifications or Service Desk for change requests, Compliance Hub detects those records automatically and includes them in certification and change review campaigns. Otherwise, add vendors and changes to the built-in Review Register.
  5. Grant access: any employee with app access can view the dashboard and their own assigned items. To control who can create controls, launch campaigns, and manage findings, set Who Can Manage Controls & Campaigns in Settings (default: Admins only). App admin rights can also be granted per user.

What silently does nothing until configured: the Review Register is where Compliance Hub finds subjects (vendors and changes) for certification and change review campaigns. If you skip the register and have no Supplier Hub or Service Desk data, the “Build Items” button on a cert or change campaign produces zero items with no error. Populate the register first, or connect the source app.

3. How it fits together

Controls — A control is a requirement your organisation must satisfy for a compliance framework (for example, “Quarterly user access review” or “Vendor SOC 2 on file”). Each control has an owner, a review frequency (monthly, quarterly, semiannual, annual, or ad hoc), a framework tag, a category, and an effectiveness rating. Controls can be active or retired. When a control’s next review date arrives, a daily job automatically creates a new draft campaign for it.

Review Campaigns — A campaign is a single cycle of review work (“Annual Access Review 2026”). Campaigns move through four states: Draft → Active → Completed → Archived. In draft, you add review items and assign reviewers. Activating the campaign notifies assignees. Completing it requires every item to have been decided (attested, flagged, or marked not applicable) and locks the campaign so items become read-only — preserving the audit record. Admins can unlock a completed campaign to allow re-attestation, then complete and re-lock it.

Review Items — Each item in a campaign is one thing to review (a user’s access, a vendor certification, a change request). The assigned reviewer records a decision: Attest (compliant), Flag (non-compliant — automatically opens a finding), or Not Applicable. Once the parent campaign is locked, items cannot be changed.

Findings — A finding is a tracked deficiency. Findings are created automatically when a review item is flagged, or raised manually. Each finding has an owner, a severity (low / medium / high / critical), a due date, and a remediation lifecycle: Open → In Progress → Remediated / Accepted / Closed.

Evidence — Evidence can be attached to controls, campaigns, review items, or findings. Evidence is either an uploaded file (up to 25 MB) or a link to an existing record in another app — a vendor certification from Supplier Hub, a change request from Service Desk, a contract obligation, or an employee certification from Practice Hub. Evidence can carry a validity date; the daily job sends reminders when evidence is expiring or has expired.

Framework Library — Platform-curated catalogs for SOX, SOC 2, ISO 27001, and HIPAA. Each catalog contains pre-built controls with categories and recommended review frequencies. Import a framework’s controls into your register in one step. Cross-framework crosswalks show equivalences (for example, SOC 2 CC6.1 maps to ISO A.9.2) so one control can satisfy requirements across multiple frameworks. Admins can view a coverage matrix showing how many controls are imported per framework and category.

Auditor Exports — A point-in-time evidence package (XLSX) covering your full program, a single campaign, or a single framework. Exports are generated in the background and can be downloaded or published as a token-gated read-only link — the auditor opens the link without logging in. Published links can carry an optional expiry. You can also set up recurring export schedules (monthly, quarterly, or annually) so packages are generated automatically.

4. Running it

Creating a control

  1. Go to Controls and click New.
  2. Enter a title, reference code (optional, unique within your business), framework, category, review frequency, and owner. Set the next review due date.
  3. The control is created as active. When its review date arrives, a draft campaign is opened automatically.

Running a review campaign

  1. Go to Review Campaigns and click New Campaign, or launch one directly from a control’s detail page.
  2. Choose a campaign type: Access Review, Certification Review, Change Review, or General.
  3. Click Build Items to populate the campaign from existing data. Access reviews create one item per active employee. Certification reviews pull vendor certifications from Supplier Hub and the Review Register. Change reviews pull change requests from Service Desk and the Register. General campaigns have no auto fan-out — add items manually.
  4. Assign a reviewer to each item (or leave unassigned for any manager to handle).
  5. Activate the campaign. Assignees receive an in-app notification and email.
  6. Reviewers open each item and choose Attest, Flag, or Not Applicable, with an optional decision note. If the setting Require Evidence When Attesting is on, evidence must be attached before attestation is allowed. A Bulk Attest button lets a reviewer clear all their pending items at once (items needing evidence are skipped).
  7. When every item has a decision, the campaign owner clicks Complete. The campaign locks, and the linked control’s next review date advances by one cadence.

Managing findings

  1. Go to Findings. The list defaults to open findings, with overdue counts shown.
  2. To raise a finding manually, click Raise a Finding and fill in the title, severity, owner, control, and due date.
  3. To resolve a finding, open it and choose a resolution status: Remediated, Accepted, or Closed.

Generating an auditor export

  1. Go to Auditor Exports and choose a scope (full program, a framework, or a campaign) and format.
  2. The export generates in the background; the page updates when it is ready.
  3. Download the package, or click Publish to create a read-only auditor link. Set an optional expiry in days. Revoke the link at any time with Unpublish.

Setting up recurring exports

  1. From Auditor Exports, go to Export Schedules.
  2. Create a schedule with a name, scope (full program or a specific framework), cadence (monthly, quarterly, or annually), and next run date.
  3. The daily job generates the export on the scheduled date and advances the next run date automatically.

5. Settings

All settings are at Apps → Compliance Hub → Settings (admin or app admin required).

Setting Default What it changes
Enable Compliance Hub AI Agent On Makes the AI agent available to answer posture and evidence-gap questions in Ask AI. Admins can also ask it to draft a control or launch a campaign.
Who Can Manage Controls & Campaigns Admins only When set to Admins only, only business admins and app admins can create controls, launch and complete campaigns, manage findings, and generate exports. When set to Any user, all app members can manage.
Enable Certification Review Campaigns On Shows the certification review campaign type. When off, cert review campaigns cannot be created and auto-recurrence falls back to a general campaign.
Enable Change Review Campaigns On Shows the change review campaign type (Service Desk integration). When off, change review campaigns cannot be created.
Enable Framework Library On Shows the Frameworks tab where admins can browse and import platform-curated SOX, SOC 2, ISO 27001, and HIPAA control catalogs.
Require Evidence When Attesting a Review Item Off When on, a reviewer must attach at least one piece of evidence (a file or a linked record) before they can attest an item. Items without evidence are skipped during bulk attest.
Require Identity Verification to Download Evidence Off When on, downloading an evidence file requires a step-up identity verification (a re-authentication prompt).
Auto-Collect Evidence from Linked Records Off When on, the daily job automatically links canonical records (vendor certifications, change requests) as evidence on pending review items, so reviewers see the proof without manual attachment.
Due-Soon Window (days) 14 How many days before a due date the dashboard shows a campaign, finding, or control as “due soon” and the daily job sends reminders.
Notify Reviewers When Assigned an Item On Sends an in-app notification and email when a review item is assigned or when a campaign is activated.
Send Due-Soon Reminders On The daily job sends in-app and email reminders for campaigns and findings within the due-soon window. Also governs evidence expiry reminders.
Send Overdue Alerts On The daily job sends in-app and email alerts for campaigns and findings past their due date. Also governs expired-evidence alerts. Overdue re-notifications stop after 90 days to avoid indefinite nagging.

6. More help

  • Compliance Hub FAQ — specific setup and operating questions
  • Ask AI — the assistant answers questions about Compliance Hub from these articles.