White square

Product Guide

Compliance & Risk

See how Datagrasp helps teams assess controls, govern AI use, prioritize findings, manage vendors, track remediation, and show measurable compliance progress.

Compliance & Risk

Everything you need to measure, prioritize, and prove progress: Audit Checklists, Tabletop Exercises, Third-Party Risk, Risk Register, Compliance Overview & Badges, and AI Governance.

Audit Checklists

Datagrasp Audit Checklist

Guided audit checklists mapped to supported frameworks (HIPAA, NIST CSF 2.0, CIS 8.1, PCI-DSS 4.0 SAQs, GLBA, ISO/IEC 27001:2022, ISO/IEC 42001:2023, SOC 2 Readiness, CMMC Level 1 SAR, NDAA Section 889, and more). Content is organized across ten domains:

  • Asset Management
  • Business Environment
  • Governance
  • Risk Assessment
  • Risk Management Strategy
  • Supply Chain Risk Management
  • Identity, Access, and Authentication
  • Awareness and Training
  • Data Security
  • Processes and Procedures
Marking progress

Each control has a status: Not Started, In Progress, Completed, or Skipped. Update one or many controls, then save your changes. Progress rolls up to the Dashboard (overall completion, per-framework completion, and domain tables).

Attaching evidence
  • Some controls require evidence. When you mark these as Completed, you can attach files directly on the control.
  • Evidence is organized by year and control so it’s easy to find during audits.
  • If matching evidence already exists for a control, the checklist will reflect that so you don’t re-upload unnecessarily.
Notes

Add internal notes to any control (e.g., where to find a policy, who owns a follow-up, or links to internal procedures).

Linking to the Risk Register

Controls can be sent to (or linked with) the Risk Register using their Control ID. When you complete or skip linked items, the Risk Register view stays in sync so owners can track mitigation without double work.

Tips for faster progress
  • Work by domain: Tackle one domain at a time to drive visible gains in the Dashboard.
  • Attach once, reuse: Upload policy and evidence packs that satisfy multiple controls across frameworks.
  • Assign owners: Keep category ownership clear so updates flow weekly without blockers.

Tabletop Exercises

Datagrasp Tabletop Exercises

Evaluate real-world scenarios across structured categories and record Probability and Impact for each factor. Datagrasp converts these into a qualitative Risk Level (Low / Medium / High) and an overall Risk Score, helping you compare and prioritize.

Categories

Evaluations are organized by domain (e.g., Organizational & Management, Personnel, Physical, Data Security, Information Integrity, Software Integrity, Personal Computer Security, Network Protection, Incident Response). Admins can create additional factors within each category to fit your program.

How scoring works
  • Probability & Impact are captured per risk factor.
  • Datagrasp translates the combination into a clear Low / Medium / High risk level and a numeric score for sorting and trend analysis.
  • Category summaries show average levels so you can see where risk concentrates.
Ownership & action
  • Assign owners to follow up on higher-risk items.
  • Add notes to capture context, planned mitigation, or links to internal procedures.
  • When you’re ready, push an item straight to the Risk Register so it’s tracked alongside other risks with status and due dates.
Keeps your views in sync

When an evaluated item is linked to the Risk Register and later resolved (e.g., mitigated or accepted), you’ll see that reflected in Risk summaries and on the Dashboard (including Top 3 Risks and Organizational Risk).

Good practices
  • Evaluate by category: Work one domain at a time to reveal patterns (for example, many Medium-Probability / High-Impact items in Network Protection).
  • Capture evidence as you go: Link policies, procedures, or control references in notes to speed audit prep.
  • Promote early: Push anything Medium/High to the Risk Register so it has an owner and due date.

Third-Party Risk (TPRM)

Datagrasp TPRM dashboard preview

Keep all vendors in one place and understand their risk at a glance. The TPRM workspace brings together a vendor directory, questionnaires, evidence, and linked risks—with AI-assisted summaries and scoring to speed up reviews.

What you can track
  • Vendor profiles: name, category, status, assignee, key links (privacy, terms, security), and review cadence.
  • Questionnaires: send templates by email; replies are summarized and scored automatically, with a completeness % and a 0–100 risk score.
  • Evidence: upload policies, reports, or certifications with validity dates; items show as current, expiring, or expired.
  • Linked risks: push material findings straight to your Risk Register for ownership and follow-through.
AI-assisted analysis

When a vendor replies to a questionnaire, Datagrasp produces a short, plain-language summary and a numeric risk score (0–100, higher means higher risk). You’ll also see a completeness percentage so you know how much was actually answered.

  • Quick read: a concise overview with the score included (“Overall risk score: n/100”).
  • Consistency: the same scale across vendors, so comparisons are simple.
Statuses & scoring
  • Vendor status: Compliant, Medium Risk, or High Risk—set this as you review.
  • Risk score bands (guide): 0–29 Low, 30–69 Medium, 70–100 High.
Reviews & reminders
  • Choose a frequency (quarterly, semiannual, or annual); the next review date is set for you.
  • Assignees get a reminder with a direct link to the vendor when a review is due.
Evidence management
  • Store files per vendor (e.g., SOC 2, ISO certificates, security policies).
  • Track valid from/to dates and see whether items are current, expiring, or expired.
From finding to action

If a response uncovers a concern, use Push to Risk Register to create a risk with likelihood and impact. Assign an owner, pick a treatment (mitigate, transfer, accept), and track it to closure.

Tip: Start with a small questionnaire, follow up only on gaps, and attach fresh evidence. Re-evaluate high-risk vendors more frequently until the score improves.

Risk Register

Datagrasp Risk Register

The Risk Register is your single place to capture issues, assign owners, set due dates, and track each item to closure. Every risk is given a unique ID (e.g., R-12) so you can reference it in reviews and audits.

How risks get into the register
  • From Audit Checklists: send any control to the Risk Register if it needs work or follow-up.
  • From Tabletop Exercises: push significant factors directly into the register.
  • From Vendors (TPRM): create a vendor-linked risk when questionnaires or evidence raise concerns (with optional “push to Risk Register” enabled).
  • Manual entry: add a new risk for anything that doesn’t fit the above.
What each record includes
  • Category (e.g., Operational, Information Security, Supplier).
  • Description — a short statement of the risk (what might happen and why it matters).
  • Probability & Impact — simple 1–5 ratings that produce an overall level (Low/Medium/High).
  • Consequences — what would happen if the risk occurs.
  • Treatment strategy — Mitigate, Transfer, Avoid, or Accept.
  • Owner — the person responsible.
  • Target date — when you plan to resolve or decide on treatment (overdue items are highlighted).
  • Status — Identified → Planning → In Progress → Mitigated / Transferred / Accepted.
Working with linked items

Some risks are linked to a specific control or factor. When you close a linked risk (Mitigated, Transferred, or Accepted), the related control is marked complete so your Compliance progress stays in sync.

Views & tracking
  • List view: search by keywords to quickly find items (e.g., category, description, or plan text).
  • Timeline view: see start and target dates at a glance; overdue items are flagged in red to help you prioritize.
  • Badges & Compliance: closing risks that block controls will improve your completion percentage and can reactivate badges.
Tip: Keep descriptions short and action-oriented, set an owner and target date the same day you log a risk, and update the status as work progresses. This keeps reviews fast and audit-ready.

Compliance Overview, Badges & Trust Center

Datagrasp Compliance Overview and Trust Center

See where you stand for each framework at a glance. The Compliance Overview combines your Audit Checklists and Tabletop Exercises to show clear progress toward completion. This progress also powers your public Trust Center, making it easy to demonstrate compliance to customers, partners, and stakeholders without extra work.

What you’ll see
  • Progress by framework: a percentage that reflects how much you’ve completed.
  • Breakdown: completed items vs. remaining items so you know exactly what’s left.
  • Badges: when a framework reaches 100%, your downloadable Compliance Validation Badge appears on the Badges page and in your Trust Center.
How progress is calculated (plain language)
  • Audit Checklists: items you mark as done count toward completion.
  • Overall percent: the combined share of completed checklist items and evaluated factors for that framework.
Badges

Hit 100% on any framework and you earn an active badge you can download and share. Active badges are automatically displayed in your Trust Center. If progress later dips below 100%, the badge becomes inactive until you close the remaining gaps.

Use it to drive action
  • Prioritize: filter by lowest-completion frameworks first.
  • Close gaps: open any framework to jump straight to the specific items that remain.
  • Build trust: share your Trust Center link to show real, up-to-date compliance progress without exporting reports.
Tip: Review this page weekly. Each update instantly reflects in your Trust Center, helping you activate badges faster and keep stakeholders confidently informed.

AI Governance

Datagrasp AI Governance overview placeholder

AI Governance gives your team one place to document AI use, assign accountability, and show that AI-related decisions are reviewed, controlled, and auditable. It is especially useful when you are working toward ISO/IEC 42001:2023 or building a more repeatable internal process for responsible AI oversight.

What this feature helps you manage
  • AI system inventory: capture what tools, models, or workflows are in use, who owns them, and what business purpose they support.
  • Governance details: track approvals, review checkpoints, human oversight, and the policies or standards each use case should follow.
  • Operational context: record data sources, outputs, affected teams, and implementation notes so AI use is understandable during reviews.
Datagrasp AI Governance register placeholder
How it fits into Compliance & Risk
  • Supports framework work: use it alongside your Audit Checklists to organize evidence and governance activities tied to ISO/IEC 42001:2023 and related controls.
  • Connects to risk management: when an AI use case raises a concern, document it clearly and escalate it into the Risk Register for tracking and remediation.
  • Improves audit readiness: keep decisions, ownership, and artifacts in one place instead of scattered across policies, tickets, and meeting notes.
Suggested workflow
  • Start by listing each active AI use case, tool, or model that matters to your organization.
  • Add an owner, business purpose, and the review details your team expects before production or ongoing use.
  • Attach supporting evidence and push any meaningful issues or gaps to the Risk Register so they are tracked to closure.
Datagrasp AI Governance evidence placeholder
Tip: Keep AI Governance records short and operational. A clear owner, intended use, review date, and linked evidence will make internal reviews and external audits much easier.
👋 Hey there, curious dev! If you’re exploring under the hood:
• Read our KB  â€˘ Review Security  â€˘ Contact us