The Compliance module is a set of questions that helps your company fulfil the ISO27001 and SOC2 standards.
It is an important and often essential step for your legal team to assess the risks and approve the SaaS tools that you want to start using.
Depending on your team's internal process, you will:
Take the questionnaire as you add a new application
Take the questionnaire in the Compliance tab
FAQ section:
What kinds of file can I upload?
What happens if the questionnaire is updated while I'm completing the form?
Take the questionnaire as you add a new application
Depending on the needs of your legal team, they can choose to make it mandatory for users to complete the Compliance Requirements questionnaire when creating a new application.
When the questionnaire is mandatory
When the questionnaire is optional
When the questionnaire is mandatory
At the bottom of the form, under Compliance requirements, you will find questions picked out from the full questionnaire your team want you to respond to before it is sent off for approval.
When the questionnaire is optional
At the bottom of the form, under Compliance requirements, you will find questions picked out from the full questionnaire your team want you to respond to before it is sent off for approval. You will also see the option to answer the questions now or later.
If you check Yes, you’ll be prompted to complete the whole Compliance questionnaire after submitting the application form. You can either do the review instantly or receive a reminder per email on a specific day:
Take the questionnaire in the Compliance tab
Admins, Team managers, Compliance and Finance users can answer questions at any time within the Compliance tab of an application, even before the application is fully approved.
Application Owners can answer the questions if they are granted the permission in the Compliance settings:
Now you are in the Compliance tab - what can you expect?
The tab leads to an Overview tab, followed by the questionnaire divided into sections:
-
Overview
Shows you all questionnaire sections and their statuses:
- Pending: The section has not been filled in at all.
- In Progress: Some responses have been saved, but the section is not ready for review yet.
- Completed: The section has been completed and submitted. Each section can only be submitted when all mandatory questions are answered. After you submit the questionnaire, you can still go back and make changes.
- Business case
- Details of the product/service
- Risk assessment
- Contract review
-
Exit plan
A conditional section that will only appear if you answer Yes to the question "Based on the risk assessment, above, is the product/service critical or important for your company?" in the Risk assessment.
Some sections might be hidden if there are no applicable questions for you to fill in.
FAQs
Supported file formats
Uploaded documents support the following formats:
- jpeg (image)
- png (image)
- bmp (image)
- pdf (application)
Updated questionnaires
If the questionnaire has gone through any changes since you last edited or submitted the form, a Form update notification will appear where you can select the version you would like to work on:
- Select Previous version to continue working on the previously displayed and answered questions
- Select New updated version to show new questions. Previously saved answers will be displayed if the questions were not removed.
The filled in questionnaire, along with all the files uploaded, can be exported in the Overview tab via the button. You have the option to download:
- a PDF without attachments
- a ZIP with a PDF file and attachments