App navigation: Governance → Document Inventory
Document Inventory is a centralized file repository for governance documents – policies, procedures, evidence artifacts, contracts, and any other files your organization needs to track and make accessible across the platform.
Screen Layout #
Navigate to Governance → Document Inventory to open a folder-based file browser. Files are organized in a folder hierarchy that you create and manage.
[Screenshot: Document Inventory folder view]
Creating Folders #
- Select New Folder.
- Enter a folder name and confirm.
- Folders can be nested to create a hierarchy (e.g., Policies → Information Security → 2026).
Uploading Files #
- Navigate to the destination folder.
- Select Upload.
- Choose the file(s) from your computer and confirm.
- Uploaded files display metadata: file name, upload date, uploaded by, and file type.
[Screenshot: Upload dialog and uploaded file listing]
Attaching Files to Assessment Questions #
During a compliance assessment, files can be attached to individual question responses as evidence. When answering a question, choose one of three options:
- Upload File – upload a new file directly from your computer.
- Upload Link to File – reference a file by URL without uploading it.
- Use Existing File – select a file already in Document Inventory, avoiding duplicate uploads.
[Screenshot: Assessment question showing the artifact upload options]
AI-Generated Risk Suggestions #
As you answer compliance assessment questions, ClearGRC can generate AI-suggested probable risks based on the controls referenced in the question and the authority document being assessed.
- Open an active assessment and open a question response that has associated control references.
- Look for the AI Generated Probable Risks section in the response panel. ClearGRC displays suggested risks – each with a Title and Description – based on an AI analysis of the control gaps for that question.
- Review each suggestion and accept the risks that are relevant to your organization. Accepted risks can be mapped to the Risk Register for formal tracking.
- Dismiss suggestions that are not applicable.
[Screenshot: AI Generated Probable Risks panel showing risk suggestions]
Note: AI-generated risks are suggestions only. Your team should validate each suggestion before adding it to the Risk Register.
Best Practices #
- Organize folders by framework or business unit to make evidence retrieval faster during audits.
- Use consistent naming conventions for files so search results are predictable.
- Store the latest approved version of each policy document here so it is available as assessment evidence.
