App navigation: Governance → Company Setup
Company Setup is the foundational configuration area of ClearGRC. Most other modules depend on configuration completed here first. The Setup Progress tile on the GRC Executive Dashboard tracks how much of this configuration is complete.
Profile #
Navigate to Governance → Company Setup → Profile to set your organization details: company name, industry, size, and contact information. This information appears on reports and exported documents.
Authority Documents #
Authority Documents are the compliance frameworks and regulations your organization tracks against (e.g., ISO 27001, NIST CSF, SOC 2, HIPAA).
- Navigate to Governance → Company Setup → Authority Documents.
- Select + to add a framework from the built-in library. ClearGRC supports over 30 frameworks including ISO 27001:2022, NIST CSF, NIST AI RMF, SOC 2, HIPAA, PCI-DSS v4, GDPR, FedRAMP, CMMC 2.0, and more.
- Once added, the authority document is available for linking to policies, controls, assessments, and cross-reference mappings.
[Screenshot: Authority Documents screen]
Security Taxonomy #
Navigate to Governance → Company Setup → Security Taxonomy to configure:
- Security Category – high-level groupings (e.g., Access Control, Data Protection).
- Security Classification – data sensitivity levels (e.g., Public, Confidential, Restricted).
- CIA Level – Confidentiality, Integrity, Availability ratings used in risk scoring.
Risk Profile #
Navigate to Governance → Company Setup → Risk Profile to configure:
- Risk Level – define the scoring bands (Low, Medium, High, Critical) and their numeric thresholds. The dashboard risk summary uses these bands.
- Risk Matrix – the Impact x Probability matrix used to derive risk scores in the Risk Register.
- Treatment Plan – predefined treatment plan templates available when creating a Risk Response.
[Screenshot: Risk Matrix configuration]
Assessment Profile #
Must be configured before any assessment can be created:
- Response Options – define the answer scale for assessment questions (e.g., Yes / No / Partial / Not Applicable).
- Parameters – configure scoring weights and acceptable risk thresholds used to calculate compliance scores.
Question Catalog #
Navigate to Governance → Company Setup → Question Catalog to define reusable sets of assessment questions mapped to authority document controls. The catalog is selected when creating any assessment type.
Status Color Setup #
Navigate to Governance → Company Setup → Status Color Setup to customize the colors used to display record statuses (Draft, Under Review, Awaiting Approval, Active, Retired, etc.) across all modules. Select a color for each status using the color picker and save. The colors appear on status badges throughout the application.
Note: Complete Authority Documents, Assessment Profile (Response Options and Parameters), and Risk Profile (Risk Level and Risk Matrix) before onboarding end users, as these are prerequisites for creating assessments and risks.
