App navigation: Compliance → Assessments → [Assessment Type]
This workflow covers completing a compliance assessment from creation through sign-off. Each assessment type has its own dedicated page under the Assessments menu.
Prerequisites #
- An administrator must have configured Company Setup → Response Options and Parameters before any assessment can be created.
- At least one Authority Document and Question Catalog must exist (configured in Governance → Company Setup → Authority Documents).
Step 1 – Start the Assessment #
- Navigate to Compliance → Assessments and select the type of assessment you want to create (e.g., Self Assessment, Readiness Assessment, Gap Assessment, Entitlement Assessment, or Third Party Assessment).
- Each type opens its own inventory page. Select Create Assessment on that page.
[Screenshot: Assessment type inventory showing Create Assessment button]
Step 2 – Executive Summary #
- Enter the assessment Title, Owner, and Start / End dates.
- Select the Authority Document (the framework being assessed against, e.g., ISO 27001).
- Select the Question Catalog to use for this assessment.
Step 3 – Scope, Timeline, and Stakeholders #
- Define the scope of the assessment and any exclusions.
- Assign Reviewers and Approvers.
- For Third Party Assessments, link to the relevant Third-Party Inventory record.
Step 4 – Answer Assessment Questions #
- Once created, open the assessment from the inventory. Status will be Initiated.
- Work through each question in the catalog, selecting the configured response option (e.g., Yes / No / Partial).
- For each question, upload supporting artifacts as evidence and add comments as needed.
- When all questions are answered, submit the assessment for review. Status moves to In Progress → Under Review.
Step 5 – Review and Approve #
- Reviewers receive a notification and submit their review.
- Approvers provide final sign-off.
- The assessment reaches Sign Off status and a compliance score is calculated.
