📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Compliance Settings

Decide who can do what in your compliance program and set the rules that every compliance page follows for your organization.

Where to find it
Compliance (GRC) › Compliance Settings
Who can use it
Anyone with a GRC role that can view compliance data can read the page; only a GRC administrator can change roles or settings
Plan
Compliance (GRC) platform
For
Everyone

What the page is for

Compliance Settings has two jobs. First, it lets a GRC administrator give each person a compliance role, such as approver or auditor, so that the people who write policies and controls are not always the same people who approve them. A role only applies where the person can already sign in; it never gives them access to another company.

People who have not been given a role here get one automatically from their console role: administrators become GRC administrators, managers become compliance managers, end-user portal accounts become viewers, and everyone else is a contributor. Console super admins are always GRC administrators.

Second, the page holds the company-wide compliance settings: separation of duties, risk appetite, reminder timing, evidence expiry warnings, AI drafting, which email domains may receive scheduled reports, and whether reminder emails are sent. Every role change and setting change is recorded in the activity log with the old and new value.

What you see

The Compliance Settings page, with the header, who can do what, the roles, company settings and save settings numbered 1 to 5.
The Compliance Settings page. Numbers match the list below.
  1. Header: the company you are working in and your own GRC role. If you cannot make changes, a note says only a GRC administrator can.
  2. Who can do what: a table of the people who can be assigned compliance work, with Person, Organization and GRC role. Administrators see a role picker on each row they can manage.
  3. The roles: a plain description of each role: administrator, manager, approver, contributor, viewer and auditor.
  4. Company settings: each setting with its current value, a help line, and "Using the default" when it has never been changed.
  5. Save settings: saves the company settings (shown to GRC administrators only).

How to change someone's compliance role

  1. In Who can do what, find the person.
  2. Open the role list on their row and choose a role, or choose Follow console role to go back to the automatic role.
  3. Read the description in the confirmation and select Change role.
  4. The row updates and shows "Set here" or "From console role" under the picker.

How to change the company settings

  1. In Company settings, change the values you need:
    • Separation of duties: Strict: nobody approves their own work (the default) or Allow self-approval, with a written reason.
    • Risk appetite (residual score): 1 to 25, default 12. Risks with a residual score above this need a formal risk acceptance.
    • Reminder lead time (days): 1 to 30, default 3. How early the "due soon" email goes out; a second reminder is sent on the due date.
    • Evidence expiry warning (days): 1 to 90, default 30.
    • AI drafting: Off (default) or On.
    • Scheduled reports may be emailed to: a comma-separated list of email domains, for example example.com, example.ca.
    • Reminder emails: On (default) or Off.
  2. Select Save settings. The page confirms "Settings saved" (or "Nothing changed") and reloads.

How to allow self-approval for a one-person practice

  1. Set Separation of duties to Allow self-approval, with a written reason.
  2. Select Save settings.
  3. In Allow people to approve their own work?, type a reason of at least ten characters (for example "One-person practice") and select Allow.
  4. From then on, each self-approval needs its own reason, is flagged on the record and is shown as self-approved in reports and to auditors.

Tips

  • Keep Strict separation of duties unless one person genuinely does everything. It is what auditors expect.
  • Use the Auditor role for internal auditors who have a console login. External auditors use the auditor portal instead.
  • Leave Scheduled reports may be emailed to empty to keep scheduled reports going only to console users of your company. That is the safe default.
  • Turning Reminder emails off stops the daily reminders only. Emails someone sends on purpose, such as evidence requests and attestation links, still go out.
  • AI drafting never saves or sends a draft on its own; a person must edit and approve it first.

Troubleshooting

  • I cannot change anything on this page. Only a GRC administrator can change roles and settings. Everyone else sees the page read-only.
  • A person's role cannot be changed. Console super admins are always GRC administrators. People who belong to your service provider show "Managed by …" and are managed by their own organization.
  • "This is the last GRC administrator…" You cannot remove the last GRC administrator of a company. Make someone else an administrator first.
  • "Allowing self-approval needs a reason of at least ten characters." Enter a longer reason in the confirmation box.
  • "Your GRC role does not include viewing compliance data." Ask a GRC administrator to give you a role that can view compliance data.

Task guides that use this page

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.