Product Updates

Declaration module: Privacy - September 2024 📉🏅

Written by Josephine Broe Moesgaard | 02-Sep-2024 09:15:00

We are excited to introduce our new Declaration Module, designed to streamline your compliance journey and help you maintain declarations and certifications with ease. Our module adapts seamlessly to your needs, whether you're pursuing certifications such as ISO 27001 and ISO 27002 or simply wish to align with industry standards. Achieving and maintaining declarations and certifications is a continuous process, requiring management of recurring tasks. Our Declaration Module simplifies this process, offering a systematic approach that makes the process more manageable and efficient. 

The Declaration Module is designed to simplify and standardize the creation, management, and approval of compliance declarations and certifications. Whether you’re working toward internal assurance or preparing for external audits, the module supports you in meeting critical standards and streamlining your compliance processes.

This tool is ideal for managing compliance with a range of internationally recognized frameworks, including:

  • ISO 27001
  • ISO 27002
  • ISAE 3402
  • ISAE 3000

The Declaration Module offers robust features to ensure efficiency and flexibility:

  • Custom Templates: Create reusable templates tailored to your organization’s needs.
  • Flexible Declaration Options: Manage both internal declarations and those requiring external certifications.
  • Comprehensive Documentation: Ensure every control and task is well-documented and audit-ready.

With these tools, you can confidently handle compliance demands, whether internal or external, while maintaining clarity and control over your processes.

Create a declaration template
When creating a new declaration, you must give it a name, description (optional), compliance areas (optional), audit frequency and next audit date (month). Furthermore, you must specify whether approval of the declaration must be internal "Internal approval sufficient" or external "External approval required". 

Click "Next" and select which group company(ies) the declaration should apply to. 

Add controls 
Now your are ready to start adding your controls to the declaration. Click "Add control". State the name of the control, add an category (optional) and provide a description (optional). Moreover, you can provide the control with an ID (optional) and state whom within your organisation is responsible for the control. It is the responsible who must approve the control before the declaration can be completed (if internal approval is sufficient) or be handed over for revision (if external approval is required). 

Add the task(s) that must be performed in order for the control to be completed. Tasks must be created in the annual wheel in order for them to be found. Tasks are added by clicking the + icon "Add related task". Simply search for the related task by writing the title of the task. 

Manage categories   
You can manage your categories by going to the edit icon in the right corner of the declaration and choose "Manage categories". Click '"Create category" and add a title and description. You can now add the category to your control. Go to the "Edit control" dialogue and click the dropdown "Category".  

Declaration statuses   
The controls can have four different statuses: 

  • Planned: When the control is created but no tasks have been completed yet. 
  • Ongoing: When one or more tasks related to the control are ongoing but are not yet completed. 
  • Ready for approval: When all tasks related to the control are completed.
  • Approved internally: When the responsible for the control has approved the control internally. 
  • Completed (only controls where external approval is required): When the auditor has completed the control. 

Add note  
You can always add a note to your declaration. Simply go to the overflowmenu and select "Note". When a note is added you can see a purple note icon in the list. You can click this to see or edit the note. 

Internal approval sufficient
When all controls are approved internally, you can now complete the declaration. All users who have edit permissions in the declaration module can approve declarations internally. Be aware that completed declarations cannot be edited. When completed, the system will automatically sent you to the next audit. So if you for instance just completed a declaration with audit month September 2024, and the audit frequency is set to "Yearly" then you will be sent to the next declaration with deadline in September 2025. You can always see your older versions by clicking the version dropdown in the right corner of the declaration. The dropdown is only visible if you have more than one declaration. 

External approval required
When all controls are approved internally and you are ready for an auditor to review the declaration, you can now click "Ready for revision". All users who have edit permissions in the declaration module can click the button. You are now ready to create an auditor access to the declaration. 

Go to "Settings" > "Manage roles". Create a new role and give it a title and description. You can for instance title it "Auditor access". Now select the following permissions: 

  • Task management (Only read access)
  • Declaration management (Read)
  • Auditor approval

Afterwards, you must create a new user. Go to Settings" > "Manage users". Create a new user and list the auditors information. In the dropdown named "Role" chose the role you previous made "Auditor access". When clicking "Create" an email with login information will be sent to the the auditor. 

The auditor can open every control but cannot edit these. The auditor can add an auditor note by clicking "Add auditor note" in the overflowmenu. Furthermore, the auditor can state if any deviations are evident by clicking "Add deviations" from the overflowmenu.

When the auditor has been through a control it can now be completed. Go to the overflow menu and choose "Complete". The control now changes status to "Completed". When all controls have been completed by the auditor, the auditor can now complete the whole declaration by clicking the button "Complete declaration". 

Versions
When completed, the system will automatically sent you to the next audit. So if you for instance just completed a declaration with audit month September 2024, and the audit frequency is set to "Yearly" then you will be sent to the next declaration with deadline in September 2025. You can always see your older versions by clicking the version dropdown in the right corner of the declaration. The dropdown is only visible if you have more than one declaration.  

We hope you will enjoy the new Declaration Module 🎉