KOMPLAIKOMPLAI

Documentation

Learn how to use KOMPLAI to manage your GRC operations effectively


Getting Started

Quick start guide to set up your KOMPLAI workspace and begin managing your GRC operations.

Introduction

KOMPLAI is a comprehensive Governance, Risk, and Compliance (GRC) platform designed to help enterprises streamline their compliance operations. This guide will help you get started with KOMPLAI and understand its core features.

Requirements

Before you begin, ensure you have:

  • A valid KOMPLAI account (contact your administrator or sign up)
  • A modern web browser (Chrome, Firefox, Safari, or Edge)
  • Stable internet connection

Quick Start Steps

  1. 1. Log in to your account

    Navigate to app.komplai.id and enter your credentials. If you don't have an account, contact your organization's administrator.

  2. 2. Complete your profile

    After logging in, complete your profile information in the Settings page. This helps with audit trails and accountability.

  3. 3. Explore the Dashboard

    The main dashboard provides an overview of your compliance posture, pending tasks, and key metrics across all modules.

  4. 4. Choose a module

    Based on your role and responsibilities, navigate to the relevant module (RegOps, PrivOps, RiskOps, AuditOps, ESGOps, or DataOps) to begin working.

Navigation Overview

The KOMPLAI interface consists of:

  • Sidebar: Access all modules and features
  • Header: Quick actions, notifications, and profile settings
  • Main Content: Module-specific views and data
  • Dashboard: Central hub for monitoring compliance status

RegOps - Regulatory Operations

Manage regulatory compliance with automated policy management, compliance assessments, and regulatory horizon scanning.

Overview

RegOps (Regulatory Operations) is the compliance management module of KOMPLAI. It helps organizations track and manage compliance across multiple regulatory frameworks including GDPR, ISO 27001, SOC 2, and more.

Key Features

Compliance Management

Track your organization's compliance status across various standards:

  • Standards Library: Access pre-built compliance frameworks
  • Assessments: Create and manage compliance assessments
  • Gap Analysis: Identify compliance gaps and remediation priorities
  • Document Checks: Verify document compliance with requirements

Policy Management

Create, manage, and distribute organizational policies:

  • Policy Creation: Use templates or create custom policies
  • Version Control: Track policy changes and history
  • Distribution: Assign policies to relevant stakeholders
  • Acknowledgment Tracking: Monitor policy acceptance

Horizon Scanning

Stay ahead of regulatory changes:

  • Regulatory Updates: Automatic monitoring of regulatory changes
  • Impact Assessments: Evaluate how changes affect your organization
  • Alerts: Receive notifications for relevant updates
  • Source Management: Configure trusted regulatory sources

AI Gap Assessment

Leverage AI for compliance analysis:

  • AI System Registry: Register AI systems in your organization
  • Automated Assessments: AI-powered compliance gap identification
  • Recommendations: Get remediation suggestions
  • Progress Tracking: Monitor remediation efforts

How to Use

  1. Creating a Compliance Assessment

    Navigate to RegOps > Compliance > Assessments, click 'New Assessment', select a framework, and follow the guided assessment process.

  2. Managing Policies

    Go to RegOps > Policies, create or import policies, assign them to stakeholders, and track acknowledgments from the dashboard.

  3. Setting Up Horizon Scanning

    Configure your regulatory sources in RegOps > Horizon Scanning > Sources, then set up alerts for relevant topics and jurisdictions.

PrivOps - Privacy Operations

Ensure privacy compliance with ROPA, DPIA, and privacy impact assessments for GDPR, CCPA, and other regulations.

Overview

PrivOps (Privacy Operations) helps organizations maintain privacy compliance by managing records of processing activities, conducting data protection impact assessments, and monitoring privacy risks.

Key Features

Records of Processing Activities (ROPA)

Maintain required processing records:

  • Processing Activities: Document all data processing operations
  • Legal Basis: Track legal grounds for processing
  • Data Flows: Map data transfers and recipients
  • Retention Periods: Manage data retention schedules

Data Protection Impact Assessment (DPIA)

Conduct privacy impact assessments:

  • Assessment Templates: Guided DPIA workflows
  • Risk Identification: Identify privacy risks
  • Mitigation Measures: Plan risk treatments
  • Documentation: Generate DPIA reports for regulators

Privacy Impact Assessment

Evaluate privacy implications:

  • Project Assessments: Assess new projects and systems
  • Threshold Analysis: Determine if full DPIA is needed
  • Privacy by Design: Integrate privacy considerations early

Consent & Preference Management

Manage data subject consents in compliance with GDPR and UU PDP:

  • Consent Records: Capture, store, and version consent decisions per individual
  • Preference Center: Public-facing consent preference portal for end users
  • Consent Lifecycle: Track consent given, withdrawn, and expired states
  • Audit Trail: Immutable log of all consent events with timestamps and IP metadata
  • Multi-Purpose Consent: Manage granular consent across multiple processing purposes

Data Subject Rights (DSR)

Fulfill data subject rights requests efficiently and on time:

  • Request Intake: Structured forms for Access, Erasure, Rectification, Portability, and Objection requests
  • Request Tracking: Status workflow from received to fulfilled with SLA monitoring
  • Identity Verification: Built-in verification step before processing sensitive DSR requests
  • Automated Responses: Template-based response generation for common request types
  • Regulatory Deadline Tracking: Automatic deadline calculation based on GDPR 30-day and UU PDP requirements

How to Use

  1. Creating a ROPA Entry

    Navigate to PrivOps > ROPA, click 'Add Processing Activity', document the processing details including purpose, legal basis, and data categories.

  2. Conducting a DPIA

    Go to PrivOps > DPIA, create a new assessment, follow the guided questionnaire, identify risks, and document mitigation measures.

  3. Managing Consent Records

    Go to PrivOps > Consent, create a consent record for each processing purpose. Share the public preference center link with data subjects so they can manage their own preferences.

  4. Handling a DSR Request

    Navigate to PrivOps > Data Subject Rights > New Request, select the request type (e.g., Erasure), log the requestor details, verify identity, and track the request through to fulfillment within the regulatory deadline.

RiskOps - Risk Operations

Identify, assess, and mitigate risks with comprehensive risk registers, vendor risk management, and incident tracking.

Overview

RiskOps (Risk Operations) is the risk management module that helps organizations identify, assess, and mitigate various types of risks including operational, vendor, and security risks.

Key Features

Risk Register

Maintain a comprehensive view of organizational risks:

  • Risk Identification: Document and categorize risks
  • Risk Assessment: Score risks based on likelihood and impact
  • Risk Treatment: Plan and track mitigation measures
  • Risk Monitoring: Regular review and update cycles

Vendor Risk Management

Manage third-party and vendor risks:

  • Vendor Onboarding: Structured vendor assessment process
  • Questionnaires: Send and track vendor security questionnaires
  • Risk Scoring: Automated vendor risk calculations
  • Continuous Monitoring: Track vendor risk changes over time

Incident Management

Track and respond to security incidents:

  • Incident Reporting: Structured incident logging
  • Classification: Categorize incidents by type and severity
  • Response Tracking: Monitor incident resolution progress
  • Post-Incident Analysis: Learn from incidents to prevent recurrence

How to Use

  1. Adding a Risk to the Register

    Navigate to RiskOps > Risk Register, click 'Add Risk', fill in the risk details including category, likelihood, impact, and treatment plan.

  2. Onboarding a New Vendor

    Go to RiskOps > Vendor Risk > Onboarding, create a new vendor profile, send them a questionnaire, and review their responses.

  3. Reporting an Incident

    Access RiskOps > Incidents > New Incident, document the incident details, assign it for investigation, and track resolution.

AuditOps - Audit Operations

Plan, execute, and track audits with evidence management, unified control frameworks, and comprehensive reporting.

Overview

AuditOps (Audit Operations) streamlines the audit process from planning through execution and reporting. It provides a centralized platform for managing both internal and external audits.

Key Features

Audit Reports

Create and manage audit reports:

  • Report Templates: Pre-built templates for common audit types
  • Finding Documentation: Structured finding and observation records
  • Recommendations: Track remediation recommendations
  • Export Options: Generate reports in multiple formats

Unified Control Framework (UCF)

Manage controls across multiple frameworks:

  • Control Mapping: Map controls across different frameworks
  • Control Testing: Document control effectiveness tests
  • Evidence Linking: Associate evidence with controls
  • Gap Identification: Identify control gaps across frameworks

How to Use

  1. Creating an Audit Report

    Navigate to AuditOps > Audit Reports > New, select a template, define the audit scope, and begin documenting findings.

  2. Working with UCF

    Go to AuditOps > UCF, select frameworks to include, map your controls, and use the matrix view to identify overlaps and gaps.

ESGOps - ESG Operations

Track and report on Environmental, Social, and Governance metrics with automated sustainability reporting.

Overview

ESGOps (ESG Operations) enables organizations to track, manage, and report on Environmental, Social, and Governance metrics. It supports sustainability reporting requirements and stakeholder communications.

Key Features

Sustainability Reporting

Generate comprehensive sustainability reports:

  • Metrics Collection: Track ESG performance indicators
  • Framework Alignment: Align with GRI, SASB, TCFD standards
  • Report Generation: Create stakeholder-ready reports
  • Progress Tracking: Monitor improvement over time

How to Use

  1. Creating a Sustainability Report

    Navigate to ESGOps > Sustainability Report > New, select a reporting framework, input your metrics, and generate the report.

DataOps - Data Operations

Gain complete visibility and governance over your data assets with an intelligent inventory, automated classification, lineage tracking, and a searchable data catalog.

Overview

DataOps (Data Operations) is the data governance module of KOMPLAI. It helps organizations discover, classify, and track all data assets across their environment β€” from databases and APIs to file storage and SaaS applications. DataOps bridges privacy compliance (PrivOps) and risk management (RiskOps) by providing a unified view of what data exists, where it lives, how it flows, and how it is classified.

Key Features

Data Asset Inventory

Maintain a complete registry of all organizational data assets:

  • Asset Registration: Document databases, APIs, file storage, data streams, data warehouses, and SaaS applications
  • Asset Status Lifecycle: Track assets from active to archived with status management
  • Ownership & Stewardship: Assign data owners and stewards per asset
  • Rich Metadata: Record location, sensitivity, retention period, and processing purposes
  • Linked Compliance: Associate assets directly with ROPA entries and risk incidents

Data Classification

Classify data assets by sensitivity and regulatory scope:

  • Classification Labels: Define custom labels (e.g., Public, Internal, Confidential, Restricted)
  • Color-coded Labels: Visual indicators for quick at-a-glance sensitivity recognition
  • Bulk Classification: Apply or update classification across multiple assets
  • Classification History: Track classification changes over time for audit trails
  • Compliance Alignment: Map labels to regulatory categories (GDPR personal data, UU PDP sensitive data)

Data Lineage & Provenance

Trace the full journey of data across your systems:

  • Lineage Nodes: Define sources, transformations, and destinations per asset
  • Directional Edges: Model data flow relationships between nodes
  • Visual Graph: Explore lineage as an interactive directed graph
  • Regulatory Evidence: Use lineage records to satisfy EU AI Act Article 10 and NIST AI RMF training data requirements
  • Provenance Audit: Document who created or modified lineage entries and when

Data Catalog

Discover and search across all data assets in the organization:

  • Full-text Search: Find assets by name, type, location, or classification
  • Filter by Type: Narrow results by asset type (database, API, file storage, etc.)
  • Asset Detail View: Access complete metadata, classification, lineage, and linked compliance records
  • Export & Reporting: Generate asset inventory reports for auditors and regulators

How to Use

  1. Registering a Data Asset

    Navigate to DataOps > Asset Inventory > New Asset, fill in the asset name, type, data location, owner, and applicable regulations. Save to add it to your inventory.

  2. Classifying an Asset

    Open any asset from the inventory, click 'Classify', and select the appropriate classification label. Classification changes are logged automatically for audit purposes.

  3. Building a Lineage Graph

    Go to DataOps > Lineage, select an asset, and click 'View Lineage'. Add source, transformation, and destination nodes, then connect them with directional edges to document the data flow.

  4. Linking Assets to ROPA or Incidents

    When creating a ROPA entry in PrivOps or an Incident in RiskOps, use the data asset selector to link the relevant assets. This cross-module linking provides end-to-end traceability.