Documentation
Quick start guide to set up your KOMPLAI workspace and begin managing your GRC operations.
KOMPLAI is a comprehensive Governance, Risk, and Compliance (GRC) platform designed to help enterprises streamline their compliance operations. This guide will help you get started with KOMPLAI and understand its core features.
Before you begin, ensure you have:
1. Log in to your account
Navigate to app.komplai.id and enter your credentials. If you don't have an account, contact your organization's administrator.
2. Complete your profile
After logging in, complete your profile information in the Settings page. This helps with audit trails and accountability.
3. Explore the Dashboard
The main dashboard provides an overview of your compliance posture, pending tasks, and key metrics across all modules.
4. Choose a module
Based on your role and responsibilities, navigate to the relevant module (RegOps, PrivOps, RiskOps, AuditOps, ESGOps, or DataOps) to begin working.
The KOMPLAI interface consists of:
Manage regulatory compliance with automated policy management, compliance assessments, and regulatory horizon scanning.
RegOps (Regulatory Operations) is the compliance management module of KOMPLAI. It helps organizations track and manage compliance across multiple regulatory frameworks including GDPR, ISO 27001, SOC 2, and more.
Compliance Management
Track your organization's compliance status across various standards:
Policy Management
Create, manage, and distribute organizational policies:
Horizon Scanning
Stay ahead of regulatory changes:
AI Gap Assessment
Leverage AI for compliance analysis:
Creating a Compliance Assessment
Navigate to RegOps > Compliance > Assessments, click 'New Assessment', select a framework, and follow the guided assessment process.
Managing Policies
Go to RegOps > Policies, create or import policies, assign them to stakeholders, and track acknowledgments from the dashboard.
Setting Up Horizon Scanning
Configure your regulatory sources in RegOps > Horizon Scanning > Sources, then set up alerts for relevant topics and jurisdictions.
Ensure privacy compliance with ROPA, DPIA, and privacy impact assessments for GDPR, CCPA, and other regulations.
PrivOps (Privacy Operations) helps organizations maintain privacy compliance by managing records of processing activities, conducting data protection impact assessments, and monitoring privacy risks.
Records of Processing Activities (ROPA)
Maintain required processing records:
Data Protection Impact Assessment (DPIA)
Conduct privacy impact assessments:
Privacy Impact Assessment
Evaluate privacy implications:
Consent & Preference Management
Manage data subject consents in compliance with GDPR and UU PDP:
Data Subject Rights (DSR)
Fulfill data subject rights requests efficiently and on time:
Creating a ROPA Entry
Navigate to PrivOps > ROPA, click 'Add Processing Activity', document the processing details including purpose, legal basis, and data categories.
Conducting a DPIA
Go to PrivOps > DPIA, create a new assessment, follow the guided questionnaire, identify risks, and document mitigation measures.
Managing Consent Records
Go to PrivOps > Consent, create a consent record for each processing purpose. Share the public preference center link with data subjects so they can manage their own preferences.
Handling a DSR Request
Navigate to PrivOps > Data Subject Rights > New Request, select the request type (e.g., Erasure), log the requestor details, verify identity, and track the request through to fulfillment within the regulatory deadline.
Identify, assess, and mitigate risks with comprehensive risk registers, vendor risk management, and incident tracking.
RiskOps (Risk Operations) is the risk management module that helps organizations identify, assess, and mitigate various types of risks including operational, vendor, and security risks.
Risk Register
Maintain a comprehensive view of organizational risks:
Vendor Risk Management
Manage third-party and vendor risks:
Incident Management
Track and respond to security incidents:
Adding a Risk to the Register
Navigate to RiskOps > Risk Register, click 'Add Risk', fill in the risk details including category, likelihood, impact, and treatment plan.
Onboarding a New Vendor
Go to RiskOps > Vendor Risk > Onboarding, create a new vendor profile, send them a questionnaire, and review their responses.
Reporting an Incident
Access RiskOps > Incidents > New Incident, document the incident details, assign it for investigation, and track resolution.
Plan, execute, and track audits with evidence management, unified control frameworks, and comprehensive reporting.
AuditOps (Audit Operations) streamlines the audit process from planning through execution and reporting. It provides a centralized platform for managing both internal and external audits.
Audit Reports
Create and manage audit reports:
Unified Control Framework (UCF)
Manage controls across multiple frameworks:
Creating an Audit Report
Navigate to AuditOps > Audit Reports > New, select a template, define the audit scope, and begin documenting findings.
Working with UCF
Go to AuditOps > UCF, select frameworks to include, map your controls, and use the matrix view to identify overlaps and gaps.
Track and report on Environmental, Social, and Governance metrics with automated sustainability reporting.
ESGOps (ESG Operations) enables organizations to track, manage, and report on Environmental, Social, and Governance metrics. It supports sustainability reporting requirements and stakeholder communications.
Sustainability Reporting
Generate comprehensive sustainability reports:
Creating a Sustainability Report
Navigate to ESGOps > Sustainability Report > New, select a reporting framework, input your metrics, and generate the report.
Gain complete visibility and governance over your data assets with an intelligent inventory, automated classification, lineage tracking, and a searchable data catalog.
DataOps (Data Operations) is the data governance module of KOMPLAI. It helps organizations discover, classify, and track all data assets across their environment β from databases and APIs to file storage and SaaS applications. DataOps bridges privacy compliance (PrivOps) and risk management (RiskOps) by providing a unified view of what data exists, where it lives, how it flows, and how it is classified.
Data Asset Inventory
Maintain a complete registry of all organizational data assets:
Data Classification
Classify data assets by sensitivity and regulatory scope:
Data Lineage & Provenance
Trace the full journey of data across your systems:
Data Catalog
Discover and search across all data assets in the organization:
Registering a Data Asset
Navigate to DataOps > Asset Inventory > New Asset, fill in the asset name, type, data location, owner, and applicable regulations. Save to add it to your inventory.
Classifying an Asset
Open any asset from the inventory, click 'Classify', and select the appropriate classification label. Classification changes are logged automatically for audit purposes.
Building a Lineage Graph
Go to DataOps > Lineage, select an asset, and click 'View Lineage'. Add source, transformation, and destination nodes, then connect them with directional edges to document the data flow.
Linking Assets to ROPA or Incidents
When creating a ROPA entry in PrivOps or an Incident in RiskOps, use the data asset selector to link the relevant assets. This cross-module linking provides end-to-end traceability.