Blog
sprinto angle right
Product
sprinto angle right
January 2026 Product Updates: Sharpen Integration Health, Risk Accuracy, and Remediation Speed Across Sprinto

January 2026 Product Updates: Sharpen Integration Health, Risk Accuracy, and Remediation Speed Across Sprinto

Integration sync errors surface differently depending on whether you are looking at Staff Devices, Incidents, or Vulnerabilities, forcing teams to context-switch just to understand what broke and where. Risk treatment effectiveness scores treat every linked control as equally important, even when a single critical control carries far more operational weight than a procedural checklist item. Repetitive manual follow-ups pile up because there is no way to trigger notifications or actions automatically when a record changes state. Control gaps get flagged but sit without a structured path from finding to assigned task to closed remediation. Teams evaluating control performance rely on ad-hoc methods with no repeatable scoring or trend visibility. And when Terraform-managed infrastructure monitors fail, engineers leave Sprinto to search external documentation for the right HCL fix.

Sprinto’s latest updates are designed to solve exactly that. You can now:

  • View standardized sync errors and AI-powered troubleshooting steps across all integration areas,
  • Assign custom percentage weights to controls linked to a risk for more accurate treatment effectiveness scores,
  • Build condition-based automation rules in the Rule Engine with triggers for notifications, emails, and AI-driven actions,
  • Add findings to controls within Zones and create remediation tasks directly from findings or controls,
  • Define custom scoring methods, assign testers, and visualize score trends for structured control testing, and
  • Copy ready-made Terraform fix-it templates to remediate failing AWS infrastructure monitors without leaving Sprinto.

Read about these updates in detail below:

1. Standardize integration error visibility across Staff Devices, Incidents, and Vulnerabilities

You can now view last-sync timestamps and error details consistently across every integration area in Sprinto, including Staff Devices, Incidents, and Vulnerabilities. Previously, error handling behavior varied between overview pages, data tables, and provider pages, making it difficult to pinpoint which integrations had active issues and why.

Sprinto now applies a unified error handling experience across all integration surfaces. Every integration area displays last sync status and detailed error information in the same format. AI-powered troubleshooting steps accompany user-side errors, giving your team specific guidance on how to resolve issues without filing a support ticket. A new error-based filter lets you surface only the integrations with active sync problems, so you can prioritize fixes across your connected tools quickly.

Why is this important?

Consistent error visibility across all integration areas means your team spends less time diagnosing where a sync broke and more time resolving it. The AI-powered troubleshooting steps provide actionable resolution paths directly in context, reducing back-and-forth with support.

When a vulnerability scanner integration stops syncing, for example, your compliance team can now filter to that integration, read the specific error, and follow the suggested fix. That remediation loop, from detection to resolution, happens inside Sprinto with full visibility into sync health at every step.

Screenshot

2. Assign control weights to improve risk treatment effectiveness accuracy

You can now assign custom percentage weights to controls and tasks linked to a risk, replacing the simple averaging method with a weighted scoring model that reflects how critical each control actually is to treating that risk.

Configure control weightage directly from Risk Register settings. Each control, task group, or task linked to a risk can receive a custom weight set to up to two decimal places. Sprinto enforces a total weight of 100% with built-in validation, so your weights always add up correctly. If you need to start over, a one-click reset redistributes weights evenly across all linked items. The weighted score then feeds into the risk treatment effectiveness calculation, giving you a more accurate picture of residual risk.

Why is this important?

A risk linked to five controls may depend heavily on one of them, such as an encryption policy, while the others play a supporting role. Weighted scoring lets risk owners and auditors see effectiveness scores that match the actual criticality of each control, improving the accuracy of risk evaluation across your registers.

This directly affects prioritization decisions. When a high-weight control drops in health, the treatment effectiveness score shifts meaningfully, signaling to risk owners that immediate attention is needed. Teams operating across multiple frameworks and registers benefit from scores that reflect real-world control importance, making audit conversations grounded in accurate data.

Screenshot

3. Automate workflows with condition-based rules in the Rule Engine

You can now create condition-based automation rules in Sprinto’s Rule Engine to trigger actions automatically when records are created or updated, removing the need for manual follow-ups and repetitive coordination.

Rules are defined using default or custom fields on any supported entity. You set the conditions that must be met, then configure the actions Sprinto should take when those conditions are true. Actions include sending notifications, triggering emails, or executing AI-driven actions. Rules fire automatically whenever a matching record is created or updated, keeping your workflows moving without manual intervention. The Rule Engine is accessible through Command Centre.

Why is this important?

Manual follow-ups, reminder emails, and status checks consume hours every week across compliance and security teams. The Rule Engine lets you encode those recurring workflows as persistent rules that execute automatically, ensuring nothing falls through the cracks as your compliance program scales.

Consider a scenario where every new high-severity risk record should immediately notify the risk owner and trigger an email to the compliance lead. With the Rule Engine, that entire sequence fires the moment the record is created. Your team standardizes response patterns across the organization, and every action is traceable back to the rule that triggered it.

Screenshot

4. Add findings and create remediation tasks directly from controls

You can now add findings to controls within Zones and create remediation tasks from those findings or directly from the control itself, closing the gap between identifying a control issue and assigning someone to fix it.

The refreshed Controls page introduces a streamlined workflow for managing control health. When a control has an issue, you can log a finding against it within the relevant Zone. From there, you can create a task linked to that finding, assigning it to the right owner with full traceability. You can also create tasks directly from a control without first logging a finding, giving you flexibility depending on the urgency and nature of the gap. Every step, from control to finding to task, stays connected, so your team always knows what was found, what was assigned, and what was resolved.

Why is this important?

Traceability between a control gap and its remediation is critical for audit readiness. By linking controls, findings, and tasks in a single workflow, Sprinto ensures that every identified gap has a clear remediation path with assigned ownership.

For teams managing controls across multiple Zones, this update means compliance gaps no longer sit in spreadsheets or chat threads waiting for someone to act. A finding logged against an access control in your production Zone immediately becomes an assignable task, and the full chain of evidence, from discovery to closure, is captured in Sprinto.

Screenshot

5. Define custom scoring methods and run structured control tests

You can now create custom scoring methods for control testing, assign testers, set testing frequency, and visualize score trends over time on control pages. This gives your team a repeatable, measurable way to evaluate control performance that aligns with your internal methodology.

Start by creating a scoring method that matches how your organization evaluates controls. Apply that scoring method to individual controls or in bulk across multiple controls. For each control, configure the assigned tester, testing instructions, and the frequency at which tests should run. When a test is initiated, the tester enters scoring values, and Sprinto automatically calculates the final score and stores the result. Scores appear as trend lines on the control page, giving you a visual history of how each control has performed over successive test cycles. Testing configurations also support Zone-specific setups, so you can tailor evaluation criteria to the operational context of each Zone.

Why is this important?

Structured, repeatable control testing replaces ad-hoc evaluation with a defined process. Custom scoring methods ensure that the way you measure control health matches your organization’s risk appetite and internal audit standards.

Over time, score trends on control pages reveal patterns. A control that scores consistently well confirms your investment in that area. A control with declining scores signals a drift that needs attention before your next audit cycle. Zone-specific testing configurations let different parts of your organization apply the evaluation criteria most relevant to their compliance scope.

Screenshot

6. Remediate failing AWS infrastructure monitors with Terraform fix-it templates

You can now access step-by-step Terraform (HCL) code templates directly inside Sprinto for failing infrastructure monitors, eliminating the need to search external documentation or troubleshooting resources for the right remediation script.

When a Terraform-managed AWS infrastructure monitor fails, Sprinto surfaces a fix-it template containing the relevant HCL code along with clear instructions and explanations. You can copy the snippet and apply it to your infrastructure configuration. Each template is tailored to the specific monitor failure, so you get the exact code needed for the issue at hand. Coverage currently includes the most common AWS monitors, with additional monitor coverage expanding based on customer demand.

Why is this important?

Infrastructure monitor failures are some of the most time-consuming compliance gaps to close because they require engineers to find the correct fix, understand the context, and apply it. Built-in Terraform templates reduce that cycle from a research task to a copy-paste operation with clear guidance.

For teams managing AWS infrastructure through Terraform, this means faster resolution of monitor failures that would otherwise block compliance posture improvements. Engineers stay inside Sprinto, read the explanation, apply the fix, and see the monitor return to a passing state, all without context-switching to external documentation.

Screenshot

Sprinto’s January 2026 Updates: Sharpen Integration Health, Risk Accuracy, and Remediation Speed Across Sprinto

With these updates, your team can resolve integration sync issues in context with AI-guided steps, apply weighted control importance to risk treatment scores across your entire register, run recurring compliance workflows through persistent rules that fire automatically on record changes, trace every control gap from finding to assigned task to verified closure, and remediate failing Terraform monitors with ready-made HCL snippets copied directly from inside Sprinto.

These updates sharpen the operational accuracy of your risk registers, compress remediation cycles for infrastructure and control gaps, and give every compliance workflow a trigger that runs without someone remembering to follow up.

Srikar Sai
Author

Srikar Sai

As a Senior Content Marketer at Sprinto, Srikar Sai believes good content should be bookmark-worthy by default. He writes about cybersecurity and GRC, aiming to move the needle with every piece. He’s also an ISO 27001-certified Lead Auditor.
Tired of fluff GRC and cybersecurity content? Subscribe to our newsletter and get detailed
research & insights curated to help you earn a seat at the table.
single-blog-footer-img