Risk registers with dozens or hundreds of entries still get populated one record at a time, turning onboarding into hours of repetitive data entry. Audit findings live in spreadsheets or email threads with no direct link to the risks or controls they reference. Vendor lists grow across departments, but each new vendor still requires manual form-filling. Risk dashboard charts use default colours that make it difficult to distinguish categories at a glance. Employees asked to review an updated policy have no way to see what actually changed between versions. Prospects visiting your Trust Center send compliance questions over email, waiting days for answers your documents already contain. And access reviews lock reviewer assignments to a single role, creating bottlenecks when ownership needs to shift across managers, admins, or staff.
Sprinto’s latest updates are designed to solve exactly that. You can now:
- Create, track, and map audit findings directly within audits
- Bulk-upload risks and vendors into registers using structured CSV templates with automatic validation
- Customize chart colours in Risk Register dashboards with hex codes and a colour picker
- Surface AI-powered answers to compliance questions on your Trust Center
- Show employees a summary of changes between policy versions in the Employee Portal
- Assign, delegate, and bulk-update access review reviewers with lifecycle-persistent assignments
Read about these updates in detail below:
1. Track and manage audit findings with risk mapping directly inside audits
You can now create, assign, and manage audit findings directly within an audit in Sprinto, giving your team a structured way to capture observations, assign remediation tasks, and map findings to risks without leaving the audit workflow.
With the Audit Findings feature, admins can create a finding inside any active audit, then assign tasks to the relevant owners for remediation or follow-up. Each finding can be mapped to one or more risks in your risk register, creating a direct traceability link between what the audit surfaced and the risks your organization tracks. This keeps the full lifecycle of a finding, from creation to task completion to risk association, inside one place.
| Why is this important? Audit findings that sit in disconnected tools or spreadsheets lose their connection to the controls and risks they relate to. By housing findings inside the audit itself, your team can track remediation progress alongside the audit timeline and link each finding to the specific risks it impacts. |
This traceability matters when preparing for follow-up reviews or demonstrating to auditors how your organization responded to prior observations. Mapping findings to risks also helps compliance leads identify patterns, such as multiple findings pointing to the same underlying risk, so they can prioritize treatment more effectively.

2. Bulk-upload risks into registers using structured templates with automatic validation
You can now upload multiple risks into a Risk Register at once using a structured CSV template, eliminating the need to create each risk record individually. Sprinto handles field mapping and validation automatically during the upload.
The bulk upload workflow uses a downloadable template that maps to your register’s fields. Once you populate the template and upload it, Sprinto validates each row against expected field formats and flags errors before the records are committed. This ensures data consistency across the register and reduces the chance of malformed entries making it into your risk data.
| Why is this important? Organizations migrating risk data from spreadsheets, legacy GRC tools, or acquired entities often need to onboard dozens or hundreds of risk records. Doing this one at a time is slow and error-prone. Bulk upload with automatic validation compresses that process into a single action with built-in quality checks. |
For teams running multiple registers across frameworks or business units, this also makes it faster to stand up new registers when scoping a new compliance program. A register that would have taken hours of manual entry can be populated in minutes with consistent, validated data.

3. Bulk-upload vendors using CSV templates with system and custom field support
You can now onboard vendors in bulk by uploading a CSV file that supports both system fields and custom fields, with automatic mapping and row-level validation. This removes the bottleneck of adding vendors one at a time as your vendor ecosystem grows.
The workflow mirrors the risk bulk upload process. You download a CSV template pre-configured with your account’s vendor fields, including any custom fields you have defined. After populating the template, Sprinto maps each column to the corresponding field and validates the data before importing. Errors are surfaced before commit, so your team can correct issues without polluting the vendor register.
| Why is this important? Vendor management programs scale quickly. A single procurement cycle can introduce ten or more new vendors, each requiring data entry across multiple fields. Manual entry at that volume introduces inconsistency and slows down the team responsible for vendor risk assessments and due diligence. |
Bulk upload with custom field support means your vendor register stays consistent with your organization’s data model from the first import. Teams onboarding vendors during a new framework rollout or post-acquisition integration can populate their register in one step, then move directly to assessment and classification workflows.

4. Customize chart colours in Risk Register dashboards for clearer visual differentiation
You can now customize chart colours in the Risks module using a built-in colour picker, allowing your team to visually distinguish risk categories, severity levels, or treatment statuses at a glance. This solves the problem of default chart palettes that make risk dashboards harder to read as the number of categories grows.
The colour picker supports both hex code input and a visual selector, so you can match your organization’s internal branding or adopt a colour scheme that maps to your risk taxonomy. Changes apply directly to the charts within the Risk Register dashboard, giving compliance leads and risk owners a view that reflects how they think about their risk landscape.
| Why is this important? Risk dashboards are often the first thing a CISO or compliance lead reviews in a weekly standup or board reporting cycle. When chart colours default to a generic palette, distinguishing between residual risk levels, treatment statuses, or risk categories forces your team to read every label instead of scanning visually. Custom colours turn the dashboard into a faster, more intuitive communication tool. |
For organizations managing multiple registers across zones or frameworks, consistent colour coding also helps leadership compare dashboards side by side. A red-amber-green scheme mapped to your risk appetite thresholds, for example, makes it immediately clear which registers need attention.

5. Surface AI-powered answers to compliance questions on your Trust Center
You can now enable an Ask AI experience on your Trust Center that lets visitors ask compliance questions and receive instant, contextual responses generated from the documents you have made accessible. This eliminates the email back-and-forth that typically slows down security reviews and prospect due diligence.
When a visitor submits a question through the Trust Center, the AI draws from the documents, certifications, and policies you have published or shared in that Trust Center instance. Responses are generated in real time, grounded in your actual compliance documentation. This means prospects, customers, and partners conducting security reviews can self-serve answers to common questions like data residency, encryption standards, or subprocessor lists without filing a request to your security team.
| Why is this important? Security questionnaires and ad hoc compliance questions from prospects are a recurring time sink for compliance teams. Each question requires someone to locate the right document, extract the relevant section, and draft a response. Ask AI shifts that work to the visitor, who gets an immediate answer sourced from the same documents your team would have referenced. |
This also improves Trust Center engagement. Visitors who can get answers in seconds are less likely to abandon the review process or escalate to your sales or security team for basic questions. For organizations fielding dozens of security reviews per quarter, that reduction in inbound requests frees up compliance team capacity for higher-value work.

6. Show employees a summary of policy changes between versions in the Employee Portal
You can now surface a summary of changes between policy versions in the Employee Portal, giving employees a clear view of what was added, removed, or modified before they acknowledge an updated policy. This solves the problem of employees receiving a new policy version with no visibility into what actually changed.
The Policy Summariser generates a breakdown of differences between the current and previous version of a policy. Employees see the added sections, removed sections, and modified sections in a structured summary directly in the Employee Portal. This means they can focus their review on the changes that matter, and skip re-reading an entire policy document to identify what is different.
| Why is this important? Policy acknowledgment rates drop when employees are asked to review a full document without context on what changed. The result is either rubber-stamped acknowledgments or delayed completions, both of which weaken your compliance posture. A change summary gives employees a focused review path, improving both the quality and speed of acknowledgment. |
For compliance teams managing quarterly or annual policy update cycles across dozens of policies, this also reduces the support burden. Fewer employees will reach out asking “what changed?” because the answer is visible in the portal. This keeps acknowledgment timelines on track and gives your compliance team an auditable record that employees reviewed the specific changes.

7. Assign, delegate, and bulk-update access review reviewers with lifecycle-persistent assignments
You can now assign reviewers to access reviews with flexible role-based delegation, bulk-update reviewer assignments from the User table, and maintain persistent reviewer assignments across the review lifecycle. This gives your team the ability to distribute access review ownership across Managers, Admins, and Staff without manual reassignment each cycle.
Key improvements in the Access Review Delegation workflow include the ability to assign a reviewer role (Manager, Admin, or Staff) to each access review, bulk-update those assignments across multiple users from the User table, and maintain those assignments persistently across the review lifecycle. Sprinto also automates task creation and reminders for assigned reviewers, so reviews move forward without manual follow-up from your compliance team.
| Why is this important? Access reviews often default to a single admin or compliance lead who becomes the bottleneck for every review cycle. When reviewer assignments reset or require manual configuration each time, the overhead compounds. Lifecycle-persistent assignments mean your reviewer configuration carries forward, reducing setup time for recurring review cycles. |
Bulk-updating reviewers from the User table is particularly valuable for organizations with large employee bases or frequent team changes. If a department lead changes, your compliance team can reassign all affected reviews in one action. Combined with automated task creation and reminders, this ensures access reviews stay on schedule and ownership stays clear, even as your organization scales.

March 2026 Product Updates: Scale Compliance Operations with Bulk Workflows, Structured Audit Findings, and AI-Driven Trust
With these updates, your team can carry full audit finding traceability from observation to risk register without leaving the platform, populate risk and vendor registers in a single validated upload, give Trust Center visitors self-serve answers to security questions in seconds, help employees acknowledge only what changed in a policy, and distribute access review ownership across roles with assignments that persist without manual reassignment each cycle.
These updates give compliance and risk teams the operational throughput to run audits, vendor assessments, and access reviews at the pace their programs actually demand.
Author
Srikar Sai
As a Senior Content Marketer at Sprinto, Srikar Sai believes good content should be bookmark-worthy by default. He writes about cybersecurity and GRC, aiming to move the needle with every piece. He’s also an ISO 27001-certified Lead Auditor.Explore more
research & insights curated to help you earn a seat at the table.





















