Blog
Sprintwinkel rechts
Produkt
Sprintwinkel rechts
December 2025 Product Updates: Automate Error Resolution, Structure Risk Programs, and Strengthen Policy Governance

December 2025 Product Updates: Automate Error Resolution, Structure Risk Programs, and Strengthen Policy Governance

Integration misconfigurations and vendor errors from platforms like AWS, GitHub, and Google Workspace stall compliance workflows while teams wait on support escalations or parse logs without clear root-cause context. Risk programs that span departments and frameworks get forced into a single register per zone, blurring ownership boundaries and scoring schemes. Policy updates move through approval chains over email threads with no sequential step tracking, rejection handling, or centralized audit trail. Security questionnaires consume hours of manual drafting per prospect review, and Trust Centers publish documentation with zero visibility into visitor engagement or download patterns. Control evaluations apply uniform scoring that does not match how individual teams measure control health, and findings tied to specific controls live outside the control page, disconnected from evidence and remediation tasks.

Die neuesten Updates von Sprinto wurden genau für dieses Problem entwickelt. Sie können jetzt:

  • Resolve integration misconfigurations with automated, step-by-step guidance through the Fix-It Agent,
  • Diagnose vendor errors with AI-generated root-cause explanations in the Sprinto AI Debugger,
  • Maintain multiple Risk Registers within a single Zone, each with independent scoring and configuration,
  • Configure multi-step Approval Paths for Policies with sequential logic, rejection flows, and progress tracking,
  • Generate complete security questionnaire responses using Sprinto AI with customizable prompts and tone,
  • Track Trust Center performance with a new analytics dashboard covering visitor activity, document engagement, and downloads,
  • Test controls using custom scoring methods with automatic notifications and score trend tracking, and
  • Create and view findings and remediation tasks directly on individual control pages.

Lesen Sie unten mehr über diese Aktualisierungen:

1. Resolve integration misconfigurations with guided, automated fixes

You can now resolve common integration misconfigurations directly from Sprinto using the Fix-It Agent. When an integration error occurs, the Fix-It Agent detects the issue, explains its cause in plain language, and walks your team through a step-by-step resolution path. This eliminates the cycle of raising support tickets, waiting for triage, and manually troubleshooting configuration drift across your connected tools.

The Fix-It Agent operates within Sprinto’s integration layer. When a misconfiguration is detected, the agent surfaces it with a clear explanation of the root cause and provides guided remediation steps your team can follow directly in the platform. Each fix is scoped to the specific integration and error type, so the guidance is contextual and actionable.

Warum ist das wichtig?

The Fix-It Agent reduces your team’s dependency on support for routine integration errors. Configuration issues that previously required a ticket, a back-and-forth thread, and hours of wait time can now be identified and resolved in minutes from within Sprinto.

For teams managing dozens of integrations across cloud infrastructure, identity providers, and HR systems, even a single misconfigured connection can break a monitor and create a compliance gap. The Fix-It Agent ensures faster recovery and helps your team maintain a real-time compliance posture without pulling in external resources for every configuration issue.

Bildschirmfoto

2. Diagnose vendor errors with AI-powered root-cause analysis

You can now use the Sprinto AI Debugger to analyze incoming vendor errors and get root-cause explanations, actionable fixes, and validation steps, all without leaving the platform. For teams managing integrations with AWS, GitHub, Jira, Google Workspace, Rippling, and other vendors, this means errors that previously required escalation or manual investigation can now be understood and resolved directly by your team.

The AI Debugger is accessible from two locations: the Integrations Errors tab and via Data Library drawers. When a vendor error surfaces, the Debugger analyzes the error context and generates a readable explanation of what went wrong, why it happened, and what steps your team should take to fix it. Each recommendation is specific to the integration, so troubleshooting guidance for an AWS permission error differs from a Jira sync failure. The Debugger also provides validation steps so your team can confirm the fix before moving on.

Warum ist das wichtig?

The AI Debugger standardizes how your team handles integration errors. Every error gets the same structured treatment: root-cause analysis, a clear fix, and a way to validate. This consistency reduces support escalations and makes error resolution a repeatable process your team can own.

Consider a scenario where your GitHub integration throws a permission error during an audit window. Previously, this would trigger a support ticket, wait for diagnosis, and require back-and-forth before resolution. With the AI Debugger, your team sees the root cause immediately, follows the prescribed fix, and validates the resolution, all from the Errors tab. That is the difference between hours of downtime and minutes of self-service resolution.

Bildschirmfoto

3. Maintain multiple Risk Registers within a single Zone for cleaner risk governance

You can now create and maintain multiple Risk Registers within the same Zone in Sprinto. This solves a long-standing structural limitation: teams that needed separate registers for different departments, frameworks, or projects were forced to create additional Zones just to achieve that separation, even when the risks belonged to the same operational context.

Each Risk Register operates with full configuration isolation. You can assign independent scoring schemes, custom risk types, categories, and fields per register. Each register supports its own risk managers, monitoring schedules, and periodic assessment cadences. This means your engineering team’s risk register can use a different scoring model and category structure than your HR team’s register, even when both sit within the same Zone. Risk segmentation now happens at the register level, giving your team the flexibility to model risk programs around departments, frameworks, or projects without creating unnecessary Zones.

Warum ist das wichtig?

Multiple Risk Registers per Zone eliminate forced structural workarounds. Your team can segment risks by department, framework, or project while keeping them organized under the Zone that represents their true operational scope. Each register maintains its own scoring, categories, and ownership, so risk programs stay clean and well-defined.

For an organization running SOC 2 and ISO 27001 within the same business unit, this means you can maintain a separate register for each framework’s risk landscape. Each register reflects framework-specific risk categories and scoring, while the Zone provides the shared organizational context. The result is more structured risk governance without the overhead of managing redundant Zones.

Bildschirmfoto

4. Configure multi-step Approval Paths for Policies with sequential logic and rejection flows

You can now define multi-step Approval Paths for policies in Sprinto, replacing informal review cycles with structured, trackable governance workflows. Policy approvals can now follow a configurable sequence of steps, each with its own approvers and logic, ensuring that every policy update passes through the right people in the right order.

When setting up an Approval Path, you can add multiple sequential steps (Step 1, Step 2, Step 3, and so on). Each step supports AND/OR approval logic: AND requires all designated approvers to approve before the policy moves forward, while OR requires only one. Once a step is completed, Sprinto automatically progresses the policy to the next step in the sequence. If an approver rejects a policy at any step, the built-in rejection and resubmission flow routes it back for revision. Your team can track the full approval progress and send reminders to pending approvers directly from the policy drawer.

Warum ist das wichtig?

Multi-step Approval Paths standardize how policies move through review across your organization. Every policy update follows the same structured path, with a clear audit trail of who approved, who rejected, and when each step completed. This eliminates the ambiguity of email-based approvals and ensures governance is documented.

For organizations with layered approval requirements, such as a policy that needs sign-off from a department head, then legal, then the CISO, this update models the actual chain of authority. Each step reflects a real organizational checkpoint, and the AND/OR logic accommodates both single-approver and committee-based review models within the same workflow.

Bildschirmfoto

5. Generate complete security questionnaire responses with Sprinto AI

You can now use Sprinto AI to generate full security questionnaire responses, cutting down the hours your team spends manually drafting answers for every prospect, partner, or customer review. The AI generates context-aware answers that reflect your organization’s security posture and compliance documentation.

Sprinto AI supports customizable prompts and tone settings, so your team can tailor responses to match the level of detail, formality, or technical depth required by each questionnaire. Once generated, responses can be fine-tuned through live editing and formatting directly within Sprinto. This means your team starts with a complete, high-quality draft and refines from there, compressing what was previously a multi-hour task into a focused editing pass.

Warum ist das wichtig?

Security questionnaires are a recurring bottleneck in sales cycles, vendor assessments, and partnership evaluations. Sprinto AI removes the blank-page problem and delivers consistent, well-structured responses that your team can review and ship faster.

For a team fielding 10 or more questionnaires per quarter, each with 50 to 200 questions, the time savings compound quickly. Consistent AI-generated drafts also reduce the risk of contradictory or incomplete answers across different questionnaires, which is a common issue when multiple team members draft responses independently.

6. Track Trust Center engagement with a dedicated analytics dashboard

You can now measure how stakeholders interact with your Trust Center through a new analytics dashboard in Sprinto. This gives your team visibility into an area that was previously opaque: who visits your Trust Center, which documents they engage with, and what gets downloaded.

The Trust Center Analytics dashboard surfaces four categories of data: visitor activity, document engagement, download patterns, and update subscription metrics. Your team can see which compliance documents attract the most attention, how frequently visitors return, and whether stakeholders are subscribing to receive updates when documentation changes. This data lives directly within Sprinto, so you do not need to layer on external analytics tools to understand Trust Center performance.

Warum ist das wichtig?

Publishing compliance documentation is only valuable if stakeholders actually engage with it. The analytics dashboard tells your team whether prospects are reviewing your SOC 2 report, whether customers are downloading your security policies, and which documents may need more prominent placement or updates.

During audit preparation, renewal cycles, or active sales conversations, this data helps your team understand stakeholder interest and tailor follow-up accordingly. If a prospect downloaded your penetration testing report but skipped your incident response policy, your team knows exactly where to focus the next conversation.

7. Test controls with custom scoring methods and trend tracking

You can now test controls in Sprinto using custom scoring methods that reflect how your team actually evaluates control performance. This replaces a one-size-fits-all approach to control testing with a flexible model where each control can be scored according to criteria that match your organization’s internal standards.

When configuring control tests, you can assign a control-specific scoring method that aligns with your team’s evaluation framework. Sprinto sends automatic notifications when tests are due, ensuring that testing cadences stay on track without manual calendar management. Once tests are completed, score trends are displayed directly on the control page, giving control owners and reviewers a clear view of how control health has changed over time.

Warum ist das wichtig?

Custom scoring methods allow your team to evaluate controls with the precision your internal standards require. A control governing access reviews may need a different scoring rubric than one governing encryption at rest. With control-specific scoring, each evaluation produces a result that is meaningful within its operational context.

Score trend visibility on the control page gives your team a longitudinal view of control health. If a control’s scores are declining over three consecutive test cycles, that signal is immediately visible, enabling your team to investigate and remediate before the issue surfaces in an audit.

Bildschirmfoto

8. Create and track findings directly on control pages for faster remediation

You can now create findings and remediation tasks directly on individual control pages in Sprinto. This centralizes the full lifecycle of a control, from evidence and testing to issue identification and task assignment, in a single location. Previously, findings tied to a specific control lived in separate workflows, making it harder for control owners and reviewers to see the complete picture.

The redesigned control page UI now includes a dedicated section where findings appear directly under each control. Your team can create a finding, assign remediation tasks, and track progress without navigating away from the control. The updated interface also improves readability, making it easier for control owners to scan their controls, see open findings, and understand what needs attention.

Warum ist das wichtig?

Centralizing findings on the control page connects evidence, test results, issues, and remediation tasks in one view. Control owners no longer need to cross-reference multiple screens to understand the status of a control. Everything that matters for a given control is visible in one place.

For audit preparation, this structure is particularly valuable. When an auditor asks about a specific control, your team can pull up the control page and show the full history: test scores, findings, remediation tasks, and resolution status. That level of traceability on a single page accelerates evidence gathering and strengthens audit readiness.

Bildschirmfoto

Sprinto’s December 2025 Updates: Automate Error Resolution, Structure Risk Programs, and Strengthen Policy Governance

With these updates, your team can resolve integration errors across dozens of connected tools through guided, AI-assisted flows without leaving the platform, segment risk programs across departments and frameworks inside a single Zone with fully independent registers, route policy approvals through enforceable multi-step chains with built-in rejection handling and complete audit documentation, turn security questionnaire turnaround into a focused review of AI-generated responses, and define organization-specific control scoring with trend visibility and findings tracked at the control level.

These updates give GRC teams tighter control over the operational workflows that sit between integration health, risk segmentation, policy accountability, and audit-ready evidence collection.

Srikar Sai
Autorin

Srikar Sai

Srikar Sai, Senior Content Marketer bei Sprinto, ist überzeugt, dass guter Content standardmäßig zum Speichern einladen sollte. Er schreibt über Cybersicherheit und GRC und hat sich zum Ziel gesetzt, mit jedem Beitrag etwas zu bewegen. Zudem ist er zertifizierter Lead Auditor nach ISO 27001.
Haben Sie genug von inhaltsleeren GRC- und Cybersicherheitsthemen? Abonnieren Sie unseren Newsletter und erhalten Sie detaillierte Informationen.
Recherchen und Erkenntnisse, die Ihnen helfen sollen, sich einen Platz am Tisch zu sichern.
Einzel-Blog-Fußzeilenbild