Repetitive compliance tasks like drafting policy refinements, mapping criteria to controls, and answering security questionnaires still consume hours of manual work across most teams. Staff records drift out of sync between identity providers and compliance platforms, forcing admins to reconcile names, emails, and departments by hand. Maturity-focused frameworks like NIST CSF, CMMC, and COBIT require graded scoring, but most compliance tools only support binary pass/fail outcomes. Policy and control deviations get tracked in spreadsheets or email threads with no structured approval trail. And compliance notifications still miss the teams that live in Microsoft Teams, creating blind spots in task completion.
Las últimas actualizaciones de Sprinto están diseñadas para solucionar precisamente eso. Ahora puedes:
- Build and run no-code AI Actions across policies, risks, vendors, and audits using the AI Playground and Ask AI assistant
- Complete security questionnaires faster with AI-powered answers and a redesigned onboarding flow
- Score audit assessments with configurable maturity levels for frameworks like NIST CSF, CMMC, and COBIT
- Create and manage staff Entity Groups directly in Sprinto with manual and dynamic membership
- Receive task notifications in Microsoft Teams alongside Slack and Email
- Continuously sync the People section with your IDP and HRMS through custom field mapping and source priority settings
- Map up to 200 compliance criteria to controls in under 2 minutes with AI-powered bulk mapping
- Raise, track, and resolve policy and control exceptions through a structured, auditable workflow
Lea a continuación información detallada sobre estas actualizaciones:
1. Bring no-code AI automation into compliance workflows with AI Playground and Ask AI
You can now build reusable AI Actions and run natural-language queries directly inside Sprinto, eliminating the need for engineering involvement in automating compliance workflows across policies, risks, vendors, and audits.
The AI Playground introduces an Action Builder where you describe a task in plain language, and Sprinto creates a reusable AI Action you can apply across your compliance program. These Actions work across 15+ entity types, covering policies, risks, vendors, audits, and more. A Starter Library provides 15+ ready-to-use AI Actions for common tasks like policy refinements and vulnerability fixes, giving your team a practical starting point. The in-app assistant, Ask AI, lets you run these Actions or ask natural-language questions directly in context, right where you are working in Sprinto. Admin Control settings let your team centrally manage, edit, or disable any AI Action to maintain governance over automated workflows.
| ¿Por qué es importante? The AI Playground and Ask AI give your compliance team the ability to automate repetitive processes like policy drafts, risk descriptions, and vendor assessments without writing code or waiting on engineering resources. Actions are reusable, centrally governed, and available in context across 15+ entity types. |
Consider a team preparing for a SOC 2 audit that needs to refine 30 policy documents and generate risk descriptions for a new register. With the Starter Library and Action Builder, that team can run AI Actions directly on each policy and risk entity, completing in minutes what would previously take hours of manual drafting and review.

2. Complete your first security questionnaire faster with AI-powered onboarding
You can now move through security questionnaire onboarding with less friction, using a redesigned flow that combines document uploads, pre-built templates, and AI-generated answers to help you reach completion faster.
The updated onboarding flow lets you upload your own documents or start with Sprinto’s pre-built templates as your knowledge base. Once your source material is in place, Sprinto generates context-aware, accurate responses to questionnaire fields in real time. The flow is designed to be seamless: you can resume where you left off at any point and export completed answers instantly when ready.
| ¿Por qué es importante? Security questionnaires are often the first compliance activity a new team encounters in Sprinto, and a slow or manual start creates friction that delays the broader program. The redesigned flow and AI-powered answers reduce the time it takes to go from setup to a completed, exportable questionnaire. |
For teams fielding multiple customer security questionnaires per month, this means each new questionnaire can draw from your uploaded documents and templates, generating relevant answers without starting from scratch. The ability to resume and export instantly keeps the process moving even when it spans multiple sessions.

3. Score audit assessments with configurable maturity levels for graded frameworks
You can now run graded audit evaluations directly in Sprinto for frameworks like NIST CSF, CMMC, and COBIT, moving beyond binary pass/fail outcomes to capture maturity and posture progression over time.
Sprinto supports configurable scoring where your team defines custom maturity levels or rating scales that match the framework’s requirements. Auditors can score assessments directly within the platform, eliminating the need for external spreadsheets or offline scoring workflows. Assessment data can be exported instantly as CSVs for deeper analysis, reporting, or sharing with stakeholders outside of Sprinto.
| ¿Por qué es importante? Frameworks like NIST CSF, CMMC, and COBIT are designed around maturity models where a simple pass/fail verdict does not capture the nuance of your compliance posture. Configurable scoring and in-platform assessment let your team and auditors work from the same data, with results that reflect actual maturity progression. |
For an organization pursuing CMMC Level 2 certification, this means auditors can assign maturity scores to each practice area directly in Sprinto, and your team can export the scored assessment as a CSV for executive reporting or remediation planning, all without toggling between tools.
4. Create and manage Entity Groups directly in Sprinto for scoping, policy assignment, and training
You can now create staff Entity Groups locally inside Sprinto without importing them from an external directory, giving your team full control over how groups are built, maintained, and used across compliance workflows.
Sprinto supports two types of Entity Groups: manual groups, where you select specific staff members, and dynamic groups, where membership is determined by staff attributes and updates automatically as those attributes change. Once created, Entity Groups can be used for scoping controls and monitors to specific teams, assigning policies to relevant groups, and targeting training programs. Dynamic groups stay current without manual updates, so membership reflects your actual team composition at all times.
| ¿Por qué es importante? Compliance programs that span multiple departments, locations, or roles need a way to assign policies, training, and controls to the right people. Creating Entity Groups locally removes the dependency on external directory imports and lets your team define groups based on the attributes and structures that matter to your compliance program. |
For a 500-person organization with separate engineering, finance, and operations teams, dynamic Entity Groups mean that when a new engineer joins and their attributes are set in Sprinto, they are automatically included in the correct group for engineering-specific policies, training modules, and control scoping, with no manual list updates required.

5. Receive compliance task notifications in Microsoft Teams
You can now receive Sprinto task notifications directly in Microsoft Teams, ensuring that staff and admins who work primarily in Teams stay informed on pending tasks and compliance actions without switching to another tool.
Sprinto delivers both staff and admin task notifications to Microsoft Teams channels in real time, alongside the existing Slack and Email notification options. Your team can see pending tasks and compliance actions as they arise, keeping completion timelines tight. Future releases will expand Teams notifications to include policy acknowledgements and employee task alerts.
| ¿Por qué es importante? Compliance task completion depends on notifications reaching people where they actually work. For organizations that use Microsoft Teams as their primary collaboration platform, adding Teams as a notification channel closes a visibility gap that previously required staff to check Sprinto or rely on email. |
A compliance admin managing a team of 200 people across multiple departments can now send task notifications, like completing security awareness training or reviewing access permissions, directly into the Teams channels those departments already monitor, reducing the lag between task assignment and completion.

6. Keep the People section accurate with continuous sync and custom field mapping
You can now continuously sync staff data from your IDP and HRMS systems into Sprinto’s People section, with the ability to set source priority and map custom fields, ensuring that names, emails, departments, and additional attributes stay consistent without manual reconciliation.
Sprinto supports continuous sync with Google Workspace, O365, Okta, OneLogin, and Zoho. You can designate a primary source of truth and pull deltas from secondary sources, so your People section always reflects the most authoritative data. Custom field mapping lets you map provider-specific fields to Sprinto fields. For example, you can map a “Role” field in your IDP to the “Department” field in Sprinto. This keeps your compliance records aligned with how your organization structures its people data.
| ¿Por qué es importante? Stale or inconsistent staff data in your compliance platform leads to incorrect policy assignments, inaccurate scoping, and audit findings tied to outdated records. Continuous sync and source priority settings ensure that Sprinto’s People section reflects reality without requiring manual edits after every organizational change. |
For a company using Okta as its primary IDP and Zoho as its HRMS, the source priority setting lets Sprinto pull identity data from Okta and supplementary HR fields from Zoho, with custom field mapping ensuring that each provider’s field names align correctly to Sprinto’s data model. Every new hire, departure, or role change flows through automatically.

7. Map up to 200 compliance criteria to controls in minutes with AI-powered bulk mapping
You can now map up to 200 compliance criteria to controls in under 2 minutes using Sprinto’s AI-powered bulk mapping, replacing the hours of manual work typically required to build and verify criteria-to-control relationships.
When you initiate bulk mapping, Sprinto auto-generates control mappings based on your existing criteria and control library. You review the suggested mappings and finalize them, giving your team full control over accuracy while eliminating the repetitive work of mapping one criterion at a time. The result is a complete, verified criteria-to-control mapping that is ready for audit review.
| ¿Por qué es importante? Criteria-to-control mapping is one of the most time-intensive steps in audit preparation, especially for frameworks with large control sets. AI-powered bulk mapping compresses this work from hours to minutes while preserving your team’s ability to review and approve every mapping before it is finalized. |
For a team preparing for a SOC 2 Type II audit with 150+ trust service criteria, bulk mapping means the initial mapping layer is generated automatically. Your compliance lead reviews and adjusts the suggestions, and the entire mapping is finalized in a single session, freeing up time for evidence collection and remediation.

8. Raise and manage policy and control exceptions through a structured, auditable workflow
You can now raise, review, and resolve exceptions to policies and controls directly in Sprinto, replacing unstructured email threads and spreadsheets with a traceable workflow that connects each exception to its associated policies, risks, and mitigating controls.
When a staff member needs to deviate from a policy or control, they raise an exception request in Sprinto. Admins can then link the request to the relevant policies, map associated risks, and define mitigating controls that address the deviation. Both the requestor and the admin can track the status of every exception through real-time dashboards, providing full visibility into open, approved, and resolved exceptions at any point.
| ¿Por qué es importante? Every compliance program encounters situations where a policy or control cannot be followed exactly as defined. Without a structured process, these deviations become invisible to auditors and create compliance risk. Sprinto’s Exception Management workflow ensures that every deviation is documented, linked to its policy and risk context, and resolved with defined mitigating controls. |
For a team that needs to grant temporary elevated access to a production environment outside of normal access control policy, the exception request captures the reason, the admin maps it to the access control policy and the associated risk, defines the mitigating control (such as a short-lived access window with enhanced logging), and both parties track the resolution through the dashboard. The full trail is available during audit.

Sprinto’s August-September 2025 Updates: Automate More, Map Faster, and Manage Compliance at Scale
With these updates, your team can automate repetitive compliance work across 15+ entity types from a single no-code AI interface, capture maturity progression for scoring-based frameworks with auditor-ready exports, map up to 200 compliance criteria to controls in under two minutes with AI-generated suggestions, keep staff records accurate through continuous sync with source priority across multiple identity and HR providers, and give policy and control exceptions a governed approval trail with full audit visibility.
These updates reduce the manual overhead sitting between your team and audit-ready compliance, whether you are scaling across new frameworks, onboarding auditors, or keeping staff data and policy assignments accurate across a growing organization.
Autor
Srikar Sai
Como especialista sénior en marketing de contenidos en Sprinto, Srikar Sai cree que el buen contenido debería ser digno de guardar en favoritos por defecto. Escribe sobre ciberseguridad y GRC, con el objetivo de generar un impacto positivo con cada artículo. Además, es auditor líder certificado según la norma ISO 27001.Explora más
Investigaciones y análisis seleccionados para ayudarte a ganarte un lugar en la mesa.





















