AI-suggested control mappings that show no rationale force teams to manually cross-reference policy sections, requirement references, and framework criteria before trusting a single suggestion. Vendor due diligence workflows restart from scratch with every new assessment because there is no reusable template for document and VSQ requests, and tracking which vendors have actually responded means toggling between screens. Framework readiness data sits in flat lists that make comparing progress across SOC 2, ISO 27001, and HIPAA difficult at a glance, while JAMF-managed devices lack automated screenlock verification for endpoint compliance. Help documentation and synced compliance policies require context-switching out of the app to query, integration setup offers no guidance on whether a tool serves one purpose or many, and external stakeholders have no way to subscribe to Trust Centre updates without manual notification.
Sprinto’s latest updates are designed to solve exactly that. You can now:
- Validate AI-suggested policy-to-control mappings with full rationale, broader coverage, and no suggestion limits
- View and manage framework readiness in a new Grid View on the Frameworks Page
- Create default vendor document request templates and track all requests from the new Requests tab in Vendor Documents
- Let external stakeholders subscribe to Trust Centre updates with automatic email notifications
- Search help documentation and synced Knowledge Hub policies with the new Ask AI assistant
- Run automated screenlock checks on JAMF-managed devices under Staff Devices
- Reconnect Azure DevOps integrations through Entra ID for uninterrupted evidence syncing
- Set up integrations faster with a guided post-connection flow that classifies single-purpose and multi-purpose tools
Read about these updates in detail below:
1. Validate AI-suggested control mappings with full rationale and broader policy coverage
You can now review every AI-suggested policy-to-control mapping in Sprinto with a clear rationale that shows which policy section, requirement reference, and linked framework criteria informed the suggestion. This solves a longstanding friction point: teams had to accept or reject AI mapping suggestions without understanding the reasoning behind them, which slowed down validation and eroded trust in automated compliance workflows.
Policy–Control AI Mapping now delivers broader coverage across large policies with no suggestion limits. Previously, mapping outputs could be constrained when policies exceeded a certain length. With this update, Sprinto processes the full policy document and surfaces every relevant control match. Each mapping result displays the specific policy section it drew from, the requirement it references, and the framework criteria it links to. This means your team can trace the logic from policy language to control selection to framework alignment in a single view.
| Why is this important? The rationale display turns AI mapping from a black-box suggestion into a verifiable, auditable recommendation. Your compliance team can review, accept, or challenge a mapping based on the exact policy language and framework criteria that generated it, cutting the time spent on manual cross-referencing. |
For organizations maintaining large policy libraries across multiple frameworks, removing suggestion limits means the AI captures mappings your team might otherwise miss. A 40-page information security policy mapped against SOC 2 and ISO 27001 criteria now returns a complete set of control suggestions with full traceability, not a truncated list that leaves gaps.

2. Track framework readiness across programs in a visual Grid View
You can now switch the Frameworks Page to a Grid View that displays every active framework as a visual card, showing readiness status and progress in a format designed for quick scanning. This addresses the challenge of monitoring compliance posture across SOC 2, ISO 27001, HIPAA, and other frameworks when all of them are stacked in a single flat list.
The Frameworks Page now offers two display modes: Grid View and List View. Grid View presents each framework as an individual card with its readiness indicators visible at a glance, letting you compare progress side by side. You can toggle between views at any time without losing context. The underlying data, controls, evidence, and audit status remain identical in both views. Grid View simply reorganizes how that data surfaces when you land on the Frameworks Page.
| Why is this important? Compliance leads managing three, four, or more frameworks simultaneously need a way to spot lagging programs quickly. Grid View surfaces readiness gaps across all active frameworks in a single scan, reducing the clicks and scrolling required to assess your compliance posture. |
For teams preparing for overlapping audit cycles, the visual layout makes it easier to prioritize which framework needs attention first. If your ISO 27001 readiness is at 85% and your SOC 2 readiness is at 60%, Grid View shows that contrast immediately, helping you allocate resources where they are needed most.

3. Standardize and track vendor document requests from a single workflow
You can now create a default vendor document request template in Sprinto and track every request you send from a centralized Requests tab, solving two related problems: the repetitive manual assembly of due diligence requests for each new vendor, and the lack of visibility into which vendors have responded.
To set up a default template, navigate to Configuration → Vendor Document Request. Here you define your preferred document list and Vendor Security Questionnaire (VSQ) selections once. You can customize the email content and notification settings, choose which team members in your organization should be notified, and decide whether to display the document list directly in the vendor-facing email. Once configured, the template applies to all future vendor assessments and can be modified and sent in one click.
Tracking happens in the new Requests tab inside Vendor Documents. This tab shows a full list of document requests sent to vendors, the specific documents and VSQs included in each request, and the response status. From this view, you can add more vendor contacts to an existing request or recall a request entirely. Every action, from initial send to vendor response, is visible in one place.
| Why is this important? Reusable templates eliminate the setup overhead that comes with every new vendor assessment. Your compliance team defines the document and VSQ requirements once, and every subsequent request follows the same standard, ensuring consistency across all vendor evaluations. |
The Requests tab gives your team end-to-end visibility into vendor submissions and follow-ups. If a vendor has not responded to a document request after two weeks, you can see that status immediately, add a new contact at the vendor’s organization, or recall and resend the request. This tightens the feedback loop on vendor due diligence and reduces the risk of assessments stalling due to lost or untracked requests.


4. Keep external stakeholders informed with Trust Centre subscriptions
You can now let customers, auditors, partners, and other external stakeholders subscribe to your Trust Centre updates directly, without requiring a login. This removes the manual effort of notifying external parties every time your compliance posture changes or a new update is published.
When a visitor lands on your Trust Centre, they can enter their email address to subscribe. From that point forward, Sprinto automatically sends them a notification whenever you publish a new update. No manual email drafts, no distribution list maintenance. On the admin side, you can view the full subscriber list in the admin panel, giving your team visibility into who is receiving your Trust Centre communications.
| Why is this important? Transparency with external stakeholders is a core part of trust operations. Automated subscriptions ensure that customers and partners stay informed about your compliance posture without requiring your team to manage outbound communications manually. |
For organizations going through active audit cycles or onboarding enterprise customers who require ongoing compliance visibility, subscriptions turn your Trust Centre into a living communication channel. A prospect evaluating your security posture receives updates as you publish them, reinforcing trust without adding work to your compliance team’s plate.

5. Get instant, doc-backed answers with Ask AI across Help Documents and Knowledge Hub
You can now use the Ask AI assistant inside Sprinto to search help documentation and get instant, doc-backed answers without leaving the app. Ask AI also extends to the Trust Knowledge Hub, where it searches your synced policies, procedures, controls, and Q&A entries to provide contextual responses about your compliance posture. Together, these two surfaces eliminate the need to context-switch between Sprinto and external documentation tools.
The Ask AI assistant in the main app covers practical use cases: learning how to connect a specific integration, troubleshooting a failed check, or understanding how a particular workflow operates. Every answer is grounded in Sprinto’s published help documentation, so the responses are accurate and verifiable. In the Trust Knowledge Hub, Ask AI draws from the documents and Q&A content you have synced into Sprinto. When a team member or an auditor asks a question about a specific policy or control, the assistant surfaces relevant passages from your own compliance documentation.
| Why is this important? Self-service access to accurate, in-context answers accelerates onboarding and daily operations. A new team member troubleshooting a failed integration check can resolve the issue directly in Sprinto, without filing a support ticket or searching an external knowledge base. |
The Knowledge Hub extension adds particular value during audit preparation. When an auditor asks about your access control procedures or your incident response workflow, your team can query Ask AI against your synced policies and get a precise, document-backed answer in seconds. This shortens the time between an auditor’s question and a verified response.


6. Verify screenlock compliance on JAMF-managed devices
You can now run automated screenlock checks on JAMF-managed devices under Staff Devices in Sprinto. This closes a gap in endpoint compliance coverage for organizations that rely on JAMF for device management but previously had no way to verify screenlock enforcement through Sprinto’s automated checks.
The screenlock check runs continuously against JAMF-managed devices in your Staff Devices inventory. Sprinto verifies that each device enforces screenlock and access control settings as required by your compliance frameworks. Any device that fails the check surfaces in your compliance dashboard alongside other device-level findings, giving your team a unified view of endpoint posture.
| Why is this important? Access control requirements in frameworks like SOC 2 and ISO 27001 include endpoint-level enforcement of screenlock policies. Automated checks on JAMF-managed devices ensure that this requirement is continuously verified, not checked once and forgotten. |
For organizations with a mixed device fleet managed across multiple MDM tools, adding JAMF screenlock support means fewer devices fall outside Sprinto’s automated compliance coverage. Every JAMF-managed laptop or workstation is now monitored for screenlock compliance alongside devices managed by other supported MDM integrations.

7. Maintain uninterrupted evidence syncing with the Azure DevOps Entra ID connection
You can now connect Azure DevOps to Sprinto through the Entra ID-based connection method, replacing the legacy authentication flow. This update aligns Sprinto’s Azure DevOps integration with Microsoft’s latest authentication standards and ensures that evidence syncing continues without interruption.
Users in the US, IN, and EU regions should reconnect their Azure DevOps accounts to Sprinto using the new Entra ID-based method. The reconnection process updates the underlying authentication mechanism while preserving your existing integration configuration. Once reconnected, evidence syncing, automated checks, and data pulls from Azure DevOps continue as expected under the updated connection.
| Why is this important? Legacy connection methods that fall out of alignment with a provider’s authentication standards create a risk of broken integrations and stalled evidence collection. Migrating to Entra ID keeps your Azure DevOps integration current with Microsoft’s requirements and prevents disruptions to your compliance automation. |
For teams that rely on Azure DevOps for code repository checks, change management evidence, or CI/CD pipeline monitoring, a broken integration can leave gaps in continuous compliance coverage. The Entra ID migration ensures those evidence streams remain active and reliable.

8. Simplify integration onboarding with a guided post-connection flow
You can now set up integrations in Sprinto through a guided post-connection flow that classifies each tool and walks you through configuration on the integration page itself. This replaces the previous setup experience where new integrations lacked clear guidance on their purpose, configuration steps, and connection status.
The guided flow introduces a clear classification between single-purpose and multi-purpose integrations. Single-purpose integrations serve one compliance function (for example, an MDM tool for device checks). Multi-purpose integrations serve several functions across different compliance areas (for example, a cloud provider used for infrastructure monitoring, access reviews, and configuration checks). After connecting an integration, Sprinto presents the appropriate setup steps based on its classification, with improved visibility into connection status throughout the process.
| Why is this important? Integration onboarding is one of the first steps in setting up Sprinto, and confusion during setup can delay time-to-value. The guided flow ensures that every new connection comes with clear context on what the integration does and how to configure it for your compliance program. |
For teams connecting 10, 15, or more integrations during initial setup, the classification system helps prioritize which integrations need detailed configuration (multi-purpose) and which can be connected and activated quickly (single-purpose). This reduces setup time and prevents misconfigurations that lead to incomplete evidence collection.

Sprinto’s October 2025 Updates: Impact at a Glance
With these updates, your team can turn every AI mapping suggestion into a verifiable, auditable decision backed by specific policy sections and requirement references, run vendor due diligence on reusable templates with request tracking that keeps assessments from stalling, scan framework readiness across all active programs visually to allocate resources based on actual progress gaps, and get instant document-backed answers to auditor questions and integration issues without leaving Sprinto.
These updates tighten the loop between vendor governance, framework visibility, and day-to-day compliance operations so your team spends less time chasing information and more time acting on it.
Author
Srikar Sai
As a Senior Content Marketer at Sprinto, Srikar Sai believes good content should be bookmark-worthy by default. He writes about cybersecurity and GRC, aiming to move the needle with every piece. He’s also an ISO 27001-certified Lead Auditor.Explore more
research & insights curated to help you earn a seat at the table.





















