iGRC Overview
What is iGRC
The four registers
Tests define how a control is checked, whether manually or automatically, and the scope of the check. Each time a test runs, it creates a test log where the evidence is validated, and the result is recorded. See managing and configuring the Tests register and using the Tests register.
Tasks contain work assigned to a person, including what needs to be done, who is responsible and how often it repeats. iGRC brings all tasks together in one register, regardless of where they were created, so they are not scattered across different modules. See managing and configuring the Tasks register and using the Tasks register.
Files provides one searchable location for every attachment and piece of evidence in your Spoke, with built-in version history and validity tracking. A file becomes evidence when it is linked to a test that has a validation guide. Until then, it remains a record that you can link to other items. See managing and configuring the Files register.
How the registers connect
Controls, tests, tasks and files link to each other directly, in any direction. A file can attach straight to a control with no test involved, and the same piece of evidence can satisfy several controls or frameworks at once. For the full walk-through of who does what and when, see the evidence submission and validation workflow.
Hailey across iGRC
Hailey supports three key activities in iGRC.
Hailey-assisted mappings. Hailey reviews a record’s data and suggests relevant links to other records, such as a control to a test or a piece of evidence to a control, shown as confidence-rated suggestions you accept or reject. Nothing links automatically, and suggestions only appear to users who can edit the register the record belongs to. See Hailey-assisted mappings in Registers.
Semantic search. When you’re working on a risk, Hailey suggests related controls and provisions automatically, and lets you search in plain language instead of guessing keywords, with a confidence level and an explanation for each match. See finding controls and provisions related to a risk.
Working with your data
Once your registers contain data, four capabilities help you make the most of it.
Filtering and search. Build simple or advanced queries on any register, including conditions based on what a record is linked to, such as showing controls where a test failed in the last seven days, and save the views you use often. See filtering and searching using linked data.
Insights. The Controls register has an Insights tab that turns your existing controls, tests and evidence into one view of how your control environment is performing: test coverage, pass rate, framework coverage, and which controls need attention. Every control also has its own Insights tab. See Control register insights.
Hailey import. Bring existing content into a register by uploading a policy document; Hailey reads it and creates the register items for you, the same way “Import control set” already works for the Controls module. See Registers overview.
Requirement-based assessments. Run a requirement-based assessment (RBA) directly against one or more items in a custom register, with the results linked straight back to those items. See creating a requirement-based assessment from a custom register.
Extending iGRC
Permissions
What’s coming
iGRC continues to add new capabilities. The upcoming items below do not prevent you from using iGRC for day-to-day work. The legacy Controls module will remain available while these capabilities are added to iGRC.
Closing the gap with the legacy modules:
- Framework cross-walking in the Controls register, to map controls against a framework and see what’s covered, partly covered, or not covered.
- Control distribution between hub and spoke, to publish a set of controls from a spoke for other business units to use.
- Risk Treatment Plan links to the Controls register, so a Risk Treatment Plan can show every control that treats a risk, wherever it’s tracked.
Beyond parity:
- Notifications with compensating controls, so a control owner is alerted only for genuinely new failures, not issues already acknowledged, suppressed, or covered by a documented compensating control.
- Policy management as its own register, with clause-level linking to controls, generated policy documents, and attestation tracked through Tasks.
- An API for automated mapping of tests to controls, extending Hailey’s mapping recommendations to programmatic use.
For a release schedule, check with your Customer Success contact.
Related articles
- Managing and configuring the Controls register
- Using the Controls register
- Managing and configuring the Tests register
- Using the Tests register
- Managing and configuring the Tasks register
- Using the Tasks register
- Managing and configuring the Files register
- Evidence submission and validation workflow
- Hailey evidence validation
- Hailey-assisted mappings in Registers
- Finding controls and provisions related to a risk
- Filtering and searching using linked data
- Control register insights
- Registers overview
- Creating a requirement-based assessment from a custom register
- Integration recipe building
- Granting a role access to iGRC