Skip to main content

Catalog - Analyzing document compliance from vendor details

Note

This option pertains to the Hyperproof TPRM product line.

Document compliance only supports the SOC 2 compliance analysis using predefined clauses to evaluate the document. Document compliance is analyzed when a document is uploaded to Vendor Details for a specific vendor and assigned SOC 2 as the document type during the upload process. Documents must be in PDF format to be analyzed.

Accessing document compliance analysis

When you upload a document in the Vendor Details window, it is automatically analyzed if you select SOC 2 as the document type. See Catalog - Manage vendor documents.

To see the results of the analysis:

  1. From the menu, select Vendors.

  2. Select Catalog.

    The Catalog window displays.

  3. Use the Search field at the top of the window to find the vendor you want.

    The list of matching vendors displays.

  4. Click the vendor tile.

    The Vendor window displays.

  5. From the left menu, select Vendor Documents.

  6. Use the Search option to locate the document and click the Shield icon.

    The Document Compliance Analysis window displays.

The Document Compliance Analysis window displays two panes:

  • Left pane:

    • Displays the uploaded PDF document.

    • Allows you to click highlighted sections to view details or navigate through the document.

    • Selecting a highlighted section in the PDF scrolls to the related issue in the right pane.

  • Right pane:

    • Lists the potential risks and compliance issues identified by the analysis.

    • Provides a brief explanation for each compliance concern.

    • Provides a severity level indicating the importance and urgency of the issue.

    • Indicates the section in the PDF where the problem occurs.

    • Clicking on a potential risk in the right pane highlights the corresponding text in the PDF.

Best practices for document compliance analysis:

  • Convert documents to PDF before uploading. Only PDF files are supported.

  • Carefully review analysis results to understand their implications.

  • Keep compliance types and clauses up to date to reflect the latest regulatory standards.