Skip to main content

Activating a framework (and what happens next)

Activating a framework links its obligations to your control register and shows you exactly what will change before you commit. You open the framework, preview the activation, and confirm, and it runs instantly with no sync or data migration.

Written by Taylor Laing

Before you start: set up your groups

Activating a framework typically surfaces a large set of controls, and how they're scoped depends on your organisation's structure. Set up your groups first so the activation lands correctly. See "Creating and managing groups" in Account and Administration, and Configuring frameworks per group or location.

Step 1: Open an available framework and choose scope

From the Frameworks page, click the Available tab, then click a framework row to open its detail drawer. The drawer shows a progress indicator for how many controls are already complete through your existing evidence, the Framework Type, Category, Location, description, and key features.

Before you can preview, choose an enrolment scope: the group or location you're enrolling the framework at, picked from your org/group tree. See Configuring frameworks per group or location.

Step 2: Preview the activation (dry run)

Click Preview Activation. This is a dry run; nothing is created yet. The preview tells you exactly what activation will do, in two columns:

  • Added: broken out as Controls, Documents, and Policies that will be newly created in your tenant

  • Retained: Controls you already have, shared from other frameworks, that will continue to satisfy the new framework's obligations

The point of the preview is that there are no surprises: you see what's new versus what's reused before committing.

Step 3: Confirm activation

Click Confirm Activate. The framework moves to Active and the activation runs immediately:

  • The Added controls, documents, and policies are created in your tenant and mapped to the new framework's obligations.

  • Retained controls, already in place from other frameworks, continue to satisfy the relevant obligations, reflecting the "controls are shared" model.

Activation does not auto-create risk assessments: Activating a framework does not create risk assessments in your Risk Register. Risk scenarios are adopted separately from the Scenario Library (or created custom). See "Adopting risks from the scenario library" in Risk Intelligence.

After activation

Open the framework's detail page (the Overview, Controls, and Roles tabs) to see:

  • Progress: percentage complete, with a Complete / Incomplete / Due Soon legend

  • Status: Active

  • Activated: the date you activated it

  • Target Compliance: click Set Target Date to choose your goal date for full compliance

  • Last Certified: an optional manual marker for when the framework was last formally certified

  • Obligations: the controls, policies, and documents this framework requires

From here your job is to work the Incomplete items down: assign control owners, add evidence, and adopt relevant risk scenarios from the Scenario Library. See "Adding evidence to a control" and "Assigning control owners and managing renewals" in Safety Orchestration.

Did this answer your question?