Product workflows
Learn the core user workflows for compliance, risk, audits, and vendor management in Stackflo.
Product workflows
Stackflo is organized around the most common compliance and risk workflows: setup, policy and control management, evidence collection, audits, and vendor collaboration.
1. Get your program started
- Complete your organization profile and team settings.
- Configure your business scope and compliance objectives.
- Connect tools and integrations that help collect evidence automatically.
- Assign responsibilities for policies, controls, and audit tasks.
2. Build a compliance program
Subscribe to frameworks
Choose the standards that apply to your business, such as:
- ISO 27001
- SOC 2
- HIPAA
- GDPR
Stackflo maps controls to these frameworks so you can track compliance across multiple standards.
Manage policies
Create governance policies, route them for review, and publish them to your team. Policies are linked to controls and evidence, so you can show how rules are enforced. Keep policy templates as the baseline in this flow; do not remove them from the compliance process.
Map controls
Define the controls your organization uses, assign owners, and connect them to the right framework requirements. This creates a single source of truth for control implementation.
3. Collect evidence and confirm readiness
Evidence collection
Upload documents, link evidence to controls, and track completion across your program.
Audit readiness
Use readiness dashboards and mock audit checks to identify gaps before an external review. Track progress with clear status counts and completion metrics.
4. Manage risk continuously
Risk register
Record risks, assign owners, and maintain mitigation plans.
Mitigation tracking
Monitor risk treatment actions and keep stakeholders informed as risks improve.
5. Coordinate audits
Active audits
Track ongoing audits, review audit timelines, and manage findings in one place.
Audit collaboration
Share evidence, communicate with auditors, and keep all audit documentation organized.
6. Work with vendors
Vendor inventory
Maintain a list of third-party providers and understand their risk impact.
Vendor assessments
Invite vendors to complete questionnaires, submit evidence, and respond to requests.
Vendor compliance
See vendor status, review uploaded documents, and manage remediation workflows.
7. Share trust internally and externally
Use reports and the trust center to communicate your compliance posture clearly.
- Keep stakeholders aligned with policy and audit progress.
- Show external partners that your controls are monitored and evidence is available.
