Compliance

Compliance statuses

Purpose

Statuses are the answer options on a Compliance board. Every question answer at every site must use one of the statuses configured for that board.

Statuses do three important things:

  • They define the words users see when answering questions.
  • They determine how site compliance is calculated.
  • They can control who is allowed to set sensitive statuses.

Because statuses affect both daily work and reporting, they should be designed before large teams start updating answers.

Status examples

Statuses are flexible. A board can use compliance language, a simple yes/no model, a review workflow, or internal work-management terms.

Example setupPossible statuses
Simple checklistYes, No, Not applicable
Compliance reviewCompliant, Non-compliant, Not applicable, Not answered
Work managementTo do, In progress, Blocked, Done
Review workflowDraft, Awaiting review, Completed, Rejected

The best status names are the names your users already understand. Avoid creating too many statuses unless each one changes how people work or how results are reported.

Status fields

Each status has configuration that controls how it appears and behaves.

FieldWhat it controls
NameThe label users select when answering a question.
ColorThe color used in the matrix, site view, tables, and summaries.
Open, Closed, or IgnoreWhether answers with this status count as open work, closed work, or are excluded from compliance calculations.
DefaultWhether the status is used for new answer items when new questions or sites are added.
Include in default viewWhether answers with this status appear in the default work views.
Restricted messageThe message shown when a user tries to set a restricted status they are not allowed to use.

Open Closed Ignore

The most important part of a status is whether it is configured as Open, Closed, or Ignore.

BehaviorWhat it means
OpenThe answer is included in the total and counts as work that is not closed.
ClosedThe answer is included in the total and counts as closed work.
IgnoreThe answer is excluded from the total. Use this for statuses such as Not applicable.

This behavior is how 21RISK calculates how compliant a site is.

Compliance percentage = closed questions / (total questions - ignored questions)

Examples:

Site answersCalculationCompliance
10 total questions, 9 closed, 1 open, 0 ignored9 / (10 - 0)90%
15 total questions, 5 closed, 5 open, 5 ignored5 / (15 - 5)50%

Replacing a status on a board

A status that is used by answers on a board cannot simply be removed. Instead, open the menu on the status row in the board's status settings and choose Replace. Pick another status that is already on the board, and 21RISK replaces every reference to the status on that board:

  • Every answer on the board that uses the status, including its history, uses the status you picked instead. No new history entries are written.
  • Automations, saved views and status rules on the board that set or filter on the replaced status now set or filter on the status you picked.
  • The status rules move to the status you picked, next to any rules it already has.
  • The status you picked becomes the default if the replaced status was the default.
  • The replaced status is removed from the board and analytics are updated at the same time.

If the replaced status is the board's status for expired answers, the status you picked takes its place. See Keeping compliance answers verified.

Only this board is affected. The status itself is kept in the organization, so other boards that use it keep working. The status you pick must have the same Open, Closed, or Ignore behavior as the replaced status, so compliance on the board does not change; statuses with a different behavior are greyed out.

Status rules

Status rules control who can use a status. They are useful when a status represents an approval, verification, or authority that should not be available to everyone.

For example, a board can use these statuses:

StatusBehaviorWho should use it
Awaiting reviewOpenSite users who believe the requirement is complete but need approval.
CompletedClosedReviewers, managers, or organization owners who are allowed to close the answer.

With status rules, Awaiting review can remain public while Completed is restricted to a specific set of users.

Public and restricted statuses

Status access works like this:

  • If a status has no enabled rules, it is public and can be set by anyone who can update the answer.
  • If a status has one or more enabled rules, it is restricted.
  • For a restricted status, the user must match at least one enabled rule.
  • If the user does not match any enabled rule, 21RISK blocks the status change and shows the restricted message if one is configured.

Organization owners can be included in rules by using the Is organization owner condition.

Rule conditions

A status rule is built from filter groups and conditions.

Within one group, all conditions must match. Between groups, only one group needs to match. In practical terms, this means:

  • Conditions inside a group use AND logic.
  • Alternative scenarios use OR logic.

Available condition types include:

ConditionUse it for
User is a member ofAllow users in selected user groups to use the status.
NameMatch answer item names by text filters.
External IDMatch answer item external IDs by text filters.
Is organization ownerAllow or deny based on whether the user is an organization owner.

Example rule design:

RuleMeaning
User is a member of ReviewersAny member of the Reviewers group can use the status.
Is organization owner is trueOrganization owners can use the status.
User is a member of Fire Safety Reviewers AND Name contains FireFire Safety Reviewers can use the status only for matching answer items.

For most boards, start simple:

  1. Create a default Open status, such as Not answered or To do.
  2. Create one or more Open statuses for work in progress, such as In progress or Awaiting review.
  3. Create Closed statuses for accepted completion, such as Completed or Compliant.
  4. Create Ignore statuses for answers that should not affect compliance, such as Not applicable.
  5. Add rules only to statuses that require authority, such as Completed, Approved, or Accepted.
  6. Configure a restricted message that tells users what to do instead, such as "Only reviewers can set Completed. Please use Awaiting review."