Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # Risk & Document Management - SoftComply: SoftComply offers powerful risk and document management solutions on Atlassian Jira and Confluence, built for AI, Cybersecurity and safety purposes. ## Sitemaps [XML Sitemap](https://softcomply.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [How SoftComply and Xray Enable Risk-Based Testing in Jira Cloud](https://softcomply.com/risk-based-testing/): With this integrated solution, you can manage your risk-based testing strategy directly in Jira Cloud, combining structured risk control with powerful test management in one place. - [Frictionless Information Security Management in Jira](https://softcomply.com/information-security-management-jira/): What if your next ISO 27001 audit required almost no preparation? - [Best E-Signature Apps for Confluence Cloud (2026 Buyer’s Guide for Regulated Industries)](https://softcomply.com/esignature-apps-confluence/): Not every Confluence e-signature app is designed for regulated industries. This guide explains how to evaluate Atlassian Marketplace apps against 21 CFR Part 11 and choose the right solution for MedTech, pharma, and biotech teams. - [Road to ISO 27001: SoftComply’s Journey](https://softcomply.com/road-to-iso-27001/): Anyone who's ever looked at ISO 27001 knows the feeling. - [Navigating Enterprise Trust in Atlassian Cloud](https://softcomply.com/enterprise-trust-atlassian/): At Atlassian Team26, the Compliance Alliance hosted the 5th Compliance Workshop on May 7th that focused on one of the biggest questions facing regulated industries today: - [Preparing Organizations for Uncertainty and Crisis: Risk Management Lessons from Sailing](https://softcomply.com/risk-management-lessons/): On March 19th, SoftComply was invited to join Not Another Webinar and present our Risk Management solution - ideally in a way that didn’t sound like, well… another webinar. So naturally, I ended up talking about sailing. - [From Missing Buses to Cyber Threats: Why SoftComply Risk Manager Plus Makes Risk Management a Breeze!](https://softcomply.com/cyber-threats-softcomply-risk-management-jira/): Risk is everywhere - even in everyday life. While missing a bus is a personal risk, organizations face more significant risks every day, from data breaches to compliance infractions. That's where SoftComply's Risk Manager Plus comes in, transforming potential chaos into manageable steps, just like planning your commute ahead of time. - [How to Implement NIST CSF 2.0 Cybersecurity Risk Management in Jira](https://softcomply.com/nist-csf-2-0-cybersecurity-risk-management-jira/): Hey there, brave souls navigating the wild seas of cybersecurity! 🌊 - [How to Build a Living GRC System in Jira and Confluence](https://softcomply.com/grc-jira-confluence/): Welcome to the wondrous world of GRC! Don't worry, you're not alone if GRC sounds like a magic spell from "Harry Potter." For most of us, Governance, Risk, and Compliance (GRC) is one of those terms that sounds important in meetings, like when someone mentions "synergy." But the truth is, GRC means different things in different industries. - [Why Your Risk Register Fails and the Jira Fix for It](https://softcomply.com/why-risk-register-fails-raid-jira/): If your risk register lives in a spreadsheet, chances are it’s already failing you - even if it looks fine. - [Achieving CE Mark Faster: Amiko’s Story of Agile Compliance with a Confluence-Based Document Management System](https://softcomply.com/agile-compliance-confluence-document-management-system/): We recently sat down with Elisa Lo Blanco, Quality Assurance and Regulatory Affairs Manager at Amiko, a digital health company focused on chronic respiratory conditions, to discuss their journey to achieving CE marking under the Medical Device Regulation (MDR). - [7 Key Tips for AI Tool Developers in Regulated Industries](https://softcomply.com/ai-tool-developers-regulated-industries-tips/): If you’re an Atlassian Marketplace app vendor or you’re exploring how to bring AI capabilities like Rovo into your products and services, this article is for you. - [Stop Juggling Spreadsheets! Build Your ISO 27001 or SOC 2 ISMS Right Inside Jira and Confluence](https://softcomply.com/build-isms-in-jira-and-confluence/): Today, every company faces a constant stream of threats, from ransomware and phishing to third-party vulnerabilities. In response, an increasing number of companies are standardizing their InfoSec efforts by following frameworks like ISO 27001 or SOC 2. These standards demand a core focus on continuous risk management, which includes identifying assets, assessing threats and vulnerabilities, and implementing controls. - [Why Medical Device Startups Need Electronic Document Management Systems (And How to Build One in Confluence)](https://softcomply.com/electronic-document-management-systems-confluence-cloud/): If you’re developing a medical device, you must prove that it is safe and effective. That proof lives in your documents: your procedures, design records, risk assessments, and test reports. Managing those documents properly is called “document control". - [Why Document Control Can Make or Break Your Regulated Business (and how SoftComply can help)](https://softcomply.com/document-control-confluence/): Watch my video breakdown of document control challenges and solutions:  - [Inside the 4th Compliance Alliance Workshop: Building Trust and Compliance on Atlassian Cloud](https://softcomply.com/compliance-alliance-atlassian-cloud-workshop-team25-europe/): During Atlassian Team25 Europe, the Compliance Alliance hosted the 4th Compliance Workshop in Barcelona. - [How to Run Vendor Security Risk Assessments in Jira: A 5-Step Process](https://softcomply.com/vendor-security-risk-assessment-jira/): Every company depends on others to survive. From your cloud provider to your payroll processor, your business is connected to a web of vendors. But here's the reality: over 60% of data breaches originate from third-party vendors. This is why managing your vendor security risks has become more important than ever. Although you can outsource various services, you can't outsource the risk. - [How to Manage Organizational Risks with ISO 31000 in Jira](https://softcomply.com/organizational-risks-iso-31000-jira/): That's where ISO 31000 comes in. It's not just another framework for large enterprises, even though many small companies think it is. Instead, it's a practical approach that can help any organization systematically manage risks and opportunities to achieve their business goals. - [How to Set Up RAID Project Management in Jira: A Complete Guide](https://softcomply.com/raid-project-management-jira/): Project managers know that uncertainty is the enemy of successful delivery. You've got potential risks lurking around every corner, assumptions that might prove wrong, current issues demanding attention and dependencies that could slip at any moment. - [5 Steps to Implement ISO 27001 ISMS in Jira](https://softcomply.com/27001-isms-jira/): That's where ISO 27001 comes in. It's the world's leading standard for information security management systems (ISMS) and it has become a business requirement in industries like MedTech, pharma, finance and SaaS. - [How to Implement Governance, Risk and Compliance (GRC) Framework in Jira](https://softcomply.com/governance-risk-compliance-grc-jira/): GRC (Governance, Risk and Compliance) isn't just corporate bureaucracy - it's your company's shield against costly surprises. Too many organizations scramble during audits, struggle with scattered risk registers, and face regulatory nightmares that could be avoided. - [How to Automate Confluence Cloud Validation for Medical Device Companies](https://softcomply.com/validation-confluence/): Medical device companies face a constant challenge: how do you validate cloud software tools that update daily? If you're using Confluence Cloud for your quality management system, you need validation documentation that keeps pace with Atlassian's frequent updates. - [How to Create Risk Reports in Jira and Confluence](https://softcomply.com/risk-reports-jira-confluence/): Watch this video to see exactly how to build risk reports in Jira dashboards and Confluence pages using the SoftComply Risk Manager apps. - [How to Implement P1 and P2 Hazard Analysis in Jira for Medical Devices](https://softcomply.com/p1-p2-hazard-analysis/): Ready to try P1 and P2 hazard analysis? 👉 Try SoftComply Risk Manager Plus free for a month - [Medical Device FMEA: 10 Steps to Bulletproof Risk Management](https://softcomply.com/medical-device-fmea/): Watch this step-by-step guide to implementing FMEA for medical device risk management. - [Complete Guide to Medical Device Hazard Analysis based on ISO 14971 and IEC 62304](https://softcomply.com/medical-device-hazard-analysis/): Medical device risk management isn't just another regulatory checkbox. It's the foundation that proves your device is safe for patients and users. When auditors come knocking, they'll scrutinize your risk management process more than almost anything else. Get it wrong and you're looking at serious compliance issues. - [6 Steps to Agile Risk Management Success in Jira for Regulated Environments](https://softcomply.com/agile-risk-management-jira/): While doing this, you're creating live end-to-end traceability in Jira from risks to requirements to mitigation to tests. This approach aligns perfectly with agile risk management best practices, which emphasize continuous risk assessment throughout development. - [Why Atlassian Solution Partners Must Pivot to Business Users in 2025](https://softcomply.com/atlassian-solution-partners-pivot-business-users/): For years, Atlassian solution partners have built successful businesses around helping IT teams configure Jira and Confluence, manage licenses, and handle technical implementations. But that world is rapidly changing. - [Beyond Configuration: How Consultants Empower Regulated Industries](https://softcomply.com/lifescience-agile-consultants-atlassian/): For regulated industries - such as Pharma, MedTech, FinTech and Aviation - compliance isn't optional; it's mandatory. Tools like Jira and Confluence are powerful, but their true potential is only realized when configured to meet industry-specific regulatory requirements. - [10 Insider Tips from a Notified Body on MDR, AI Act, Audits & Software Tool Validation](https://softcomply.com/10-notified-body-tips-mdr-aiact-audits-validation/): Structure your documentation according to your notified body's preferences (BSI has one, follow it → here) - [How to do FMEA for Medical Devices: Step-by-Step Guide to Risk Management](https://softcomply.com/fmea-medical-devices-risk-management-guide/): One of the most widely used methodologies in medical device risk management is Failure Modes and Effects Analysis (FMEA). FMEA is a systematic approach used to identify potential failure modes within a product or process, evaluate their potential impact, and prioritize them based on factors such as severity, likelihood of occurrence, and detectability. - [Risk Management Software: Buyer’s Guide for 2025](https://softcomply.com/risk-management-software-buyers-guide/): How do organizations manage risks? Organizations manage their risks in a manual or automated manner. By the term "manual," you can imagine that this method involves using spreadsheets. One of its main advantages is that it is suitable for startups and small businesses. However, these manual methods are time-consuming, prone to human errors, and cannot be scaled once the business starts to grow. While manual risk management may work well with startups and smaller organizations, larger organizations require automated tools to manage risks effectively. This guide aims to assist decision-makers in organizations in selecting the appropriate risk management software. - [Compliance Workshop Recap from Team25](https://softcomply.com/compliance-workshop-recap-from-team25/): This is also why SoftComply hosted the 3rd edition of the Compliance Workshop on April 10, 2025 during Atlassian Team event. The workshop’s title was “How to best support Regulated Industries on Atlassian Cloud” and was aimed at discussing the compliance requirements of regulated industries & collaboration between Atlassian, app vendors and solution partners to best support our customers from regulated domains. - [The Ultimate Guide to ISO 14971 Risk Management](https://softcomply.com/ultimate-guide-iso-14971-risk-management/): At SoftComply, we understand the importance of proper risk management. - [Doccle: How an Integrated Risk Management System paved the road to ISO27001 compliance](https://softcomply.com/iso27001-compliance-jira/): Having the ISO27001 features built-in was the biggest purchase decision for us. All the Controls are readily within the SoftComply Risk Manager Plus app, we are able to prepare Statement of Applicability within seconds, and have the Traceability between Assets, Controls and Risks built automatically just by using different elements of the app. - [How to Prepare for ISO 27001 Compliance in Jira Cloud](https://softcomply.com/how-to-prepare-iso-27001-jira/): Risk-based approach provides the most efficient way to manage and protect your organisation’s critical information assets, and prepare for ISO 27001 certification. - [Why ISO27001 Should Stay Within Jira for Atlassian Marketplace Partners](https://softcomply.com/iso27001-jira-atlassian-marketplace-partners/): Atlassian’s updated Marketplace Partner Program underscores the need for robust security management. With increasing customer expectations around data protection, security, and compliance transparency, Gold and Platinum Marketplace Partners are required to demonstrate adherence to compliance framework like SOC 2 or globally recognised standards such as ISO 27001. This shift is particularly critical for vendors managing sensitive customer data, access permissions, and enterprise integrations. - [How to build Risk Automation with Jira Automation & SoftComply Risk Manager Plus](https://softcomply.com/risk-automation/): Risk Manager Plus on Jira Cloud is the most advanced risk management app supporting a wide range of risk management frameworks. You can easily customize the built-in Risk Models or build your own Risk Model from scratch, e.g. 2- or 3-dimensional Risk Matrix or Risk Score based ones. You can also specify your risk assessment parameters (e.g. Impact, Likelihood, etc.) and the number of risk assessment iterations (e.g. Initial, Current and Target). - [What does FDA Guidance on Predetermined Change Control Plan mean for Medical Device Manufacturers?](https://softcomply.com/fda-predetermined-change-control-plan/): In August 2024 the FDA release a new Draft Guidance “Predetermined Change Control Plans for Medical Devices” (PCCP), shortly followed in December 2024 by “Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions”. - [AI-enabled Medical Devices – FDA Guidance](https://softcomply.com/ai-enabled-medical-devices/): The guidance reinforces the importance of a “Total Product Life-Cycle” approach to the management of AI-enabled medical devices. The most important aspect of the Total Product Lifecycle (TPLC) approach in the FDA's guidance on AI-enabled medical devices is the comprehensive management of risks throughout the entire lifecycle of the device, from design and development to real-world use and potential decommissioning. - [ISO 13485 Implementation Guide for Startups in 2025](https://softcomply.com/iso13485-qms-implementation-guide/): The Internet is full of articles about the implementation of ISO 13485. They talk about “Getting management support”, “Obtain The Documents And Study The Requirements”, “Develop An Implementation Plan”, “Evolution of a Quality Management System”, and other seemingly complex topics. - [Software as a Medical Device (SaMD) Startup Guide to Compliance for 2025](https://softcomply.com/samd-compliance-guide/): The first contact with the Medical Device regulatory world is a shock for most startups. These companies usually have excellent technical and clinical ideas on how to improve the patient’s life, but little knowledge of the legal burdens required to bring the medical device to the market. - [Introducing Advanced Cybersecurity Risk Management on Jira Cloud](https://softcomply.com/cybersecurity-risk-management-jira/): NOTE: These recommendations of controls have been added to the Risk Manager Plus in Jira to be used during the cybersecurity risk management. - [How a Compliance Solution on Atlassian Cloud Empowered a Leading MedTech Company](https://softcomply.com/compliance-medtech-cloud/): A mid-sized company in the medical technology sector faced a growing challenge: meeting the stringent requirements of the Medical Device Regulation (MDR) and FDA 21 CFR. As the company expanded, the existing ways of managing risks and documentation – such as Excel spreadsheets and paper-based processes – became increasingly inefficient and error-prone. This not only led to delays but also increased the risk of compliance violations. - [Medical Device Compliance Guide for 2025](https://softcomply.com/medical-device-compliance-guide/): This medical device compliance guide focuses on the key requirements and strategies for navigating the regulatory landscape. We will cover the role of major regulatory bodies like the FDA, the classification of devices, and the importance of quality management. We will also discuss the challenges of global compliance and offer strategies to overcome them. - [Navigating FDA Cybersecurity Requirements for Medical Devices – A Case Study](https://softcomply.com/case-study-fda-cybersecurity-medical-devices/): This case study describes the experience of a multinational medical device manufacturer meeting the FDA cybersecurity requirements. The company is operating in the MedTech sector developing a class 2/IIb device consisting of hardware and software. - [Information Security (ISO 27001) Risk Management Best Practices for 2025](https://softcomply.com/information-security-risk-management-guide/): Information Security Risk Management is all about identifying, assessing, and managing risks to keep your data safe. Think of it like a security guard who not only spots potential threats but also takes steps to neutralize them. Here’s why it’s crucial: - [Integrate Risk Management in Software Development Lifecycle – Guide for 2024](https://softcomply.com/integrating-risk-management-sdlc-guide/): Integrating risk management into the Software Development Lifecycle (SDLC) of a product is crucial to its success. It enhances the safety, security and reliability of your software product. When you identify, assess, and mitigate risks early, you can avoid bigger problems down the line. - [Hazard Analysis In Jira (Quick Guide)](https://softcomply.com/what-is-hazard-analysis/): By following these steps and integrating best practices, you'll be well on your way to mastering hazard analysis in Jira with SoftComply's Risk Manager Plus app. This structured approach not only optimizes the efficiency and thoroughness of your risk management processes, but also helps ensure your products meet stringent safety standards. For further reading and to enhance your product safety with FMEA, please check out our recent blog post on how hazard analysis and FMEA relate to each other. - [How to use CVSS in Jira](https://softcomply.com/guide-cvss-jira/): The Common Vulnerability Scoring System (CVSS) is a standardized framework for rating the severity of security vulnerabilities. The CVSS was developed and is maintained by the Forum of Incident Response and Security Teams (FIRST). FIRST is an international consortium that aims to foster cooperation and coordination in incident prevention and response, as well as to promote the sharing of information among member organizations. ## Pages - [Solution Briefs](https://softcomply.com/solution-briefs/): SoftComply Solution Briefs SoftComply Risk Manager Plus Download the Risk Manager Plus Information Sheet SoftComply Document Manager Download the Document Manager Information Sheet - [SoftComply Toolbox for Confluence User Guide](https://softcomply.com/toolbox-confluence-userguide/): Add the “Page Info” macro to your page; - [SoftComply GRC Solution](https://softcomply.com/product/grc-solution/): SoftComply GRC Solution on Atlassian Cloud - [Migration Guide to SoftComply Document Manager](https://softcomply.com/migration-guide-dm/): This feature allows the user to import Comala Document Management Cloud data and SoftComply Change History App for the same. - [SoftComply Change History Table End of Life](https://softcomply.com/cht-eol/): Dear customer, - [Risk Reporting User Guide](https://softcomply.com/risk-confluence-userguide/): SoftComply Risk Manager for Confluence is an extension of the SoftComply Risk Manager apps on Jira Cloud to visualize and report risks in Confluence. - [Subscribe](https://softcomply.com/subscribe/): Stay connected with SoftComply and receive new blog posts in your inbox. - [Risk & Document Management](https://softcomply.com/): SoftComply provides an Atlassian-native GRC Solution with Risk Management, Document Control and Compliance Automation directly inside Jira and Confluence - [Contact us](https://softcomply.com/contact-us/): SoftComply apps are available on Atlassian Marketplace – you can try them all out for free! - [About](https://softcomply.com/about/): SoftComply offers the most affordable and feature rich regulatory compliance products on the market. - [Data Security Statement](https://softcomply.com/data-security-statement/):   - [Privacy Policy](https://softcomply.com/privacy-policy/): This Policy describes the rules by which SoftComply processes personal data and is valid from October 18th, 2022. - [Service Level Agreement](https://softcomply.com/service-level-agreement/): SoftComply’s business hours are from 10am to 4pm CET, from Monday to Friday (except for Estonian national holidays).  All requests are answered within reasonable time and we strive to respond to your request as fast as possible! - [Terms of Service](https://softcomply.com/terms-of-services/): Risk Manager Plus TERMS OF SERVICE Information Security Risk Manager TERMS OF SERVICE Risk Manager TERMS OF SERVICE Document Manager TERMS OF SERVICE SoftComply eQMS TERMS OF SERVICE Validation for Confluence TERMS OF SERVICE Static Snapshots TERMS OF SERVICE Change History TERMS OF SERVICE Validation for Risk Manager Plus TERMS OF SERVICE - [SoftComply Information Security Risk Manager User Guide](https://softcomply.com/infosec-risk-manager-user-guide/): Risk management for InfoSec risks is divided into 2 sheets and managed via the Risk Table view in the selected Jira project. - [Guides](https://softcomply.com/guides/): Risk Manager Plus Cloud USER GUIDE Risk Manager Plus Server/DC USER GUIDE Risk Reporting USER GUIDE Information Security Risk Manager USER GUIDE Risk Manager USER GUIDE Document Manager QUICK GUIDE Document Manager USER GUIDE SoftComply eQMS USER GUIDE Validation for Confluence USER GUIDE Static Snapshots USER GUIDE Change History USER GUIDE Validation for Risk Manager Plus USER GUIDE - [SoftComply eQMS User Guide](https://softcomply.com/eqms-userguide/): Welcome to the SoftComply eQMS. - [eQMS Terms & Conditions](https://softcomply.com/eqms-terms-conditions/): We are SoftComply (registry code 14013101, with a legal address: Sininuku tn 1, Nõmme, Tallinn, Harju County, 10919, Republic of Estonia), (hereinafter “SoftComply” ,“we”, “us” or “our”) a company established and existing under the laws of the Republic of Estonia, operating the www.softcomply.com website (hereinafter “Web Site”) and providing the Quality Management System (QMS) Software (hereinafter also “QMS Software”). - [Change History User Guide](https://softcomply.com/change-history-user-guide/): Change History app has three main parts: - [Change History Terms of Service](https://softcomply.com/change-history-terms-of-service/): We are SoftComply (registry code 14013101, with a legal address: Sininuku tn 1, Nõmme, Tallinn, Harju County, 10919, Republic of Estonia), (hereinafter “SoftComply” ,“we”, “us” or “our”) a company established and existing under the laws of the Republic of Estonia, operating the www.softcomply.com website (hereinafter “Web Site”) and providing the SoftComply Change History app (hereinafter also “Change History app”). - [User Guide of the SoftComply Validation App for Confluence](https://softcomply.com/validation-app-user-guide/): SoftComply Validation for Confluence is an app that automates integrity checks of Confluence Cloud in regular intervals – 1 x a week. - [Validation for Confluence app Terms & Conditions](https://softcomply.com/validation-terms-conditions/): We are SoftComply (registry code 14013101, with a legal address: Sininuku tn 1, Nõmme, Tallinn, Harju County, 10919, Republic of Estonia), (hereinafter “SoftComply” ,“we”, “us” or “our”) a company established and existing under the laws of the Republic of Estonia, operating the www.softcomply.com website (hereinafter “Web Site”) and providing the SoftComply Validation for Confluence app (hereinafter also “Validation app”). - [User Guide Snapshots](https://softcomply.com/snapshots-userguide/): Welcome to the SoftComply Static Snapshots app! - [Static Snapshots Terms & Conditions](https://softcomply.com/snapshots-terms-of-service/): We are SoftComply (registry code 14013101, with a legal address: Sininuku tn 1, Nõmme, Tallinn, Harju County, 10919, Republic of Estonia), (hereinafter “SoftComply” ,“we”, “us” or “our”) a company established and existing under the laws of the Republic of Estonia, operating the www.softcomply.com website (hereinafter “Web Site”) and providing the SoftComply Static Snapshots Software (hereinafter also “Static Snapshots app”). - [User Guide for Validation app of the Risk Manager Plus](https://softcomply.com/validation-risk-manager-plus-user-guide/): SoftComply Validation for Risk Manager Plus is an app that automates integrity checks of Jira Cloud in regular intervals – 1 x a week. - [Validation for Risk Manager Plus app Terms & Conditions](https://softcomply.com/validation-riskmanager-terms-conditions/): We are SoftComply (registry code 14013101, with a legal address: Sininuku tn 1, Nõmme, Tallinn, Harju County, 10919, Republic of Estonia), (hereinafter “SoftComply” ,“we”, “us” or “our”) a company established and existing under the laws of the Republic of Estonia, operating the www.softcomply.com website (hereinafter “Web Site”) and providing the SoftComply Validation for SoftComply Risk Manager Plus app (hereinafter also “Validation app”). - [Document Manager Terms & Conditions](https://softcomply.com/document-manager-terms-conditions/): We are SoftComply (registry code 14013101, lwith a legal address: Sininuku tn 1, Nõmme, Tallinn, Harju County, 10919, Republic of Estonia), (hereinafter “SoftComply” ,“we”, “us” or “our”) a company established and existing under the laws of Republic of Estonia, providing SoftComply Document Manager software as a service (hereinafter also “Software”). - [Manual for SoftComply Document Manager](https://softcomply.com/document-manager-manual/):   - [SoftComply Document Manager User Guide](https://softcomply.com/document-manager-user-guide/): SoftComply Document Manager app on Confluence Cloud will take your Confluence to a new level. You can edit the content of your Documents using the power of Confluence while the Document Manager adds the compliance aspects to the document management such as document lifecycle and electronic signatures. - [Information Security Risk Manager Terms & Conditions](https://softcomply.com/infosec-riskmanager-terms-conditions/): We are SoftComply (registry code 14013101, with a legal address: Sininuku tn 1, Nõmme, Tallinn, Harju County, 10919, Republic of Estonia), (hereinafter “SoftComply” ,“we”, “us” or “our”) a company established and existing under the laws of Republic of Estonia, providing SoftComply Information Security Risk Manager software as a service (hereinafter also “Software”). - [Risk Manager Plus Terms & Conditions](https://softcomply.com/riskmanagerplus-terms-conditions/): We are SoftComply (registry code 14013101, with a legal address: Sininuku tn 1, Nõmme, Tallinn, Harju County, 10919, Republic of Estonia), (hereinafter “SoftComply” ,“we”, “us” or “our”) a company established and existing under the laws of Republic of Estonia, providing SoftComply Risk Manager software as a service (hereinafter also “Software”). - [Risk Manager Plus User Guide](https://softcomply.com/riskmanagerplus-userguide/): Success! You have just created a new risk management project and you can now start managing risks in Jira. - [Risk Manager Plus on Cloud User Guide](https://softcomply.com/riskmanagerpluscloud-userguide/):   - [Risk Manager Terms of Service](https://softcomply.com/risk-manager-terms-conditions/): We are SoftComply (registry code 14013101, with a legal address: Sininuku tn 1, Nõmme, Tallinn, Harju County, 10919, Republic of Estonia), (hereinafter “SoftComply” ,“we”, “us” or “our”) a company established and existing under the laws of Republic of Estonia, providing SoftComply Risk Manager software as a service (hereinafter also “Software”). - [Webinars & Training Courses](https://softcomply.com/learnmore/): Atlassian Courses Compliance Courses Webinars All - [Risk Manager User Guide](https://softcomply.com/riskmanager-userguide/): Success! You have just created your first risk management project and you can now start managing risks. - [Industries](https://softcomply.com/product/industries/): Plugins for Risk Management Solution - [Document Management Solution](https://softcomply.com/product/quality-management/): Plugins for Document Management Solution - [SoftComply eQMS](https://softcomply.com/product/eqms/): SoftComply eQMS is a Quality Management System packaged as an app on Confluence. - [Compliant Content](https://softcomply.com/product/compliant-content/): How we can help releave it - [Cloud eQMS Solution](https://softcomply.com/product/cloud-eqms/): How we can help releave it - [Risk Manager](https://softcomply.com/product/risk-manager/):  Use the ready-made templates of Risk Matrix or RPN based Risk Models or build your own Risk Model from scratch.  - [Validation for Risk Manager Plus](https://softcomply.com/product/validation-for-riskmanager-plus/): Scheduled weekly automated validation tests ensure that the Risk Manager Plus stays validated and up-to-date without the manual effort.  - [Static Snapshots](https://softcomply.com/product/static-snapshots/): Static Snapshots will help you freeze the content of a dynamic macro with a timestamp. This means you can use the content of the macro on an official final report and approve it. - [Risk Manager Plus](https://softcomply.com/product/risk-manager-plus/): SoftComply Risk Manager Plus is the most advanced risk management solution on Atlassian Jira. Supporting various risk assessment methods. - [Validation for Confluence](https://softcomply.com/product/validation-for-confluence/): Run your validation tests automatically each week. Download Validation Results on the Validation app page in Confluence. - [Information Security Risk Manager](https://softcomply.com/product/infosec-risk-manager/): Full traceability between Assets, Risks and Controls is built automatically as you manage your Information Security Risks. Risk Dashboard includes the Coverage reports between Controls, Risks and Assets in a Traceability Matrix. - [Risk Reporting](https://softcomply.com/product/risk-confluence/): Add your Risk Table on a Confluence page and you will always have an up to date report ready to be shared with others. - [Product](https://softcomply.com/product/) - [FAQs](https://softcomply.com/faqs/): FAQs Document Manager Home Information Security Risk Manager Risk Manager Risk Manager Plus SoftComply eQMS Static Snapshots Validation for Confluence Validation for Risk Manager Plus ## Clients Feedback - [SoftComply Document Manager has transformed our Confluence into a fully functional eQMS!](https://softcomply.com/clients-feedback/softcomply-document-manager-has-transformed-our-confluence-into-a-fully-functional-eqms/): SoftComply Document Manager integrates our quality management and software development processes, turning Confluence into a fully functional eQMS. With this app we can efficiently manage document approvals, track changes, and ensure compliance - all within the Atlassian ecosystem. The ability to streamline design control and software release processes has been a game-changer for our team. Highly recommended for anyone looking for a reliable and compliant document management solution. - [Excellent for ISO27001 Risk Management in Jira!](https://softcomply.com/clients-feedback/excellent-for-iso27001-risk-management-in-jira/): As we are managing our ISMS in Confluence and JIRA, I was looking for an integrated Risk Management system. With this product we now have the perfect solution: we have implemented the product for our information risks, business risks, supplier and product risks. The good thing is that it also integrates nicely with our ISO27001 documentation. Also, when you need to comply with NIS2 or DORA you can also use this app to start off with good risk management. And finally, the support is great, very responsive. Glad to have chosen this app ! - [Static Snapshots is a very good app!](https://softcomply.com/clients-feedback/very-good-app/): The app allows to freeze the content of a page in Confluence, and as another user pointed out, is especially useful in freezing content from external sources (like Jira tickets). - [The report and plans of Validation for Confluence app are great!](https://softcomply.com/clients-feedback/the-report-and-plans-are-great/): The topic of sofware validation for medical devices is not an easy step in setting up the QMS, there seems to be comparably little actual information available on how to go about things the "right" way. There's some good lessons in your planning and reporting. - [Automated tools validation for our eQMS in the cloud? Yes please](https://softcomply.com/clients-feedback/automated-tools-validation-for-our-eqms-in-the-cloud-yes-please/): This addon aligns perfectly with the work my organization is doing with AAMI to help drive the acceptance and safety of modern technology in the regulated medical device space. Using automated validation means we don't need to spend resource time on manually testing and keeping our Jira and Confluence tools in a validated state. - [This tool works flawlessly in validating your eQMS for Confluence!](https://softcomply.com/clients-feedback/this-tool-works-flawless-in-validating-your-eqms-for-confluence/): The extensive test cases and clear reports make validation a breeze. And if a test fails, the SoftComply team is there to help you promptly in figuring out what could be an issue. The setup does take some time, but nothing an experience Atlassian administrator can't handle. I highly recommend this tool as it gives you automated weekly validation reports on a cloud system that might change without you noticing it. - [The Best Risk Management Tool for Jira!](https://softcomply.com/clients-feedback/a-fantastic-app-that-helped-us-simplify-and-automate-how-we-manage-risk/): SoftComply Risk Manager Plus is very useful if you want to do different kinds of risk management. It is more advanced than the Risk Manager! It enables us to do any kind of risk management e.g. information security risks, data privacy risks, business continuity risks etc. in a very comfortable way ! (e.g. ISO 14971/27001/27701/22301 risk management). You just have to create a risk model and a risk table. As these are almost fully customizable it allows you to implement the risk management method without constraints. I can highly recommend this app. Such an improvement compared to SoftComply Risk Manager! - [This vendor is very responsive and has worked with us in different time zones](https://softcomply.com/clients-feedback/the-softcomply-static-snapshots-is-a-very-good-app-2/): You can easily book time with them in their Calendar to get help. We observed that new features are coming out fortnightly. We have used this app to do a Risk Register with Risks, Issues, Assumptions and Dependencies for our squads. - [An Exceptional Application for Comprehensive Risk Management](https://softcomply.com/clients-feedback/an-exceptional-application-for-comprehensive-risk-management-2/): Our initial adoption of this platform dates back several years when it played a pivotal role in overseeing our information security risks at a prominent FinTech establishment. Following a compelling demonstration of its capabilities, the executive team advocated for its expansion to encompass enterprise-wide risks. Upon my transition to a new FinTech venture in early 2023, I seamlessly integrated this tool into our operations, where it initially focused on information security risk management. As its inherent value became apparent to the executive leadership and the board, the decision was made to extend its application to holistically address enterprise and project-related risks. - [The Risk Manager is an excellent app from SoftComply](https://softcomply.com/clients-feedback/the-risk-manager-is-an-excellent-app-from-softcomply/): The Risk Manager supports Risk Management for both Jira Service management and Jira Software! I would definitely recommend it to other companies. - [The SoftComply Static Snapshots is a very good app](https://softcomply.com/clients-feedback/the-softcomply-static-snapshots-is-a-very-good-app/): It allows you to freeze the content of a page in Confluence, especially when including data from external sources (like Jira tickets) - [An exceptional application for comprehensive risk management](https://softcomply.com/clients-feedback/an-exceptional-application-for-comprehensive-risk-management/): Our initial adoption of this platform dates back several years when it played a pivotal role in overseeing our information security risks at a prominent FinTech establishment. As its inherent value became apparent to the executive leadership and the board, the decision was made to extend its application to holistically address enterprise and project-related risks. ## FAQs - [Where can I get the Validation Results?](https://softcomply.com/faq/where-can-i-get-the-validation-results/): You can download Validation Results from the Validation for Confluence app’s page. - [Where can I learn more about the SoftComply Information Security Risk Manager?](https://softcomply.com/faq/where-can-i-learn-more-about-the-softcomply-information-security-risk-manager-2/): We have an extensive set of Knowledge Base articles about customisation and additional automation for the Risk Manager apps. - [Why are some SOPs and Templates empty?](https://softcomply.com/faq/why-are-some-sops-and-templates-empty/): The Trial version of the SoftComply eQMS contains the full structure of a QMS, but very limited content is available in the Trial mode. You can access the entire content of the eQMS by purchasing the full license. - [What happens when my evaluation period ends?](https://softcomply.com/faq/what-happens-when-my-evaluation-period-ends/): When your evaluation period ends and you did not purchase the license, the SoftComply eQMS’ functionality will stop working. Any Trial space deployed during the evaluation will still be available but it will not be possible to create any additional Trial QMS spaces and the macros will not be working. - [What happens if I decide not to renew the license?](https://softcomply.com/faq/what-happens-if-i-decide-not-to-renew-the-license/): Any QMS space that you have already deployed will not be affected, but it will not be possible to create any additional QMS spaces and the macros will stop working.If you choose to purchase the license, all features will become available again. - [What standards is the SoftComply eQMS based on and where can I find them?](https://softcomply.com/faq/what-standards-is-the-softcomply-eqms-based-on-and-where-can-i-find-them/): SoftComply eQMS is based on the latest version of: ISO 13485:2016, IEC 62304:2006 (as amended in 2008 and 2015), ISO 14971:2012 and 21 CFR 820. - [I need help to customize my eQMS!](https://softcomply.com/faq/i-need-help-to-customize-my-eqms/): We are happy to support you. Contact us at info@softcomply.com or BOOK A CALL with our Regulatory Team. - [Why can’t I create a new Risk Project?](https://softcomply.com/faq/why-cant-i-create-a-new-risk-project-2/): There could be several reasons for this. Please have a look at your SoftComply Risk Manager configuration and answer the following questions here. - [Why did my Risk Severity values change?](https://softcomply.com/faq/why-did-my-risk-severity-values-change/): This is a feature of the SoftComply Risk Manager app that is related to the requirement of ISO 14971 for medical device risk management. To learn more about it and how to disable this option, please continue reading here. - [Why do I see empty Risk Rows in the Risk Table?](https://softcomply.com/faq/why-do-i-see-empty-risk-rows-in-the-risk-table-2/): For more information about why you may be seeing empty risk rows in the risk management table and how to avoid it, please continue reading here. - [Which permissions do I need for the SoftComply Risk Manager?](https://softcomply.com/faq/which-permissions-do-i-need-for-the-softcomply-risk-manager/): Please read the Security and Permissions related questions and answers at the Risk Manager Security post. - [What are the differences between the Risk Manager and Risk Manager PLUS on Jira?](https://softcomply.com/faq/what-are-the-differences-between-the-risk-manager-and-risk-manager-plus-on-jira/): There are a few differences between the Risk Manager and the Risk Manager Plus apps: - [What happens if my evaluation period ends?](https://softcomply.com/faq/what-happens-if-my-evaluation-period-ends-4/): For more information about accessing your risk data when your app evaluation period ends, please continue reading here. - [How to rename locked SoftComply Risk Manager fields in Jira Server/DataCenter?](https://softcomply.com/faq/how-to-rename-locked-softcomply-risk-manager-fields-in-jira-server-datacenter/): After installing the SoftComply Risk Manager app in your Jira Server or Jira Data Center, the app will create new custom fields in your Jira. Sometimes you may already have fields with the same names and may want to rename the new fields that were created. Please continue here to learn how you can rename the locked Risk Manager fields. - [How is your data secured in the SoftComply Risk Manager?vHow is your data secured in the SoftComply Risk Manager?](https://softcomply.com/faq/how-is-your-data-secured-in-the-softcomply-risk-managervhow-is-your-data-secured-in-the-softcomply-risk-manager/): For information about how data is secured, the security accreditations we hold and how has the app security been assessed, please read on about the Data Security of the SoftComply Risk Manager in our Knowledge Base. - [How many snapshots can I take per Confluence page?](https://softcomply.com/faq/how-many-snapshots-can-i-take-per-confluence-page/): There is a limit of 50 snapshots that you can take per Confluence page. - [Where are the snapshots stored?](https://softcomply.com/faq/where-are-the-snapshots-stored/): All static snapshots are stored together with your Confluence pages, i.e. your data is managed and stored by Atlassian. SoftComply only gathers the data, encrypts and zips it, and stores it with your Confluence page itself. SoftComply does not store your data anywhere outside Confluence. - [Why does the snapshot of a single Jira issue look different from its dynamic (original) version?](https://softcomply.com/faq/why-does-the-snapshot-of-a-single-jira-issue-look-different-from-its-dynamic-original-version/): Due to Atlassian’s export limitations, exporting (or taking a snapshot of) a single issue will result in having an export (or a static page) of only the Jira issue key and no other information, e.g. Jira issue title and status will not be exported even though you might have had it in the dynamic (original) version of the page. - [What information does the Snapshot app share with the external domains?](https://softcomply.com/faq/what-information-does-the-snapshot-app-share-with-the-external-domains/): The Static Snapshot app sends data to the following external domains: - [How can I install the Validation app?](https://softcomply.com/faq/how-can-i-install-the-validation-app-2/): The Validation app can be installed directly from Atlassian Marketplace. - [What exactly does the Validation app test?](https://softcomply.com/faq/what-exactly-does-the-validation-app-test/): The Validation app for Confluence includes automated tests on the main functionalities related to the management of permissions, users, spaces and pages. - [How often can I run the validation tests?](https://softcomply.com/faq/how-often-can-i-run-the-validation-tests-2/): SoftComply Validation for Confluence tests are executed once a week automatically. - [What Documented Evidence is being generated by the Validation app?](https://softcomply.com/faq/what-documented-evidence-is-being-generated-by-the-validation-app-2/): With each test run, 4 Validation documents are being generated: - [What exactly does the Validation Results document include?](https://softcomply.com/faq/what-exactly-does-the-validation-report-include-2/): Validation Results document describes each of the 40 test cases in detail including the expected and actual test results together with the documented evidence. - [Where should I create Documents for the SoftComply Document Manager – in Confluence or inside the Document Manager?](https://softcomply.com/faq/where-should-i-create-documents-for-the-softcomply-document-manager-in-confluence-or-inside-the-document-manager/): You should create Documents inside the Document Manager to be managed by the App. - [What is a Task?](https://softcomply.com/faq/what-is-a-task/): A Task is an activity assigned to one or more users that must be completed in a specific step of the workflow, before the Container can transition to the next step. - [What is a Regular Task?](https://softcomply.com/faq/what-is-a-regular-task/): A “Regular” task is a general activity that needs to be completed. The assignee(s) can only confirm that the task was Completed. - [What is an Approval Task?](https://softcomply.com/faq/what-is-an-approval-task/): An “Approval” task involves a decision from the assignee(s). The outcomes are typically referred to as “Approval” and “Rejection”. A Rejection from any assignee immediately triggers the associated transition (if any). A transition triggered by an Approval requires all assignees to Approve all tasks. - [What is a Container?](https://softcomply.com/faq/what-is-a-container/): In the SoftComply Document Manager, a “Container” is an object that contains Documents and/or Fields. - [How does the Document Manager app affect my Confluence instance?](https://softcomply.com/faq/how-does-the-document-manager-app-affect-my-confluence-instance/): The SoftComply Document Manager DOES NOT impact your day-to-day activities in Confluence. You can still create spaces, pages, add content and macros to pages, and so on. - [How can I create a new version of a Document?](https://softcomply.com/faq/how-can-i-create-a-new-version-of-a-document/): From the Folder view, click on the document you want to create a new version of. The detailed view of the document opens with the list of all versions. Click on “Create New Version” button on the Top-Right corner of the View. - [Why is the “Create New Version” button not available in the detailed view of my document?](https://softcomply.com/faq/why-is-the-create-new-version-button-not-available-in-the-detailed-view-of-my-document/): This is because there is already a Draft version of the document. There can only be one document version in the Draft, Approved or Released state at any given time. - [Do I have to manually obsolete Approved or Released versions of a document when a new one is Approved or Released?](https://softcomply.com/faq/do-i-have-to-manually-obsolete-approved-or-released-versions-of-a-document-when-a-new-one-is-approved-or-released/): No. The App automatically obsoletes older versions of the Approved or Released documents when a new version is available. - [How are the document version in the App related to the Confluence page versions in the Page History?](https://softcomply.com/faq/how-are-the-document-version-in-the-app-related-to-the-confluence-page-versions-in-the-page-history/): Document versioning in the Document Manager app is independent of the Confluence page versioning system. - [What happens to existing Containers when I modify their Template?](https://softcomply.com/faq/what-happens-to-existing-containers-when-i-modify-their-template/): Nothing. When a Container is created it inherits all the information from the Template. Updating a template has no impact on the existing Containers. - [Why has the information that I added to a Container disappear?](https://softcomply.com/faq/why-has-the-information-that-i-added-to-a-container-disappear/): Updates to fields must be saved manually, i.e. you have to use the button at the bottom of the page to save the information. - [Why can’t I see any folder in the folder view?](https://softcomply.com/faq/why-cant-i-see-any-folder-in-the-folder-view/): It is possible that the App Setup was not completed correctly. Remove all App Data using the option in the bottom left corner of the App page in the Confluence Settings, then repeat the setup. Uninstalling and re-installing the App will NOT fix the issue. - [What happens if my evaluation period ends?](https://softcomply.com/faq/what-happens-if-my-evaluation-period-ends-3/): All your Confluence data as well as your field data is retained. You will be able to access your documents through Confluence. The App functionalities will stop working. - [What are the main differences between the Risk Manager apps of SoftComply?](https://softcomply.com/faq/what-are-the-main-differences-between-the-risk-manager-apps-of-softcomply/): There are a number of differences between the 3 Risk Manager apps offered by SoftComply. You can read the comparison between them here. - [How to assign fields to my Risk Table columns in the Information Security Risk Manager?](https://softcomply.com/faq/how-to-assign-fields-to-my-risk-table-columns-in-the-information-security-risk-manager/): To learn how to assign fields to Risk Table columns in the Information Security Risk Manager, please continue reading the tutorial here. - [My Risk Table of the Information Security Risk Manager shows the warning “Field not mapped“. How can I get rid of this warning?](https://softcomply.com/faq/my-risk-table-of-the-information-security-risk-manager-shows-the-warning-field-not-mapped-how-can-i-get-rid-of-this-warning/): To learn more about the fields and mapping of fields in the Information Security Risk Manager, please continue reading the tutorial here. - [The Risk Table of the Information Security Risk Manager shows the warning “Field will be available for …“. How to solve this?](https://softcomply.com/faq/the-risk-table-of-the-information-security-risk-manager-shows-the-warning-field-will-be-available-for-how-to-solve-this/): To learn more about the fields and mapping of fields in the Information Security Risk Manager, please continue reading the tutorial here. - [What are Object Registers and how to use them?](https://softcomply.com/faq/what-are-object-registers-and-how-to-use-them-2/): Object Registers are a feature of the Information Security Risk Manager that allows you to create custom data structures (i.e. data tables) and link these structures to Jira issues like you would link other issues. Custom data structures are like database tables that you can build inside the Information Security Risk Manager application. When these registers are filled with data you can link Jira issues with the data objects. In other words, the object registers are like complex customisable dropdown lists you can use as Jira issue fields - [What happens if my evaluation period ends?](https://softcomply.com/faq/what-happens-if-my-evaluation-period-ends-2/): For more information about accessing your risk data when your app evaluation period ends, please continue reading here. - [Where can I learn more about the SoftComply Information Security Risk Manager?](https://softcomply.com/faq/where-can-i-learn-more-about-the-softcomply-information-security-risk-manager/): We have an extensive set of Knowledge Base articles about customisation and additional automation for the Risk Manager apps. - [How to connect Confluence to the Information Security Risk Manager for risk reporting?](https://softcomply.com/faq/how-to-connect-confluence-to-the-information-security-risk-manager-for-risk-reporting/): Just follow the guide here: Connecting Confluence to Jira. - [How can I install the Validation app?](https://softcomply.com/faq/how-can-i-install-the-validation-app/): The Validation app can be installed directly from Atlassian Marketplace. - [What exactly does the Validation app test?](https://softcomply.com/faq/what-exactly-does-the-validation-report-include/): The Validation app for Risk Manager Plus includes automated tests on the main functionalities related to the risk model and risk table. - [What Documented Evidence is being generated by the Validation app?](https://softcomply.com/faq/what-documented-evidence-is-being-generated-by-the-validation-app/): With each test run, 4 Validation documents are being generated: - [How often can I run the validation tests?](https://softcomply.com/faq/how-often-can-i-run-the-validation-tests/): The Risk Manager Plus validation tests are automatically executed once a week.