Compliance controls
Configure frameworks, suppressions, exceptions, and recomputation.
Use Settings → Compliance to configure the Compliance module.
This area is available to admins.
It is the control plane for Compliance. Use it to manage framework behavior, suppressions, exception rules, and recomputation.
If you are new to the feature, start with Compliance overview. If you want the monitoring and triage workflow, go to Compliance posture.
Frameworks tab
The Frameworks tab lists supported frameworks.
Each row shows core framework details such as name, short name, description, and version. Superseded frameworks also show their replacement.
Open a framework to review its criteria.
The framework detail view shows each criterion with:
Name
Severity
Suppression status
Exception status
Mapped controls count
Deleted or superseded state
Filter and grouping criteria such as the associated standard, region or general category of the framework.
Admins can open a criterion row to add a suppression or exception scoped to that criterion.
This view is useful when you want to understand how a framework is structured before deciding whether to suppress or except a criterion.
Enabling and disabling a framework
Every framework might not be relevant to your organisation or usecase. In order to control noise, you can disable irrelevant or noisy frameworks (or enable newly added ones) by using the enable/disable button present in each row.
A disabled framework no longer shows up on the Compliance Posture dashboard, and a newly enabled framework will be included in the next compliance compute (i.e., the next violation detection run).

Suppressions tab
The Suppressions tab lists suppression rules across frameworks.
Use it to review active rules and remove outdated ones. For guidance on when to suppress rather than except, and general information on terminology, see Suppressions and exceptions.
Each record includes framework, criterion, scope, reason, authorship, dates, and status.
Filter the table by Active, Deleted, or All.
Use View scope to inspect the entity filter, if any.
Suppressions can be either:
Blanket — hide all violations for a criterion (or set of criteria)
Scoped — hide only matching violations for entities defined by a filter
Add a suppression
Use blanket suppressions carefully. They are faster to configure, but they remove the entire criterion from posture visibility.
Use scoped suppressions when you want to carve out a known subset of entities without hiding the broader control signal.
Exceptions tab
The Exceptions tab lists rule-based exceptions across frameworks.
Use it to review existing exceptions and remove stale rules. For the decision model behind this flow, see Suppressions and exceptions.
Filter the table by Active, Deleted, or All.
Each record includes framework, criterion, reason, authorship, dates, and status.
Add an exception
Define the scope
Build an entity filter.
Exceptions are always scoped. See Working with filters if you need help defining the scope.
Exceptions always require a scope. There is no blanket exception. This keeps accepted risk explicit and traceable to a defined set of entities.
Admins can also use this tab to review who created an exception rule and when it was last updated.
Exceptions created on specific violations from Compliance posture by risk managers will also show up here.
Recompute compliance violations
Use Recompute compliance violations when you need to refresh posture after a meaningful change.
This action queues a background job.
You can scope the recompute to one integration.
If you do not select an integration, BalkanID recomputes all integrations.
This is especially useful after changes to one connected system. For integration context, see Viewing your application integrations and Application Integrations.
This is useful after:
enabling a new framework,
changing suppressions or exception rules,
adjusting control configuration,
or validating changes for one integration without recomputing everything.
After submission, BalkanID confirms:
Compliance violations recompute has been queued. Once complete, you'll be able to view them on the Compliance Posture Dashboard.
Once the job finishes, review the results in Compliance posture.
Out-of-date posture warning
If control configuration changed after the last scan, BalkanID shows a warning banner on Compliance posture.
The banner indicates that summary statistics may be stale until you run a recompute.
This warning is especially relevant after changes to control mappings, suppressions, or exception rules.

Last updated
Was this helpful?

