BlogProduct updates
February 12, 2024

New in Vanta | February 2024

Written by
Joe Goldberg
Product Marketing
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

We recently rolled out new capabilities including:

  • NIST AI Risk Management Framework
  • Custom Tests
  • New system integrations
  • Updates to Trust Center, Access Reviews, and Vendor Risk Management
  • Plus additional updates!

NIST AI Risk Management Framework

The NIST AI Risk Management Framework (RMF) is now available in beta, giving customers a governance framework to mitigate the risks associated with the usage and development of AI products. 

With 60 pre-built requirements — including dozens of existing tests, 10 new risk scenarios within Risk Management, and over 40 bespoke document requests such as risk assessment reports, compliance documentation, and incident response guidance — Vanta helps customers navigate the NIST AI RMF in an informed way. And, as is the case with any Vanta framework, it can be customized to meet your unique needs.

Custom Tests

Customize a parameter in a Vanta pre-built automated test.

You can now customize automated tests in multiple ways to meet your unique needs. With Custom Tests, you can change parameters such as a number or string in Vanta’s pre-built tests. Or create a custom test from scratch with new logic that leverages a pre-built or private integration. 

Custom Tests let you align automation with your compliance program’s specific requirements, industry-specific or region-specific controls such as local data residency requirements, or specific auditor asks.

For example, you may need to collect evidence to ensure private Github repos have at least one required approval to merge to a default branch. Simply create a Custom Test and Vanta will continuously monitor this.

To try this out, log in to the Tests page and click on “Create Custom Test” in the top right.

Four new: integrations: Zoho People, Humi, Wiz, and Zinc

Last month, Vanta released four new integrations :Zoho People and Humi (HRIS), Wiz (Access), and Zinc (background checks). 

Integrations like these are core to powering robust automated compliance Whether you want to integrate with your in-house tools or an unsupported vendor, fill out the integrations feedback form to request an integration.



View available integrations

Trust Center updates

Improved Trust Center home page analytics

Vanta Trust Center now includes improved home page analytics that show data in a more visual way with charts and graphs to better highlight trends and patterns. The visuals better illustrate how buyers are interacting with Trust Centers content, including total visits, individual page views, and resource downloads. Also, a new navigation side bar makes it easier to view access and activity data as well as Trust Center settings.

Access Reviews updates

AI Data Import for Access Reviews

We’ve made several new improvements to Vanta Access Reviews that reduce risk and manual data entry, including: 

  • You can now take a screenshot or export a PDF of users from a system that is not integrated with Vanta and AI Data Import will auto-extract the user data. 
  • The System Reviewer dashboard now flags for accounts where the user has not logged in for more than 90 days.
  • The access review process shows a new “Change roles” option to denote accounts that need a role or permissions change.
  • Access Reviews now supports bulk linking account owners to system accounts via an uploaded .xlsx file containing unlinked account info.
  • Vanta user accounts can no longer be associated with an out-of-scope user. You now also have the option to automatically scope out existing user accounts associated with an out-of-scope user.

Vendor Risk Management: Private Link emails

Private Link Emails

Vanta Vendor Risk Management now lets you send a documentation request invitation directly from Vanta, including an email with the requested documentation and a link to upload questionnaires and documents. No more being limited to a URL copy/paste option.


See our Release Notes for all updates this month.

Try it out

Log in to your Vanta account to try out these new features. If you’re not a Vanta customer and want to learn more, request a demo.

As always, we welcome your feedback. Let us know what you think by reaching out to your Customer Success Manager. And stay in the loop on Vanta news on LinkedIn.

Or see it live - What’s New in Vanta: February Webinar

Join us for our monthly “What’s New in Vanta” webinar taking place February 28, 11am PT/2pm ET. This series provides you a live look at some of our newest releases and product improvements, including the new features mentioned in this blog.

Register here

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.