ModulesAssessments

Assessments

Create and manage privacy and risk assessments for processing activities, vendors, and organisational practices through structured flows with defined ownership and assignments.

Assessments let you run structured privacy and risk reviews, such as Data Protection Impact Assessments (DPIAs) or your own custom questionnaires, against a processing activity, a vendor, or an organisational practice. Every assessment starts from a template, has one owner, and can be delegated question by question to the colleagues who hold the answers.

Templates

Open Assessment > Templates. The list mixes two kinds of template.

System templates ship with Neostra and are read-only. You cannot edit one directly or run an assessment from it as is. Use its Customize action to create an editable copy in your tenant, then adjust and publish that copy.

Custom templates are yours. Build one from scratch, or import one that was exported from another template.

Customizing a system template does not change the original. The copy becomes an ordinary custom template in your tenant that you own, edit, and publish like any other, while the system template stays available for anyone who wants a fresh starting point.

Building a template

A template has ordered sections, and each section has ordered questions. A question is one of four types: Text, Single Choice, Single Select, or Multiple Select. For every question you choose whether notes and file uploads are Required, Optional, or not shown at all, and you can add a hint with hint attachments. Sections and questions can be reordered and cloned.

A template is either Standard, which only tracks completion, or Scored, which adds points and risk bands as described below.

Scoring

On a scored template, enable scoring at the section level and at the question level. Give each answer option a point value, and optionally exclude a "not applicable" option from the maximum so it does not count against the score. Section maximums must add up to the template's total point budget, and each question's option points must add up to the question's own maximum, so the template stays internally consistent before you can publish it. If either check fails, Neostra tells you which section or question is unbalanced and by how much, so you can fix it before publishing.

You also define risk thresholds: named bands such as Compliant, Low Risk, Medium Risk, and High Risk, each as a percentage range with a label and a colour. When someone runs the assessment, earned points divided by maximum points gives a percentage for each section and for the assessment overall, and the matching band is shown on the assessment and in list views. A question that a rule disables is left out of both earned and maximum points, so hidden questions never distort the score.

Rules

Rules are written on the template and copied into every assessment created from it.

Basic rules react to an answer with no side effects outside the assessment itself. A basic rule enables or disables a target question or section, or applies a requirement, Notes Required, Uploads Required, Both Notes & Uploads Required, or Either Notes or Uploads Required, when its conditions match. Conditions compare a question's answer to a specific value with "is" or "is not", and multiple conditions combine with All or Any. A disabled question or section is excluded from both completion tracking and scoring.

Advanced rules fire on an event: a question is completed, a section is completed, the assessment starts, or the assessment is completed. You can restrict the trigger to the owner, an assignee, or anyone, and add extra conditions on answers before the rule fires. Available actions:

ActionEffect
Add Tag / Remove TagAdds or removes tags on the assessment
Send EmailSends an email, with a subject and body that can include placeholder values from the assessment
Call APICalls a configured API with placeholder values in the payload
Answer QuestionFills a question's answer from a linked inventory record
Start an AssessmentCreates a new assessment from another template, with its name, owner, and other fields prefilled
Add response to inventoryWrites an answer back into the linked inventory record

Advanced rules only fire on the main assessment. They do not fire from a question that has been delegated out as its own assignment.

Default assignees and inventory placeholders

On each question you can set a default assignee. When an assessment is created from the template, those questions are delegated to that person automatically. You can also mark a question to be answered by the requester, the person who asked for the assessment to be created.

A template can also declare inventory placeholders: a Data System, Data Collection Source, Data Subject, Processing Activity, or Vendor. When someone creates an assessment from the template, they pick the actual record for each placeholder, and an Answer Question rule can then pull details from that record into an answer automatically. Inventory records themselves live in Data Discovery. See Data Discovery & Inventory.

Import and export

From a template's menu, choose Export to download it as a file. On the Templates list, use Import to bring one back in. Neostra validates the file before creating anything, so a template built or edited in one tenant can be moved into another.

Draft, publish, and discard

Editing a published template opens a draft alongside it. A template with an open draft shows Draft; one with no pending changes shows Published. Publish the draft to make it the live version, or discard it to revert to what was last published. An assessment keeps the template version it was created from, so publishing a new version of the template never changes an assessment already in progress.

Running assessments

Open Assessment > Assessments. Toggle between assessments assigned to or owned by you and the full set you have access to.

Create

Choose a published template, name the assessment, and set its owner and other assignment details. If the template declares inventory placeholders, pick the actual Data System, Data Collection Source, Data Subject, Processing Activity, or Vendor record for each one.

Answer or delegate

Answer questions yourself, or delegate a question to a colleague. A delegated question becomes its own child assessment for that assignee, showing only the question or questions assigned to them. If a template rule ties one question to another, the linked question is delegated along with it.

Review delegated answers

When an assignee submits an answer, review it and either Accept it, which makes it the assessment's official answer, or use Request Changes to send it back for another attempt. Undo reverses an acceptance. You can also Send Reminder to nudge an assignee, or Cancel Assignment to withdraw a delegation for a question or for the whole assignment.

Complete and export

Once every in-scope question has an answer, in the required notes or uploads where those are mandatory, Complete Assessment becomes available on the main assessment (Complete Assignment on a delegated child assessment). Completing freezes the answers and fires any completion rules. Export a single assessment to PDF, or select several from the list and export them together to Excel.

An assessment is In Progress, Completed, or Cancelled. Cancelling stops further edits. A question only counts as answered once any required notes or uploads for it are also present, so completion tracks real evidence, not just a filled-in field. A delegated question moves through its own assignment status as the assignee works on it and the owner reviews it, independent of the main assessment's own status.

Dashboard

Assessment > Dashboard summarises activity across the tenant: Total, Completed, Overdue, and Due Soon Assessments, and Total Open Assignments, each with a short description of what it counts. Below the summary, chart cards break assessments down by status, by brand, by owner, and by template, alongside an assessment velocity trend showing completion over time and a view of assessments currently under review by their approvers. Filter the whole dashboard by brand and by template to focus on one part of the programme at a time.

Assessments and the readiness scanner

Assessments and the Governance module's readiness scanner are related but answer different questions. The readiness scanner is a single, built-in scan that measures how ready your whole organisation is against a fixed regulatory checklist. Assessments measure a specific processing activity, vendor, or practice, using a template you choose or build yourself, and can be split across a team through delegation. See Governance for the readiness scanner.