Introduction to Assessments

Learn how assessments work in MineOS, from templates to linked risks, and find the right article for every assessment feature.

Assessments are how you evaluate privacy, security, vendor and AI risk in MineOS. Whether you're running a DPIA, reviewing a new vendor or documenting an AI system, every assessment follows the same model: you start from a template, fill it in with help from your data map and Mira AI, and keep it current as your organization changes.

How assessments work

An assessment template defines the structure of an assessment: its sections, questions and answer types. MineOS includes a catalog of ready-made templates, such as PIA, DPIA, LIA, TIA, vendor risk and AI assessments, and you can build your own. [confirm current template catalog]

An assessment is a single instance of a template, filled in for a specific system, vendor, project or process.

What makes MineOS assessments different is their live connection to your data map. Questions can pull directly from your inventory, including data sources, data types, processing activities and employees. When your inventory changes, for example when you add a new SaaS tool, the connected answers stay up to date without manual rework.

📸 [IMAGE: Assessments list page]

Key concepts

TermWhat it means
TemplateThe reusable structure an assessment is based on
OwnerThe person responsible for completing and maintaining the assessment
StatusWhere the assessment is in its lifecycle, such as draft, in progress, rejected or completed
Review dateWhen the assessment should be reviewed again
CollaboratorSomeone outside your MineOS team, or without full access, who you invite to answer specific questions

Assessment features at a glance

FeatureWhat it doesLearn more
TemplatesBuild custom templates or start from the MineOS catalogBuilding and managing templates
Creating assessmentsStart an assessment, assign an owner and set review datesCreate and manage assessments
Processing activitiesDocument the business purposes behind your data processingMap business purposes with processing activities
Linked recordsConnect assessments to risks, systems and other assessmentsLink assessments to risks and other records
Mira AI autofillDraft answers automatically using your data map, documents and business profileDraft assessment answers with Mira AI autofill
Collaboration and commentsInvite coworkers, leave comments and work on assessments togetherCollaborating on assessments
Custom viewsFilter and save views of your assessments listOrganize assessments with custom views
Audit log, versions and exportsSee every change, restore earlier versions and export for auditsTrack changes and export assessments

Why assessments matter

Many privacy and AI laws require documented assessments of higher-risk processing. GDPR Article 35 requires DPIAs for processing likely to result in high risk. Under the CCPA regulations and several US state laws, such as those in Colorado and Virginia, businesses must conduct risk or data protection assessments for activities like targeted advertising, selling personal data or processing sensitive data. The EU AI Act and DORA add assessment obligations for AI systems and ICT third-party risk. Keeping these assessments in one place, connected to live data, makes them easier to complete, maintain and show to regulators.



Did this page help you?