Introduction to Assessments
Learn how assessments work in MineOS, from templates to linked risks, and find the right article for every assessment feature.
Assessments are how you evaluate privacy, security, vendor and AI risk in MineOS. Whether you're running a DPIA, reviewing a new vendor or documenting an AI system, every assessment follows the same model: you start from a template, fill it in with help from your data map and Mira AI, and keep it current as your organization changes.
How assessments work
An assessment template defines the structure of an assessment: its sections, questions and answer types. MineOS includes a catalog of ready-made templates, such as PIA, DPIA, LIA, TIA, vendor risk and AI assessments, and you can build your own. [confirm current template catalog]
An assessment is a single instance of a template, filled in for a specific system, vendor, project or process.
What makes MineOS assessments different is their live connection to your data map. Questions can pull directly from your inventory, including data sources, data types, processing activities and employees. When your inventory changes, for example when you add a new SaaS tool, the connected answers stay up to date without manual rework.
📸 [IMAGE: Assessments list page]
Key concepts
| Term | What it means |
|---|---|
| Template | The reusable structure an assessment is based on |
| Owner | The person responsible for completing and maintaining the assessment |
| Status | Where the assessment is in its lifecycle, such as draft, in progress, rejected or completed |
| Review date | When the assessment should be reviewed again |
| Collaborator | Someone outside your MineOS team, or without full access, who you invite to answer specific questions |
Assessment features at a glance
| Feature | What it does | Learn more |
|---|---|---|
| Templates | Build custom templates or start from the MineOS catalog | Building and managing templates |
| Creating assessments | Start an assessment, assign an owner and set review dates | Create and manage assessments |
| Processing activities | Document the business purposes behind your data processing | Map business purposes with processing activities |
| Linked records | Connect assessments to risks, systems and other assessments | Link assessments to risks and other records |
| Mira AI autofill | Draft answers automatically using your data map, documents and business profile | Draft assessment answers with Mira AI autofill |
| Collaboration and comments | Invite coworkers, leave comments and work on assessments together | Collaborating on assessments |
| Custom views | Filter and save views of your assessments list | Organize assessments with custom views |
| Audit log, versions and exports | See every change, restore earlier versions and export for audits | Track changes and export assessments |
Why assessments matter
Many privacy and AI laws require documented assessments of higher-risk processing. GDPR Article 35 requires DPIAs for processing likely to result in high risk. Under the CCPA regulations and several US state laws, such as those in Colorado and Virginia, businesses must conduct risk or data protection assessments for activities like targeted advertising, selling personal data or processing sensitive data. The EU AI Act and DORA add assessment obligations for AI systems and ICT third-party risk. Keeping these assessments in one place, connected to live data, makes them easier to complete, maintain and show to regulators.
Updated about 1 hour ago
