DocsHelp
What's new
Updated 2026-10-07
This page tracks what changed in Zovos from your side of the screen. That covers new areas, workflow changes, and anything that alters what an examiner would see. We keep it in plain English, and we only list changes that are live for customers.
October 2026
- Examiners can see more of what their access covers. Within the frameworks you grant, an examiner can now open the controls mapped to them with their tests and attestations, read your regulatory updates, obligations and documents, and search and follow links between those records. A request in the exam room links to the policy version that was in force, and your own impact assessments, internal audit work and suspicious activity report decisions stay out of view.
- Ready-made prompts for your AI assistant. One prompt prepares an exam request list by gathering the evidence on file and the gaps for each open request, and another writes a monthly compliance summary from your regulatory updates, overdue findings, key risk indicators and approvals. The assistant proposes next steps and you decide. Members whose access is limited to a business line can now search their own records from the assistant and look up and acknowledge their findings in Slack.
- Follow a record to everything it touches. Vendors, key risk indicators, risk assessments, exam requests, board meetings, decisions, models and AI systems now show their linked records, and a record ID printed elsewhere in the product opens the record it names. A linked record you are not permitted to open shows as restricted.
- See the same requirement across frameworks. A citation now lists the requirements in other frameworks that your control objectives cover alongside it, and says how closely each one matches. Two new control baselines, one for cybersecurity and one for AI and model risk, map each objective across frameworks such as the FFIEC information security booklet, NIST CSF 2.0, the CRI Profile, ISO 27001, SR 26-2 and the NIST AI RMF.
- Report credit risk review to the board. Each review produces an internal report that lists every credit reviewed, the rating differences and the open exceptions, and a board edition that carries totals only, as a PDF or a Word document. The board pack gains a credit risk review section that keeps overdue exceptions from earlier reviews in view.
- Ready for the new examination and MRA rules. The exam cycle screen works out the longest interval your regulator may allow before the next safety-and-soundness examination, condition by condition, and flags an expected date that falls after it. Examiner findings record the basis of a matter requiring attention and the date it was issued, and the findings register separates items issued before and after the rule that takes effect on November 2, 2026. An examiner observation can close on an independent sign-off alone, while every other finding needs remediation evidence before it closes.
- Cybersecurity has its own home. The Cybersecurity group brings your security frameworks, findings, controls and open incidents together, and a security incident register shows each notice your charter and the facts call for, with its deadline counted from the determination a named person records. The annual information security program report to the board is built from your registers, with the officer's recommendations written in a shared draft. An automated control test can now confirm that AWS Backup covers your resources with recent completed backups.
- Your AI assistant can now see your own work and read more of your program over the Zovos connector. Under your own role it can show your approvals queue, find a record by its ID, and read your findings, key risk indicators, vendors, regulatory updates, exam request lists and policies. It can also create a task or comment on a finding or a risk, each shown as a dry run and written only when you confirm.
- Limit access by business line. Access groups give their members a set of roles, and a group can be limited to a member's own records or to named business units. The limit applies to what members can read and to what they can change.
- Run credit risk review in Zovos. Loan review teams can load the loan universe, select a sample, record their rating of each credit beside the institution's rating, and track exceptions to closure. Reviewers are assigned under an independence check, and the lead reviewer attests before the review is submitted for sign-off.
- Track fraud losses and fraud cases beside your AML/CFT program. Fraud losses come from the loss event register, and a case log records each case with a two-person decision on whether to file a suspicious activity report. The log records the decision and not the contents of any report.
- The sidebar is organized around your job. Each member can be given one or more job families, such as BSA/AML, third-party risk or internal audit, and the sidebar opens with My work and the sections that family uses. Families only arrange the screen. What a member can open is still decided by their permissions.
September 2026
- Set how long a session lasts. An owner can set your institution's session lifetime between one and twelve hours, and a session left idle for 30 minutes ends. An owner can also record a dated attestation that your identity provider enforces multi-factor authentication, and Settings shows who attested and when.
- Model risk sections now cite SR 26-2 and OCC Bulletin 2026-13 as the operative guidance. SR 11-7 and OCC 2011-12 appear only as history, and the retired FFIEC Cybersecurity Assessment Tool no longer shows up as a live framework in packs, templates, exports, or the regulatory corpus.
- Keep your old record IDs when you migrate. The main registers hold the ID a record had in your previous system, imports match on it first, and each import screen offers a downloadable template.
- Connect your AI assistant. Zovos has an MCP server, so an assistant that supports the Model Context Protocol can answer questions from our documentation and read your controls, risks and obligations under your own sign-in and permissions.
- Test controls with your own AI assistant. An assistant can submit a control test with its evidence, and it arrives marked unverified in a review inbox where a person accepts or rejects it before it counts.
- A page for every area of the platform. zovos.ai now explains each part of the product on its own page, from regulatory change, controls and policies to risk, third parties, internal audit and exam management.
- From rule change to exam close-out. Take an exam from the report of examination through the board's review and your response letter into findings, let examiners upload documents in the exam room, see before-and-after rule text when a regulation is amended, and generate supervisory progress reports.
- Enterprise risk with appetite in force. Risk appetite cascades into limits on key risk indicators and business units, residual scores draw on live control evidence, and each risk shows its treatment plans, loss experience and the severe-but-plausible scenarios you capture.
- Internal audit, end to end. Plan an engagement, write the audit report as a document, take a structured management response, validate remediation in a follow-up, and issue the report to the audit committee.
- Consumer compliance you can show an examiner. A compliance-management-system scorecard across the four CFPB pillars, HMDA data scrubbing with quality and macro edits, complaint root causes that can raise a finding, training rosters that name who is delinquent, and a consumer-compliance exam package.
- Third-party and model risk, deepened. Vendor risk assessments on the same scoring scale as your risk register, questionnaire templates with SIG and CAIQ exchange, AI-assisted contract review you confirm clause by clause, and an annual third-party program report for the board.
- Approvals can be redirected to a different role. When the named signing role cannot act on a decision, it can be reassigned or escalated to another role that holds the authority, with a rationale on the record.
August 2026
- An onboarding guide joined the documentation portal, covering what Zovos provisions, what your identity team supplies, and the order an owner should work in on day one.
- This documentation portal launched. Guides for every area of the platform, a support page, an FAQ, and a What's new page, written in plain English for the people who run the program.
- A partner's own BSA/AML figures. Record a fintech partner's BSA/AML figures month by month, with where each one came from, and see them trended on the program.
- Thresholds on partner program figures. Set your own threshold lines on figures such as complaint volume and the age of the oldest open diligence item, and see when a partner program breaches one.
- Fintech partners answer your diligence themselves. Send a program's open diligence items to the partner contact as a scoped link, see which links are still live, and revoke one. Answers arrive marked unverified and await your review.
- Confidence on proposed gaps. A gap proposed by an agent shows the confidence behind it, on the same scale used everywhere else an AI proposal is reviewed.
- Review cadences, an advisory log and more. Disclosures carry a review cadence, fair-lending reviews can be scheduled, each examination type records its next expected date and preparation window, training programs link to the rules they teach, an advisory log records the questions your team answered and why, and a decision can record the earlier decision it supersedes.
- Internal audit sampling and co-source workpapers. Draw a re-performable sample from a recorded seed, test each item and conclude, and import a co-source firm's workpapers from a spreadsheet manifest.
- Bulk actions and saved views. Reassign or change the status of many findings, risks or vendors in one step, and save named views of your filters, sort and columns on the big registers.
- Your own fields and assessment templates. Define custom fields on the core registers, and clone a curated assessment template or write your own from scratch.
- Complaint response clocks and consumer harm. Complaints routed through the regulator's company portal carry their response clocks, and a finding records the redress, the consumers affected and where restitution stands.
- Keep your mass-notification tool in step with your continuity plans. A signed event goes out when a plan goes into force or an exercise is recorded, and a tab shows which endpoints are live.
- End a member's sessions. An administrator can list a member's active sessions and revoke one or all of them, and signing out ends a session immediately.
- A broader assessment template catalogue. Curated assessment templates now cover ACH, electronic banking, remote deposit capture, insider lending, UDAAP, CRA self-assessment and more.
- Supervisory actions. An area for consent orders, formal agreements, memoranda of understanding and matters requiring attention, holding each article, its dated milestones and the evidence of completion.
- Set your institution's timezone. A date-only deadline now means the end of that day in your zone, and the daily digest is built for your morning.
- Scoped API keys read your registers. A key can page through risks, assessments, controls, policies and third parties, with a last-updated stamp on every row for incremental pulls.
- The proof ledger is browsable. Read sealed events in order, with who sealed each and when, alongside the external anchoring runs. See the content packs available to you in a content library, and manage the tokens that feed readings into your key risk indicators.
- Board portal trends and receipts. Headline figures are plotted across board packs so directors see the direction of travel, and opening a pack records a receipt for that director.
- Comment threads with mentions. Findings and risks carry append-only comment threads, and mentions are limited to people on your roster.
- Send a filed policy for signature. Route a policy version's filed PDF to an attestation campaign or to named board signers, and the signed copy is archived as evidence against that version.
- Fixed statutory dates on the calendar. The obligations calendar understands deadlines a rule fixes on the calendar, lets you move an institution-set date onto your real board cycle, and rolls an obligation forward when you record the filing.
- Correct what you created. Edit a live policy's effective date, review cadence and board approval record. Mark a citation not applicable with your rationale, edit or retire internal authorities, and open a legal hold to see and change the documents it preserves.
- Spreadsheet imports everywhere. Every register importer accepts an Excel workbook as well as CSV, still with a dry run and per-row errors that do not abort the file, and each core register gained an audited export in the exact shape the importer accepts.
- Choose your own notification volume. Each person decides, per type of notification, whether it arrives immediately, waits for the daily digest, or stays off, and mentions are a type of their own. Email delivery is not switched on yet, and the screen says so. The choices are stored for when it is. When you grant an examiner access, the screen also tells you plainly whether the credential was delivered or whether you need to hand it over yourself.
- Tasks and action plans. Assigned, dated work in its own area, where an action plan groups ordered tasks with a progress rollup and a triaged regulatory change can become a plan with an owner and a task per line.
- Search your records from the keyboard. The command palette searches records across the product, not just navigation, and a pasted record ID is the first result.
- More dates reach the calendar. Partner program review dates, board meetings and complaint deadlines now appear on the obligations calendar alongside everything else.
- Disposition review. Records that reach the end of their lifecycle queue for an explicit human decision instead of aging out silently. Nothing is disposed of automatically, and a record under legal hold cannot be reviewed until the hold is released.
- Partner program oversight. A dedicated area for banking-as-a-service and fintech partner programs, with program-level risk and oversight records, periodic reviews on a cadence, and a wind-down checklist tracked like a runbook.
July 2026
- An integrations directory. Settings now lists the available integrations by category, and each one says what it reads and the permissions it asks for before you connect it.
- Single sign-on and directory sync you can see. Settings shows your directory provisioning status and event log, guides your identity team through Entra ID, Okta or Google Workspace, and lets an owner map directory groups onto Zovos roles.
- Bring your Word policies in and publish them out. Import a Word document as an editable draft, redline it with tracked changes, route policies to the board and procedures to management, and file a branded, locked PDF of every published version.
- Workspaces for the rest of the GRC team. Internal audit, model risk, training oversight, marketing and disclosure review, loss events, risk appetite and board meetings each gained their own area, with internal audit walled off from the teams it audits.
- Exam rehearsal and enforcement intelligence. A mock examiner that works your first-day letter, an enforcement radar that scores peer enforcement actions against your own controls, a time machine that shows your program as it stood on any past date, and a launch check that lists the obligations a new product brings.
- A much broader regulatory library. The framework library added consumer-protection rules such as Regulation B, Regulation DD, RESPA and HMDA, security standards such as NIST CSF 2.0 and SOC 2, and control and audit frameworks such as COSO and the IIA standards.
June 2026
- HMDA data-integrity checks. Load your HMDA loan application register and see the records that fail the federal data edits before you file.
- AI-drafted questionnaire answers. Zovos drafts answers to due-diligence and security questionnaires from your own evidence, with the source cited for each, for you to review before anything is sent.
- Regulatory change that applies to you. New rules and guidance from the federal agencies arrive continuously, are tagged against your frameworks and products, and come with AI-proposed impacts on the policies and controls they touch, queued for your review.
- Complaint oversight. Log or import complaints, capture the root cause, link them to the policies, controls and findings involved, and see trends and an export for the exam binder.
- Policy templates for financial institutions. Start a new policy from a library of starter templates written for banks and credit unions instead of a blank page.
- Write policies together in real time. Several people can edit the same draft at once and see who else is in the document and where they are working.
- Vendor due diligence. Send a vendor a due-diligence questionnaire and collect its documents in one place, tied to the vendor's record.
- Access reviews. Run a periodic recertification campaign in which reviewers record a keep-or-remove decision on each person's access, and keep the result as evidence.
- Risk and control self-assessments. Run an RCSA from launch through rating and attestation, with each assessment's history kept on the record.
- A portal for examiners. Give an examiner time-limited, read-only access to their request list and the evidence you have attached to it.
- An AI policy drafter. Ask for a first draft of a policy and it arrives as an editable draft, citing the regulations it draws on, for your team to review and revise.
- Every AI result waits for a person. Agent output is queued for human review, and a reviewer accepts, edits or rejects it before it becomes part of the record.
- A trust center for your institution. Publish your security posture on a public page, share sensitive documents behind an NDA, answer security questionnaires from a reusable library, and let subscribers hear about updates.
- Framework coverage at a glance. Open any framework to see its requirements and which of your controls and policies cover each one.
- Key risk indicators with thresholds. Set numeric thresholds on each indicator and its red, amber or green status follows from the readings you record.
- Remediation deadlines that enforce themselves. Findings carry remediation due dates, and overdue remediation is flagged.
Cadence
We ship continuously and collect notable changes here monthly. Some changes affect your examination story, such as a change to a report format, an export, or audit-trail behavior. Those appear in this list the month they land.