---
title: "Getting started with Zovos"
summary: "Your first sign-in, how the workspace is laid out, where the daily work starts, and where to get help."
updated: "2026-10-07"
section: "Get started"
url: "https://zovos.ai/docs-getting-started.html"
---

# Getting started with Zovos

Zovos is the compliance workspace for every line of defense at community banks, credit unions and national institutions. First-line owners in the business handle their own tasks, attestations and vendor records, and they complete the risk and control self-assessments for their business units. The second line runs the compliance and risk program, and internal audit works behind its own independence wall. Zovos holds your frameworks, policies, controls, risks, findings and exam evidence in one place, and it keeps a record of who decided what. This guide covers your first session. If you are the person standing the workspace up for your institution, start with [Onboarding your institution](docs-onboarding.html) and read this alongside [Set up your team and SSO](docs-team-setup.html).

## Signing in

You sign in through your institution's own identity provider. There is no separate Zovos password to remember and no local account to manage. Your administrator grants access, and single sign-on carries your identity into the workspace.

If you were invited by email, your first sign-in is what accepts the invitation and turns your access on. Nobody can activate the account for you from inside the product, and that is by design. An account that has never signed in is an unverified identity, and we will not count one as an approver.

If sign-in is refused, contact your administrator first. The usual cause is a directory group or role assignment that has not been mapped yet, and that is fixed on your side of the connection. If your administrator confirms the mapping and sign-in still fails, [contact support](support.html).

Examiners do not sign in this way. A regulator gets a time-boxed, scope-limited session, read-only apart from a few fieldwork actions, that an owner grants for a named examination. See [Roles and permissions](docs-roles-permissions.html).

## The workspace at a glance

The layout is the same on every screen. The sidebar on the left holds the navigation, grouped by the work each person does. The top bar holds four things you will use constantly:

- The approvals pill reads **Approvals** and has a count beside it. It counts only the decisions *you* are entitled to make, so it is never a queue of other people's work. Open it and the drawer heads the list **Awaiting your sign-off**.
- The notification bell shows items routed to you.
- The command palette opens with **Command-K** (or **Ctrl-K**) and jumps to any screen by name without navigating.
- Your user menu holds the in-app help center and **Report a bug**. For owners, it also holds the control that grants an examiner access.

Two conventions are worth knowing on day one. First, anything you do not have permission to see is **hidden rather than greyed out**, so the workspace you see is the workspace you have. Second, panels that are withheld from your role render nothing rather than showing a fabricated zero.

## Find your starting point

The sidebar is grouped by the work each person does. Every group header folds, so you can close the groups you rarely open. If you hold one or more job families, the sidebar puts My work first and your families' groups next, and only those groups start open. The **All sections** switch at the top of the sidebar brings back the full order with every group open. Job families only arrange the sidebar. Your permissions still decide which items you see, and a group with nothing you can open does not appear at all.

Three groups belong to everyone. **My work** holds the Dashboard, Tasks & plans, Findings, Audit requests, Audit responses, the Obligations calendar, Drafts, Documents, and Agent runs. Audit requests and Audit responses are the auditee's side of internal audit, so they sit here and not with the audit function. **Library** holds your regulatory content. That means Frameworks, Governing docs, the Control catalogue, Control objectives, Citations & Authorities, Coverage, the Proposal inbox and the Content library. **Administration** holds Team, Governance, the Audit trail, and Settings. Exam prep, Supervisory actions, Reg updates and the other regulatory-change screens sit in the **Exams & regulatory change** group.

The rest of the sidebar follows the job families. Find the family closest to your job below and read its pages in order. At a community bank or credit union, one person often holds several families, so read every list that describes your work.

### Compliance, including fair lending & CRA

The **Compliance** group holds the Gap report, Monitoring & testing, Absence testing, Training oversight, the Advisory log, the CMS scorecard, Complaints, Disclosures, and Marketing reviews. HMDA and CRA sit under their own heading, **Fair lending & CRA**. A credit union's sidebar leaves CRA out.

1. [Frameworks & reg updates](docs-frameworks.html)
2. [Consumer compliance](docs-consumer-compliance.html)
3. [Monitoring & absence testing](docs-monitoring.html)
4. [Policies & documents](docs-policies.html)
5. [Findings & remediation](docs-findings.html)

### AML/CFT & fraud

The **AML/CFT & fraud** group holds the AML/CFT program, Fraud losses, and the Fraud case log. The AML/CFT program is where the AML/CFT officer evidences the five pillars. Fraud losses reads the fraud events in the loss-event register by channel, and the Fraud case log records the two-person SAR decision on each escalated case.

1. [AML/CFT program & training oversight](docs-bsa-program.html)
2. [Risk management](docs-risk-management.html)
3. [Connecting integrations](docs-integrations.html)
4. [Monitoring & absence testing](docs-monitoring.html)

### Enterprise & operational risk

The **Risk** group holds the Risk register, Assessments, KRIs, Appetite, Exceptions, Loss events, Emerging risks, and the Decision register. Assessments are the risk and control self-assessments, and Exceptions holds exceptions and waivers.

1. [Risk management](docs-risk-management.html)
2. [Controls & testing](docs-controls.html)
3. [Approvals & authority](docs-approvals.html)
4. [Findings & remediation](docs-findings.html)

### Third-party risk

The **Third parties** group holds TPRM, Partner programs, and Questionnaires.

1. [Third-party risk](docs-third-party-risk.html)
2. [Risk management](docs-risk-management.html)
3. [Findings & remediation](docs-findings.html)
4. [Connecting integrations](docs-integrations.html)

### Cybersecurity

The **Cybersecurity** group holds the Cybersecurity page, Security incidents and Continuity (BCM), the business continuity register. The Cybersecurity page brings together your information security and continuity frameworks, the findings and controls tied to them, the open security incidents with the notices still due on them, and the annual report to the board. **Security incidents** is the incident register, where each incident's notification deadlines are tracked. See [Cybersecurity](docs-cybersecurity.html).

1. [Controls & testing](docs-controls.html)
2. [Test with your AI assistant](docs-ai-control-testing.html)
3. [Business continuity](docs-business-continuity.html)
4. [Findings & remediation](docs-findings.html)

### Model & AI governance

The **Model & AI** group holds Model risk and AI systems. Model risk has two tabs, the Model inventory of your institution's models and the Model governance pack for the AI inside Zovos. AI systems is the registry of every AI use case in the institution.

1. [Model & AI governance](docs-model-ai-governance.html)
2. [How AI works in Zovos](docs-ai-in-zovos.html)
3. [Controls & testing](docs-controls.html)
4. [Findings & remediation](docs-findings.html)

### Credit risk review

The **Credit risk review** group holds the Loan universe, Credit reviews, and Review exceptions. A reviewer cannot be assigned a credit they originated or approved, and the universe holds loan references and no borrower names.

1. [Credit risk review](docs-credit-risk-review.html)
2. [Findings & remediation](docs-findings.html)
3. [Approvals & authority](docs-approvals.html)
4. [Roles & permissions](docs-roles-permissions.html)

### Internal audit

The **Internal audit** group holds the audit Universe & plan and audit Engagements. It is visible only to the audit function and the board. Management, including the chief compliance officer, does not see in-progress audit work, because management is the auditee.

1. [Internal audit](docs-internal-audit.html)
2. [Roles & permissions](docs-roles-permissions.html)
3. [Controls & testing](docs-controls.html)
4. [Findings & remediation](docs-findings.html)
5. [Audit trail & exports](docs-audit-trail.html)

### Board or Supervisory Committee

The **Board** group holds the Board portal. A credit union sees this group as **Supervisory Committee**.

1. [Board & governance](docs-board-governance.html)
2. [Approvals & authority](docs-approvals.html)
3. [Findings & remediation](docs-findings.html)
4. [Internal audit](docs-internal-audit.html)

### Executive management

Executives read across the program rather than working one register, so the reading path starts with the Dashboard.

1. [Dashboard & triage](docs-dashboard-triage.html)
2. [Risk management](docs-risk-management.html)
3. [Exam management](docs-exam-management.html)
4. [Approvals & authority](docs-approvals.html)
5. [Board & governance](docs-board-governance.html)

### Business-line owner

Business-line owners in the first line work their own tasks, attestations, vendor records, and self-assessments, so most of their day starts in My work.

1. [Tasks & action plans](docs-tasks-action-plans.html)
2. [Policies & documents](docs-policies.html)
3. [Risk management](docs-risk-management.html)
4. [Third-party risk](docs-third-party-risk.html)

## Where the day starts

Open the Dashboard. It leads with what needs you today rather than a wall of charts. You get a **Needs your attention** panel, overdue and at-risk work, the approvals queue, the findings tracker, framework health, recent agent runs, audit readiness, incoming regulatory updates, and recent activity. Every tile drills through into the register behind it, so triage is one click from the number. [Dashboard and daily triage](docs-dashboard-triage.html) covers that routine in detail.

If an owner has turned on the AI assistant connector, you can also ask the assistant you already use what is on your plate. It reads your open tasks, the attestations and certifications waiting on you, and your approvals queue, under your own role. It can create a task or comment on a finding or a risk after showing you a dry run, and it never approves or signs off anything. See [Connect your AI assistant](docs-connect-ai-assistant.html).

A new workspace also shows a short getting-started checklist, titled **Set up your compliance workspace**, which is the fastest honest path to a program you can show an examiner. Its four steps, in the product's own words, are these:

1. **Enroll your regulatory frameworks.** Pick the ones you are actually examined against, in the [framework library](docs-frameworks.html). Only an owner can enroll a framework, and until one is enrolled both the framework library and Citations are empty.
2. **Import your controls and policies.** Bring in your control baseline and upload your policy documents, so analysis is grounded in your real program. See [Policies and document management](docs-policies.html) and [Controls, testing and evidence](docs-controls.html).
3. **Run your first gap analysis.** This step has two prerequisites the checklist itself does not mention. First, the regulatory library has to be indexed for your workspace, or the agents decline to run rather than answer without sources. Confirm that with your Zovos contact before the first run. Second, choose **Run mapping** on the Gap report before you go to Agent runs. Mapping is what produces the gaps, and the Gap Analysis agent works against a gap that already exists. Agent output arrives as a proposal and never as a decision. See [How AI works in Zovos](docs-ai-in-zovos.html).
4. **Triage a finding.** Assign an owner, a due date and a root cause. See [Findings and remediation](docs-findings.html).

Two settings are worth correcting in the same sitting, because both ship with generic defaults. Your institution profile starts as a bank under one billion dollars in assets with no charter states recorded, and regulatory-change applicability is judged against whatever is there. Your workspace timezone starts on UTC, which skews the daily digest hour and calendar due dates until an owner sets it. Notifications, meanwhile, are delivered in the workspace. The product sends no email today, so nothing in this list will chase you by inbox. [Onboarding your institution](docs-onboarding.html) walks through the whole sequence.

## Where to get help

The product ships an in-app help center in your user menu, with task guides and the **Report a bug** entry point. A bug report carries the screen you were on and your recent actions, and you see exactly what is attached before it sends.

This portal is the fuller reference. If a term in the product is unfamiliar, start with the [glossary](docs-glossary.html). If something is behaving unexpectedly, start with the [FAQ and troubleshooting](docs-faq.html). For anything else, [contact support](support.html). Support is staffed Monday to Friday, 9am to 6pm Eastern. We usually acknowledge new requests within a week, and we prioritize anything blocking an examination.
