RegScale 6.32.2.0
[6.32.2.0] 07-19-2026
Enhancements
AI & RegML Improvements
- Expanded AI provider compatibility with improved support for Azure OpenAI, AWS Bedrock, and OpenAI-compatible endpoints, providing greater deployment flexibility across enterprise environments.
- Improved configuration and validation for AI services with clearer error messaging and streamlined setup for embedding providers and API authentication.
- Enhanced RegML guidance, learning resources, and user experience with clearer instructional content and improved workflow navigation.
- Added feature flag support for additional AI-powered capabilities, allowing organizations to enable new functionality in a controlled manner.
- Improved long-running AI operations with better handling of complex SSP authoring, auditing, evidence mapping, and response automation scenarios.
AI Report Builder
A new RegML AI agent turns plain-language requests into a ready-to-run report. Users describe what they want to see (i.e. show me all open issues with the name and status of the security plan they belong to, grouped by severity) and the agent drafts the entire report: it picks the right module, selects the fields, applies filters and grouping, joins in related modules, and even configures the chart.
Change Log Feature
This new scorecard tab within a Security Plan displays every control implementation change made within a time frame you select, grouped by control family, with drill-down into the field level for before and after comparisons.
Control Inheritance
Expanded Control Inheritance Capabilities
Control inheritance has been enhanced to provide a more complete and consistent experience for organizations leveraging shared compliance implementations. In addition to inheriting configuration settings such as assessment frequency, parameters, and control ownership, administrators can now choose to inherit associated evidence and assessment records, reducing duplicate effort and improving consistency across inherited controls.
Identity & Access Management
- Expanded SSO provisioning capabilities with support for additional application-specific user claims and improved synchronization of application access during user provisioning.
- Enhanced profile management and user administration with improved account management workflows and more intuitive administration experiences.
- Improved role-based access controls to better align permissions with administrative responsibilities throughout the platform.
Reporting & Analytics
- Added enterprise reporting enhancements to provide greater flexibility for creating and managing reports.
- Improved report filtering and support for date and time custom fields, enabling more accurate reporting and analysis.
- Enhanced dashboard reliability and data presentation across scorecards, visualizations, and reporting widgets.
Workflow & Automation
- Improved workflow management with enhanced workflow designer capabilities, notification processing, and automation reliability.
- Added batch API support for additional record types to improve performance when managing large datasets through integrations.
- Enhanced evidence approval and workflow collaboration capabilities.
Platform & Administration
- Improved export builder capabilities to provide more reliable document generation and token replacement.
- Enhanced application configuration and feature flag management for improved administrative control.
- Improved documentation accessibility and platform guidance throughout the user interface.
Fixes
User Experience
- Resolved multiple interface issues affecting dialogs, modals, date pickers, navigation, tab behavior, spacing, styling, and responsive layouts across user experiences.
- Corrected several display issues involving user names, organization fields, metadata presentation, read-only fields, dashboards, and status boards.
- Fixed inconsistencies in menus, action buttons, and contextual navigation to provide a more intuitive user experience.
Forms & Custom Fields
- Fixed issues affecting Form Builder, Rule Builder, questionnaires, and custom field processing to ensure rules, values, and conditions are saved and applied correctly.
- Resolved problems with date, date/time, checkbox, and filtering behavior for custom fields throughout reporting and forms.
- Corrected issues preventing questionnaire file uploads and improved questionnaire navigation and editing.
- Resolved issue where custom user dropdown fields auto-fill the wrong name. Custom name/user dropdown fields built with the Form Builder could display a name simply when the field was hovered over.
- Addressed issue which prevented stale custom-field values from crossing between modules.
Security & Permissions
- Fixed multiple permission validation issues affecting workflow designers, application administrators, external users, cause code management, and workflow access.
- Corrected several authorization inconsistencies to ensure users receive the appropriate access based on assigned roles.
- Strengthened HTML rendering protections to further reduce exposure to cross-site scripting (XSS) risks.
Compliance & Assessments
- Resolved issues affecting control implementations, security profiles, SSPs, questionnaires, CCIs, POA&M workflows, FedRAMP exports, and eMASS integrations.
- Fixed validation and save issues impacting maturity assessments, continuous monitoring, evidence mapping, and control ownership.
- Corrected several issues affecting control metadata, inheritance, responsibilities, and profile application.
- Improved Synchronization of Inherited Control Status
- Resolved an issue where inherited controls only copied the source control's status at the time inheritance was established. Inherited controls now remain synchronized with the source control's status, ensuring compliance posture accurately reflects changes made to the originating control.
- Resolved an issue that prevented inherited controls from including evidence associated with the source control. Customers can now optionally inherit evidence as part of the control inheritance configuration, streamlining evidence reuse across related compliance programs.
- Resolved an issue where assessment results were not inherited with controls. Customers can now optionally inherit assessments from the source control, providing greater visibility into inherited compliance activities and reducing the need to recreate assessment records.
Reporting & Exports
- Fixed multiple export reliability issues affecting FedRAMP, OSCAL, eMASS, report exports, custom exports, and document generation.
- Corrected report builder issues involving custom fields, dashboard data, report accessibility, and export formatting.
- Improved handling of incomplete or missing data during export operations.
APIs & Integrations
- Corrected several API validation and error handling issues to provide more accurate responses and improve integration reliability.
- Fixed issues affecting application provisioning, batch processing, deviation creation, export endpoints, and data validation.
- Improved consistency across REST APIs by returning appropriate validation responses instead of unexpected server errors.
Dashboards & Data Integrity
- Fixed dashboard rendering issues, data rollup inconsistencies, scorecard calculations, and stale data presentation.
- Resolved several issues affecting dashboard permissions, access control, and inventory reporting accuracy.
Notifications & Email
- Fixed issues preventing notifications from being generated during record reassignment.
- Corrected inconsistent email history displayed on user records.
- Resolved issues affecting evidence request email links and approval workflow comments.
Platform Stability
- Resolved numerous stability issues related to upgrades, application provisioning, feature flags, background processing, validation, and data integrity.
- Improved reliability of application configuration, imports, workflow processing, and catalog synchronization.
- Corrected several edge cases that could lead to unexpected errors when processing incomplete or invalid data.
- Resolved issue where expired passwords no longer lock users out. Previously, when a user's password expired under a tenant's password-rotation policy, they could be logged out and returned to the login screen without ever reaching a working Change Password page.
- Fixed an issue that prevented the system from automatically capturing a snapshot of record data when a workflow was saved without a snapshot supplied by the browser. Server-side snapshot capture now works as intended, ensuring workflow history reflects the correct record state.
