Creating an Assessment

Overview

Assessment Manager allows you to create, distribute, and manage privacy and compliance assessments across your organization. An assessment consists of a survey sent to one or more respondents, with configurable approval workflows, scheduling, and reporting options.

This article explains how to create a new assessment, including how to complete each configuration section: Details, Managers & Respondents, Users, and Advanced Settings.

What you can do
Create a new assessment from an existing or custom template
Assign owners, approvers, and respondents — including external (non-system) users
Link the assessment to a Data Mapping & Risk Manager record
Configure scheduling, reminders, approval tiers, labels, and tags
Creating an Assessment

To create a new assessment, follow these steps:

1

From the left side of the page, hover over the Assessment Manager icon (1), then select Assessments (2).

Assessment Manager icon in the left nav with the Assessments option highlighted
2

In the upper-right corner of the page, click Create Assessment (3).

Assessments list page with the Create Assessment button highlighted in the upper-right corner
📋 Note: For some accounts, assessments must be created from a template. To use this method, hover over the Assessment Manager icon (1), then navigate to Template Builder (2). From the right side of any published template record, click the ellipsis icon and select Build Assessment.
Assessment Manager navigation to Assessment Templates
Assessment Templates list with ellipsis menu open showing Build Assessment option

 

3

From the New Assessment page, complete the fields in each of the following sections. See the detailed guidance below for each section.

4

When you are done, click Save as Draft to save the assessment without sending it, or click Publish & Send to publish and send the assessment to respondents immediately.

Details
New Assessment page — Details section

Assessment Name

Enter a unique name for the assessment.

Template

Select an existing Assessment Template — either pre-configured by TrustArc or by your company's privacy team — or create a new one. Templates that are associated with a particular assessment configuration are marked with an AAC indicator.

Template selection dropdown showing AAC-marked templates

An Assessment Template defines the questions in the survey, the question flow logic, the compliance and risk assignment logic, and many other aspects of the assessment.

For information on how to create custom templates, see Creating a New Assessment Template.

Record to Assess

If you have both Assessment Manager and Data Mapping & Risk Manager, this field allows you to associate the assessment with a record — such as a business process, company affiliate, primary company, department, system, or vendor. The template's question flow logic can then draw on information from that record. You can select two or more records at the same time.

To associate a new Data Mapping & Risk Manager record, click Add New Record and select a record type. The system redirects you to the relevant Data Mapping & Risk Manager page where you can create the record.

Record to Assess field showing the Add New Record option and record type selection

Description

Provide a clear, detailed description of the initiative — including relevant URLs if applicable. Where available, attach supporting documentation such as process flow diagrams or presentations. The description appears on the survey start page shown to respondents, and in email notifications sent to assessment stakeholders. Use it to explain the purpose of the assessment and provide instructions to respondents before they begin.

📋 Tip: In the upper-right corner of the Details section, click Generate Assessment URL to create a smart URL that automatically generates an assessment. For more information, see Creating a Smart URL to Automatically Generate an Assessment.
Details section showing the Generate Assessment URL link in the upper-right corner
Managers & Respondents
New Assessment page — Managers and Respondents section

Use this section to set the owner, approvers, and respondents for the assessment. For details on each role, see Understanding the Different Assessment Manager User Roles.

Assessment Owner

The assessment creator is the default owner.

📋 Note: Once the assessment is published, you can change the owner from the Edit Assessment page by clicking Reassign and selecting another system user. An acceptance notification email is sent to the new owner, who must click Accept Assessment Owner Reassignment to complete the change. If the Reassign link does not appear, contact TrustArc Support.
Edit Assessment page showing the Reassign ownership option

Owning Entity

Assign an owning entity to the assessment. The dropdown list contains all entities from the Organisation Hierarchy platform. If an entity is deleted or updated in Organisation Hierarchy, that change is automatically reflected in any associated assessments.

📋 Note: The Owning Entity field is only visible if you have admin access to Organisation Hierarchy.

Approvers

Each assessment must have one or more approvers, who approve the assessment after all respondents have submitted their answers. A reviewer — who can be the assessment creator, owner, or one of the approvers — is responsible for reviewing the submitted answers and resolving any identified issues.

Approvers can be added in tiers. Enter the first-tier approvers in the Tier 1 field (1) — the assessment creator is added by default. To add a subsequent tier, click Add New Tier (2) and enter the names of those approvers. Only system users can be added as approvers.

📋 Notes
There is no limit to the number of approval tiers.
Tier 2 approvers can only begin stamping their approval after all Tier 1 approvers have approved or failed the assessment.
An approver can exist in multiple tiers, but their approval is counted only once.
The majority rule still applies when determining whether the assessment reaches an Approved or Failed state.
When an approval routing condition is met, current behaviour still applies — the approval chain is not implemented.
For auto-generated and cloned assessments, the approval chain of the parent assessment is copied when configured to copy parent approvers.

Respondent

By default, the assessment is assigned to you — the creator. To assign it to someone else, remove your name from the System users field (3) and select the intended respondent. If that person is not yet registered, click Add New System User (4). Registration may take up to 30 minutes; the new user receives a password reset email once their account is active.

Respondent field showing system user selection

You can also assign the assessment to external individuals — for example, a contact at a vendor company. To do so, click the Non-system users field (5) and select the person from the dropdown. If they are not yet registered, click Add New Non-system User (6).

Non-system users field for assigning external respondents
📋 Note: If the third-party authentication setting is enabled, set the Non-System User PIN Setting (7) to Persistent PIN, One-Time PIN, or No PIN (the default). For information on enabling this setting, see Enabling the Assessment Link Authentication Setting.
Non-System User PIN Setting field
Users
New Assessment page — Users section

Participants

An Assessment Participant is a user who, without being assigned another role, has read access to the assessment and can view the respondents' answers. You can add multiple participants.

Non-System Participants

External users you wish to add as assessment participants.

📋 Note: Click Add New System User or Add New Non-system User if the person is not yet registered. Adding a system user may take up to 30 minutes; a password reset email is sent to the new user once their account is active.
Advanced Settings
New Assessment page — Advanced Settings section
Schedule

Assessment Expiration

The expiration date is the date after which respondents can no longer submit their answers, unless a privacy officer explicitly extends it or email reminders are configured below.

Allow Assessment to be Deleted

Setting this to No prevents users from manually deleting the assessment. To delete a protected assessment, the Assessment Creator, Assessment Owner, or a user with Admin or Data Privacy Officer privileges must first return to the Edit Assessment page and set this field to Yes.

⚠️ Warning: Once all respondents have submitted and the assessment moves automatically to the Survey Complete state while this setting is still No, it can no longer be changed back to Yes. To delete such an assessment, contact TrustArc Support at support@trustarc.com. See Deleting the Assessment for more information.

Workflow

Override the default workflow with the TrustArc default workflow without acceptance if you do not want to require remediation of identified issues before approvers can approve the assessment. For details on the difference between workflows, see Assessment Manager Workflows.

Assessment Config (advanced)

Select an assessment configuration to override specific settings inherited from the parent assessment. The following settings can be superseded:

Workflow
Email Templates
Respondents
Approvers
Start Reminders
Assessment Expiration

Email Reminders

Configure the assessment to send periodic reminders to respondents. Set the interval (in days) in the Email reminder frequency field (1). Once a non-zero value is entered, the Start reminders field (2) becomes available to set when reminders should begin. Use the Message to include in reminders field (3) to add a custom message to the automated reminder emails.

Email reminder configuration fields: frequency, start date, and custom message
📋 Note: Access links automatically emailed to non-system respondents expire 30 days after the assessment is published. The system then sends a new reminder with a fresh link every 30 days until the respondent submits.

Schedule and Revalidation

Click Configure next to Schedule and Revalidation to set assessment-level revalidation settings. For more information, see Configuring the Assessment Revalidation Settings on an Assessment Level.

Labels

Assign one or more custom labels to the assessment, regardless of whether custom fields are in use. Labels can be used to filter assessments on the Assessments page. Start typing the label name — the system displays suggestions based on labels already created by other users.

Labels can also be assigned to individual answer choices, so that when a respondent answers a question in a particular way, the system automatically assigns the corresponding label to the assessment. This is useful for tracking assessments where specific questions were answered in a specific way.

For more information, see Using Assessment Labels.

Tags

All tags and tag groups associated with Assessment Manager appear in this section. You can create a new tag value or associate the assessment with an existing value from a predefined tag group.

The order of tags in this section follows the ordering configured on the Associations page. For more information, see Changing the Order of Tags in the Assessment Wizard.

Related Documents

Click Comments & Attachments to add comments and supporting documents to the assessment. A commenting section appears below the link after you click it.

TrustArc Trust Center  ·  Creating an Assessment  ·  support.trustarc.com