![]()
SimpleRisk 20260828-001 — Audits Reworked, AI Analysis Stays Current, and More Security Hardening
This release brings a redesigned audit workflow, AI risk analysis that keeps itself current automatically, and another round of security hardening across the application, alongside a batch of fixes to imports, workflows, and single sign-on.
Highlights
Manage Audits and Initiate Audits, rebuilt. The separate Active Audits and Past Audits pages are gone, replaced by a single Manage Audits view with filters, bulk actions, and columns you can customize per user. Initiate Audits gets the same treatment, so starting new audits and tracking existing ones now share a consistent, faster interface.

AI risk analysis that stays current on its own. Previously, AI-generated risk analysis could go stale as a risk's connected records changed. It now automatically re-runs when those connections change, so the analysis you see reflects the current state of the risk without you having to trigger a refresh.
More security hardening. This release continues our ongoing security review: authorization checks were strengthened on API endpoints, workflow outbound actions, risk associations shown in Compliance, and risk-management review actions, and a data-isolation gap in cached AI analysis results was closed so results respect team-separation boundaries.
Other improvements
Several fixes round out this release: default risk-workflow emails now send correctly on instances without the Workflows Extra installed, a large policy's associated controls no longer silently drop on save, data grids no longer fail to load after importing data with special characters, and the Self-Assessments status and by-control filters work again. Vulnerability findings now match correctly to assets on InsightVM, InsightVM Cloud, Nexpose, and Qualys imports, and a workflow-picker decryption issue on instances running the Encrypted Database Extra is fixed. We also resolved an issue that could prevent SAML-based single sign-on from working.
Upgrading
The upgrade is delivered through the standard SimpleRisk upgrade flow. As always, we recommend backing up your database before applying any release in production.
For the full list of changes, see the release notes. For upgrade instructions, see the SimpleRisk admin guide. If you run into anything unexpected, our support team is here to help.