Setting up your Universe
Who is this article for?
Users who need to structure their organisation's data hierarchy.
Create Location permission to add locations or Create Process permission to add processes is required.
Your Universe is the backbone of audit and risk management, defining where in your organisation data lives (Locations) and what activity it relates to (Processes).
This article uses the platform's default terms, location and process. Your administrator may have renamed these for your organisation, so the labels you see could differ.
Universe structure
Most operational records - risks, controls, objectives, tests, actions, incidents, and audits - are linked to a Location and often a process. Proper setup is important for two reasons:
- Data aggregates up the hierarchy, so parent locations or processes show combined scores, counts, and trends from all sub-levels.
- Locations and processes control visibility: linking user groups to them determines which records users can access.
Your Universe’s structure impacts both reporting and access control.
Recommended structure
General
Use these guidelines to structure your hierarchy effectively:
| Guideline | Recommendation | Why |
|---|---|---|
| Hierarchy depth | 3 - 5 levels | Too shallow lacks granularity; too deep becomes unmanageable |
| Children per parent | 5 - 15 levels | Too few makes the hierarchy unnecessarily deep; too many clutters views |
| Location levels | 3 - 4 levels | Align with reporting structure (e.g., Region → Country → Site) |
| Process levels | 2 - 3 levels | Align with process frameworks (e.g., Process Area → Process) |
By organisation size
Below are some considerations when deciding on a structure, depending on your organisation size.
Large organisation
A multinational with multiple legal entities and regulators usually creates a hierarchy:
- Region
- Country
- Legal Entity
- Site
- Legal Entity
- Country
Alongside a Process tree, e.g.
- Finance
- Procurement
- Accounts Payable
- Procurement
This allows granular access - local teams see only their site, while regional and group functions access broader levels. The Location and Process trees work together to grant specific combinations, such as "Procurement in the UK entity only."
Medium organisations
A single-country business with a few offices typically organises by department and location: one level of physical sites (e.g., Head Office, Manufacturing, Distribution) and a simple process tree by function (e.g., Operations, HR, IT, Finance).
Access is department-based, allowing leadership a clear, organisation-wide overview without complex nesting.
Small organisations
A single-site team benefits from a simple structure - one or two locations and a brief list of processes. Since everyone has full visibility, focus on keeping the Universe straightforward and categories clear for reporting.
You can expand the hierarchy as the organisation grows.
Tip
In many cases, it's wise to create a top-level Universe, allowing access to the entire universe through one group and process. This also consolidates all analytics.
Preparing for setup
Before building your Universe:
- You need permission to create records: Create Location for locations, or Create Process for processes. If controls are missing, contact your administrator.
- Plan your hierarchy before starting. It's easier to create records correctly than to reorganise later.
- Ensure your location and process types are set up. Type is required when creating records. If missing, an administrator can add it via list management.
- Locations and processes are managed separately but similarly. Follow the same steps, choosing the appropriate menu.
We recommend a phased approach to help determine whether the hierarchy you've built is effective before expanding it further.
Phase 1: Foundation
- Build the top two levels only (e.g., Regions and Countries for Locations; Process Areas for Processes)
- Link a pilot set of risks and controls
- Test with a small group of users
Phase 2: Expansion
- Add the next level (e.g., Business Units, Departments)
- Refine types and naming conventions
- Train additional users
Phase 3: Full coverage
- Complete the hierarchy
- Migrate remaining items from any legacy systems
- Establish ongoing governance
Ongoing: Refinement
- Review periodically as the organization changes
- Archive unused Locations/Processes
- Restructure as needed (note: moving nodes affects all descendants)
Accessing the Universe
To access the Universe:
- Go to Universe.
- Select Locations or Processes.
The Universe opens with a tree menu down the left showing your hierarchy, and a hierarchy diagram in the main area. - Use the search box at the top of the tree to find an item.
- Tick Include Archived to show archived records alongside active ones.
Creating a location/process
The platform uses a single create form - there is no multi-step wizard.
To create a new record:
- Click Create control.
The form opens in a drawer. - Complete the Parent field (optional).
Leave blank to create a top-level record, or select an existing record to nest the new one beneath it. - Enter the Title.
- Choose the relevant Type.
- Complete the Description field (optional).
- Click Save.
Tip
To add multiple records at once, click Add another to save and open a new form. Use the Parent field to create your hierarchy. Records without a parent are top-level; those with a parent become sub-records.
Creating a sub-location/sub-process
Sub-records (children) are just locations or processes that have a parent. There are two ways to create one.
Using the tree
To create a sub-record from the tree:
- Hover over the record you want to nest beneath in the left-hand tree.
- Click the Add (Plus icon) button that appears.
The create form opens with the Parent already set to that record. - Complete the form.
- Click Save.
Using a form
To create a sub-record from the create form:
- Start a new record as above.
- Select the Parent yourself.
- Complete the form.
- Click Save.
The new record appears indented under its parent in the tree. You can nest records to as many levels as you need.
Viewing record data
To view a record's data:
- Click any record in the tree (or in the hierarchy diagram) to open it.
- The record opens with a Summary displaying charts, scores, and tabs for related records like audits, objectives, risks, controls, tests, actions, incidents, groups, users (users in linked groups), and questionnaires.
Visible tabs depend on your licences. - Use the breadcrumbs above to navigate back up the hierarchy.
Note
Data rolls up: when you open a parent record, its Summary includes aggregation of the items within that location and all its sub-records. The tabs will only show records linked to that specific location, not all of its sub-records as well.
Exporting the Universe
To export your Universe:
- Go to Universe.
- Select Locations or Processes.
- Click the Export button on the toolbar above the diagram.
- Choose what to export:
- Export to Excel - a spreadsheet listing your Locations or Processes with their path, type and status
- Export to SVG - an image of the hierarchy diagram, useful for documents and presentations
Maintaining records
Archiving a record
Archiving keeps a record for reference but takes it out of active use; deleting removes it permanently.
To archive a record:
- Open the location or process you want to change.
- Click Options.
- Choose Set as Archived.
Archived records are hidden by default - tick Include Archived in the tree to see them.
Reinstating a record
To reinstate an archived record:
- Open it.
- Use the Set as Active command.
Deleting a record
To delete a record:
- Open the location or process you want to change.
- Click Options.
- Choose Delete.
- Confirm deletion in the pop up.
Important
Deletion is permanent and cannot be undone. Deleting a record that has sub-records affects the whole branch, so review it first. If you may need the record - or its history - again, archive it instead of deleting it.