Ideagen Internal Audit and Risk Management v2.7.0 release notes
Who is this article for?
Administrators wanting to learn more about this solution release.
No special access or permissions are required.
We're excited to introduce our latest release – the release that brings Mazlan, Ideagen's AI, to Ideagen Internal Audit and Ideagen Risk Management customers. Ask questions about your audits in plain language and get answers drawn from your own data, without building a query or leaving the page. Alongside this, audit reports now generate from the report templates you design yourself, assessment history arrives on audit risks and controls, and there are substantial improvements to queries, filtering, copying, and everyday reliability across the product.
This article outlines the full changes, enhancements, and fixes that have been implemented in this release, available from 24 September 2026.
Features
Using Mazlan in Ideagen Internal Audit and Ideagen Risk Management
Mazlan is now available in Ideagen Internal Audit and Ideagen Risk Management. You'll find a new AI button in the header on every page. Select it and a chat panel opens, ready to answer questions about your audit and risk data in plain language.
Mazlan understands where you are. Ask a question while you're working on an audit and it answers in the context of that audit — searching across objectives, risks, controls, tests, findings, and actions to find what you need. Ask while you're on a specific record and it narrows further still. You can also ask about a particular audit by name from anywhere in the product, or search across your whole instance when you're not working inside a single audit.
A few examples of what you can ask:
- "Which findings in this audit are still open and high severity?"
- "Show me the actions assigned to me that are overdue."
- "What controls in this audit haven't been tested yet?"
Your data stays your data. Mazlan only ever sees what you are already permitted to see — every question is answered against your own access rights, so it cannot surface a record you couldn't open yourself. Mazlan suggests, finds, and summarises; it never changes your records on your behalf.
Mazlan is switched on for everyone by default. There's nothing to request and nothing to configure to start using it. If your organisation would prefer not to use AI features, your administrator can turn them off for everyone at any time by going to System Settings, opening the new AI section, and switching on Hide Mazlan. Every reference to Mazlan then disappears from the product for all users, and the setting can be switched back at any point. The change takes effect without anyone needing to sign out and back in, and like every other system setting, it is recorded in your audit trail so you can see who changed it and when.
Note: All customers have the ability to use Mazlan in Ideagen Internal Audit and Ideagen Risk Management as part of v2.7.0. In a later release (to be determined), this functionality will only be available to those customers that have a Premier or Standard Customer Success Plan.
Using Mazlan in Mazlan Home (in conjunction with v2.7.0)
Mazlan AI Assistants are also available in Mazlan Home, for those customers with a Premier or Standard Customer Success Plan. Within Mazlan Home, in addition to the existing chat bot, a number of AI Assistants have been added. These include assistants such as:
- Audit Finding Assistant – Drafts a clear, structured audit finding from your rough notes, ready to share or paste into your audit system
- Flowchart Assistant – Creates a process narrative and flowchart from walkthrough notes or a procedure document, with control points and risk areas marked
- Risk List Assistant – Identifies a starter set of candidate risks for a process or business area or pulls them from a document you upload
Note: These AI Assistants that are available within Mazlan Home do not yet integrate with Mazlan in Ideagen Internal Audit and Ideagen Risk Management.
If you do not wish to have this functionality enabled, please let your Account Manager know.
Generating audit reports from your own templates
Audit reports now only generate from report templates. When custom reporting arrived in v2.6.0 you could design your own Word and PDF documents for audits, registers and quality risks — but audit reports themselves were still produced by the product's original fixed report builder, which couldn't use your templates.
Using new ready-made report blocks
Two more blocks assemble themselves in a single step, so content you've already recorded doesn't need retyping into a report:
- A Description block, available on every template type, which inserts a heading and pulls in the record's own description with its formatting intact
- An Audit Introduction block for audit templates, which brings across both the audit's description and its background under their own headings
Viewing assessment history on audit risks and controls
Audit risks and audit controls now have their own Assessment History. Universe risks and controls have offered this for some time; now the equivalent records inside an audit do too, so you can see how a rating has moved over time without leaving the record and judge how much confidence to place in the current conclusion.
The history lists that record's assessments newest first, showing when each was created and by whom, along with its type, method, score, rating band and origin. Sorting and filtering work the same way as on the universe view, and residual risk assessment visibility follows your existing system setting. Where a record has no assessments yet, you'll see a clear message rather than an empty grid.
Preserving original authors when copying assessments
When you bring assessments or test results into an audit using a Get From workflow, they now keep the person who originally performed the work and the date they did it — rather than being stamped with whoever ran the copy. Previously, every copied assessment looked as though it had been created by the person copying it on the day they copied it, which made assessment history misleading.
This applies across Get From Audit, Get From Universe and Get From Library, and to inherent risk assessments, residual risk assessments, and actual control assessments. Where an item had been copied before, the true original author carries all the way down the chain. Existing records are not altered, and where an original author has since left your organisation, the record still displays safely. You can still see that an item was brought in from elsewhere through the origin information introduced in v2.6.0.
Controlling what to include when rolling an audit forward
Rolling an audit forward now respects your choices. Previously, the roll forward always brought everything across — every linked risk, control, and test, and an automatically widened scope — whether you wanted it or not. You can now choose exactly what comes over, using the same options you already know from Get From Audit: whether to expand scope, whether to include risks, controls, and tests, whether to include attachments, and whether to bring across inherent risk assessments, residual risk assessments, actual control assessments, and test results. Defaults match how the product behaves today, so nothing changes unless you choose to change it.
Selecting all when bringing content across
Every Get From workflow now offers Select all and Clear when you're choosing items, so populating or resetting a long list takes one action instead of dozens of individual ticks. Both work on the items you can currently see — matching your search term, your filters, and the page you're on — and anything you selected under a different search or filter stays selected. Where a list is grouped into sections, you can select a whole section at once.
This works identically in Get from Audit, Get from Universe, Get from Library into an audit or the universe, Origin Sync, and when selecting existing records into the risk register and child grids.
Building richer queries
Incidents can now be pulled into queries from elsewhere. Incident is now available as a sub-query beneath objectives, risks, controls, and actions, so you can extract the incidents linked to your risk and control universe and to your remediation work in a single output rather than cross referencing by hand. It works in the other direction too: a query starting from incidents can now bring in objectives, risks, controls, and actions. Tests are not included, because the product doesn't link incidents to tests.
Risk Profile fields are now available in risk queries. A new expandable Risk Profile section in the field selector lets you include Risk Perspective, Risk Source, Risk Effects and Principal Risk in your results, each appearing as its own column in the output and in exports.
Seeing how each risk is being treated
The latest residual quality risk strategy now appears on the risk record, as a read-only Risk Strategy field on both universe risks and audit risks — so you can tell how a risk is being treated without opening each assessment in turn. It's available as a column in Views and the risk register, as a filter, and in your masthead configuration. The field is blank until a residual risk assessment has been completed and is only ever set through that assessment, and it's hidden everywhere if you've switched off residual risk assessments in your system settings.
Filtering and finding more of your content
Roles are now available as register filters. The filter bar introduced on the main registers in v2.6.0 offered standard and custom fields; it now also lists every role configured for that register — risk owner, control owner, and any others you've defined — so you can narrow a register down to the records assigned to particular people. Your role filter chips and their values are remembered as you navigate, just like your other filters.
Archived list values can now be included in filters. Filter dropdowns that draw their options from your configurable lists previously showed active values only, which meant records still holding a value you'd since archived couldn't be filtered to at all. An Include archived toggle now sits at the top of those dropdowns. Leave it off and nothing changes; switch it on and archived values appear, clearly marked, ready to select. Switching it back off hides them from the list but won't silently drop an archived value you've already applied. This covers both standard and custom list filters.
Global search reaches further. Problems, Principle Risks, Views, and Queries are now returned by global search and selectable in the perspective filter, so you can jump to them from the navigation bar instead of going to their registers. As always, results respect your licensing, your system settings, and what you're permitted to see — anything you've hidden won't appear.
Accessing test result guidance where you need it
When your administrator writes a description for a test result value explaining when to use it, that guidance now reaches the auditor. Hovering or keyboard-focusing a result option in the perform tray shows its description in a tooltip, so your team rates tests consistently and against the same understanding. Values without a description simply show no tooltip. The guidance is instant, because it comes from information the screen has already loaded.
Protecting against losing unsaved work
Refreshing the page, using your browser's Back control, or closing a tab partway through a workflow could previously discard everything you'd entered without warning. Your browser will now confirm before you leave, whenever there's unsaved work to lose — covering refreshes, tab closures, and moving around within the product. Once you've saved or deliberately discarded your changes, leaving is quiet again, as it should be.
Working with documents
You can now see which documents are locked, straight from the register. A lock icon appears beside the name of any Office file currently held for editing, so you know why editing may be unavailable without opening the document. A file being co-authored rather than locked shows a "being edited" label instead.
View files without downloading them. PDFs, images and other read-only formats previously offered nothing but Download. A View command now opens them read-only in a new browser tab, using the standard viewer for that file type with its own scrolling for longer documents. It's available on attachments, reports, and audit reports wherever you're permitted to view the file.
Getting more accurate summary cards
Summary cards were counting records that shouldn't be reported on, and did so inconsistently between chart types. They now count only live records, consistently, across every chart on the card including heat maps and gauges. On audits, audit objectives, audit risks, and audit controls, closed and cancelled records are excluded. On risks, registers, objectives, principal risks, locations, and processes, draft, closed, cancelled and archived records are excluded.
Note: Your summary card figures may change when you upgrade, usually downwards. This is the intended correction - records that were never meant to be counted are now properly excluded.
Fixes
This release includes a wide range of fixes for reliability and accuracy across the product:
Reporting and Report Designer fixes
- Fixed a missing space between a paragraph and an immediately following table in generated report output.
- Fixed rich text fields bound into a report template exposing their markup instead of rendering as formatted text.
- Fixed a regression where a Risk-perspective template using a Risk Source data source failed to generate, leaving the report in a failed status with no console error.
- Fixed the Target Assessment Date field exporting from Views to Excel as a raw timestamp rather than a date, making it unreadable and unusable in the spreadsheet.
- Fixed the Audit Test Comment field displaying as a missing-resource placeholder in the Reporting column selector.
Audit and execution fixes
- Fixed an error page being shown when opening a Step from the Origin panel inside an assessment.
- Fixed the test result comment field on the masthead not truncating long values, so the page scrolled instead of offering the pop-out used by other long text fields.
- Fixed the test result comment field being mislabeled on the masthead.
Risk and assessment fixes
- Fixed a missing-resource error that prevented inherent and residual assessment of existing risks for all users including administrators, while newly created risks assessed successfully.
- Fixed Library Risk and Risk Matrix copies being rejected outright when a linked classification had since been archived.
Register and questionnaire fixes
- Fixed long customer-defined values in colored list cells truncating with no tooltip to reveal the full title.
- Fixed custom list item descriptions not being shown to respondents completing a questionnaire, even though the descriptions were saved and visible in the list configuration.
Third-party integration fixes
- Fixed unscoped global styles in the shared component library overriding Gainsight survey and engagement styling, which caused in-product surveys to render incorrectly. Input and text-area selectors are now scoped to elements the shared components own, so they no longer apply to markup injected by other scripts on the page.