Oreno GRC documentation

Start with the work you need to complete.

This guide explains how records connect across Oreno. The exact screens and permissions available to you depend on your tenant and assigned role.

01

Before you begin

Sign in through your organization’s Oreno address. Your role controls what you can view or change, and records are scoped to your organization.

If something is missing

Ask your tenant administrator to confirm your organization, role and module access. Do not share another person’s account.

02

Move from the audit plan to evidence

  1. Plan the engagement.Set the engagement, objectives and assigned work.
  2. Perform procedures.Record the work completed and retain supporting evidence.
  3. Raise issues.Capture the finding in Oreno and connect recommendations to it.

03

Keep issue follow-up in one chain

ISSUEWhat was identified
RECOMMENDATIONWhat should change
FOLLOW-UPProgress and evidence
RETESTAssurance and closure

An open issue with a target remediation date before today is overdue. When the necessary date is missing, Oreno does not invent an overdue result.

04

Use the module that owns the record

RiskRisk registers, assessment and treatment.
ComplianceRequirements, controls and evidence.
ContractsAgreements, obligations and renewals.
DocumentsControlled files and supporting records.
LegalMatters, actions and related documents.
AI governanceAI inventory and governance work.

05

Reporting follows the same source records

Reports should reflect the records maintained in Oreno. Tenant administrators can manage approved integrations such as Power BI from Application Administration; ordinary users and report viewers should never handle integration credentials.

Ask about Oreno GRC