Skip to content
fullCircle GRC

Product update

New in fullCircle: December 2025

New frameworks, built on the work you've done

December introduced Framework Deployment, a guided way to add frameworks that reuses the controls and evidence you already have. Service accounts give every integration its own API keys, and new locks keep signed-off risks and tasks from drifting.

Share
01Controls

Deploy a new framework on top of your existing program

Adding a framework shouldn't mean rebuilding your program. Framework Deployment walks you through it. Pick frameworks and scopes, choose pre-configured controls with recommended descriptions and mappings, and approve every change. You see how much you'll reuse before anything is created.

Guided steps: select, scope, configure, approve controls, approve evidence, deploy
Pre-configured controls and evidence from risk3sixty's library
Coverage before and after, with reused controls, reused evidence and hours saved
Replaced evidence keeps its files, owners, comments and scopes
Explore Compliance Management

Managers and Admins can deploy frameworks.

02Platform

Give every integration its own identity

Integrations that borrow a person's login break when that person leaves, and nobody can tell which system did what. Admins can now create service accounts with their own module access and API keys. API and MCP automations then run under an identity you control and can audit.

Service accounts with their own name, description and module access
Generate API keys, with created and last-used dates for each
Keys work with the REST API and the MCP Server
Explore the platform

Admins manage service accounts.

03Risk

Lock risks and tasks once they're signed off

An accepted risk or a finished task shouldn't change without anyone noticing. Managers and Admins can now lock risks and tasks, making them read-only for everyone else. Subtasks follow their parent's lock.

A lock on risk and task side cards
Locked records are read-only for everyone else
Subtasks follow their parent's lock
Managers can still assign owners

Also in this release

Smaller changes that make everyday work smoother.

RiskLink a risk to related risks in any register
ControlsRenumber controls and evidence within each domain or across all domains, with a preview first
EvidenceTag and scope files in Documents, with matching columns and filters
RiskRisk register exports list attached files
fullCircle AIfullCircle AI can read .txt files

See December's release in action.

Book a demo and we'll show you what's new, using the frameworks and workflows your team runs today.

Or see how audit-ready you are