Initiatives

The Initiatives module helps organisations identify and address privacy, security, AI governance, and compliance requirements early in the lifecycle of a new project, vendor, product requirement, business process, or other internal change.

Teams can submit structured information through TrustWorks, Slack, or Microsoft Teams. Privacy and compliance teams can then review the Initiative, document its data mapping, run Assessments, connect related records, manage Risks, and use AI-generated Insights to turn identified requirements into actions.


Before you begin: configure Initiatives

Administrators can configure Initiative Types, type-specific intake fields, and AI-assisted Insight generation from Settings > Initiatives.


Configure Initiative Types

Initiative Types help distinguish between different intake workflows, such as a vendor onboarding request, new business process, or AI use case.

TrustWorks includes the following default types:

  • Business Process
  • Product Requirement
  • Project
  • Vendor Onboarding

The default types can be edited but cannot be deleted. Administrators can also create additional custom types to reflect their organisation's workflows.

To create an Initiative Type:

  1. Go to Settings > Initiatives > Initiative Types.
  2. Click + New Type.
  3. Enter a name and description.
  4. Set the type as active and save it.

To update an existing type, click the edit icon beside it. Custom types can also be deleted when they are no longer needed.


Configure custom fields for Initiative Types

Custom fields allow you to collect additional information relevant to a particular Initiative Type. A field can appear for one type, several types, or remain outside the intake form and only be available within the Initiative's additional information.

To assign a new custom field to one or more Initiative Types:

  1. Go to Settings > Custom Fields.
  2. Click + New Custom Field.
  3. Enter the field details and select Initiative as the related object.
  4. Select the relevant values under Initiative Type.
  5. Save the custom field.


Configure the intake form

Use the Intake Form tab to control which custom fields are collected during Initiative intake.

For each available custom field, administrators can:

  • Make the field active or inactive in the intake form.
  • Make an active field mandatory or optional.
  • Control the order in which fields are displayed (in additional info on any initiative's page).

The standard fields Name, Description, Type, and Reference Documents are included in every intake form. Name, Description, and Type are mandatory, while Reference Documents are optional.

The form shown during intake adapts to the selected Initiative Type. Required fields must be completed before an Initiative can be submitted through Slack or Microsoft Teams.


Enable automatic AI-assisted Insights

Administrators can choose whether TrustWorks automatically generates AI-assisted Insights for newly created Initiatives.

  1. Go to Settings > Initiatives > Other Configurations.
  2. Enable or disable Automatic AI-Assisted Insights Generation.

When this option is enabled, TrustWorks starts generating Insights after an Initiative is created. When it is disabled, users can generate Insights manually from the Initiative by clicking AI Assistant.

Note: the insights will be automatically generated for Initiatives submitted via Slack and MS Teams. For initiatives that are manually created, insights must be triggered manually.


Creating  an Initiative

Initiatives can be created directly in TrustWorks or submitted through an enabled Slack or Microsoft Teams integration.

Create an Initiative in TrustWorks

  1. Go to Initiatives.
  2. Click + New.
  3. Complete the Initiative details:
    • Name: Enter a clear name for the Initiative.
    • Description: Explain the purpose, scope, and relevant processes.
    • Status: Select the Initiative's current stage.
    • Type: Select the relevant default or custom Initiative Type.
    • Owner: Assign a user or team responsible for the Initiative.
    • Reference Documents: Add relevant files, URLs, or text.
    • Custom fields: Complete any additional fields configured for the selected Initiative Type.
  4. Click Create.

Newly submitted Initiatives display a New badge in the Initiatives list and on the Initiative details page. The badge is removed after a user updates the Initiative or changes its status and saves the change.


Submit an Initiative through Slack or Microsoft Teams

If the relevant integration has been enabled, business users can submit Initiatives without navigating to TrustWorks.

  1. Start the Initiative submission flow from Slack or Microsoft Teams.
  2. Select the Initiative Type.
  3. Complete the corresponding intake form.
  4. Submit the Initiative.

The form changes according to the selected type and prevents submission until all mandatory fields have been completed.

TrustWorks identifies the submitter and assigns them as the Initiative owner. If the submitter already exists in TrustWorks, the existing user is assigned. If no matching user is found, TrustWorks creates an imported user with the Contributor role and assigns that user as the owner. This ensures that reviewers can always see who submitted the Initiative and contact the correct person for follow-up.


Working with an Initiative

The Initiative details page brings the Initiative's core information and related compliance work together in one place. Depending on the features enabled for your organization, it can include the following tabs:

  • Insights
  • Data Mapping
  • Reference Documents
  • Risks Management
  • Assessments
  • Related Objects
  • AI Use Cases
  • Comments
  • Additional Information

Insights and actions

The Insights tab contains AI-generated or manually created recommendations based on the Initiative. Insights can identify relevant existing records as well as missing compliance work that should be completed.

Each Insight includes:

  • A recommended action or outcome.
  • A status of Pending or Complete.
  • A justification explaining why the action is recommended.
  • A Take Action menu with the recommended action and any other available actions.

The completion counter above the list shows how many Insights have been completed.

Generate AI Insights

If automatic generation is enabled, TrustWorks begins generating Insights after the Initiative is created. A message appears while generation is in progress, and the Insights become available when processing is complete.

To generate or refresh Insights manually:

  1. Open the Initiative and select Insights.
  2. Click AI Assistant.

  1. Wait for generation to complete. You can continue working elsewhere in TrustWorks while the suggestions are generated.

Completed Insights are retained when suggestions are regenerated. TrustWorks also applies safeguards to prevent an already executed Insight from creating the same object again.


Add or manage an Insight manually

Click + New Insight to add an Insight manually. Existing Insights can be edited or deleted from the available actions.

Deleting an Insight removes it from the list but does not reverse an action that has already been completed. For example, deleting a completed Insight does not delete the Task, Risk, Assessment, or related object created from it.

Take action on an Insight

To act on a recommendation:

  1. Review the Insight and its justification.
  2. Click Take Action.
  3. Select the recommended action or another available action.
  4. Review the information provided in the action-specific form. TrustWorks pre-fills relevant details where possible.
  5. Complete and save the action.

After successful execution, the Insight status changes to Complete automatically. The completed Insight remains in the list and displays the action taken, providing a record of how the recommendation was addressed.

Available actions depend on the Insight and may include:

  • Create or update a Processing Activity.
  • Create or update an Asset.
  • Link an existing Processing Activity or Asset.
  • Import a detected Asset from staging.
  • Add missing data mapping information.
  • Run an Assessment.
  • Create a Risk.
  • Create or link a Legal Entity.
  • Create and assign a custom Task.

Data Mapping

The Data Mapping tab allows teams to document personal data processing while an Initiative is still being reviewed, before it becomes part of a formal Processing Activity.

You can map:

  • Categories of Individuals, such as candidates, customers, or employees.
  • Categories of Personal Data, such as contact details, names, job titles, dates of birth, or profiling data.

The available values come from the taxonomy configured under Settings > Data Practices, keeping Initiative data consistent with Assets and Processing Activities.

To add data mapping:

  1. Open the Initiative and select Data Mapping.
  2. Select a Category of Individuals.
  3. Select the related Categories of Personal Data.
  4. Click + New to add another mapping where necessary.
  5. Save your changes.

Initiative data mapping can also be used in Assessments through the Initiative data mapping question type and is included when those Assessment responses are exported.

Reference Documents

Use Reference Documents to add or review supporting material associated with the Initiative. Documents provide reviewers and the AI Assistant with relevant context, such as project specifications, vendor documentation, policies, or process descriptions.

Depending on the document type, reference material can be added as a file, URL, or text.

Risks Management

Use Risks Management to connect identified Risks to the Initiative and track risk-related work alongside the Initiative. Risks may be created manually or from a relevant AI-generated Insight.

Assessments

The Assessments tab contains Assessments associated with the Initiative, such as a DPIA, vendor assessment, or AI risk assessment.

Assessments can be started directly from this tab or through an Insight's Take Action menu. When launched from an Insight, relevant details are pre-filled where possible, and the Insight is marked complete after the Assessment is successfully created.

Related Objects connect an Initiative to existing records elsewhere in TrustWorks, giving reviewers a broader view of the systems, processing, and organisations involved.

An Initiative can be related to:

  • Assets
  • Processing Activities
  • Legal Entities

To add a relationship:

  1. Open the Initiative and select Related Objects.
  2. Click + New.
  3. Select the object type.
  4. Search for and select the record.
  5. Add a description explaining its relationship to the Initiative.
  6. Click OK.

Related Objects can also be linked through AI-generated Insights when TrustWorks identifies an existing relevant record.

AI Use Cases

Where AI Governance is enabled, the AI Use Cases tab shows AI Use Cases associated with the Initiative. This helps teams review AI-specific governance requirements alongside the broader privacy and compliance workflow.

Comments and collaboration

Use Comments to keep discussions and follow-up information connected to the Initiative. This provides a shared record for privacy, compliance, security, and business stakeholders reviewing the request.

For a complete Initiative review:

  1. Confirm that the Initiative details, owner, type, and supporting documents are complete.
  2. Review or add the relevant data mapping.
  3. Generate AI-assisted Insights if they have not already been generated.
  4. Review the justification for each Insight and remove any irrelevant suggestions.
  5. Use Take Action to create, update, or link the necessary records and assign follow-up work.
  6. Review associated Risks and Assessments.
  7. Confirm that all required Insights are complete.
  8. Update the Initiative status when the review or implementation is finished.

Using Initiatives as the starting point for new projects and changes helps teams identify compliance requirements earlier, preserve the context behind decisions, and connect intake information to the work completed across TrustWorks.

Still need help? Contact Us Contact Us