Compliance Assistant supports and helps you to:
Make sure the app is installed in your environment.
The following table describes the required permissions.
Compliance Assistant uses data sources from across Dynatrace capabilities to monitor compliance risks.
The specific configuration steps required or recommended to maximize the value of compliance insights depend on the framework you want to configure. See the prerequisites section for your framework:



Compliance Assistant offers monitoring and automation capabilities streamlined to specific compliance frameworks. To start managing compliance, set up a compliance framework applicable to your organization.
Compliance Assistant.
Business Flow.
Compliance Assistant.
Compliance Assistant users.A compliance framework is a structured set of requirements, guidelines, and best practices to support organizations in meeting regulatory and industry-specific standards.
Compliance Assistant consolidates insights and functionalities tailored to a specific compliance framework.
Compliance Assistant currently offers monitoring and automation capabilities supporting compliance with the EU DORA Regulation and APRA CPS 230 Operational Risk Management.
A real-time, tiered score summarizing your current ICT risk posture across potential incidents, security detection findings, vulnerabilities, and misconfigurations. This score is an indicative metric based on current data and tier logic. This score is a high-level indicator based on real-time observability and automated systems. It does not replace comprehensive or formal compliance assessments.
Compliance Assistant allows you to map compliance-relevant IT assets to end-to-end business processes. By integrating with
Business Flow, you can identify compliance-critical business processes, leveraging Smartscape entities for enhanced visibility and context.
Depending on the compliance framework, these include:
Critical or important functions (CIFs): EU DORA Regulation, financial entities must identify, classify, and document ICT-supported business functions and their supporting assets. CIFs are processes that, if disrupted, could significantly impact financial performance or service continuity.
Critical operations: According to APRA CPS 230, regulated entities must identify and document the processes and resources needed to deliver critical operations, along with their interdependencies, risks, and controls. Critical operations are processes that, if disrupted beyond tolerance levels, would have a material adverse impact on depositors, policyholders, beneficiaries, or other customers, or on the entity's role in the financial system.
Compliance Assistant relies on vulnerability findings to proactively mitigate risks before they escalate into incidents. A vulnerability finding is a security event that highlights a detected weakness in a system, software component, or environment.
Compliance Assistant relies on detection finding events to support in prioritizing cyber risks. A detection finding event is generated when suspicious activity is observed around an object.
Compliance Assistant relies on compliance events to detect potential misconfigurations. Compliance events represent the assessment of a resource in the context of the rule specified in the compliance standard.
Compliance Assistant enables you to achieve and manage compliance across supported frameworks:
The Dynatrace score is a real-time indicator based on your current ICT risk posture and impacted by the severity of findings. To improve your score:
Compliance Assistant?Insights on conversions and errors KPIs on CIFs are updated on the basis of the configured generation frequency of the KPI monitoring in
Business Flow. The evaluation timeframe for the monitored KPIs of critical or important functions (CIFs) is also defined in setting up a business configuration as an entity.
To ensure reliable KPI evaluation and avoid missing data from long‑running processes, set the evaluation timeframe to at least three to four times the process's average duration (for example, if the average duration of the CIF is 5 minutes, set the window to at least 15–20 minutes).
If you have recently edited or added business processes configured as entity and selected any of those as a CIF in
Compliance Assistant, it may take up to the maximum defined frequency for the monitoring KPIs of those business processes to be updated in
Compliance Assistant. You can adjust the monitoring frequency in the business flow configuration.