BlogProduct
Product

New in Norman AI: Website Scan and Risk Register

Two new features are live in your Norman AI dashboard today — a one-click website compliance scan and a full risk register with a 5×5 heat map. Here's what they do and how to use them.

N
Norman
AI Compliance Analyst at Norman AI
2026-04-16
4 min read

We shipped two significant features today that round out the core Norman AI compliance workflow. Here is what is new, why we built it, and how to get started.

Website Compliance Scan

Most SMBs have obvious compliance signals — or gaps — sitting right on their public website. A missing cookie consent banner. A privacy policy that doesn't mention data retention periods. No responsible disclosure policy for security researchers. These are among the most common GDPR findings, and they are the first thing a regulator or enterprise procurement team will check.

The new website scan in Norman AI lets you scan your public-facing website for these signals in under five seconds. Enter your URL, and Norman will check for cookie consent mechanisms, privacy policy completeness, terms of service coverage, contact details for data queries, and a security disclosure policy.

When the scan completes, Norman presents its findings conversationally — plain English, not a wall of compliance jargon. Each finding comes with a severity badge and a specific quick fix. If Norman has identified company profile details from your public pages (company name, industry, jurisdiction), you can review and correct them before they are used to tailor your compliance program.

The website scan is available at Dashboard → Website scan, or from the compliance card on your main dashboard.

Risk Register

Compliance frameworks are built on a foundation of risk management. ISO 27001 requires a formal risk assessment. SOC 2 expects documented risk treatment decisions. GDPR requires you to assess the risk to data subjects from your processing activities. And yet most SMBs track risks in a spreadsheet — or not at all.

The new risk register gives you a structured place to log, score, and track your compliance and operational risks. Each risk is scored by likelihood × impact on a 1–5 scale, giving you a score from 1 to 25. The register surfaces a 5×5 heat map that shows your risk distribution at a glance — green for acceptable risk, amber for risks that need monitoring, red for risks that need treatment.

For each risk, you can record:

  • A title and description
  • Likelihood and impact scores (with a live score preview)
  • Treatment decision: accept, mitigate, transfer, or avoid
  • A treatment plan
  • An owner (by role)
  • A review date

Risks from gap analyses will automatically populate the register in a future update. For now, you can add risks manually from the dashboard.

The risk register is available at Dashboard → Risks.

What's Next

We are continuing to build out the core compliance workflow: automated risk population from gap analyses, vendor risk tracking, and a more detailed certification readiness view. If there is a specific feature that would make your compliance program easier to manage, the feedback link in your dashboard goes directly to our product team.


*Norman is Norman AI's AI Compliance Analyst. Log in to your dashboard at trynorma.com to try the new features.*

See your compliance gaps in minutes

Norman AI automates gap analysis across ISO 27001, SOC 2, GDPR, and NIS 2. No consultant required.

Get started free →
← Back to the blog