Communication templates

Customise the wording of the e-mails and chat messages the platform sends.

Every e-mail and chat message the platform sends starts from a template. This article explains how to review those templates, customise their wording per language, and check the result before it reaches anyone.

Customising a template changes only its wording. It does not change when the message is sent or who receives it.

Overview

Navigate to: Left menu: Content, then Communication.

The page has two tabs:

  • Mail: the e-mails the platform sends to your colleagues and to your third parties.
  • Chat: the messages the platform posts to Microsoft Teams and Slack.

Every template already has default wording, so you only need to visit this page when you want to change something. A template you have never edited keeps working exactly as shipped.

Note: the Chat tab does not control the messages that appear inside the platform itself on a record. Those are described in Messages.

1. The Communication page

Table

  • Notification: the name of the e-mail or chat message.
  • Languages: one flag per available language. A flag is in colour when that language has wording of your own, and grey when it does not.
  • Adjust by: who last changed the template.
  • Actions: the ••• menu described below.

Search and filter

  • Search: find a template by name.
  • Clear search: remove the search term and show every template again.
  • Filters: opens the filter panel.
  • No custom template for language: shows only the templates that have no wording of your own in the language you pick. Use this to find the gaps after adding a new language.
  • Clear filters: reset the filter panel.
  • Number of rows per page: change how many templates are listed at once.

Adjust by

Hover the avatar to see when the template was last changed and by whom.

There are three states in this column:

  • An avatar: someone in your organisation has customised this template.
  • An empty circle: the template has been customised, but no record of who did it is available. This happens for changes made before the platform started keeping that record.
  • An empty circle with the message "No template yet": the template still uses its default wording.

Actions

Click on the ••• menu on a template row.

  • View: open the template read-only. This is what you see if you have permission to read templates but not to change them.
  • Edit: open the template editor.
  • Delete: remove your own wording, so the template returns to its default. See 5. Reset, delete, and defaults below.

On a template that still uses its default wording, the menu offers Add template instead.

2. Mail templates

Edit a mail template

  • Open the Mail tab.
  • Search for the template you want to change.
  • Click on the ••• menu, then on Edit (or Add template).
  • Change the Subject and the Contents.
  • Click on Save.

The Contents field is a rich text editor, so you can use headings, bold, italics, underline, links and lists. Subject is a single line of plain text.

Along the top of the editor is one tab per language, with English marked Required. See 4. Languages below.

Preview

The panel on the right shows the message as the recipient will receive it, and updates as you type. Placeholders are filled with example values so you can read the result as a sentence.

Note: the preview uses example names, dates and reference numbers. The real message uses the details of the actual record.

Placeholders

Placeholders are the parts the platform fills in, such as the name of your organisation or a button linking to the assessment. They are written in square brackets, for example [ORGANISATION].

Below the editor is the list of placeholders you can use in this template.

  • Placeholder: the text to paste into the subject or the body.
  • Description: what the platform fills in.
  • Status: a green tick when the placeholder is used, a cross when it is not. A red cross marks a placeholder this template cannot do without.

A required placeholder may sit in either the Subject or the Contents — it does not matter which. If one is missing from both, Save reports an error and nothing is stored.

Note: placeholders are case-sensitive and must keep their square brackets. The easiest way to add one is to copy it from this list.

Global signature

Global signature is a block of text you maintain once and reuse across your e-mails, typically a sign-off and any legal wording your organisation needs.

It has no Subject, because it is never sent on its own. To include it in an e-mail, put [SIGNATURE_BLOCK] in that template's Contents.

3. Chat templates (Microsoft Teams and Slack)

The Chat tab holds the messages the platform posts to Microsoft Teams and Slack. Both services receive the same wording, each rendered in its own format.

Editing works as it does for e-mail, with two differences: the fields are Title and Message, and Message is plain text rather than a rich text editor.

The preview panel shows the message as it will appear in the chat.

Note: these templates only reach anyone once Microsoft Teams or Slack is connected. Setting that up is described in Microsoft Teams. The templates are listed here whether or not a connection exists.

4. Languages

Four languages are available: Nederlands, English, Deutsch and Español. Each has its own tab in the editor.

The platform picks the language per recipient. For a third party, that is the communication language set on the third party; for a colleague, their own language setting.

English is required. You cannot save a template without English wording.

Note: for a language to use your wording, both the subject and the body must be filled in for that language. If either is empty, the platform ignores your version for that language and sends the default wording instead — it does not fall back to your English text. After adding wording in one language, use the No custom template for language filter to find the templates you have not translated yet.

5. Reset, delete, and defaults

Every template has default wording that the platform falls back to whenever you have not supplied your own.

Reset template

Reset template in the editor puts the default wording back into the fields, for the language tab you are currently on only. Your other languages are untouched.

It fills in the fields but does not store anything, so:

  • Click on Save to keep the default wording.
  • Close the editor without saving to keep what you had.

Delete

Delete on a template row removes your wording and returns the template to its default.

Click on Confirm to continue, or Cancel to keep your version.

Note: this deletes your customisation, not the notification. The message carries on being sent, with its default wording. Deleting removes every language at once, so use Reset template if you only want to restore one.

Who receives each notification

The page does not show who a notification goes to, so the tables below list it. Recipients are fixed by the platform and cannot be changed here.

Mail

Notification

Sent to

Global signature

Not sent on its own - included in other e-mails via [SIGNATURE_BLOCK]

Import failed

The user concerned

Password changed

The user concerned

Password reset

The user who requested the reset

Two-factor authentication enabled

The third-party contact filling the assessment

Two-factor authentication disabled

The third-party contact filling the assessment

Assessment finished (Account holder)

The third-party manager and the assessment's reviewers

Assessment finished (third-party)

The third-party contact filling the assessment

Assessment cancelled

The third-party manager and the assessment's reviewers

Assessment cancelled (third-party)

The third-party contact filling the assessment

Assessment submitted confirmation (Third party)

The third-party contact filling the assessment

Assessment ready for review (reviewer)

The assessment's reviewers

Assessment ready for verification (Verifier)

The assessment's verifiers

Assessment Started

The third-party contact filling the assessment

Assessment review comments follow-up (third-party)

The third-party contact filling the assessment

Assessment completed by secondary user

The third-party contact filling the assessment

Mention in message

The user concerned

Assessment reminder (third-party)

The third-party contact filling the assessment

Assessment passcode

The third-party contact filling the assessment (as a separate e-mail)

Assessment answers copy (third-party)

The primary third-party contact for the assessment

Assessment answers copy password (third-party)

The primary third-party contact for the assessment

External form submission submitted for review

The assessment's reviewers

External form registration started

The contact on the submission

External form submission approved

The coordinator of the external form

External form submission confirmation

The contact on the submission

Consolidated message mentions

The user concerned

Download ready

The user who started it

Download failed

The user who started it

Import completed

The user concerned

Third-party screening report request

The requesting user (or the configured report address)

Assessment overdue (third-party)

The third-party contact filling the assessment

Assessment overdue (requestor)

The user who requested the assessment

Assessment moved from verification to review (reviewer)

The assessment's reviewers

Secondary assessment user invite

The third-party contact filling the assessment

External form - Additional information requested

The contact on the submission

Organisation element assessment review requested

The assessment's reviewers

Organisation element assessment review reminder (30 days)

The reviewer of the organisation element

Organisation element assessment review reminder (7 days)

The reviewer of the organisation element

Organisation element assessment review reminder (due today)

The reviewer of the organisation element

Residual risk acceptance request

The user concerned

External form workflow completed

The coordinator of the external form

Residual risk accepted

The owner of the risk

Residual risk denied

The owner of the risk

Document signed by a signer

The user who sent the document for signing

Document signing completed

The user who sent the document for signing

Contract due date

The contract manager and the contract owner

Contract notice deadline

The contract manager and the contract owner

Control assessment batch - will start soon

The roles selected on the scheduled-notification definition

Control assessment batch - has started

The roles selected on the scheduled-notification definition

Control assessment batch - reminder

The roles selected on the scheduled-notification definition

Control assessment batch - reminder (tomorrow)

The roles selected on the scheduled-notification definition

Control assessment batch - testing deadline

The roles selected on the scheduled-notification definition

Control assessment batch - testing deadline passed

The roles selected on the scheduled-notification definition

Control assessment batch - validation deadline

The roles selected on the scheduled-notification definition

Control assessment batch - validation deadline passed

The roles selected on the scheduled-notification definition

Control assessment batch - validation has started

The roles selected on the scheduled-notification definition

User invite

The invited user

User invite (SSO)

The invited user

User invite (API)

The invited user

User invite (SSO via API)

The invited user

Chat

Notification

Sent to

Control owner assigned

The newly assigned control owner

Control auditor assigned

The newly assigned control auditor

Control executor assigned

The newly assigned control executor

Control validator assigned

The newly assigned control validator

Catalogue owner assigned

The owner of the third party

Catalogue next review date alert

The owner of the third party

Catalogue risk profile wizard alert

The owner of the third party

Contract owner assigned

The owner of the contract

Contract due date

The contract manager and the contract owner

Contract notice deadline

The contract manager and the contract owner

Contract risk profile wizard

The owner of the contract

Contract security review required

The risk officer of the contract

Third-party report received

Not currently sent - no code dispatches this template

Third-party report requested

The user who made the request

Risk register officer assigned

The risk officer of the risk

Risk register officer closed

The risk officer of the risk

Risk register officer updated

The risk officer of the risk

Risk register owner assigned

The owner of the risk

Risk register owner closed

The owner of the risk

Risk register owner updated

The owner of the risk

Residual risk acceptance request

The user concerned

Action plan owner assigned

The owner of the action plan

Action plan owner closed

The owner of the action plan

Action plan owner reopened

The owner of the action plan

Action plan owner updated

The owner of the action plan

Action plan owner re-evaluation due

The owner of the action plan

Action plan person to act assigned

The person to act on the action plan

Action plan person to act closed

The person to act on the action plan

Action plan person to act reopened

The person to act on the action plan

Action plan person to act updated

The person to act on the action plan

Action plan person to act re-evaluation due

The person to act on the action plan

Action plan person to act re-evaluation exceeded

Not currently sent - no code dispatches this template

Action plan issue owner assigned

The owner of the issue

Action plan issue owner closed

The owner of the issue

Action plan issue owner reopened

The owner of the issue

Action plan issue owner updated

The owner of the issue

Action plan issue owner re-evaluation exceeded

The owner of the issue

Action plan issue officer assigned

The risk officer of the issue

Action plan issue officer closed

The risk officer of the issue

Action plan issue officer reopened

The risk officer of the issue

Action plan issue officer updated

The risk officer of the issue

Action plan issue officer re-evaluation due

The risk officer of the issue

Action plan issue officer re-evaluation exceeded

The risk officer of the issue

Issue owner assigned

The owner of the issue

Issue owner closed

The owner of the issue

Issue owner reopened

The owner of the issue

Issue owner updated

The owner of the issue

Issue owner re-evaluation due

The owner of the issue

Issue owner re-evaluation exceeded

The owner of the issue

Issue officer assigned

The risk officer of the issue

Issue officer closed

The risk officer of the issue

Issue officer reopened

The risk officer of the issue

Issue officer updated

The risk officer of the issue

Issue officer re-evaluation due

The risk officer of the issue

Issue officer re-evaluation exceeded

The risk officer of the issue

Assessment finished (contract owner)

The owner of the contract

Assessment cancelled (initiator)

The user who initiated the assessment

Assessment due date (initiator)

The user who initiated the assessment

Assessment due date reminder (initiator)

The user who initiated the assessment

Assessment due date extension request

The user who initiated the assessment

Assessment due date extended

The user who initiated the assessment

Assessment due date extension denied

The user who initiated the assessment

Assessment cancelled (officer)

The risk officer of the third party

Assessment finished (officer)

The risk officer of the third party

Assessment ready for review

The assessment's reviewers

Assessment ready for verification

The assessment's verifiers

Control assessment negative result (owners)

The owner of each linked risk

Control assessment negative result (risk officers)

The risk officer of each linked risk

Control assessment pushed to next status

All stakeholders of the control assessment

Control assessment finished

All stakeholders of the control assessment

Control assessment testing started

All stakeholders in the testing phase

Control assessment testing to validation (first)

All stakeholders in the validation phase

Control assessment testing to validation (resubmitted)

The most recent validator

Control assessment validation pushback to testing

All stakeholders in the testing phase

Control assessment validation to verification (first)

All stakeholders in the verification phase

Control assessment validation to verification (resubmitted)

All stakeholders in the verification phase

Control assessment re-opened

All stakeholders of the control assessment

Control assessment verification pushback to validation

The most recent validator

Control assessment testing due (tester)

All stakeholders in the testing phase

Control assessment testing due (validator)

All stakeholders in the validation phase

Control assessment validation due (auditor)

All stakeholders in the verification phase

Control assessment validation due (validator)

All stakeholders in the validation phase

Control assessment verification due

All stakeholders in the verification phase

Permissions needed

Permissions needed: Notification templatesRead to open the page, Update to change a template, Create to add one, and Delete to remove a customisation.

To grant it, navigate to: Left menu: Configuration, then Roles, open the role, and set the Notification templates permissions. Managing roles is described in Users.

A user with only Read sees the page and can open a template with View, but cannot change it.

Known limitations

  • Every template is listed, including modules you do not use. The list is not filtered by your subscription, so you may see templates for features your organisation has not enabled. Customising one of those has no effect until the feature is in use.
  • Three notifications share their wording between Mail and Chat. Contract due date, Contract notice deadline and Residual risk acceptance request exist on both tabs. Because of a known issue the e-mail can pick up the wording from the chat version. If you customise one of these, check the other tab as well, and let us know if the e-mail does not read as you expect.
  • Two chat templates are listed but not currently sent: Third-party report received and Action plan person to act re-evaluation exceeded. Customising them has no effect for now.
  • Assignment messages are not sent to you when you assign yourself. Assigning a control to yourself, for example, sends no message.
  • Not every Microsoft Teams or Slack message is editable here. A small number of messages, such as the organisation element review reminders, are sent outside this list and keep their built-in wording.
  • The layout of e-mails is not editable here. Colours, logo and overall styling come from your branding. See Custom branding.
  • There is no version history. Once you save, the previous wording is not recoverable, though Reset template always brings back the platform default.