CoreStream 2.5 Release Notes

Our 2.5 release is a combination of showcase features, and some smaller changes that will help us continue our work on ensuring CoreStream is the most intuitive GRC Platform available. We have also ensured that non-functionals continue to receive the attention they deserve. In terms of showcase features, CoreStream can now automatically generate a risk…

Richard Eddolls Avatar
CoreStream GRC logo against dark blue background and blue and green gradient

Our 2.5 release is a combination of showcase features, and some smaller changes that will help us continue our work on ensuring CoreStream is the most intuitive GRC Platform available. We have also ensured that non-functionals continue to receive the attention they deserve.

In terms of showcase features, CoreStream can now automatically generate a risk bowtie, showing the causes and consequences for a given risk, along with the preventative and recovery controls and mitigation that are being performed. We have received positive feedback on this from clients already, many of whom are keen to utilise this in risk workshops with the aim of making them more interactive.

The 2.5 release of CoreStream also introduces our support for the submission of items by users who are not authenticated. This helps us broaden our offering in the whistleblowing / speak-up areas as well as opening up opportunities for members of the public to submit items directly into CoreStream. This is a welcome addition for clients utilising CoreStream for subject access requests (SARs) and freedom of information (FOI) requests, removing the need for users to key cases into CoreStream when they are received through other means.

Continuing our focus on acting upon client feedback, we are also providing the ability for users to interrogate version history at the field level. The data to do this has always been available, and we are now changing the way we surface the information, in line with the way users interact with the Platform. The ‘view versions’ feature in CoreStream will still be available, with the field level option being supplementary.

As we close 2.5, we are already excited about 2.6. CoreStream has utilised Artificial Intelligence (AI) for some time but we are about to take this to the next level…

Thanks,

Rich

FAQ

What was introduced in CoreStream GRC version 2.5?

In December 2023, CoreStream GRC 2.5 delivered a blend of showcase features and usability improvements designed to make the platform even more intuitive. The headline updates included automatic risk bowtie generation, support for unauthenticated submissions, and field-level version history visibility, all driven by client feedback.

What did the unauthenticated submission feature in version 2.5 enable?

Version 2.5 introduced the ability for external users, such as members of the public or third parties, to submit items directly into CoreStream GRC without logging in. This opened new possibilities for handling whistleblowing, speak-up reports, and data access or freedom of information (FOI) requests more efficiently.

What guided the version 2.5 release improvements?


Every enhancement in version 2.5 stemmed from direct client feedback and CoreStream’s ongoing commitment to improving user experience. The focus remained on building the most intuitive and flexible GRC platform available—while continuing to invest in non-functional improvements such as performance, scalability, and security.

What was next for CoreStream GRC after version 2.5?

Clients were able to download the full 2.5 Release Notes from the CoreStream portal or contact their account manager for a personalized demonstration. New users could request a demo to explore how CoreStream GRC helped organizations visualize risk, simplify compliance, and enhance transparency across every process.

  • Regulatory compliance including SCF compliance frameworks

    Regulatory compliance including SCF compliance frameworks

    What is regulatory compliance? Regulatory compliance is the process of meeting the laws, rules, standards, and requirements set by regulators, governments, and supervisory bodies. It helps organizations understand which external obligations apply, assign ownership, operate controls, collect evidence, and report when required. In governance, risk, and compliance (GRC), regulatory compliance matters because regulatory expectations rarely…

  • Compliance

    Compliance

    What is compliance? Compliance is the process of meeting the laws, regulations, standards, policies, contractual requirements, and ethical expectations that apply to an organization. In simple terms, compliance helps organizations understand what they are required to do, assign ownership, operate controls, evidence activity, and respond when something goes wrong. In governance, risk, and compliance (GRC),…

  • Beyond the token bill: why AI governance now means budgeting, sovereignty and capacity, not just risk 

    Beyond the token bill: why AI governance now means budgeting, sovereignty and capacity, not just risk 

    Key takeaways  Introduction: the hidden costs of AI for GRC teams  In May, engineers at Uber found that they had spent an entire year’s AI budget in just four months. The culprit was Claude Code, rolled out enthusiastically across the organization to speed up software development. It worked. It also cost so much, so fast, that leadership had to step in and cap…