Skip to main content

The Audit module

In this guide, you will learn how to set up and manage Audits in Formalize.

Overview

The Audit module allows auditors to plan, run and close audits. With this audit management solution you can cover internal audits from end to end.

How to access the Audit module

You can access the Audit module from the left-hand sidebar menu through Compliance > Audits.
​

From here you will be able to create a new engagement, have an overview of your audits, and filter them by template, timeframe, user or folder. This is also where you can download a report of the audit, archive or simply open it.

Step 1: Configure audit types

You will first and foremost need to define the exact audit scope. By defining the scope, you will grant the auditor access to a certain number of items such as controls and requirements. Go to Settings > Compliance > Audit > Audit templates > Create. For example, create an audit type called DORA ICT Risk verification.

Step 2: Give relevant access to the auditor

You want to give the internal or external auditor access to the platform, without necessarily giving them access to all the data and functionalities available. To restrict what the auditor can have access to, follow these steps:

  • Go to Settings > Users & access > Options > Add user

  • Enter the first name, last name, email address and select the role Auditor

Once the user is created, you can verify what the auditor will have access to by going to Settings > Users & access > Access Roles.

There are 3 levels of permissions. For example, you can decide that:

  • The auditor will have access to Controls (level 1)

  • The auditor will have access to Controls but only see them (level 2)

  • The auditor will have access to Controls and see the controls pertaining to one specific user or company entity (level 3)

Don't forget to click on Save if you have made changes.

Step 3: Create an Engagement & define the audit scope

After you have created audit templates, you will need to create an audit. By clicking on Compliance > Audits > Create an engagement you will create a new audit.

Afterwards you have the possibility to:

  • Select an audit template

  • Chose a name

  • Define a timeframe (optional)

  • Select responsible users & a folder (optional)

Now you need to define the list of items (risks, incidents, suppliers, policies, etc) that the auditor needs to audit in Subjects.

To define the items that need to be audited click on Subjects > Configure audit scope.

For our audit example DORA ICT Risk verification we will chose suppliers, risks & incidents.

Once you have selected all relevant subjects, click on Update audit scope.

Step 4: Review the data

Now it is time to review the data which has previously been defined in the scope of the audit. This is done by:

  • Reviewing the subjects: review each subject, such as suppliers or incidents

  • Reviewing the evidence: assets, policies

  • Reviewing the connections: between risks and suppliers for example

Click on the subject you want to review on the subjects overview page.

You can easily switch from one subject to the previous/next one. If you need flag a finding (missing evidence for example) you can do so at the bottom of the subject view by clicking on Flag Finding. Change the status of the review to either Not started, In progress or Completed.

After the review, the auditor can elaborate conclusions directly in the platform, ensuring the end-to-end audit trail.
​

You will first need to create Conclusion custom fields. Follow these steps to create them:

  1. Go to Settings > Compliance > Audits

  2. Find the Audit template for which you need to create conclusions

  3. Click on Edit next to the Audit template name

  4. Scroll down to the section Conclusion custom fields

  5. Create the custom field you need, for example a large text, a single select field or even a date

  6. Save the changes after you have created the necessary custom fields

Now you can go back to your audit and add conclusions.

Step 5: Raise findings

To register findings, click on Findings > Flag new finding. Enter a title, a summary (optional), a finding type (optional) and a subject (optional). You can save it as a draft or issue the finding. Once you have issued a finding, you can always go back and edit it in order to add new information.

All findings you have flagged in the Audits tab will also be visible in the Findings tab, in the left menu.


We hope this article was helpful!


​If you have any additional questions, please reach out to us via chat in the bottom right corner of the page - our team is always happy to assist you further.

Did this answer your question?