Overview
The Audit module allows auditors to plan, run and close audits. With this audit management solution you can cover internal audits from end to end.
How to access the Audit module
You can access the Audit module from the left-hand sidebar menu through Compliance > Audits.
From here you will be able to create a new engagement, have an overview of your audits, and filter them by template, timeframe, user or folder. This is also where you can download a report of the audit, archive or simply open it.
Step 1: Configure audit types
You will first and foremost need to define the exact audit scope. By defining the scope, you will grant the auditor access to a certain number of items such as controls and requirements. Go to Settings > Compliance > Audit > Audit templates > Create. For example, create an audit type called DORA ICT Risk verification.
Step 2: Give relevant access to the auditor
You want to give the internal or external auditor access to the platform, without necessarily giving them access to all the data and functionalities available. To restrict what the auditor can have access to, follow these steps:
Go to Settings > Users & access > Options > Add user
Enter the first name, last name, email address and select the role Auditor
Once the user is created, you can verify what the auditor will have access to by going to Settings > Users & access > Access Roles.
There are 3 levels of permissions. For example, you can decide that:
The auditor will have access to Controls (level 1)
The auditor will have access to Controls but only see them (level 2)
The auditor will have access to Controls and see the controls pertaining to one specific user or company entity (level 3)
Don't forget to click on Save if you have made changes.
Step 3: Create an Engagement & define the audit scope
After you have created audit templates, you will need to create an audit. By clicking on Compliance > Audits > Create an engagement you will create a new audit.
Afterwards you have the possibility to:
Select an audit template
Chose a name
Define a timeframe (optional)
Select responsible users & a folder (optional)
Now you need to define the list of items (risks, incidents, suppliers, policies, etc) that the auditor needs to audit in Subjects.
To define the items that need to be audited click on Subjects > Configure audit scope.
For our audit example DORA ICT Risk verification we will chose suppliers, risks & incidents.
Once you have selected all relevant subjects, click on Update audit scope.
Step 4: Review the data
Now it is time to review the data which has previously been defined in the scope of the audit. This is done by:
Reviewing the subjects: review each subject, such as suppliers or incidents
Reviewing the evidence: assets, policies
Reviewing the connections: between risks and suppliers for example
Click on the subject you want to review on the subjects overview page.
You can easily switch from one subject to the previous/next one. If you need flag a finding (missing evidence for example) you can do so at the bottom of the subject view by clicking on Flag Finding. Change the status of the review to either Not started, In progress or Completed.
After the review, the auditor can elaborate conclusions directly in the platform, ensuring the end-to-end audit trail.
You will first need to create Conclusion custom fields. Follow these steps to create them:
Go to Settings > Compliance > Audits
Find the Audit template for which you need to create conclusions
Click on Edit next to the Audit template name
Scroll down to the section Conclusion custom fields
Create the custom field you need, for example a large text, a single select field or even a date
Save the changes after you have created the necessary custom fields
Now you can go back to your audit and add conclusions.
Step 5: Raise findings
To register findings, click on Findings > Flag new finding. Enter a title, a summary (optional), a finding type (optional) and a subject (optional). You can save it as a draft or issue the finding. Once you have issued a finding, you can always go back and edit it in order to add new information.
All findings you have flagged in the Audits tab will also be visible in the Findings tab, in the left menu.
We hope this article was helpful!
If you have any additional questions, please reach out to us via chat in the bottom right corner of the page - our team is always happy to assist you further.












