Skip to main content

Audit Management

Overview

The Audits section helps you prepare for, execute, and track compliance audits. Organize evidence, collaborate with auditors, and maintain audit history. Your vCISO coordinates with the auditor on your behalf, handles scheduling, and ensures your evidence package is complete before fieldwork begins.

Audit Lifecycle

  1. Planning

    Your vCISO schedules the audit and defines scope with the auditor.

  2. Preparation

    Collect evidence and prepare documentation.

  3. Fieldwork

    Auditor reviews evidence and conducts testing.

  4. Reporting

    Receive audit report and address findings.

  5. Closure

    Complete remediation and close the audit.

Audit Dashboard

The audit dashboard shows:

SectionDescription
StatusCurrent audit phase
ProgressEvidence collection progress
EvidenceCollected and pending evidence
IssuesOpen findings and requests
TimelineUpcoming milestones

Evidence Bundles

Evidence bundles organize documentation for auditor review:

Creating a Bundle

  1. Open the audit
  2. Click Create Evidence Bundle
  3. Select controls to include
  4. Add relevant evidence to each control
  5. Review and finalize

Bundle Contents

Each bundle contains:

  • Control Listing - All in-scope controls
  • Evidence - Documents, screenshots, exports
  • Test Results - Automated and manual test outcomes
  • Notes - Context and explanations

Managing Requests

Information Requests

Auditors may request additional information:

  1. Review request in the audit dashboard
  2. Gather required evidence or documentation
  3. Upload response and mark as addressed
  4. Auditor reviews and closes request

Request Statuses

StatusMeaning
OpenAwaiting response
SubmittedResponse provided, awaiting review
AcceptedAuditor satisfied
Needs RevisionAdditional information required

Findings and Remediation

Audit Findings

Auditors may identify findings:

  • Observations - Minor issues or recommendations
  • Exceptions - Control failures during audit period
  • Deficiencies - Significant control weaknesses

Remediation Process

  1. Review Finding

    Understand the finding and its impact.

  2. Create Remediation Plan

    Document steps to address the finding.

  3. Implement Changes

    Execute the remediation plan.

  4. Collect Evidence

    Document the remediation actions.

  5. Close Finding

    Submit evidence and close the finding.

Audit History

Past Audits

View completed audits:

  • Audit Reports - Final audit reports
  • Evidence Archives - Point-in-time evidence
  • Findings History - Past findings and remediation

Continuous Improvement

Use audit history to:

  • Track improvement over time
  • Identify recurring issues
  • Prepare for future audits

Best Practices

Start Early

Begin audit preparation at least 2-3 months before fieldwork. This provides time to address gaps and gather comprehensive evidence.

Maintain Ongoing Readiness

Don't treat compliance as a point-in-time activity. Continuously collect evidence and maintain controls throughout the year.

Communicate Proactively

Keep your auditor informed of any changes or issues. Surprises during fieldwork create delays and complications.

Document Everything

When in doubt, document it. Better to have too much evidence than too little.

Next Steps