Skip to main content

Audit Profile

This section explains how to select a framework, review controls, assign owners, and provide evidence to stay audit-ready.

Updated over 2 months ago

AI Compliance Profiles

At the top level, you can browse and select from available compliance frameworks. Examples include:

  • SOC 2

  • ISO 27001:2022

  • HIPAA

  • GDPR

  • PCI DSS

Each profile card provides a short description of the framework, its purpose, and status (e.g. Available).

Clicking on a profile (e.g. SOC 2) takes you to its Summary and Controls view.

Summary

Once inside a framework, the Summary shows:

  • Total Coverage — The number of controls covered out of the total required.

  • Status indicators — Count of controls that are:

    • Failed

    • Needs attention

    • Passed

    • No evidence

  • Audit Score — A numerical score reflecting current audit readiness.


Controls

This section lists all controls for the selected framework. Each control shows:

  • Score — How much evidence has been provided (e.g. 0/17).

  • Risk Level — The control’s risk classification (e.g. High, Low).

  • Owner — The assigned responsible user.

  • Completion % — How much of the control’s requirements have been fulfilled.

You can expand control groups (e.g. CC 1.0 Control Environment) to view individual items and manage evidence.


When you click on a control in your Audit Profile, a detailed panel opens on the right side of the screen. This panel provides all necessary information about the selected control, helping you manage compliance tasks efficiently.


🔍 What you see in the control details panel

  • Control name & description
    The title at the top (e.g. Code of Conduct acknowledged by contractors) specifies the control’s requirement. A short description explains what is expected — in this case, that contractor agreements include a code of conduct.

  • Metadata

    • ID — The unique identifier for the control (e.g. HRS-2).

    • Source — The origin or framework of the control (e.g. DSALTA).

    • Owner — The person responsible for completing the control (can be assigned here).

    • Frequency — How often the control must be reviewed or updated (e.g. Annual).

    • Risk Level — The risk rating (e.g. High).

    • Score — Current score against the total evidence points (e.g. 0/17).

    • Results — Status of evidence collected (e.g. No evidence).


Mapped elements

Below the metadata, the panel shows the elements linked to this control:

  • Policies — Any policies that apply (e.g. Code of Conduct), with progress indicators.

  • Documents — Supporting documentation (e.g. Contractor agreement).

  • Tests — Related tests or validation checks (if any).

You can review or add evidence to each mapped element by clicking on it or using the owner assign button.


How to use the Audit Profile

  • Select a framework to get started.

  • Track progress via the summary dashboard and control list.

  • Assign owners and upload evidence to close compliance gaps.

  • Review your audit score regularly to stay on track for certification.

Did this answer your question?