Skip to main content
The Audits page is where you create, manage, and track formal compliance audits. Each audit corresponds to a framework and tracks evidence readiness through the entire audit lifecycle.

Creating an audit

Click New Audit to start. The dialog asks for two things, both required:
  • Compliance Framework — the framework being audited, picked from your active frameworks
  • Invite your auditor — the auditor’s email address
Then click Create Audit.
When you invite an auditor, they receive an email with access to a dedicated audit view. Auditors have limited permissions — they can view and comment on evidence but cannot modify your compliance data.

Audit dashboard

Each audit displays three key sections:

Timeline

Key milestones — when the audit started, when the auditor was assigned, and current status.

Evidence Status

Donut chart of evidence items. Its legend reads Not Ready, Flagged, Ready, Accept, and No Applicable — the last two are worded differently here than in the status dropdown.

Compliance Process

Progress bars for Controls, Automated Tests, Policies, and Documents.

Audit statuses

Working with your auditor

Each evidence row carries a single status dropdown, not a set of action buttons. Opening it offers five values:
  • Ready — the evidence is ready for the auditor to look at
  • Not Applicable — the requirement does not apply
  • Flagged — the auditor needs more information or has concerns
  • Not Ready — the evidence is not yet in a reviewable state
  • Accepted — the evidence satisfies the requirement
Both you and the auditor can leave comments on any evidence item. A comment icon appears next to items with active discussions.
The audit detail page has an Export dropdown with Export evidence list, Export policy packet, Download criteria list, and Download control list — useful for auditors who prefer working outside the platform.