> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance FAQ

> Answers to common compliance and audit-related questions.

## Frameworks and controls

<AccordionGroup>
  <Accordion title="How are controls mapped to frameworks?" icon="diagram-project">
    When you activate a framework, DSALTA automatically maps all relevant controls. Each framework area has criteria, and each criterion maps to specific controls. A single control can satisfy requirements across multiple frameworks.
  </Accordion>

  <Accordion title="What does 'Needs attention' mean?" icon="circle-exclamation">
    A control shows "Needs attention" when some evidence exists but is incomplete — a test may have failed, a document is missing, or a policy is not yet approved. Click into the control to see exactly what is needed.
  </Accordion>

  <Accordion title="How is audit readiness calculated?" icon="calculator">
    Audit readiness is the ratio of controls with complete evidence to total controls in your active framework. A control is "complete" when all required policies, documents, and tests are satisfied.
  </Accordion>
</AccordionGroup>

## Policies

<AccordionGroup>
  <Accordion title="Are policies pre-generated?" icon="robot">
    Yes. DSALTA uses AI to generate policies tailored to your company and activated frameworks. Customize any policy before approving. Every change is version-tracked.
  </Accordion>

  <Accordion title="How often do policies need renewal?" icon="calendar">
    Policies run on an annual cycle: approving a policy sets its next review date 365 days out. Once that date passes, the nightly **Periodic review of policies completed** system test fails and reports how many policies are overdue, and the controls that test backs stop passing. Watch that test for renewals — re-approving a policy counts as its review and resets the cycle for another year.
  </Accordion>
</AccordionGroup>

## Audits

<AccordionGroup>
  <Accordion title="How do I start an audit?" icon="play">
    Go to Compliance → Audits → New Audit. The dialog asks for two things, both required: a framework from your active list, and your auditor's email address. The audit belongs to whoever created it.
  </Accordion>

  <Accordion title="What can auditors see?" icon="eye">
    Auditors view evidence, controls, policies, documents, and test results. They can flag items, accept evidence, and leave comments. They cannot modify compliance data.
  </Accordion>

  <Accordion title="What if a test fails during an audit?" icon="triangle-exclamation">
    A failed test changes the control to "Needs attention." Check the test detail for what failed. You can deactivate a non-applicable test — the auditor will see it was intentionally excluded.
  </Accordion>
</AccordionGroup>
