Audits
An audit is the evaluation of a perimeter against a framework. Creating one spawns a requirement assessment for every requirement in the framework — those rows are where the result, the score, the observation, the applied controls and the evidence live. Because applied controls are decoupled from requirements, the same controls can back many audits in parallel: doing ISO 27001 does not mean redoing the work for CMMC.
Where to find it
Section titled “Where to find it”Compliance → Audits in the sidebar. The list shows Reference ID, Name, Version, Framework, Domain, Perimeter and Progress, and can be filtered by domain, perimeter, framework and status.
Creating an audit
Section titled “Creating an audit”- Click the add button and give the audit a Name and a Version.
- Pick the Domain it belongs to, and optionally a Perimeter to narrow it further.
- Choose the Target framework. Frameworks come from the catalog — import one first if the list is empty. See Frameworks and Libraries.
- If the framework ships implementation groups, pick them under Selected implementation groups.
- Optionally tick Suggest controls to pre-create applied controls from each requirement’s suggested reference controls. This checkbox only appears on the create form.
- Save. The requirement tree is generated immediately.
A full walkthrough lives in Create your first audit.
Key concepts
Section titled “Key concepts”Implementation groups
Section titled “Implementation groups”Many frameworks tag their requirements into implementation groups — maturity tiers such as CIS IG1/IG2/IG3, or scope slices such as ISO 27001’s Statement of Applicability group. Selecting groups narrows what the audit counts as in scope; requirements outside the selection are simply not counted. The selection is editable afterwards, and work already done on requirements that stay in scope is preserved. See Multi-level support.
Result, status and score
Section titled “Result, status and score”Each requirement assessment records several independent dimensions so the auditor’s verdict, the analyst’s progress and the depth of the implementation never get conflated:
| Dimension | Values |
|---|---|
| Result | Not assessed, Compliant, Partially compliant, Non-compliant, Not applicable |
| Status | To do, In progress, In review, Done |
| Extended result | Major nonconformity, Minor nonconformity, Observation / sensitive point, Opportunity for improvement, Good practice |
| Score | A number on the framework’s scale, optionally split into an implementation score and a documentation score |
Observation is the free-text field where the auditor records what was actually seen. Extended result is only meaningful when the result is non-compliant or partially compliant.
Progress
Section titled “Progress”The Progress percentage answers one question: how much of the audit has been assessed. When the status field is visible, a requirement counts only once it is marked Done. When status is hidden, it counts as soon as the result leaves Not assessed, or the questionnaire is fully answered, or the score moves above the scale minimum. Only assessable requirements inside the selected implementation groups count toward the denominator. Progress is an activity signal, not a compliance signal — an audit can reach 100% and still be largely non-compliant.
Audit statuses
Section titled “Audit statuses”The audit itself carries Planned, In progress, In review, Done or Deprecated. Setting the audit to In review, or ticking Locked, makes every requirement read-only.
Working with the requirement tree
Section titled “Working with the requirement tree”The Associated requirements panel shows the framework as a tree with a donut per node. Filters narrow it by status, result, extended result, applied-control coverage and evidence coverage, and Only assessable hides section headings. Click a requirement to open its edit page.
The Power-ups panel beside the donuts gathers the rest:
- Flash mode and Table mode — two faster ways to answer. See Flash mode and Table mode.
- Apply mapping — choose Map to a framework to create a new audit in another framework mapped from this one, or Map from an audit to pull mapped results from an existing audit into this one. A preview shows what would change before anything is written. See Mappings.
- Clone audit, Compare to (side-by-side scores, radar and a list of requirements that differ), Sync to actions, Suggest controls and Assignments.
Related
Section titled “Related”- Audit tailoring — take requirements out of an audit’s scope and scoring.
- Evidences — the proof behind each requirement.
- Exports — every export format an audit offers.
- Summary — all audits, one page.
