Audits
Internal, external and technical audit in one place.
What it does
Audit work usually happens outside the GRC platform, in a shared drive and a mail thread, and the findings are typed back in afterwards. This module keeps the engagement, the evidence and the findings on the same records everyone else is using.
External auditors get their own role, assigned to the folders their engagement covers. They see the evidence in that scope and nothing else.
One findings model runs across audits, assessments, incidents and vendor reviews, so a control weakness raised in three places is one item, tracked once.
Internal audit
Engagements with scoped assessments, findings raised against real records, and follow-up tracked to closure.
Follow-up is where internal audit programmes fail. Tracking closure on the same record as the original finding removes the reconciliation step entirely.
AUD-2026-014
External audit
A dedicated external auditor role, assigned to the folders the engagement covers. The auditor sees the evidence for that scope and nothing beyond it.
The alternative is exporting a folder of documents to a third party and losing track of it. Scoped access keeps the evidence in one place and leaves an access trail.
Technical audit and VAPT
Import penetration test and scan results, band them by severity, and turn them into tracked findings against the affected assets.
A penetration test report is a PDF that ages badly. Turning its contents into findings against assets is what makes it get remediated.
Vulnerability findings
A vulnerability register with CVE enrichment from an NVD cache, severity banding, asset linkage and remediation tracking.
Linking a vulnerability to the asset, and the asset to the perimeter, is what lets you answer whether a published CVE affects a regulated system.
CVE-2026-1041 · Critical
Findings
One findings model links across audits, assessments, incidents and vendor reviews, so nothing is tracked twice.
The same weakness found by internal audit and by a vendor questionnaire is one problem. Two registers means it gets closed in one and stays open in the other.
FND-0873
Roles that live here
- Internal Auditor
- Audit Manager
- External Auditor
- Control Owner
- CISO
Drawn from sixteen built-in roles, each scoped along the org tree. Access control
Related frameworks
See Audits on your engagement plan.
A 45-minute working session focused on the frameworks and requirements that matter to your organization.