Run an engagement
This page covers the internal half of an audit: creating it, scoping it, and collecting evidence until the request list is fulfilled. The external half — the auditor's portal and the frozen export — is the next page.
Create the audit
Click New Audit (top right). The form asks for:
- Title and audit type. The type comes from a standard list — SOC 2 Type I and Type II, ISO 27001, PCI DSS 4.0, SOX, HIPAA, FedRAMP, and others.
- Framework. Optional but consequential: scoping the audit to one of your activated frameworks is what lets you generate evidence requests from its control list and track readiness against it.
- External auditor. Firm, contact name, and contact email.
- Audit period and evidence deadline. The deadline turns red in the table once it passes with the audit still open.
- Description and internal notes. Notes stay internal to your team.
The form says it plainly before you save: an audit scopes chosen frameworks and evidence into one engagement, and your auditor works in a separate portal with clean-gated downloads. Creating one is the start of an exchange with an outside party, not just a record.
Find your way around
The module has three tabs. Dashboard is the roll-up view across engagements. Engagements is the working table — search matches title, firm, or description, and the status and type filters narrow the list. My Assignments shows only the evidence requests assigned to you, which is the tab most of your team will live in.
Clicking an engagement row expands its working panel: framework readiness, the evidence request table, freeze and export controls, and auditor access — everything about that audit in one place.
Build the request list
Evidence requests are the unit of work: each one names a thing the auditor needs, and the engagement is done when they are all accepted. Three ways to build the list:
- Generate requests from the framework panel — one request per applicable control of the scoped framework, in a click. The readiness meter then tracks how many applicable controls have accepted evidence.
- Import PBC — bulk-load the provided-by-client list your auditor sent.
- Add Request — one at a time, for anything else.
Auditors can also raise requests themselves from their portal once invited, so the list stays live during fieldwork.
Assign, attach, track
Assign each request to an owner — it appears in their My Assignments tab. Owners fulfill a request by uploading a file or linking evidence the platform already holds; a request moves through Pending → Assigned → In progress → Submitted, and lands at Accepted or Rejected when the auditor rules on it. A rejected request comes back to its owner with the auditor's comments attached.
Two progress signals tell you where the engagement stands:
- The fulfilled/total bar on the engagement row — requests accepted versus requested.
- The framework readiness meter in the expanded panel — applicable controls with accepted evidence, including how many are requested and still awaiting.
Advance the status
As phases complete, move the audit forward from the row's actions menu: Planning → Collecting Evidence → In Review → Submitted → Completed → Closed. Each step can also go one step back, so reopening for auditor follow-ups doesn't require deleting anything.
A frozen audit cannot be deleted. Unfreeze it first — with a recorded reason — if you genuinely need to remove it.