Plan and run an internal audit end-to-end
Schedule the audit, pick the scope, gather evidence against a checklist, capture findings, and raise corrective actions — all in one place.
Step-by-step
- 1
Create an audit
From Audits, click New audit. Pick a scope (a standard, a control set, or a business area), a lead auditor and dates.

- 2
Use a template
Choose a template — the checklist auto-populates with the right control questions. Amend as needed.
- 3
Reassign work
Click any section to change the assignee. Consultants often split audits across their team; this is the fastest way.
- 4
Log findings
Against any checklist item, log a conforming or non-conforming finding. Attach evidence directly from the vault.
- 5
Raise corrective actions
One click turns a non-conformity into a CAPA with owner, due date and root-cause fields. Track it to closure.

- 6
Feed the management review
Completed audits appear as inputs to your next management review automatically.
- "When was your last internal audit?"
- "Were findings raised, and are corrective actions being tracked to closure?"
- "Do management reviews take the audit output as input?"
What this workflow produces: A completed internal-audit report plus an open CAPA log is a strong signal to buyers that the ISMS is actually operating.
FAQ
Open Audits → click any audit card. From there you can edit scope, reassign auditors, add findings or reopen closed sections.
Yes — invite them with a read-only role scoped to specific audits.
Ready to run this in your workspace?
Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.
