Core workflows

Plan and run an internal audit end-to-end

Schedule the audit, pick the scope, gather evidence against a checklist, capture findings, and raise corrective actions — all in one place.

9 min read · updated July 2026

Step-by-step

  1. 1

    Create an audit

    From Audits, click New audit. Pick a scope (a standard, a control set, or a business area), a lead auditor and dates.

    Create an audit
  2. 2

    Use a template

    Choose a template — the checklist auto-populates with the right control questions. Amend as needed.

  3. 3

    Reassign work

    Click any section to change the assignee. Consultants often split audits across their team; this is the fastest way.

  4. 4

    Log findings

    Against any checklist item, log a conforming or non-conforming finding. Attach evidence directly from the vault.

  5. 5

    Raise corrective actions

    One click turns a non-conformity into a CAPA with owner, due date and root-cause fields. Track it to closure.

    Raise corrective actions
  6. 6

    Feed the management review

    Completed audits appear as inputs to your next management review automatically.

What corporate buyers look for
  • "When was your last internal audit?"
  • "Were findings raised, and are corrective actions being tracked to closure?"
  • "Do management reviews take the audit output as input?"

What this workflow produces: A completed internal-audit report plus an open CAPA log is a strong signal to buyers that the ISMS is actually operating.

FAQ

How do I go back into an existing audit?

Open Audits → click any audit card. From there you can edit scope, reassign auditors, add findings or reopen closed sections.

Can external auditors be given access?

Yes — invite them with a read-only role scoped to specific audits.

Ready to run this in your workspace?

Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.

Related

ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation