Audit and trust

Audit

Plan internal and external assurance work, assemble evidence packages, and keep an audit calendar.

Audit

The Audit section turns the operating records elsewhere in Noru into reviewable assurance work.

/audit redirects to /audit/calendar. The calendar is coordination; the internal and external registers hold the actual engagements and records.

How audit relates to compliance

Internal audit is an explicit ISMS requirement in ISO 27001 and a widely used way to test governance and control operation in other programs. External audits and certifications require a controlled exchange of scope, controls, evidence, policies, and risk material.

Noru helps assemble and preserve that material. It does not establish auditor independence, determine sample sufficiency, or guarantee an opinion or certification.

Before starting an audit

  • confirm framework and organizational/system scope
  • confirm the audit period and evidence time boundaries
  • resolve obvious control ownership and coverage gaps
  • identify the auditor and responsibilities
  • make risk treatment and policy approval records current
  • agree a secure method for transferring sensitive evidence