Audit and trust

External audit

Track an external engagement and build a controlled package of controls, evidence, policies, and risk reports.

External audit

The register at /audit/external tracks engagements by framework, type, auditor, window, and lifecycle. Lifecycle states include planned, package preparation, in progress, report review, completed, and cancelled. Audit types include initial, surveillance, and recertification.

Create the engagement and package

The builder creates the external audit workflow and its package together:

  1. Details: name, framework, audit type, package type, dates, audit firm/contact, and notes.
  2. Controls: select the controls inside the audit scope; filter by domain.
  3. Evidence: review evidence associated with the selected controls and include only the relevant period.
  4. Policies: select policy documents and the exact versions the auditor should receive.
  5. Risk reports: include a risk assessment report and/or treatment plan where relevant.
  6. Review: verify the package contents before creation.

Package types can be a full package, control summary, or evidence-only package. The narrowest appropriate package reduces accidental disclosure, but it must still meet the agreed request.

Download and share

The external audit row provides a package download when a package is linked. Before transfer:

  • inspect every included artifact for tenant, period, and scope
  • remove secrets, personal data, and unrelated customer information where not required
  • verify policy versions and evidence status
  • use the auditor's approved secure transfer channel
  • record later requests and package changes rather than overwriting what was originally sent

An evidence item being linked to a control does not automatically make it suitable for external disclosure.