Audit

External audit

Track engagements and build controlled evidence packages for auditors.

RolesViewerEditorAdminRoute/audit/externalShown toCompliance organizations

What it is

External audit tracks each engagement with a certification body or assessor: who the auditor is, which framework, what kind of audit, and when. Each engagement owns an audit package, a bundle of the controls, evidence, policies, and risk reports you chose to share, built in one guided flow and downloaded as a single archive. The list and its milestones feed the audit calendar.

Where to find it

AuditExternal Audit
External audits list with framework, type, auditor, and audit window columnsExternal audits list with framework, type, auditor, and audit window columns
Engagements. Each row has its own package.

Key actions

Create an engagement and its package

Click New External Audit. The builder ("Create a new external audit and its package in one workflow.") walks through six steps.

Details: enter the External Audit Name ("e.g., ISO 27001 Surveillance Audit 2026"), Package Name, Compliance Framework, Audit Type, Package Type, Audit Start Date, Audit End Date, Auditor Name ("Audit firm or lead auditor"), and Auditor Contact.
Controls: tick the controls in scope. Use Select All or Deselect All, "Search controls...", and Filter by domain.
Evidence: "Review evidence linked to selected controls." Untick anything you do not want to share; Filter by type narrows the list. For an evidence-only package the step reads "Select evidence items from this framework." instead.
Policies: search and, for each policy, Select version so the auditor gets the text that was in force.
Risk Reports: Select risk assessment report and Select risk treatment report from generated snapshots, or generate one in place.
Review: when the summary reads "We have everything we need and are ready to create your audit package.", click Create External Audit.
The audit package builder on the Controls step with the step indicator across the topThe audit package builder on the Controls step with the step indicator across the top
The builder. Steps run Details, Controls, Evidence, Policies, Risk Reports, Review.

Leaving the builder with changes asks whether to discard; Keep editing returns you to the step.

Download the package

Click Download Audit Package on the engagement. The button reads "Preparing Download..." while the archive is assembled, then the file downloads.

Track status and milestones

Move the engagement through its statuses as the audit proceeds. Milestones (upcoming, completed, overdue) are what the calendar draws as markers.

Delete an engagement

Delete External Audit removes the engagement and its package. Download first if the package was shared.

Statuses and fields

StatusMeaningSet by
PlannedplannedEngagement recorded; package not started.Create
Package Preparationpackage_preparationPackage being assembled or revised.You
In Progressin_progressFieldwork underway.You
Report Reviewreport_reviewAuditor's report received and being reviewed.You
CompletedcompletedEngagement closed. Result recorded as passed, failed, conditional, or pending.You
CancelledcancelledEngagement did not proceed.You
Audit typeMeaning
InitialFirst certification audit
SurveillancePeriodic check during the certificate's life
RecertificationFull audit at the end of the cycle
Package typeContents
Full Package - Includes controls, evidence, assets, personnel, and policiesEverything the framework touches
Control Summary - Controls and status onlyStatus table without artifacts
Evidence Only - Just evidence artifactsThe files, selected directly

A package moves from draft to exported when it is downloaded, and can be archived afterwards. The list columns are Audit, Framework, Type, Auditor, and Window.

Tips and gotchas

Review every step before Create External Audit. The package is what leaves the building: personnel lists and evidence files may contain personal data or secrets that belong in scope for your auditor but not for anyone the archive is forwarded to.

Generate the risk reports before you start the builder. The Risk Reports step can generate in place, but doing it from Risk reports first lets you read the preview and pick the version deliberately.

Policy versions are pinned at package creation. If you publish a new version during the audit, the package still holds the one you selected; build a new package if the auditor needs the newer text.

What Noru does not do

Noru does not communicate with the auditor, host a portal for them, or record their findings. The package is a snapshot: evidence collected after you create it is not added. Noru does not judge whether your selection is sufficient for the audit type, and it does not decide the result; you record passed, failed, conditional, or pending after the auditor tells you.

Last updated on