Audit

Internal audit

Plan, perform, document, finalise, and export an internal audit.

RolesViewerEditorAdminRoute/audit/internalShown toCompliance organizations

What it is

Internal audit is where you run the audits your frameworks require you to run on yourself. Each audit has a framework, a type, an auditor, a date, and a report. Noru drafts the report from your current controls, evidence, and policies for that framework; you edit it, record findings, finalise it, and export the PDF for management review and for the external auditor.

Where to find it

AuditInternal Audit

/audit redirects here. The list shows Audit, Framework, Status, Auditor, and Date of Audit, with filters for Framework and Status and the search "Search internal audits by name, framework, or auditor...".

Internal audits list with framework and status filters and the calendar stat cardInternal audits list with framework and status filters and the calendar stat card
The list. Draft, In Progress, and Finalised are the three working states.

Key actions

Create an audit and generate the draft report

Click Create Internal Audit. The "New internal audit" dialog opens.
Enter the Audit name and instructions ("Describe the audit focus, scope, systems, teams, or special instructions. The generated report will include this once and can be edited afterwards.").
Pick the framework with Choose framework. ISO 27001 and 27002 appear as one "ISO 27001" entry.
Set the Audit type: Full audit, Focused audit, or Follow-up.
Choose the auditor: a member under Members, or a typed name under Custom ("Choose auditor").
Click Generate audit report. Noru creates the audit and a draft report; the toast "Internal audit report generated" confirms.
The New internal audit dialog with name, instructions, framework, audit type, and auditor pickerThe New internal audit dialog with name, instructions, framework, audit type, and auditor picker
Creating an audit. The instructions are written into the draft once.

Edit and save the report

Open the audit. The report panel shows Name and Auditor and the editor ("Start writing the internal audit report...").
Edit the text. An "Unsaved changes" notice appears until you click Save.
Use Generate report to redraft from current data. This replaces the text, so save or copy your edits first.
An internal audit's report panel with the editor, Save, Download PDF, and Finalise audit actionsAn internal audit's report panel with the editor, Save, Download PDF, and Finalise audit actions
The report. Finalise when the text is what you will stand behind.

Record findings

Findings have a type (non-conformity, observation, or opportunity), a severity (critical, major, or minor), and a status (open, in remediation, closed, or verified). They are recorded through the MCP server or the API rather than from the report panel, and the report templates count major and minor non-conformities when the report is generated.

Export the PDF

Download PDF in the report options menu renders the current saved text. Finalise first if the PDF is going to an auditor.

Finalise

Finalise audit asks for confirmation, then makes the report read-only and sets the audit to Completed; the toast reads "Report finalized and audit completed" and the panel shows an "Audit finalised" notice.

Reopen

Reopen to edit unlocks a finalised report. Use it for corrections, and finalise again when done.

Delete

Delete Audit on the audit page, or the row action on the list, opens Delete Internal Audit. The report goes with it.

Statuses and fields

StatusMeaningSet by
PlannedplannedCreated; the list filter calls this Draft.Create
In Progressin_progressFieldwork and report editing underway.You
Under ReviewreviewReport drafted, awaiting sign-off.You
CompletedcompletedReport finalised; the list filter calls this Finalised.Finalise audit
CancelledcancelledAbandoned; not drawn on the calendar.You
Audit typeUse it for
Full auditThe whole framework in scope
Focused auditOne domain, system, or team
Follow-upChecking remediation of earlier findings
Finding fieldAPI values
Typenon_conformity, observation, opportunity
Severitycritical, major, minor
Statusopen, in_remediation, closed, verified

The report itself is draft or finalized.

Tips and gotchas

Finalising is a governance act. The PDF you export after finalising is what a certification auditor will compare against your management review minutes. Reopening is possible but leaves a trail; do not finalise to "lock in" a draft you have not read.

Pick an auditor who does not own the controls being audited. The Custom option exists so an external consultant or a colleague from another team can be named without a Noru seat.

The instructions you type at creation are inserted into the draft once. Changing them later means editing the report text.

What Noru does not do

The generated report is a draft assembled from your control statuses, evidence, and policies. It has not observed your operations, interviewed anyone, or tested a control, and it does not know what you left out of scope. Noru does not judge whether a finding is a non-conformity; you record that. It does not schedule the next audit or remind you that one is due.

Last updated on