📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Audits

Run an audit from start to finish: the auditor's request list, the evidence for each request, Type II samples, findings, external auditor access and the final evidence package.

Where to find it
Compliance (GRC) › Audits
Who can use it
Anyone with a GRC role that can view compliance data; creating, editing and locking engagements, accepting or returning requests, sampling and inviting auditors need audit permission (internal auditors may accept, return and sample); working on requests needs a role that can edit; exports need a role that can export
Plan
Compliance (GRC) platform
For
Everyone

What the page is for

The Audits page manages audit engagements. Each engagement has a framework, an audit type, a period and an audit firm, and holds the auditor's list of requests (often called the PBC or "provided by client" list). For each request you assign an owner and due date, link or upload evidence, ask someone outside the console for it, and submit it to the auditor, who accepts it or returns it.

You can build the request list from an internal assessment or a framework, generate it from a framework, or import the auditor's own spreadsheet. Collect evidence automatically fills in what Lavawall can already provide.

External auditors can be invited to a private portal for this engagement only. Each visit needs a code emailed to them, and every view and download is logged. You choose what each auditor may do. Findings raised during the audit are tracked with a management response and can be turned into issues. When the engagement is finished, you can lock it and export the evidence package.

What you see

The Audits page, with the audit engagements, engagement header, tabs, requests, request dialog and external auditors numbered 1 to 6.
The Audits page. Numbers match the list below.
  1. Audit engagements: the list of engagements with Engagement, Framework, Period, Status, Progress and Auditors, and New engagement.
  2. Engagement header: title and details, with Edit, Collect evidence automatically, Lock and Export (Evidence package (.zip), Evidence index (.pdf), Request list (.xlsx)).
  3. Tabs: Requests, External auditors, Findings and Details.
  4. Requests: filters (All statuses, Mine), Build requests from…, Generate from framework, Import spreadsheet, New request, and the table of Request, Title, Owner, Due and Status.
  5. Request dialog: tabs for Details, Control design, Evidence, Samples, Comments and History.
  6. External auditors: Invite auditor, sharing of control designs (Share all, Withdraw all), and the table of Auditor, Can, Expires, Last visit and State.

How to set up an engagement

  1. Select New engagement.
  2. Enter the Title, choose the Framework (only your active frameworks are listed) and Audit type, and set Period start, Period end, Status and Audit firm.
  3. Add Notes (scope, contacts, milestones). External auditors see these notes as the engagement scope.
  4. Select Save.

How to build the request list

  1. Open the engagement and stay on Requests.
  2. Choose one of:
    • Build requests from…: from An internal assessment or A framework, then Build the requests.
    • Generate from framework.
    • Import spreadsheet: upload the auditor's list, Match the columns, check the Preview and select Import.
    • New request: add one by hand.
  3. Select Collect evidence automatically to link evidence Lavawall already has.

How to answer a request

  1. Click a request to open it and set its owner and due date on Details, then Save request.
  2. On Evidence, use Link existing evidence (search and link), Upload new evidence (then Upload and link), or Request it from someone (then Send request).
  3. Use Comments to discuss with the auditor, and Management response where one is needed.
  4. Select Submit to auditor. The auditor (or someone with audit permission) selects Accept or Return to owner. Whoever owns or submitted a request cannot accept it themselves. Other status buttons include Start work, Reopen and Not applicable.

How to draw a Type II sample

  1. Open the request and go to Samples.
  2. Select Show population to see the items the sample is drawn from.
  3. Select Draw sample, then mark each sampled item as it is tested.

How to invite an external auditor

  1. Open External auditors and select Invite auditor.
  2. Enter their Email, Name and Firm.
  3. Choose what they can do: Can download evidence files, Can comment on requests, Can add new requests, Can raise findings and Can evaluate the control designs shared with them.
  4. Set Access ends (defaults to 90 days after the period ends) and select Send invitation.
  5. On Details, under What the external auditor may do with evidence, choose View only. or Downloads allowed. and select Save settings.

How to handle findings

  1. Open Findings and select Raise finding, or open one the auditor raised.
  2. Record the Management response and select Save the response.
  3. Select Open an issue from this finding to track the fix in Issues & Remediation.
  4. When it is resolved, select Close.

Tips

  • Lock the engagement when the audit is complete. A locked engagement refuses changes to its requests, samples and evidence links.
  • Downloads for an auditor must be allowed both on their invitation and for the whole engagement.
  • Download this request's evidence in a request gives you just that request's files.
  • Use Mine to see only the requests you own.
  • Set How long management has to answer a finding on the Details tab.

Troubleshooting

  • I can't accept a request I submitted. Separation of duties stops owners and submitters accepting their own work, unless your company allows self-approval and you give a reason.
  • Changes are refused. The engagement is locked.
  • The auditor can't download files. Turn on Can download evidence files for them and choose Downloads allowed. in the engagement settings.
  • A framework is missing from the list. Only your company's active frameworks can be chosen. Adopt it on the Frameworks page first.

Task guides that use this page

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.