Skip to main content

Assessment Workspace

Each external assessment gets a dedicated full-page workspace for managing the entire engagement lifecycle. The workspace is used by both GRC tenants (managing their external audits) and audit firm tenants (conducting assessments for clients). Both see the same workspace structure with role-appropriate access.

tip

For GRC tenants, the assessment workspace is documented in Compliance > Assessments. This page focuses on additional capabilities available to audit firm tenants managing assessments for clients.

Creating an Assessment

From the Assessments page, click New Assessment to create an engagement:

  1. Select Client -- Choose from your client directory
  2. Assessment Type -- Initial Certification, Surveillance, Recertification, Readiness Review, Gap Assessment, or Compliance Audit
  3. Framework -- Select the compliance framework(s) being assessed
  4. Dates -- Set start date and due date
  5. Lead Auditor -- Assign the engagement lead
  6. Roll Forward (optional) -- Copy controls, evidence requests, and prior findings from a previous assessment for this client

Workspace Tabs

The workspace organizes work across ten tabs:

Dashboard

Progress overview showing:

  • Overall completion percentage
  • Controls tested vs. total
  • Evidence collected vs. requested
  • Open findings count
  • Timeline and deadline tracking

Clauses

The primary testing surface. Clauses are organized by domain or clause reference from the selected framework.

Each clause tracks two independent dimensions -- testing status (has the auditor examined it?) and conformity status (what was the result?):

Testing Status

StatusMeaning
Not StartedClause has not been examined
In ProgressTesting is underway
TestedTesting is complete
DeferredTesting deferred to a later phase or engagement

Conformity Status

StatusMeaning
ConformityControl meets requirements
Minor Non-ConformityIsolated lapse that does not affect overall system capability
Major Non-ConformitySignificant failure to meet a requirement
Opportunity for ImprovementControl works but could be strengthened
ObservationNoted for awareness, no action required
Not ApplicableClause excluded from scope

Additional clause fields:

FieldDescription
ReferenceClause/control ID (e.g. A.5.1, CC6.1)
TitleControl objective description
Auditor NotesInternal auditor observations (not visible to clients)
Testing ProceduresHow the control was tested
Evidence ReviewedSummary of evidence examined
ConclusionAuditor's conclusion narrative

Each clause also has sub-tabs for linked evidence files, associated findings, and threaded comments.

Clauses support bulk updates. Select multiple and update status in one action.

Evidence Requests

Evidence collection using a structured request-and-response workflow:

  1. Firm creates evidence requests -- Define what documentation is needed from the client
  2. Client receives requests in their Client Portal
  3. Client uploads evidence -- Documents, screenshots, exports
  4. Auditor reviews -- Marks evidence as sufficient, insufficient, or needs clarification

Evidence Request Status

StatusMeaning
Not RequestedRequest drafted but not yet sent to client
RequestedSent to client, awaiting response
SubmittedClient has uploaded evidence
AcceptedAuditor confirmed evidence is sufficient
RejectedEvidence does not meet requirements, resubmission needed
Not ApplicableRequest no longer relevant to this engagement

For DRL-model assessments, evidence collection uses a Document Request List (DRL) -- a structured, reusable template that maps evidence requests to specific clauses and control families.

Findings

Track non-conformities and observations discovered during testing:

FieldDescription
Finding NumberSequential identifier within the assessment
TitleBrief finding description
SeverityCritical, High, Medium, Low, or Informational
DescriptionDetailed finding narrative
ImpactBusiness impact of the finding
Remediation GuidanceSuggested remediation steps
SourceHow the finding was discovered (Control Testing, Observation, Interview, or Document Review)
StatusSee table below

Finding Status

StatusMeaning
DraftFinding authored but not yet issued to client
IssuedSent to client for review
OpenClient has acknowledged the finding
In ProgressRemediation work underway
RemediatedClient reports remediation complete, pending auditor verification
ClosedAuditor has verified remediation
AcceptedRisk accepted without remediation
WithdrawnFinding retracted by the auditor

Scope

Define and curate the scope of the assessment. Manage which clauses are in scope, document exclusion reasons, and configure scope boundaries for the engagement.

Projects

Track tasks and work items related to the engagement. Organize testing assignments, remediation activities, and follow-up actions.

Team

Manage who has access to this assessment:

RoleDescription
Lead AuditorPrimary person responsible for the engagement
AuditorTeam member conducting testing
ReviewerReviews work and signs off on conclusions
ObserverRead-only access for oversight or training

Meetings

Schedule and track meetings related to the engagement -- opening meetings, progress check-ins, closing meetings, and ad-hoc discussions.

Report

Generate assessment deliverables from templates. Reports pull data from the workspace (clauses tested, evidence collected, findings recorded) into formatted output for client delivery. See Reports and Branding for details.

Prior

Compare this assessment against prior engagements for the same client. View how findings, conformity results, and evidence have changed across assessment years to track improvement trends.

AI Features

When AI Features is enabled for an assessment (configured in the assessment detail sidecar), auditors can use AI-assisted evidence review to:

  • Summarize uploaded documents
  • Check evidence relevance against control requirements
  • Identify gaps in submitted documentation

This is an opt-in feature controlled per assessment. Firms can enable or disable it based on client preferences or engagement requirements.