Assessment Workspace
Each external assessment gets a dedicated full-page workspace for managing the entire engagement lifecycle. The workspace is used by both GRC tenants (managing their external audits) and audit firm tenants (conducting assessments for clients). Both see the same workspace structure with role-appropriate access.
For GRC tenants, the assessment workspace is documented in Compliance > Assessments. This page focuses on additional capabilities available to audit firm tenants managing assessments for clients.
Creating an Assessment
From the Assessments page, click New Assessment to create an engagement:
- Select Client -- Choose from your client directory
- Assessment Type -- Initial Certification, Surveillance, Recertification, Readiness Review, Gap Assessment, or Compliance Audit
- Framework -- Select the compliance framework(s) being assessed
- Dates -- Set start date and due date
- Lead Auditor -- Assign the engagement lead
- Roll Forward (optional) -- Copy controls, evidence requests, and prior findings from a previous assessment for this client
Workspace Tabs
The workspace organizes work across ten tabs:
Dashboard
Progress overview showing:
- Overall completion percentage
- Controls tested vs. total
- Evidence collected vs. requested
- Open findings count
- Timeline and deadline tracking
Clauses
The primary testing surface. Clauses are organized by domain or clause reference from the selected framework.
Each clause tracks two independent dimensions -- testing status (has the auditor examined it?) and conformity status (what was the result?):
Testing Status
| Status | Meaning |
|---|---|
| Not Started | Clause has not been examined |
| In Progress | Testing is underway |
| Tested | Testing is complete |
| Deferred | Testing deferred to a later phase or engagement |
Conformity Status
| Status | Meaning |
|---|---|
| Conformity | Control meets requirements |
| Minor Non-Conformity | Isolated lapse that does not affect overall system capability |
| Major Non-Conformity | Significant failure to meet a requirement |
| Opportunity for Improvement | Control works but could be strengthened |
| Observation | Noted for awareness, no action required |
| Not Applicable | Clause excluded from scope |
Additional clause fields:
| Field | Description |
|---|---|
| Reference | Clause/control ID (e.g. A.5.1, CC6.1) |
| Title | Control objective description |
| Auditor Notes | Internal auditor observations (not visible to clients) |
| Testing Procedures | How the control was tested |
| Evidence Reviewed | Summary of evidence examined |
| Conclusion | Auditor's conclusion narrative |
Each clause also has sub-tabs for linked evidence files, associated findings, and threaded comments.
Clauses support bulk updates. Select multiple and update status in one action.
Evidence Requests
Evidence collection using a structured request-and-response workflow:
- Firm creates evidence requests -- Define what documentation is needed from the client
- Client receives requests in their Client Portal
- Client uploads evidence -- Documents, screenshots, exports
- Auditor reviews -- Marks evidence as sufficient, insufficient, or needs clarification
Evidence Request Status
| Status | Meaning |
|---|---|
| Not Requested | Request drafted but not yet sent to client |
| Requested | Sent to client, awaiting response |
| Submitted | Client has uploaded evidence |
| Accepted | Auditor confirmed evidence is sufficient |
| Rejected | Evidence does not meet requirements, resubmission needed |
| Not Applicable | Request no longer relevant to this engagement |
For DRL-model assessments, evidence collection uses a Document Request List (DRL) -- a structured, reusable template that maps evidence requests to specific clauses and control families.
Findings
Track non-conformities and observations discovered during testing:
| Field | Description |
|---|---|
| Finding Number | Sequential identifier within the assessment |
| Title | Brief finding description |
| Severity | Critical, High, Medium, Low, or Informational |
| Description | Detailed finding narrative |
| Impact | Business impact of the finding |
| Remediation Guidance | Suggested remediation steps |
| Source | How the finding was discovered (Control Testing, Observation, Interview, or Document Review) |
| Status | See table below |
Finding Status
| Status | Meaning |
|---|---|
| Draft | Finding authored but not yet issued to client |
| Issued | Sent to client for review |
| Open | Client has acknowledged the finding |
| In Progress | Remediation work underway |
| Remediated | Client reports remediation complete, pending auditor verification |
| Closed | Auditor has verified remediation |
| Accepted | Risk accepted without remediation |
| Withdrawn | Finding retracted by the auditor |
Scope
Define and curate the scope of the assessment. Manage which clauses are in scope, document exclusion reasons, and configure scope boundaries for the engagement.
Projects
Track tasks and work items related to the engagement. Organize testing assignments, remediation activities, and follow-up actions.
Team
Manage who has access to this assessment:
| Role | Description |
|---|---|
| Lead Auditor | Primary person responsible for the engagement |
| Auditor | Team member conducting testing |
| Reviewer | Reviews work and signs off on conclusions |
| Observer | Read-only access for oversight or training |
Meetings
Schedule and track meetings related to the engagement -- opening meetings, progress check-ins, closing meetings, and ad-hoc discussions.
Report
Generate assessment deliverables from templates. Reports pull data from the workspace (clauses tested, evidence collected, findings recorded) into formatted output for client delivery. See Reports and Branding for details.
Prior
Compare this assessment against prior engagements for the same client. View how findings, conformity results, and evidence have changed across assessment years to track improvement trends.
AI Features
When AI Features is enabled for an assessment (configured in the assessment detail sidecar), auditors can use AI-assisted evidence review to:
- Summarize uploaded documents
- Check evidence relevance against control requirements
- Identify gaps in submitted documentation
This is an opt-in feature controlled per assessment. Firms can enable or disable it based on client preferences or engagement requirements.