Skip to main content

Auditor Portal

The Auditor Portal is a dedicated interface for external auditors who are invited to participate in assessments. Auditors authenticate separately and can access multiple assessments across different firms, making it suitable for contract auditors who work with several organizations.

Access

Auditors access the portal at a dedicated URL and authenticate with Cognito credentials tied to their email address. The system matches the authenticated email to auditor contact records to determine which assessments they can access.

Login Flow

  1. Navigate to the Auditor Portal URL
  2. Enter email and password (or use SSO if configured)
  3. If invited to multiple assessments, an Assessment Picker shows all available engagements
  4. Select an assessment to enter its workspace

My Assessments

After login, auditors see a list of all assessments they've been invited to, with:

  • Assessment name and client
  • Framework being assessed
  • Status and progress
  • Due date
  • Their role (Lead Auditor or Team Member)

Auditor Workspace

Once inside an assessment, auditors have full access to:

Control Testing

The primary auditor workflow:

  1. Navigate clauses - Browse controls organized by domain/section
  2. Review evidence - See what the client has submitted for each control
  3. Perform testing - Document testing procedures and results
  4. Record status - Mark each clause as Conforming, Non-Conforming, or Not Applicable
  5. Add auditor notes - Internal observations not visible to clients

Evidence Review

  • View all client-submitted evidence
  • Accept or reject submissions with comments
  • Request additional evidence or clarification
  • Upload auditor-side evidence (testing screenshots, sampling records)

Finding Recording

When control testing reveals issues:

  1. Create finding - Linked to the relevant clause
  2. Classify - Set conformity type and severity
  3. Describe - Document the non-conformity in detail
  4. Recommend - Provide remediation guidance
  5. Track - Monitor client management response and remediation status

Comments & Collaboration

  • Threaded comments on evidence requests and findings
  • @mention client contacts to request clarification
  • Activity feed showing assessment-wide progress

Auditor vs. Client Visibility

Auditors see everything; clients see a filtered view:

FeatureAuditorClient
All clause detailsYesNo (only public fields)
Auditor notesYes (read/write)No
Testing proceduresYes (read/write)No
Evidence reviewed summaryYes (read/write)No
Client evidence submissionsYesYes
FindingsYes (create/edit)Yes (read + management response)
Management responsesYes (read)Yes (read/write)
Assessment progressYesYes (limited)

Permissions

Auditor Portal access is controlled through invitations:

  • Auditor contacts are registered with an email address
  • Contacts are invited to specific assessments
  • Invites can be enabled or disabled without deleting the contact
  • Removing an invite immediately revokes portal access to that assessment

AI Features

When AI is enabled for an assessment, auditors can:

  • Use AI-assisted document summarization on uploaded evidence
  • Get relevance assessments for evidence against control requirements
  • Generate draft finding descriptions from testing notes

AI features are opt-in per assessment and controlled by whoever manages the assessment, not the auditor.