Skip to main content

ConcertoGRC for Audit Firms

ConcertoGRC includes a dedicated product for audit firms and assessment practices - organizations whose business is conducting compliance assessments on behalf of clients. This is not a feature within the GRC platform; it is a standalone offering with its own tenant type, navigation, and purpose-built workflows.

Audit firms get their own ConcertoGRC instance with everything needed to run an assessment practice:

What You Get

CapabilityDescription
Client ManagementDirectory with status tracking (Active, Inactive, Prospect) and contact details
Multi-Framework AssessmentsSOC 2, ISO 27001, PCI DSS, HIPAA, ISO 42001, and custom frameworks
Control Testing WorkspaceClause-level testing with structured auditor workflows and status tracking
Evidence Collection PipelineRequest-and-response evidence workflow with client submissions and auditor review
Findings ManagementNon-conformity tracking with severity classification and remediation monitoring
Client PortalBranded portal where clients upload evidence and provide management responses
Auditor PortalRemote access for team members to test controls and record findings
Roll-ForwardCopy controls, evidence requests, and findings from prior assessments
Report GenerationFramework-specific report templates with data pulled from the workspace
Firm BrandingCustom logo, colors, and contact details on portals and deliverables
AI-Assisted ReviewOpt-in AI evidence summarization and relevance assessment per engagement

How It Works

Three-Portal Architecture

Each assessment connects three participant groups through dedicated interfaces:

PortalWho Uses ItWhat They Do
Firm DashboardFirm staffManage clients, create assessments, assign teams, generate reports
Auditor PortalAuditors (including remote/contract)Test controls, review evidence, record findings
Client PortalAssessment clientsUpload evidence, respond to findings, track progress

Each participant authenticates independently. Field-level visibility ensures auditor notes, testing procedures, and internal observations are never exposed to clients.

Assessment Lifecycle

UPCOMING --> IN_PROGRESS --> CLOSED --> ARCHIVED
  1. Upcoming - Assessment scoped with framework, client, dates, and team assigned
  2. In Progress - Auditors actively testing controls and collecting evidence
  3. Closed - Assessment complete, report delivered to client
  4. Archived - Historical record retained for roll-forward reference

Assessment Types

TypeWhen to Use
Initial CertificationFirst-time assessment against a framework
SurveillancePeriodic check between full assessments (e.g., ISO annual surveillance)
RecertificationFull reassessment at end of certification cycle
Readiness ReviewPre-audit evaluation to identify gaps before formal certification
Gap AssessmentIdentify gaps and build a remediation roadmap
Compliance AuditGeneral compliance verification engagement

Firm Navigation

Audit firm tenants see a purpose-built navigation structure:

SectionPurpose
DashboardActive engagement overview, upcoming deadlines, team workload
AssessmentsCreate and manage all client engagements
ClientsClient directory with contact and status tracking
TeamAuditor roster and role management
BrandingLogo, colors, and portal customization
Report TemplatesFramework-specific report templates

Documentation

Explore each area of the platform in detail:


For GRC Tenants Being Audited

If you are a GRC tenant (not an audit firm) and need to manage an external audit of your organization, see Managing External Audits for how to register audit firms, invite auditors, and coordinate evidence collection from within the standard ConcertoGRC app.