Skip to main content

Auditor Portal: Understanding the Audit Workspace

Overview, Framework, Controls, Evidence — the same data viewed through four different lenses, plus the read-only Supporting Data tabs.

Written by Upendra Varma

Opening an audit from Clients or Audits drops you into its workspace — the same underlying evidence, organized through a few different lenses depending on what you're trying to answer.

Overview

The audit window (start/end dates) and an Evidence Review Progress summary — Total, Accepted, Flagged, Pending — front and center. Mark Completed finalizes the audit once your review is done — if any evidence is still unreviewed, it'll warn you first ("Not all evidence has been accepted") and let you jump straight to Evidence, or proceed anyway if you're completing the audit using evidence exported and reviewed outside ComplyJet.

Further down, an Audit Data section lets you generate a downloadable ZIP of the audit's mappings, plus per-section exports (Framework Mapping, Controls, Evidence, People, Policies, and more) for offline work — see Downloading Audit Data.

Framework: "does the control set satisfy the requirement?"

Framework shows each individual framework criterion (e.g. HIPAA §164.308(a)(1)(i)) alongside the specific controls mapped to it. This is the highest-level lens — use it to sanity-check that the client's control set actually covers what the framework requires, before you get into evidence-level detail.

Controls: "what's the evidence status per control?"

One level down, Controls lists every control with a rolled-up evidence count (e.g. "10 Pending, 1 Flagged"). Use this to prioritize — a control with several flagged items needs attention before one that's all pending.

Evidence: the actual review queue

The Evidence tab is the item-by-item worklist — see Reviewing and Accepting Audit Evidence for the full workflow there.

Supporting Data: read-only context

Below the main tabs, Supporting Data — People, Policies, Inventory, Devices, Risk, Vendors, Access, Vulnerabilities — gives you direct visibility into the client's underlying records, not just the evidence generated from them:

People, for example, lists every employee and former employee in scope for the audit window, with policy acceptance status per person. Each of these tabs follows the same pattern: a filtered, searchable table scoped to this specific audit, useful when an evidence item's summary isn't enough and you need to check the underlying record directly.

Several tabs add a filter specifically for the audit window — People's New Employees / Left Employees, Vulnerabilities' Detected During Audit Period — so you can isolate what actually changed during the period you're auditing, rather than the client's full all-time history.

Did this answer your question?