How to use the Audit Module
The audit module plans, executes and documents your internal and external audits: the audit programme (which audits recur and when), the audit team, the scope of every audit, the day-by-day division of the work over the auditees, the findings that come out of it, and the audit report. Everything an auditor asks you to demonstrate - who audited what, when, against which procedure, with which conclusion - is recorded per item and stays available for the next audit.
Before you startIn short: a series describes a recurring audit. Every occurrence of the series is an audit that moves through a timeline: Created, Planned, Preparing, Executing, Completed, Published. On the Prepare and Execute tab you divide the scope over the days of the audit and assign it to auditees; each assignment creates a task, and the audit is completed when all those tasks are done.
- The Audit module must be part of your subscription, and it must be switched on for your organisation under Admin > Company > Modules > Audit. It then appears as Audit in the navigation. The module is currently in preview: if you do not see it at all, ask ISOPlanner support to enable it for your tenant.
- Working with audits is for users with a manager role (manager, consultant or administrator). Starting a new audit series also requires the Create Audit Template permission, which an administrator grants per role under Admin > Authorization > Permissions > Audit. The standard roles have it by default.
- Everything after that - the team, the scope, the planning, the assignments, the statuses and the report - is governed by the authorization schema on the series: whoever may edit the series may run its audits, and whoever may delete it may delete them. Set the schema and only its members see and manage the audits of that series. Without a schema, every manager can.
- An auditee needs no audit permission at all: being assigned an audit task is enough to open it and record the result.
- A Teams meeting and participant availability require the Outlook integration to be configured. Without it you can still run the whole audit; only the meeting buttons are disabled.
- The audit report is stored as a document in your library, so it requires the SharePoint integration for reports. Without it you can run the whole audit, but the Reporting tab cannot create a report.
- Audit tasks are dated with the working hours from your ISOPlanner settings: a task planned on an audit day starts when your working day starts and is due when it ends. Check those settings once if your organisation does not work from 08:00 to 17:00.
- The AI features - scope suggestions in the scope picker and the audit assistant in the Copilot panel - only appear when AI is enabled for your tenant.
1. Create an audit series
Go to Audit and choose New. A series holds everything that stays the same year after year, so you only have to set it up once.
| Field | What it does |
|---|---|
| Name | Name of the series, for example "Software development". Every occurrence is named after it with its period, for example "Software development - August 2026". |
| Type | Internal audit or external audit. |
| Description | The purpose and the standing scope of the audit. It is copied into every occurrence and printed in the report. |
| Owner | The user or role responsible for the audit programme. |
| Authorization schema | Optional. Limits who can see and manage the audits of this series. |
| Recurrence | How often the audit comes back - see the next step. A series without a recurrence is valid; you then only create audits ad hoc. |
| Audit team (optional) | The participants who are always involved. Copied into every occurrence, and editable per audit. |
Use Copy on an existing series to reuse a proven set-up (team, description, procedures) for another subject.
2. Plan the audit programme
Set a recurrence on the series, for example every year in March, or every six months. Two things follow from it:
- The start of the recurrence is the start of the series. As soon as the recurrence is active, the first audit is created on that date. There is no separate start date to maintain.
- Each time you publish an audit, the next occurrence of the series is created automatically on the next date in the pattern. You are always one audit ahead, never more.
The series and its occurrences also appear in the annual plan, next to your other recurring work. Occurrences that are still in the future are shown as a preview.
Do you need an extra audit outside the schedule? Select the series in the overview and use New audit: an ad hoc occurrence is created that behaves exactly like a scheduled one. A series without an active recurrence is perfectly valid - you then only work ad hoc.
3. Put the audit team together
Add the participants under Audit team, on the series (for everyone who is always involved) or on a single audit (for this occurrence only). Every participant has a role:
| Role | Meaning |
|---|---|
| Lead auditor | Runs the audit: scope, planning, assignments, conclusion, report. Counts as an auditor. |
| Auditor | Audits along with the lead auditor. |
| Auditee | Is audited and does the work: only auditees can be assigned scope items. |
| Observer | Attends, is invited to the meeting, has no work of their own. |
An audit cannot move to Planned until there is at least one auditor and at least one auditee - without those two roles there is nobody to do the audit and nobody to audit.
4. Determine the scope
Open an audit and use Add to scope on the Details tab. The scope picker is a draft editor: your changes are applied when you press Save. You can put items from the whole management system in scope:
- Requirements and controls
- Processes
- Risks
- Assets and suppliers
- Processing activities
- Objectives
- Documents from the library
Helpers in the picker:
- Never audited / Last audited on ... per item, so you can spread coverage over the years.
- Risk score per item, so you can start with the risky parts.
- Add related items: preview and add everything connected to an item, for example the controls of a risk.
- AI Suggestions (when AI is enabled): a proposal based on your management system and your standard, optionally steered with an extra instruction such as "focus on cloud suppliers". Every suggestion is a proposal; you decide what goes in scope.
An audit needs at least one scope item to move to Preparing. Up to and including Executing you can still add or remove items - removing an item also removes its audit task. Save writes the whole scope at once, so the scope you see in the picker is the scope you get - it is never left half applied.
5. Plan the meeting and invite the participants
The timeline at the top of the audit shows the current step and the actions belonging to it. For the opening meeting there are two separate actions, each with its own button and its own "done on" state:
- Create Teams meeting - creates an online meeting in your calendar and invites the team. Change the date or the times later and the meeting is updated with the audit.
- Send invitations - mails the participants. Moving to Executing prompts you for the final invitation with the definitive team, scope and times.
Before you fix a moment, use Participant availability: ISOPlanner reads the free/busy information of the required participants from their calendars (times only, never the subject of their appointments) and suggests moments when everyone is free. A conflict is always a warning, never a blockade - you decide.
In the Preparing step the timeline also links straight to Go to Prepare and Execute. Dividing the work and assigning it does not have to be finished before you invite the team: many lead auditors do it with the auditees, for example during the opening meeting, and send the final invitation afterwards.
6. Standardise how you audit: the procedures
An audit is only repeatable if the way of auditing is fixed. That is what the procedures of the series are for. Open them with the Procedures button on the Prepare and Execute tab - that is where you see which item still has no procedure. A series without procedures gets its library on first use, so there is no separate set-up step.
The Procedures screen shows a short explanation, the matching rules and the list of procedures. Add, open and reorder them there. Each procedure is one way of auditing and can contain:
- an instruction in the name and description ("check for these five things ...");
- a form, for example "Risk evaluation" or "Supplier assessment", so the answers are recorded in a structured way;
- a checklist with the steps to walk through;
- a link to specific scope items on its Context tab, when the procedure is written for exactly those items.
A procedure can be generic ("Process audit") or specific ("Assess A.8.34"). Everything except the name is optional: an item without a matching procedure still gets a task with the instruction to audit that item. A procedure describes work, not a person or a status - you assign the work per audit on the Prepare and Execute tab, so the same procedure can go to a different auditee each year.
How a scope item gets its procedure
On the Prepare and Execute tab the Procedure column shows how each scope item will be audited. The match is deterministic and predictable - ISOPlanner never guesses on the basis of similar wording, because a procedure silently attached to the wrong item is worse than no procedure at all. The rules are tried in this order:
| # | Rule | Shown as |
|---|---|---|
| 1 | A procedure is linked to this exact item (for example the procedure "Assess A.8.34" is linked to control A.8.34). | linked to this item |
| 2 | This item was audited in the previous audit of the series. That procedure comes back, and the auditee who did it then is proposed as well. | from the previous audit |
| 3 | A procedure has a form about this type of item (a form with a risk field for a risk, an asset field for a supplier, and so on), as long as there is exactly one such procedure. Two candidate forms leave the choice to you. | matched by form |
| 4 | Optional: you ask the audit assistant in the Copilot panel to propose a procedure for the items that are still open. Only for tenants with AI enabled, and only when you ask for it. | AI suggestion |
| 5 | You pick a procedure yourself while assigning. | chosen manually |
No match? The column reads No matching procedure and the item still gets a task named after the item, with the instruction "Perform the audit of ...". Note that a document from the library can only be matched by rule 1 or 2, and that a series without procedures has nothing to match against - every item then gets such a generated task.
7. Prepare and execute: divide the work and assign it
The Prepare and Execute tab is where the audit is organised. It lists every scope item with its procedure, its auditee, the status of its task and its outcome - the whole audit at a glance - grouped by the audit day the item is planned on. You can work here from the moment there is scope; until the audit is completed everything on the tab stays editable.
Plan the audit days
An audit usually runs over more than one day. Every scope item sits under the day it is audited on, with the date as the group header ("August 3"). Items you have not planned yourself sit under the first day of the audit, so nothing is ever hidden.
- Add day - the first button in the command bar. Pick a date inside the audit period and the day appears as an empty group, ready to receive items. Days that are already in the planning are greyed out in the picker. Has the audit no end date yet? Then the callout asks for it first and the day picker stays disabled until you fill it in; audit days can only be planned inside the period of the audit. Both values are stored when you press Save, so Cancel really cancels.
- Drag and drop - drag a row onto another row of the target day, or straight onto the day header, to move it to that day.
- Move to day - select rows and pick the target date. This does exactly the same as dragging, which makes it the reliable route for long lists and touch screens.
- Remove - select a day header and remove the whole day. Its items move to the previous day of the audit and their tasks move along with them; you are asked to confirm when the day still holds items. The first day of the audit cannot be removed - it has no day before it, and it is where unplanned items live.
Click a day header to select the day itself. That selection is about the day: the only thing you do with it is remove it, so the commands that act on scope items (Assign, Unassign, Assess, Merge, Move to day) stay switched off until you select rows instead. Selecting rows and selecting a day are mutually exclusive, which is what keeps one click on a header from re-assigning a whole day of work.
The planned day drives the dates of the audit task: it starts at the beginning of your working day and is due at the end of that same day. Move an item to another day and its open task is re-dated with it. Tasks that are already done keep their own dates. Change the period of the audit and the planning is moved along into the new period.
Assign the scope to the auditees
- Select one or more rows.
- Choose Assign and pick an auditee. Only auditees of this audit are offered. Leave the procedure on "Use the matched procedure per item" to give every row its own proposal, or pick one procedure for the whole selection.
- Each row gets one task for that auditee, linked to the item to audit and dated with its audit day. The tasks are subtasks of one event for the audit, so the audit as a whole closes only when all of them are done.
Assigning again is how you correct yourself: hand the item to another auditee, or pick another procedure and the open task is rewritten with the new instruction, form and checklist. Answers already filled in under the old form are not carried over, so change the procedure before the auditee starts. Tasks that are already done are never touched by a re-assignment.
Merge tasks into one visit
Auditing ten controls of the same process in one conversation should not mean ten tasks. Select the tasks that belong together and choose Merge tasks: pick the task to merge into, and the scope items of the others move into it while those tasks are deleted. The surviving task keeps its own procedure, instruction, form and checklist, covers all the items, and runs from the first to the last day those items are planned on. Its name loses the single item it was named after, because it now covers several.
One outcome and one conclusion are then recorded for all the items of that task - the auditee sees a note saying so - which is exactly what you want for one conversation about one process, and not what you want when the items have to be judged separately.
The rest of the command bar
- Unassign - releases the item and deletes the task of the auditee, including anything filled in but not yet finished in it. A result already recorded on the scope item stays, and tasks that are already done are left alone. Assign the item again to hand it to someone else.
- Assess - record the result of an item yourself, for the parts you audit without handing them to an auditee.
- Remove - with rows selected it takes the items out of scope, including their tasks. Handy for last-minute changes to the scope. Findings raised from those tasks are kept. With a day selected it removes that day (see above).
- Procedures - opens the procedures of the series (see step 6) without leaving the tab.
- Refresh - re-reads the list. The auditees work in their own tasks, so their status and outcome appear here after a refresh.
Click a row (or the procedure link) to open the task itself.
Let the audit assistant do the work
With AI enabled, the Copilot panel knows which audit you have open and offers ready-made actions for it:
- Divide the work over the audit days - spreads the scope evenly over the days you created and updates the planning.
- Assign procedures to auditees - proposes and assigns the best matching procedure and auditee for every item that has no task yet.
- What is still missing? - summarises the preparation: which items have no task, which have no procedure, and what to do next.
The buttons only start the conversation; you can ask the same things in your own words ("give Monday to Sarah and Tuesday to the IT team", "merge the access control items into one interview"). The assistant changes the planning and the assignments directly instead of handing you a list to copy, and every change is one you can undo yourself on the tab. The list refreshes when the assistant is done.
8. The auditee's work
An auditee finds the audit task in their own task list, in Teams and in their mail. The task opens in a focused view showing only what matters for the audit:
- the audit and the item to audit, both clickable. A task that covers several items shows them as a list;
- the day the work is planned on;
- the instruction from the procedure, plus its form and checklist when it has them;
- the result: an outcome and a conclusion in which the auditee describes what was examined, which evidence was seen and what the judgement is;
- the result of the previous audit of this item, collapsed. The outcome is pre-filled from it and the previous conclusion can be copied in with one click - but it is never copied silently, because this year's conclusion has to be about this year's evidence.
The name of an audit task cannot be changed: it says which item is audited with which procedure, and the lead auditor steers it from the Prepare and Execute tab.
| Outcome | Use it for |
|---|---|
| Not assessed | Not yet judged. |
| Conform | Meets the requirement, no action needed. |
| Observation | No non-conformity, but worth an improvement. |
| Minor non-conformity | Isolated shortcoming. |
| Major non-conformity | Structural shortcoming, the requirement is not met. |
Found something? Create a follow-up task from the audit task - a finding, an incident or an improvement. Such a task is linked to the audit automatically, appears in the report, and keeps its own life: a finding is not thrown away when the audit is finished. The result (outcome, conclusion, who assessed it and when) is saved on the scope item itself, which is why it can be shown as the previous result at the next audit.
A non-conformity always needs a follow-up finding. Minor and major non-conformities are the outcomes that ask for work, so the audit cannot be published while one of them has no finding yet. The Prepare and Execute tab says so per row - Finding required until there is one, Finding created afterwards - so you see it while you are still executing, not when the publish is refused. One finding raised from a task covers every item that task audited, and a finding you raise by hand on the item itself counts too. Observations never hold up the publish: an observation is a remark, not a shortcoming.
9. Complete the audit
Moving to Completed is subject to two hard rules and two checks:
- Blocking: all audit tasks with an auditee must be done. As long as such a task is open the audit cannot be completed - the auditees are still working.
- Blocking, but you can clear it: open tasks without an auditee. Nobody is doing them, so the confirmation dialog offers to delete them and continue in one go. Assign them instead if the work still has to happen.
- Warning: scope items that were never assigned. You can continue, but you are then completing an audit with scope nobody looked at.
- Warning: scope items without an outcome.
Warnings never block; they are shown in the confirmation dialog so that skipping something is a decision, not an accident. Once the audit is Completed the results are frozen: the outcomes and conclusions can no longer be changed. Completing changes nothing outside the audit yet - that happens when you publish. Moving a step back in the timeline is always allowed, and it unfreezes the results again.
Record your own judgement of the audit as a whole in the conclusion of the audit, on the Details tab.
Decide what publishing changes: the "State on publish" column
The audit judges; you decide what the organisation does with that judgement. The last column of the Prepare and Execute list, State on publish, holds that decision per scope item. The audit fills it in from the outcome - a non-conformity proposes the state that says the item has to be worked on again - and you can override it, including with Do not change to leave the item exactly as it is. Nothing is written until the audit is published.
Not every scope item works the same way:
- controls, requirements and processes get their implementation status;
- objectives, risks, assets, suppliers and processing activities each get a status from their own list;
- a document has no status the audit can set. What a conform document produces is an approval round instead - see the next step;
- a non-conformity does both: it can write a status back and it needs a follow-up finding. The column shows the status choice with the finding state underneath it.
The Reporting tab has three sub-tabs: Overview with the numbers, Findings with the tasks that came out of the audit, and Report with the report document. The tab becomes available once the audit reaches Executing.
The report
Generate report writes the report from the audit: header data, participants, the documents reviewed, the result per scope item, the findings, and your conclusion. When AI is enabled for your tenant it opens with a written summary of the audit; without it you get the same report without that summary.
The report is a document in your library, not a one-off download. It is built on your own report template, so it carries your styles, header and footer, and you can edit it straight in the preview on this tab - correct a sentence, add a paragraph. Regenerate report rewrites it from the current results and keeps the same document, so its link, its version history and any approval on it survive.
- A report you generate before the audit is Completed is marked INTERIM in the title: it is a draft of a running audit.
- A report with scope items that have no outcome yet says so, with the number of items - so nobody mistakes an unfinished audit for a clean one.
- Download report (PDF) and Send report to team use exactly the document that is stored, so what you send is what you signed off. Sending mails it as a PDF attachment to the whole team - auditors, auditees and observers - and everyone also gets a notification in ISOPlanner.
Publish
Publish makes the audit final and is the moment the verdict becomes binding. Four things happen:
- The report is frozen. The PDF is rendered once and stored with the audit. Downloads and mails from then on serve that exact file, whatever happens to the document in the library afterwards, and the Report sub-tab shows it read-only.
- The statuses are written back. Every scope item whose State on publish is not "Do not change" gets that status, with an entry in its own change log.
- Approvals are offered for the documents you found conform. A document has no status to set, so what the audit produces for it is an approval round. The timeline offers Create approvals: ISOPlanner opens the approval panel on exactly those documents, pre-filled with the approvers it can work out - the workflow of the template, the people who approved the previous round, or the document owner. You review them, and you send or cancel. Closing the panel creates nothing, so the action stays available on the Published step for as long as you need it. Documents already out for approval are left alone: a second parallel round asks the same people the same question.
- The next audit of the series is created on the next date in the pattern. It starts with the same scope, without the results - and it proposes per item the procedure and the auditee of this audit, so a repeat audit is a matter of reviewing and confirming.
Publishing is refused while a non-conformity has no follow-up finding (see step 8). It is also walked one step at a time: you cannot jump from Created straight to Published. If the SharePoint integration for reports is off you can still publish - you are warned that the audit is published without a report.
Findings are the exception to the lock. They keep a life of their own, so you can still manage them on the Findings sub-tab after the audit has been published: a finding has to be solved, or escalated to an incident, long after the audit is closed.
Let the assistant check your findings
Open the assistant on an audit that is being executed or later and choose Analyze results and propose findings. It goes through the results you recorded and answers two questions: is there a result that warrants a finding but has none yet, and does an existing finding still contain only the generic text of the template it was created from? It then proposes new findings and rewrites of existing ones, with a description and a checklist about the item that was actually audited, and labels where they fit.
Nothing is saved until you approve it. Review the proposal, ask for changes in your own words, remove what you do not want, and pick per new finding the template it should be created from - that template gives the finding your own form and the label that says what kind of finding it is. Findings you already solved yourself are left alone.
The statuses at a glance| Status | What happens | Condition for the next step |
|---|---|---|
| Created | Complete the details and put the audit team together. | At least one auditor and one auditee. |
| Planned | Determine the scope and collect the documents to review. Create the Teams meeting and invite the participants. | At least one scope item. |
| Preparing | Divide the scope over the audit days and assign it to the auditees, with the team if you like. Then send the final invitation. | - |
| Executing | The auditees record their results and findings; you keep steering the planning and the assignments. | All audit tasks done, and no open task left without an auditee. |
| Completed | Results are frozen. Write the conclusion and the report. Nothing outside the audit changes yet. | Every non-conformity has a follow-up finding. |
| Published | The report PDF is frozen, the statuses are written back, approvals are offered for the conform documents, the audit is locked and the next occurrence is created. | - |
Questions and troubleshooting
The Procedure column says "No matching procedure" for every item
The series has no procedures yet, or none of them matches the items. Use the Procedures button to add them, or simply assign the items anyway: each one then gets a task with the instruction to audit it. From the second audit onwards the previous audit fills the column by itself.
Add day and Move to day are greyed out
The audit has no start date, so there is no period to plan days in. Set the dates of the audit on the Details tab. Missing only the end date? Then Add day asks for it and sets it for you.
Dragging a row does not move it
Drop it on a row of the target day or on the day header - the empty space below a day is not a drop target. Move to day always works and can move a whole selection at once.
Assign and Merge are greyed out although I selected something
You selected a day, not rows. A selected day can only be removed; select the rows you want to work on and the item commands come back.
An auditee says they cannot open the audit
That is by design. An auditee works from their task, not from the audit. Everything they need - the item, the instruction, the previous result and the result to record - is in the task. The audit itself is for managers, and only for the ones the authorization schema of the series lets in.
I do not see the Audit menu item
Four things have to allow it: you need a manager role, Audit has to be part of your subscription, the module has to be on under Admin > Company > Modules, and - while the module is in preview - it has to be enabled for your tenant by ISOPlanner. Your administrator can check the first three; for the last one, contact support. The same conditions decide whether audits appear in your annual plan and whether the Active audits widget is offered on your dashboard.
New is greyed out in the audit overview
You do not have the Create Audit Template permission. An administrator can grant it per role under Admin > Authorization > Permissions > Audit. You do not need it to run an existing series - only to start a new one.
I cannot complete the audit
There is still an audit task open. The Prepare and Execute tab shows the status of every task (use Refresh for the latest state); chase the auditee, or take the item out of scope if it turns out not to be relevant. Is the task without an auditee? Then the confirmation dialog offers to delete those tasks and complete the audit in one step.
I cannot publish the audit
A non-conformity has no follow-up finding yet. The confirmation dialog names the items; the Prepare and Execute tab marks them Finding required. Create a follow-up task from the audit task of each one, or let the assistant propose them with Analyze results and propose findings. Also check that you are moving one step at a time: an audit is published from Completed, not straight from Executing.
The report says INTERIM
It was generated while the audit was still running. Regenerate it once the audit is Completed and the marker is gone. The same goes for the notice about items without an outcome: it disappears when every scope item has been assessed.
A document I audited did not get an approval
Approvals are only offered for documents you assessed as conform, and they are never created automatically - you send them yourself from the panel behind Create approvals in the timeline. If the panel says everything is already out for approval, a round on those documents is still pending and ISOPlanner will not start a second one alongside it.
I moved the audit to another period
The open audit tasks, the day planning and the Teams meeting move with it; days that would fall outside the new period are pulled inside it. Tasks that are already done keep their own completion date.
What happens to the findings if I delete the audit?
The audit tasks disappear with the audit, but the findings, incidents and improvements stay: they have value of their own and are still in your task list.
Where do I see the audits I am involved in?
Add the Active audits widget to your dashboard. In the audit overview you can also filter on auditor, status, type and period.