Audits

Run the internal audit,
close every finding.

Work through an internal audit check by check, recording a finding against each. When a check fails, log the finding with its root cause and the corrective measure, give it a deadline, and carry it to completion in the non-conformity register — so nothing falls between the audit and the next surveillance visit.

Start for freeBook a conversation
++++
app.devguard.ch / audits
00:42 elapsed
Audit progress
Audit progress
12/20
checks done
Passed12
Open03
N/A05
ISO 27001 internal audit · Q2
Access controls
A.5.15
Backup & recovery
A.8.13
Incident response
A.5.24
Use of cryptography
reviewing
Supplier security
A.5.19
3 findings logged — carried to closure in the register
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
How it works

From check to closed finding.

An internal audit, worked check by check, with every finding tracked from the moment it’s logged to the day it closes.

01

Work through the checks

Open an internal audit against a framework and go check by check. You review each check against your evidence and record a finding wherever it falls short.

02

Log the finding with cause and measure

Where a check fails, record a finding: its root cause, the corrective measure you’ll take, and a deadline to act by. The deadline shows up in your Deadlines view, so a non-conformity can’t quietly slip past its date.

03

Carry it to closure

Every finding stays open in the register until you mark it complete, visible in one place across audits.

Findings carried to closure

Each non-conformity sits in the register with its cause, measure and deadline until it’s closed — so the auditor sees a tracked corrective action, not a forgotten note.

Why it’s built this way

Built for the surveillance audit.

Four choices behind how audits work here — each one you can check, not an adjective.

01

Findings recorded check by check

You run an internal audit and record a finding against each check, so the result is a structured audit, not a standalone checklist.

02

Findings carry cause and measure

A finding records its root cause and corrective measure together, so the fix is documented next to the problem.

03

Every finding has a deadline

A finding’s due date appears in Deadlines, so a non-conformity is tracked to a date instead of a backlog.

04

A register, not a snapshot

Non-conformities stay open in the register until closed, so closure is a state you can show, not a claim.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where audits sit.

An audit sits alongside the evidence, controls and coverage you maintain, and feeds the reports you hand to an auditor.

342
artifacts captured
linked to controls

Evidence

Keep the proof behind your controls in one place to review.

86%
Shared with
JDAKMR+3

Reports

Export the audit and its findings as a PDF to share.

ISO 27001SOC 2GDPRNIST CSF

Frameworks & controls

Run an audit against the framework and control set you hold.

coverage86%

Coverage

See which controls are met before you open the audit.

FAQ

The questions evaluators ask.

What’s the difference between an audit and the audit log?

An audit here is an internal review you run against your controls — working through checks, logging findings and closing non-conformities. The audit log is the automatic history of changes to your records. Different things: one you run, one runs itself.

What happens to a finding after I log it?

It carries its root cause, corrective measure and deadline into the register and stays open there until you mark it complete. The deadline also appears in Deadlines, so it’s visible in your wider compliance planning, not just inside the audit.

Can I run audits for more than one framework?

Yes. You run an internal audit against whichever framework you hold, working through its checks and recording a finding against each. Every finding carries its own root cause, corrective measure and deadline, so each audit stands as its own tracked record.

How is this different from running the audit in a spreadsheet or another GRC tool?

In a spreadsheet, a finding is a row in a tab that nobody reopens, and the corrective action is whatever you remember. Here, you record a finding against each check, each one carries its cause, measure and deadline, and it stays open in the register until it’s complete — so a surveillance auditor sees a tracked corrective action instead of a list you rebuilt the week before.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Your audits, findings and the full register are yours and exportable, as a PDF audit report or in full, at any time, with no lock-in.

Run the audit, and carry every finding to closure.

Work through the checks, log each finding with its cause, measure and deadline, and close out the register before the surveillance audit — not the week of it.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free