Skip to content

Audit Engagements

An engagement is a time-bounded audit scoped to one or more frameworks (e.g. ISO 27001, or ISO 27001 + SOC 2). It pulls in the SCF controls that map to those frameworks, presents them from the framework’s own perspective alongside the evidence you’ve already collected, and gives an external auditor a read-only workspace to review and raise queries.

Find it in the app under Engagements, in the Admin section of the sidebar.

Click + New Engagement and fill in the drawer:

  • Name — how you’ll recognise this audit, e.g. ISO 27001:2022 Certification — FY26.
  • Frameworks — search and tick one or more. Each row shows the framework’s full name, its key, and how many SCF controls map to it. Selecting frameworks is what pulls controls into the engagement.
  • Audit period — the start/end of the window evidence is matched against:
    • SOC 2 Type 2 — use the full observation period.
    • ISO 27001 — use the surveillance year.
    • You can leave the dates blank and set them later by editing the engagement.

On save, the engagement materialises its scope: a frozen snapshot of every control mapped to the chosen frameworks, tagged with how your organisation scoped each one. The snapshot is the audit assertion — evidence and control status stay live, but the membership and exclusion rationale are captured at this moment.

Each engagement card has four actions.

The complete set of framework-mapped controls, grouped by scope status:

GroupMeaning
In scopeA control your organisation selected
ExcludedA control your organisation deliberately put out of scope — the exclusion justification is shown inline, which is what an auditor reviews to understand why a mapped control was excluded
Not trackedMapped to the framework but not yet in your control set

The controls re-sequenced under the chosen framework’s own clause / Annex A identifiers (for ISO 27001, its numbered clauses and Annex A controls). Switch frameworks with the pills at the top.

Each control shows its live implementation status, owner, and evidence. Evidence chips are green when the artifact was uploaded inside the audit window and muted when outside it — nothing is hidden, so the auditor decides.

Manage who can see this engagement from outside your organisation. An auditor you add gets read-only access to this engagement only — its controls, evidence (including exclusion justifications and evidence window flags), and queries, and nothing else in your organisation. Revoking access takes effect immediately; re-granting a revoked auditor reactivates their access.

The audit’s question log. It runs a simple lifecycle:

  1. Open — an auditor raises a question or request against a control.
  2. Answered — the control owner responds. (Any response moves an open query to answered.)
  3. Closed — the auditor closes the query once satisfied.

A closed query can be reopened if there’s more to discuss. Each query is raised against a control by its SCF identifier, and when a query is raised, your organisation’s admins are notified.

ActionWho can do it
Create or edit an engagementOrg editor or admin
Delete an engagementOrg admin
View scope, present, list queriesOrg members and granted auditors
Grant / revoke auditor accessOrg admin
Raise / respond to / close queriesOrg members and granted auditors

Deleting an engagement is only possible while it’s a draft.

  • Evidence window uses the artifact’s upload date as a proxy for when the evidence is from. This is adequate for ISO’s last-period framing; stronger SOC 2 Type 2 fidelity (a distinct effective date per artifact) is a planned enhancement.
  • Framework outline is derived from the controls that map to it, so clauses no control maps to won’t appear — the view is control-centric rather than a gap-complete framework tree.
  • Framework and control pickers currently take identifiers directly; friendlier pickers are planned.