Audit Engagements
An engagement is a time-bounded audit scoped to one or more frameworks (e.g. ISO 27001, or ISO 27001 + SOC 2). It pulls in the SCF controls that map to those frameworks, presents them from the framework’s own perspective alongside the evidence you’ve already collected, and gives an external auditor a read-only workspace to review and raise queries.
Find it in the app under Engagements, in the Admin section of the sidebar.
Creating an engagement
Section titled “Creating an engagement”Click + New Engagement and fill in the drawer:
- Name — how you’ll recognise this audit, e.g. ISO 27001:2022 Certification — FY26.
- Frameworks — search and tick one or more. Each row shows the framework’s full name, its key, and how many SCF controls map to it. Selecting frameworks is what pulls controls into the engagement.
- Audit period — the start/end of the window evidence is matched against:
- SOC 2 Type 2 — use the full observation period.
- ISO 27001 — use the surveillance year.
- You can leave the dates blank and set them later by editing the engagement.
On save, the engagement materialises its scope: a frozen snapshot of every control mapped to the chosen frameworks, tagged with how your organisation scoped each one. The snapshot is the audit assertion — evidence and control status stay live, but the membership and exclusion rationale are captured at this moment.
The four things you can do per engagement
Section titled “The four things you can do per engagement”Each engagement card has four actions.
View scope
Section titled “View scope”The complete set of framework-mapped controls, grouped by scope status:
| Group | Meaning |
|---|---|
| In scope | A control your organisation selected |
| Excluded | A control your organisation deliberately put out of scope — the exclusion justification is shown inline, which is what an auditor reviews to understand why a mapped control was excluded |
| Not tracked | Mapped to the framework but not yet in your control set |
Present
Section titled “Present”The controls re-sequenced under the chosen framework’s own clause / Annex A identifiers (for ISO 27001, its numbered clauses and Annex A controls). Switch frameworks with the pills at the top.
Each control shows its live implementation status, owner, and evidence. Evidence chips are green when the artifact was uploaded inside the audit window and muted when outside it — nothing is hidden, so the auditor decides.
Auditors
Section titled “Auditors”Manage who can see this engagement from outside your organisation. An auditor you add gets read-only access to this engagement only — its controls, evidence (including exclusion justifications and evidence window flags), and queries, and nothing else in your organisation. Revoking access takes effect immediately; re-granting a revoked auditor reactivates their access.
Queries
Section titled “Queries”The audit’s question log. It runs a simple lifecycle:
- Open — an auditor raises a question or request against a control.
- Answered — the control owner responds. (Any response moves an open query to answered.)
- Closed — the auditor closes the query once satisfied.
A closed query can be reopened if there’s more to discuss. Each query is raised against a control by its SCF identifier, and when a query is raised, your organisation’s admins are notified.
Roles at a glance
Section titled “Roles at a glance”| Action | Who can do it |
|---|---|
| Create or edit an engagement | Org editor or admin |
| Delete an engagement | Org admin |
| View scope, present, list queries | Org members and granted auditors |
| Grant / revoke auditor access | Org admin |
| Raise / respond to / close queries | Org members and granted auditors |
Deleting an engagement is only possible while it’s a draft.
Notes & current limitations
Section titled “Notes & current limitations”- Evidence window uses the artifact’s upload date as a proxy for when the evidence is from. This is adequate for ISO’s last-period framing; stronger SOC 2 Type 2 fidelity (a distinct effective date per artifact) is a planned enhancement.
- Framework outline is derived from the controls that map to it, so clauses no control maps to won’t appear — the view is control-centric rather than a gap-complete framework tree.
- Framework and control pickers currently take identifiers directly; friendlier pickers are planned.
Related Guides
Section titled “Related Guides”- Framework Management — activating and mapping frameworks
- Evidence Management — collecting the evidence auditors review
- Consultant Portal — managing multiple client organisations
