Skip to main content

Compliance

Exporting the compliance audit pack

What the audit pack PDF and its JSON manifest contain, who can export them, and how to check the pack.

What the pack contains

The audit pack is a PDF report of the saved audit record:

  • the audit's title, period, stage and scope, when independence was recorded, and whether the report is signed
  • the conclusion
  • control testing: each control, the sample, the result and notes
  • evidence requests: due date, status and whether evidence is linked
  • findings: severity, stage, fix date, root cause, impact, recommendation, management's response and the retest, each with the date it was recorded
  • an integrity manifest: a SHA-256 digest of the record

The evidence files themselves are not attached. They stay in the workspace's documents, linked to their requests.

The JSON manifest

You can also export the same record as a JSON manifest. It holds the audit, requests, findings and control tests, the time it was made, and the same SHA-256 digest as the PDF. The digest covers the record only, not the time it was made, so it changes only when the record changes. To check that a pack has not been changed, compare its digest with a fresh export.

How to export

Open the audit workspace, pick the audit and choose Export audit pack. The JSON manifest is on the report card. The pack uses the saved conclusion, so save any change to the conclusion first.

Signed or working

You can export at any stage. Until the lead auditor signs, the report says it is a working report, not signed. Once signed, the audit is read-only and the pack is final.

Who can export

Anyone who can open the audit workspace: the compliance auditor, and agency staff with compliance and audit access.

Still have a question?

Can't find what you're looking for? Get in touch and we'll help you out.

No card required · Every plan free for now