xmodoxmodo

Auditors and assessors

Audit the same evidence your client manages

You work in a portal limited to your engagement. You see the same evidence your client's team manages, with its validity, owners and dates. Every access is recorded.

Evidence and expiry dates

Quarterly access reviewValid
Penetration test reportValid
Internal audit reportExpires in 12 days
Disaster recovery testExpired

The owner of each item received a renewal task before its expiry date.

Example data.

How an engagement runs

  1. 1

    Scoped access

    You are invited to one engagement, with its framework, period and evidence requests. You cannot see anything else in the client's account.

  2. 2

    Evidence and its validity

    Each piece of evidence shows what it proves, when it was collected and when it expires. You do not need to search a shared drive.

  3. 3

    Request, comment and mark as reviewed

    Ask for more evidence, comment on what you see and mark items as reviewed. Owners are notified, and the audit trail records each action.

  4. 4

    Export pack

    At the end of the engagement, you receive an indexed export of the evidence you relied on for your working papers.

Certification, regulatory and internal audits

You can use the same portal for an ISO/IEC 27001 certification audit, a SOC 2 examination, a DESC certification, a PCI DSS assessment by a QSA, a regulator's inspection and an internal audit. Each finding has an owner and a due date. It is closed with evidence on the same record.

Frequently asked questions

Can I edit or delete evidence?

No. Auditors have read-only access to evidence. You can request more evidence, add comments and mark items as reviewed.

Is there a charge to the audit firm?

No. Auditors and assessors use the portal at no cost.

Can I see the client's whole account?

No. You see only the engagement you are invited to, with its scope and evidence requests.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo