For the Internal Audit Head
Findings that close. Repeat findings that stop repeating.
An audit function is judged on whether findings stay closed. That needs root causes linked to control gaps and incidents, not a tracker of tickets.
Questions you can answer on demand
- What is our repeat-finding rate, and is it trending down?
- Which findings link to a control gap that is still open today?
- Which corrective actions are overdue, by how long, and with whom?
- For any control tested last cycle, what evidence was served and was it valid then?
Each answer drills to the control, the evidence, the owner and the date.
Today
Monday morning, before Compli-Once
Last year's finding is this year's finding. Evidence requests go out by email and come back by apology. Certification audits and internal reviews run on different trackers that disagree.
Repeat findings signal a broken loop
When closure means a ticket was marked done rather than a chain being closed, the same finding returns next cycle and the function loses credibility.
Evidence gathering consumes the engagement
Chasing artefacts by email spends the fieldwork budget on logistics instead of testing.
Two audit universes disagree
Internal reviews and certification audits kept on separate trackers produce two versions of the control's state, and both get quoted.
After
What changes
One machinery for every audit
Internal readiness audits run beside certification audits with the same finding and CAPA machinery. Trackers stop disagreeing because there is one.
Scoped evidence requests
Requests go through a portal. The artifact served is the same object the programme manages, with its validity visible.
Root causes, not repeats
Findings link to the control gaps and incidents behind them. Closure means the chain closed, not the ticket.
The number you take to the committee: repeat-finding rate, trending down, provable.
Your first week
What a proof of concept looks like from your desk
Day 1
Set up one readiness audit with your own scope, severity scale and methodology.
Day 3
Issue scoped evidence requests through the portal; the artefact served is the same managed object, with its validity visible.
Day 5
Raise one finding, link it to the control gap behind it, and watch the CAPA carry an owner and a due date.
What you own
Artefacts you can produce from the platform
Audit programme with scope, schedule and testing status
Findings register linked to control gaps, incidents and corrective actions
Evidence request log with what was served, by whom and when
Closure report showing the chain closed, not just the ticket
The engine
The modules that do the work
Audit & CAPA
Findings with owners, due dates, closure.
OpenEvidence
A vault with expiry tracking.
OpenPolicy
Versions, reviews, acknowledgement rates.
OpenRun your next readiness audit inside the platform.
Frequently asked questions
Can external audit firms use the portal at no cost?
Yes. External auditors get scoped access to the engagement's evidence requests at no charge. They see only what the engagement scope allows, and every access is logged.
How is finding severity configured?
Severity scales are tenant configuration, matched to your audit methodology. Severity drives SLA expectations and dashboard visibility for overdue corrective actions.
