Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Updated how to start the creation of an audit since it was outdated.


Live Search
spaceKeyZenGRCOnboardingGuide
additionalnone
placeholderSearch our site
typepage

Overview


The first step in the audit setup is providing basic information. The setup can be paused for an indefinite amount of time after this step is completed and resumed when there is enough data to continue. 

Creating the Audit


To begin the creation of an audit, complete the following steps:

  1. Click Audits in In the left-hand navigation to open the Audits page.
    Image Removed
  2. Click an existing audit.
  3. Click Create new dropdown box.
    Image Removed
    Select Internal audit or External audit.
    , click the New button and select Audit (External) or Audit (Internal).

    Image Added


    Tip
    titleTIP

    Select External audit for the ability to export information to outside auditors. This allows external auditors to prepare a Document Request List (DRL). Select Internal audit when all assessors and verifiers are internal to your organization and don't need the exported information for preparing a DRL. 


    Info
    titleNOTE

    In this step, internal and external audits are the same, with the exception that external audits include two additional fields for auditors and audit firms outside your organization.


Adding Basic Information


On the first step, complete the following fields:

  1. Audit title - Add a name for the audit. This is a required field.

    Tip
    titleTIP
    The audit title needs to be unique. The system prompts you to select another heading if there is a duplicate in the system.


  2. Audit managers - This is the person who oversees These people oversee this particular audit, and it defaults to the person creating the audit. If you are setting up an audit for someone else, set that person as Audit manager. The users added to this field can be the default selections for assessors and verifiers in the audit's assessments.

    Info
    titleNOTE

    To see how users added to the Audit managers field can be selected as assessors or verifiers for the audit's assessments, please see Setting up a Template in Step 3: Exporting Audit Data or Setting up a Template


  3. Related program - This is the framework for the audit. If a selection is made, the controls mapped to the program are displayed in Step 2 - Defining the Scope. It is optional.

    Info
    titleNOTE

    For instances using the ZenGRC default storage, Google Drive storage, or customized Amazon Web Services (AWS) storage, you no longer select a storage space for each audit, as it is now globally configured. For more information, please see Integrating Your Storage System. Those who connect to their own Box accounts are still able to select the Box folder designated for each audit's evidence upload. Please see the Box information within Integrating Your Storage System.


  4. The following fields only exist for an external audit:

    1. External auditors (optional) - Select ZenGRC users who need access to the visual display of an audit. Those outside your organization need to be added as a user in the application with Creator access.
    2. Audit firm (optional) - Enter the name of the audit organization.

      Info
      titleNOTE

      If your organization has configured ZenGRC to communicate with your Jira instance, you may have an additional selection in the first step. Please see Creating a Jira Audit.


      Info
      titleNOTE

      If your organization has configured ZenGRC to communicate with ServiceNow, you may have an additional selection in the first step. Please see ServiceNow Integration.


  5. Click Next. The page for defining the scope is displayed.

    Tip
    titleTIP
    When you click Next, the audit is created and is located in the Draft Audit tab. 


    Info
    titleNOTE
    Continue to the next section - Step 2: Defining the Scope.