Evidence and findings
How to answer an auditor's evidence requests, respond to findings, and keep the record of the engagement in one place.
Once a contract is funded, the project workspace is where the engagement happens. Its tabs: overview, messages, milestones, evidence, findings, sessions, files and disputes.
Evidence requests #
An auditor asks for evidence by posting a request in the evidence tab: what they need, why, and by when. Each request is a row in the evidence register with a state: open, provided, accepted, or rejected with a note.
To answer one, upload the document against the request or attach a file already in the engagement. Files are stored encrypted, only the parties to the contract and Auditly's mediators can open them, and every download is logged. The auditor then accepts the evidence or explains what is missing.
The register is the record of the engagement. Nothing in it is deleted; a withdrawn request or a replaced file stays visible as such.
Findings #
When the auditor identifies a gap, they raise a finding: the observation, the clause or control it relates to, its severity, and what would satisfy it. A finding is open until you respond.
Your response is written into the finding: what has been done, or is planned, and by when. The auditor then closes the finding as addressed, keeps it open with a note, or withdraws it. Every response and decision stays on the finding, so the final report matches the record.
Sessions #
Interviews, walkthroughs and review meetings are scheduled in the sessions tab. The auditor proposes a slot, you confirm or decline it with a note; both calendars show the same thing.
Messages #
Messages in the workspace belong to the contract and stay with its record. Before the contract is funded, contact details typed into a message are masked; after funding they pass through.
Files #
Documents that belong to the engagement but to no single request live under files: the report, the scope statement, the signed proposal.