Skip to main content

Running an assessment

An engagement is one assessment of one framework over a period. This is the core compliance workflow.

1. Create the engagement

Compliance → Assessments → New Engagement

FieldNotes
NameWhat you will recognise it by later, e.g. "2026 Annual Assessment".
FrameworkCannot be changed afterwards — the control set is copied in at creation.
Audit planGroups related engagements.
Start / due dateDrives the overdue indicators on the dashboard.

On save, a workpaper is created for every assessable control in the framework. A large framework produces hundreds; this is expected.

2. Assess each control

Open the engagement, then Assess. Each control has its own workpaper.

Effectiveness is graded on two independent axes:

  • Design effectiveness — is the control designed to work?
  • Operating effectiveness — is it actually operating?

The overall maturity is the more conservative of the two. A perfectly designed control that nobody follows is not a mature control, and the platform will not let the design score flatter the result.

Compliance status is your conclusion: compliant, partially compliant, non-compliant, or not applicable.

Not applicable needs a justification

Marking a control not applicable requires a written reason. Scoped-out controls are excluded from the compliance rate, so a regulator will ask why — the justification is what you show them.

Observation is your narrative — what you looked at and what you concluded.

3. Attach evidence

Upload files against the control. Each is stored with a SHA-256 hash, so you can later prove the file has not changed since it was assessed.

4. Raise findings

Where a control falls short, Add Finding. Record severity, root cause, risk and recommendation. Findings have their own remediation lifecycle and appear under Observations.

5. Sign off

See Sign-off. A control is only complete once it has been prepared and reviewed.

Status, and why you cannot set it

A workpaper's status moves by itself:

StatusSet when
Not startedCreated with the engagement.
In progressYou save any content on it.
In reviewThe preparer signs off.
DoneThe reviewer signs off.

There is no status dropdown, deliberately. Status reflects what has actually happened in the sign-off chain, so it cannot be set to "done" by hand without the review really occurring.