Running an assessment
An engagement is one assessment of one framework over a period. This is the core compliance workflow.
1. Create the engagement
Compliance → Assessments → New Engagement
| Field | Notes |
|---|---|
| Name | What you will recognise it by later, e.g. "2026 Annual Assessment". |
| Framework | Cannot be changed afterwards — the control set is copied in at creation. |
| Audit plan | Groups related engagements. |
| Start / due date | Drives the overdue indicators on the dashboard. |
On save, a workpaper is created for every assessable control in the framework. A large framework produces hundreds; this is expected.
2. Assess each control
Open the engagement, then Assess. Each control has its own workpaper.
Effectiveness is graded on two independent axes:
- Design effectiveness — is the control designed to work?
- Operating effectiveness — is it actually operating?
The overall maturity is the more conservative of the two. A perfectly designed control that nobody follows is not a mature control, and the platform will not let the design score flatter the result.
Compliance status is your conclusion: compliant, partially compliant, non-compliant, or not applicable.
Marking a control not applicable requires a written reason. Scoped-out controls are excluded from the compliance rate, so a regulator will ask why — the justification is what you show them.
Observation is your narrative — what you looked at and what you concluded.
3. Attach evidence
Upload files against the control. Each is stored with a SHA-256 hash, so you can later prove the file has not changed since it was assessed.
4. Raise findings
Where a control falls short, Add Finding. Record severity, root cause, risk and recommendation. Findings have their own remediation lifecycle and appear under Observations.
5. Sign off
See Sign-off. A control is only complete once it has been prepared and reviewed.
Status, and why you cannot set it
A workpaper's status moves by itself:
| Status | Set when |
|---|---|
| Not started | Created with the engagement. |
| In progress | You save any content on it. |
| In review | The preparer signs off. |
| Done | The reviewer signs off. |
There is no status dropdown, deliberately. Status reflects what has actually happened in the sign-off chain, so it cannot be set to "done" by hand without the review really occurring.