Skip to main content
Sign in See the demo

The audit is in three weeks. Your evidence is ready.

Regulatory inspection, certification audit, client review: every request is handled from your documents, with the document, page, version and the name of the person who approves it. This is where we come from: preparing files that a third party will scrutinise.

  • Evidence plans per requirement
  • Gaps identified before the auditor
  • Replayable history
  • 0 data outside your environment1

What is an external audit?

An external audit is the examination of a company’s practices by an independent third party: a supervisory authority, a certification body, or an auditor appointed by a client. The auditor asks for documented evidence, checks that it is consistent with what has been declared, and records any nonconformity found.

Definition as used on this page. See the glossary.

1 “Environment” means your private instance, whichever deployment mode applies: SaaS, private cloud or on-premise.

The scene

The engagement letter has arrived. The list of documents requested runs to four pages.

  1. 01Each requirement expects specific evidence, not a verbal explanation.
  2. 02Some documents exist, but in a version that predates the audited scope.
  3. 03The nonconformities from the last audit were supposed to be closed; two are not.
  4. 04Three people who held the information have changed roles.
  5. 05What you have declared to your clients must match what the auditor will see.
  6. 06A major nonconformity can suspend a certification, and with it contracts.

The real cost

What makes preparation expensive

An auditor does not judge your intentions: they compare what you say with what you can prove.

  1. Week −3

    Collection

    Chasing eight departments for documents that already exist, and checking that they really cover the audited period.

  2. Week −2

    The version

    The policy produced is the right one, but not in the version applicable at the time. The auditor will notice.

  3. Week −1

    The inconsistent declaration

    What was written to a client last year no longer matches current practice. Nobody had compared the two.

  4. Week +1

    The action plan

    The nonconformities are recorded. Now the missing documents have to be produced, against a deadline, with the same teams.

With Optivalue.ai

Seven stages, from engagement letter to close-out

Stage 1 of 7

Connect your sources

Policies, procedures, registers, review minutes, incident reports, previous audit reports and their action plans. Everything that makes up the memory of your controls.

Stage 2 of 7

Indexing, with version history

In an audit, the version applicable to the period under review matters as much as the current version. The librarian keeps both and knows which one to cite according to the date of the requirement.

Stage 3 of 7

Upload the list of documents requested

Engagement letter, audit plan, the certification body’s grid or the authority’s request for information: each requirement is extracted and becomes a line to cover, with its deadline.

Stage 4 of 7

The agents assemble the evidence file

For each requirement: the answer, the document that proves it, the page, the applicable version. Where several documents are needed, they are listed together rather than summarised.

Stage 5 of 7

Checks, score and reconciliation with past declarations

The answers are compared with what you declared to your clients in your previous questionnaires. Any divergence between the sales message and the audit evidence is flagged before the auditor finds it.

Stage 6 of 7

Missing documents produced before the audit

Each uncovered requirement is declared, prioritised by severity and assigned to an expert, and the missing document can be drafted with you. Better three weeks to write than three months of action plan afterwards. See the mechanism.

See the mechanism

Stage 7 of 7

Named sign-off and handover to the auditor

The file goes out with, for each requirement, the answer, the document, the page and the approver. Six months later, the history can still be replayed: you can show on what basis the answer was given.

What remains afterwards

The next audit starts with the previous audit’s file.

The evidence plan stays in place, the documents produced stay in the repository, and closed nonconformities are documented with their date. Client questionnaires draw on the same foundation: you no longer tell two different stories.

A permanent evidence plan

Each requirement knows which document covers it, and since which version.

Tracked nonconformities

What was found, what was corrected, when, and by whom.

One consistent story

What the auditor reads and what the client receives come from the same repository.

The difference

Why this file holds up in front of an auditor

Where we come from

We come from governance, risk and compliance (GRC): writing the policies, running the controls, producing the evidence for large groups under inspection. That practice is trained into 72 function agents, 12 sector agents and a librarian.

Born in compliance

Replayability, an auditor’s requirement

An auditor asks how an answer was produced, and from which version. The platform provides it: source, page, version, score, approver, timestamp, reconstructable months later.

The anatomy of a defensible answer

Your audit findings never leave

Audit reports, nonconformities, incidents: a private instance that is never shared, the jurisdiction of your choice among more than 80 countries, on-premise deployment with air-gap support. ISO/IEC 27001-certified vendor.

Sovereignty in detail

Frameworks evolve; grids follow

A new version of a standard or a sector-specific text changes the requirements expected. Optivalue Watch monitors 193 jurisdictions and updates the assessment grids when a text changes.

The ecosystem

We replace neither your auditor nor your certification body: audit and certification remain the work of an independent third party. We prepare the file they will read, and we show what is missing before they do.

Ecosystem

To build and maintain over time the policies, controls and registers that an audit checks, the group publishes Smart Global Governance. The response platform works without it; together, they close the loop.

See the ecosystem →

Frequently asked

Audits: the eight questions that keep coming up

01

Do you replace our auditor or our certification body?

No. We prepare your answers and gather your evidence; audit and certification remain the work of an independent third party. We issue no certification and attest to no compliance.

02

Can we answer a request for information from an authority?

Yes: the request is handled like a questionnaire, each answer citing the document, page and version that prove it, with a named approver. The traceability is designed for this kind of adversarial scrutiny.

03

How do you handle the versions applicable to the audited period?

Version history is kept at indexing. Depending on the date of the requirement, the platform cites the version in force at that time, and flags cases where only a later version exists.

04

Do you detect gaps before the auditor does?

Yes, within the limits of what is documentary: a requirement with no document, an out-of-date document, a divergence from what you have declared elsewhere. A gap in practice, on the other hand, is found on the ground.

05

Who approves the file that is handed over?

Your compliance, quality or security managers, by name, in the platform. Each approval is timestamped and stays attached to the answer.

06

What if a document does not exist at all?

The requirement is declared uncovered, prioritised by severity, and the document can be drafted with you before the audit. We do not write a procedure describing a control that does not exist: that would be fabricating evidence.

07

Do our audit reports stay confidential?

Yes: indexing and processing take place in your private instance, never shared, in the jurisdiction you choose, with on-premise and air-gap support if needed. Nothing is used to train a model.

08

How long before an audit should we start?

Three weeks is enough to assemble the file and write most of what is missing. Earlier is better: the time saved goes into closing gaps, not collecting documents.

Bring the list of documents your auditor has requested.

We process it in front of you, on your documents, in your environment. In one hour you will see what is covered, and what is still to be written.

Demo on your documents See the interactive demo