Create an inspection item in an audit
An inspection item is the specific unit you audit – an application, a building, or an ISMS process. This guide shows how to create a new inspection item with designation, inspection object type, and applicability in the “Inspection items” section of an audit.
An inspection item is the specific unit you audit: an application, a building, a process, or an ISMS process. The checklists, requirements, and hazards from your audit catalog are all attached to it later on. This guide shows how to create an inspection item in a running audit.
Prerequisites
- You have access to the audit via the organisation assignment or via the “All organisations” setting.
- You have permission to edit audits.
- An “Audit catalog” is already assigned to the audit. Without a catalog, no inspection object types, applicability levels, or checklists are available for selection.
Step by step
- Open the audit detail view.
- In the “Inspection items” section, click “New” at the top right. The “New test object” page view opens.
- Under “Designation”, enter the name of the inspection item. This is a mandatory field, for example
HR management IT systemorHead office building. - Select the “Inspection object type” from the types defined in the audit catalog, such as “Applications”, “Compliance”, “Buildings”, “Infrastructure”, “ISMS process”, or “Process”.
- Optionally use the “Data processing systems” field to link the inspection item to one or more entries from the system landscape. Enter a search term or select from the suggestion list; multiple entries are permitted. This anchors the audit assessment to a specific asset.
- Select the “Applicability” from the levels defined in the audit catalog, for example “Relevance: MUST”, “Relevance: SHOULD”, or “Relevance: CAN”. Together, the inspection object type and the applicability determine which checklists are offered to you for assignment afterwards.
- Click “Create”. The new inspection item appears in the “Inspection items” section of the audit detail page.
How this differs from the inspection object type in the audit catalog
You create the inspection item inside the audit, whereas the “Inspection object type” is master data maintained in the audit catalog. The catalog describes the methodology (which types, applicability levels, and checklists exist), the audit describes the execution. If the type you need is missing from the selection list, add it in the audit catalog first.
Practical tip
Structure inspection items as a hierarchy, for example “Site > Business unit > Application”. Using the menu on an existing inspection item, “Add” creates a subordinate inspection item. For several similar units, use “Duplicate” – the copy includes the assigned checklists and their requirements. The hierarchical view makes navigation easier in large audits under ISO/IEC 27001, BSI IT baseline protection, or CISIS12, and produces a comprehensible table of contents in the PDF export.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.