Zum Hauptinhalt springen

Create and plan an audit

How to create a new audit and equip it with a designation, association, scope and audit catalog. The catalog determines the methodology the audit is carried out against – for example ISO/IEC 27001, BSI IT baseline protection or CISIS12.

Last updated:

An audit documents the execution of a structured review in your ISMS. In this guide you create a new audit and add the master data that later makes it suitable as evidence: designation, association, scope and audit period, plus the audit catalog as its methodological basis.

Prerequisites

  • You are logged into a team that uses the “Audits” module.
  • At least one published or in-progress “Audit catalog” exists that applies to the assigned organisations – for example for ISO/IEC 27001, BSI IT baseline protection or CISIS12.
  • You have permission to view audits, plus the respective permission to create and edit them.

Create a new audit

  1. In the left menu, click “Audits” and then the “Audits” entry. The overview page shows all audits of your team with the columns “Status”, “Designation”, “Association”, “Audit catalog”, “Tasks” and “Tags”.
  2. Click the arrow icon next to the “New” button at the top right and select “Create audit”.
  3. Under “Designation”, enter a meaningful name that includes methodology, scope and period – for example ISO 27001 Audit Q2 2026 — Munich site.
  4. Under “Organisations”, select one or more organisations the audit is assigned to. Alternatively, activate “All organisations” to make it available to the entire team; confirm the “Change access” dialog that then appears with “Change access”.
  5. Click “Create”. You are taken directly to the detail page of the new audit.

Maintain master data, period and audit catalog

  1. In the audit detail view, click “Edit” in the top right. The edit form opens as a page view with the “General” section.
  2. Set the “Status” to match your planning stage: “New” for the freshly created audit, “In progress” once execution is underway, “Published” for the completed, auditable state and “Archived” for audits that are no longer operationally relevant.
  3. Optionally assign a “Document ID” following your internal nomenclature, such as the ISO audit number.
  4. Record the scope, audit period, methodological notes and the persons involved in the “Description” field.
  5. In the “Audit catalog” section, use the selection menu to choose the catalog the audit is carried out against. All catalogs available for the assigned organisations can be selected.
  6. Click “Save and close” at the bottom right.

If an audit catalog is already assigned and you select a different one, the “Change audit catalog” confirmation dialog opens. The change may affect inspection items already created and requirements already answered – confirm it only if you are aware of this effect, otherwise cancel.

Practical tips

  • Create a separate audit entry for each audit cycle (quarter, annual financial statement, site) instead of overwriting existing audits. Only then is the historical comparability of results preserved.
  • The designation appears unchanged in PDF and DOCX exports as well as in the activity history – choose it carefully.
  • Only set the status to “Published” once all MUST requirements of all inspection items have been answered and all tasks derived from the findings have been created.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms