Release and complete an audit
How to move an audit to the “Released” status, secure the reviewed state as evidence for your ISMS and use the actions for export, duplicate and association.
Releasing an audit freezes a reviewed state: from that moment the audit counts as a versioned, auditable record you can present in an ISO/IEC 27001 certification audit or to your internal audit function. This guide shows how to complete an audit, export the state and prepare the next audit cycle.
Prerequisites
- You have access to the associated organization, or the audit is released for “All organisations”.
- You have the authorization to edit and release audits.
- The audit status is “New” or “In progress” – only then is the release offered.
- All requirements of the inspection items have been answered and the findings are recorded as “Tasks”.
Edit and release the audit
- Open the detail view of the audit and check the sections “General”, “Association”, “Inspection items” and “Audit catalog” in the “Contents” tab. The progress indicator on each inspection item shows how many requirements have already been answered.
- Click “Edit” at the top right if something is still missing – for example the audit period or the persons involved in the “Description” field. Then save with “Save and close”.
- Click the green “Release” button at the top right. The audit moves to the “Released” status and is then considered a versioned, auditable audit state.
- In the “Activities” tab, confirm that the release has been logged. Observers and assigned users are additionally notified by email and in the application.
Further actions after the release
Click “Actions” at the top right to open the additional functions.
- “Download as PDF” or “Download as DOCX” – exports the audit with all inspection items and requirements as a file; the record to file with your audit documentation.
- “Audit objects with status as XLSX” – exports an overview of all inspection items with their current processing status, ideal for status reporting to management or handover to external auditors.
- “Duplicate” – creates a copy of the audit as a new draft for the next audit round using the same methodology.
- “Change affiliation” – adjusts only the organizational assignment without reopening the released content.
- “Watch” – adds you as an observer so that you are notified about later changes.
- “Delete” – permanently removes the audit together with its inspection items, audit lists, answers, hazards and attachments after a security prompt.
Practical tip: create a “Task” for every identified gap instead of merely noting it in the description of the requirement – tasks can be tracked via follow-ups and status. Release the audit only once these tasks exist, and duplicate the released state for the next cycle so that the historical comparability of your ISMS evidence is preserved.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.