54 received / 51 missing, 105 controls
26 compliant / 74 open / 5 N/A
HIL review and evidence upload
30 day remediation SLA enforced
Common Audit Operations
1 external, 2 internal
7 due this week
artifacts this cycle
| Audit | Type | Stage | Auditor | Window | Status |
|---|---|---|---|---|---|
| ISO 27001:2022 Certification | External | Stage 1 prep | Certification body | Nov 2026 | On track |
| SOC 2 Type II | External | Observation window | CPA firm | Jan to Jun 2026 | Evidence flowing |
| Internal ISMS Audit | Internal | Fieldwork | Internal audit | Aug 2026 | 2 findings |
| Vendor Security Review | Internal | Planning | GRC team | Sep 2026 | Scheduled |
| Request | Control | Owner | Due | AI Verdict |
|---|---|---|---|---|
| MFA configuration export | A.5.17 | IT Ops | Tomorrow | Confirmed |
| Access review Q2 sign off | A.5.18 | HR | Fri | Needs human review |
| Backup restore test log | A.8.13 | Infra | Fri | Downgraded, retest |
| Incident postmortem SEC-1142 | A.5.26 | SecOps | Mon | Awaiting upload |
Audit Modules
Run a test now. Run it when it's due. Or let GRXForce build the evidence stack when the auditor asks, all powered by one Audit Engine.
AI prepares the evidence and workpaper. Your auditor retains the final judgement.
Real-Time Audit
Initiate New Control Test
Select a framework, domain and control to see the control description.
Read-only access scopes. Sources are matched to the selected control and intersected with your selected in-scope applications where applicable.
| Source | Records | Status |
|---|
| Rule | Population | Result |
|---|
| Control | Framework | Date | Auditor | Result | Workpaper |
|---|---|---|---|---|---|
| A.5.15 Access control | ISO 27001:2022 | Jul 31, 2026 | John Smith | Compliant | View |
| A.5.18 Access rights | ISO 27001:2022 | Jul 28, 2026 | John Smith | Compliant | View |
| A.8.16 Monitoring activities | ISO 27001:2022 | Jul 25, 2026 | John Smith | Non-Compliant | View |
Demonstration data shown.
Pre-Defined Tests
Configured once, GRXForce runs each test on its frequency: evidence collected, AI review completed, result or exception identified, workpaper generated and placed in the workpaper repository for auditor review and conclusion.
| Control | Scope | Frequency | Next Run | Status | Workpaper |
|---|---|---|---|---|---|
| Employee Termination | HRIS + Identity Provider | Monthly | Sep 1 | Ready | Ready for Review → View Workpaper |
| User Access Review | Finance Applications | Quarterly | Oct 1 | Ready | Ready for Review → View Workpaper |
| Privileged Access Review | Cloud Infrastructure | Quarterly | Oct 15 | Ready | Ready for Review → View Workpaper |
| Vulnerability Management | Production Servers | Monthly | Sep 5 | Exception | Ready for Review → View Workpaper |
| Backup Testing | Core Systems | Quarterly | Nov 1 | Ready | Ready for Review → View Workpaper |
| Security Awareness | All Employees | Quarterly | Dec 1 | Ready | Ready for Review → View Workpaper |
| Vendor Review | Critical Vendors | Annual | Jan 15 | Ready | Ready for Review → View Workpaper |
| Policy Review | Information Security Policy Set | Annual | Feb 1 | Ready | Ready for Review → View Workpaper |
Schedule → Test → Evidence → Review → Workpaper
26/105 verified compliant
Trust services criteria, security and availability
privacy program baseline
consent and notice architecture in progress
harmonized alignment via common control framework
one artifact satisfies several controls
Collect once, satisfy every framework that needs it. Adding a framework maps existing evidence automatically.
operating with fresh evidence
evidence older than policy
missing or rejected evidence
| Control | Family | Owner | Evidence | Health |
|---|---|---|---|---|
| A.5.15 Access control | Organizational | IT Ops | Fresh, 3 days | Healthy |
| A.5.17 Authentication | Organizational | IT Ops | Fresh, 1 day | Healthy |
| A.6.3 Security awareness | People | HR | Stale, 94 days | Degrading |
| A.7.4 Physical monitoring | Physical | Facilities | Missing | Failing |
| A.8.13 Backup | Technological | Infra | Rejected, retest | Failing |
| A.8.16 Monitoring activities | Technological | SecOps | Fresh, 6 hours | Healthy |
version controlled
within 30 days
current versions
| Policy | Version | Owner | Next review | Status |
|---|---|---|---|---|
| Information Security Policy | v5.0 | CISO | Mar 2027 | Published |
| IT Asset Management Policy | v5.0 | IT | Feb 2027 | Published |
| Access Control Policy | v3.2 | IT Ops | Sep 2026 | Review due |
| Incident Response Plan | v4.1 | SecOps | Oct 2026 | Published |
| Data Retention Policy | v2.0 | Legal | Aug 2026 | In revision |
Board ready summary of posture, gaps and trajectory. Generated monthly.
PDF Auto scheduled
All 93 Annex A controls with applicability, justification and status. Auditor formatted.
XLSX Current
Every artifact with AI verdict and human sign off trail, exportable per audit.
ZIP 126 approved
Framework by framework deltas with remediation owners and dates.
PDF 74 open
Residual risk heatmap and treatment decisions for management review.
XLSX Current
Certificates, attestation letters and audit reports in one shareable trust page.
Coming with your first cert
12 critical tier
this quarter
rolling 12 months
| Vendor | Tier | Data access | Last assessment | Risk |
|---|---|---|---|---|
| Cloud hosting provider | Critical | Production data | May 2026 | Low |
| Payroll processor | Critical | Employee PII | Apr 2026 | Low |
| Marketing analytics | Standard | Pseudonymized | Jan 2026 | Medium |
| Print and logistics | Standard | Contact data | Overdue | Assess now |
21 critical or high
SLA enforced
with verified evidence
| Issue | Severity | Owner | Due | Status |
|---|---|---|---|---|
| Enable MFA on legacy admin portal | Critical | IT Ops | 3 days | In progress |
| Upload DR test results | High | Infra | 6 days | Not started |
| Close access review exceptions | High | HR | 8 days | In progress |
| Refresh security training records | Medium | HR | 14 days | In progress |
| Vendor DPA renewal, logistics | Medium | Legal | 21 days | Not started |