The Audits Page in Vanta is your one-stop location for all compliance audit-related information. You can manage reports and timelines from here and connect with your auditors.
Audits page overview
From the left-hand navigation panel, select Audits
There will be two tabs, Active and Completed
The active page details current audits, while the completed page gives you access to previous audits and audit reports.
You can filter for specifics, including Audit Firm, Framework, and Status, or search for terms directly from the search bar.
The Completed page will allow you to view previous audits and download the reports.
Audits can be deleted, and audit reports can be downloaded by selecting the three-dot menu.
Starting the audit
Audits can be created by selecting +Add Audit
From here, you can select the Framework and choose your auditor
Do not select an auditor from the dropdown if you prefer to begin the audit process before adding an auditor.
The Auditor can be added at a later time by selecting the three-dot menu and choosing Assign to audit firm.
Select the Framework, enter the full domain of the audit firm, and who will be performing the audit
Establish the dates for you Audit window, and select Add Audit
Choose the dates for the audit window and which date you would like to give your auditor access to your audit information
The early access date will allow for the auditor to access your Vanta instance before the audit window. Early access means the auditor can help you with a readiness check and can ensure that you are audit-ready.
Click Add Audit
Active audits will be visible from your Active tab on the audit page
From here, you can edit the audit dates and view the timeline of your audit—please keep in mind that dates still must be confirmed with your auditor
📖 Learn more: Adding and managing auditors covers what auditors can access and how to configure their permissions.
Audit progress
The Audit progress bar will visually show your level of audit readiness and any evidence that has been flagged, accepted, or not applicable.
N/A is a status for evidence that an auditor has marked not applicable. Only auditors can mark evidence as N/A (in their audit engagement)
If you need to edit your audit dates, you can do so from the Audit Page
Select the three-dot menu of the audit you would like to edit
Select Edit Audit Dates
Add the appropriate date information
Select Save
ℹ️ Note: Only Evidence Requests (document uploads) can have their Audit Evidence status retroactively updated. For example, if a test changed to passing after the Audit window has begun, that piece of evidence will still be marked as Not ready for audit.
Auditor view
Previewing Vanta as an auditor: Select Open Audit to preview your audit and see what your auditor will have access to.
Managing auditor views: The data your auditor can access depends on your audit configuration.
Auditor comments
With Vanta's Comment section, users can communicate with their auditor in Vanta, keeping all correspondence in one succinct location.
From the Audits page, select Open Audit from any current audits
From the evidence tab, click on the evidence item you would like to address with your auditor.
Select the Comments tab
View and respond to comments made by your Auditor.
All Admin and Editor users will get notified of new Auditor comments, and Auditors will be notified of any comments made by Vanta Users.
