Running the ISMS

Handling audits and nonconformities

Purpose

The audit programme plus recording and resolution of deviations from internal and external audits. Where you work in the hub: the Audit Management work area (with the audit calendar) and Nonconformity Management.

Who does this

Internal audit and the CISO (project role Bearbeiter); resolution is done by the assignees of the corrective actions.

Running an audit

  1. + New ISMS item → type Audit. Maintain the audit fields: 📅 Audit from / to, 👤 Lead auditor and the standard references (🔒 ISO 27001 Standard chapter, 🔐 ISO 27001 Appendix A).
  2. Move the audit file through the workflow: 📝 Draft → ✏️ In preparation → 🔍 Under audit → 📄 Report in progress → ✅ Completed.
  3. During the audit, record every finding as its own issue: Major Nonconformity, Minor Nonconformity or Opportunity for Improvement — with 👤 Identified by and 📅 Identified on.
  4. Link every finding via found in to the audit file (nonconformity → audit).

Result: completing the audit (✅ Completed) triggers a RACI notification if the rule is enabled. The audit calendar in the work area shows the planned audits.

Audit Management: audit calendar in the “Calendar” view with the “Quarter” range (Q3 2026) and planned audits as entries in the calendar weeks.
Audit Management: “Matrix” tab showing the coverage of the ISO 27001 standard chapters (7/7 covered) by the planned audits.

Handling nonconformities

  1. Move the deviation through the workflow: ✏️ In recording → 🔵 In progress → 🔄 Under review → ✅ Resolved.
  2. Create a Corrective action for the resolution and link it to the nonconformity (Implementing and reviewing measures).
  3. If a deviation leads to a risk of its own, move it via 🔥 In risk assessment to ❌ Risk recorded and create a risk scenario (Managing assets and risks).
Nonconformity Management: major and minor nonconformities plus opportunities for improvement with status, type, assignees and due dates through to closure.

What happens automatically

  • Due Date Monitoring for Nonconformities (daily): reminds before the due date — 30 days ahead for major and minor nonconformities, 14 days ahead for opportunities for improvement.
  • Status Sync From Measure: once a linked action reaches 🟢 Implemented, the nonconformity and connected risks automatically move to 🔄 Under review — you then verify and close with ✅ Resolved.
  • Moving to ❌ Risk recorded triggers a RACI notification if the rule is enabled.

Verify

  • The dashboard shows the Non-conformities & audits tile; overdue deviations appear in the Action center.
  • For the management review, the Management Review report compiles the audit results with findings automatically (Generating reports).

Screenshots from the development environment with sample data.

Documentation baseline: app version 1.1.15 · 2026-08-20