Fussion_GRC domain 4 of 15
Audit Management
Run internal and external audits from one place: scope, requests, evidence, findings, corrective actions and closure.
Fussion_GRC consumes data from your existing tools. It does not perform security scanning.
- Compliance moduleReal time
- Evidence repositoryReal time
- Jira / ServiceNowEvery 15 minutes
The problem
What problem this domain solves
Audit management covers planning audits, handling auditor requests, providing evidence, recording findings and tracking corrective action requests (CARs) through to verified closure.
For the CISO
Why this matters to the CISO
Audits consume weeks of senior time. Requests arrive by email, evidence is shared over file links, and findings are tracked in a separate spreadsheet. A CISO needs one controlled trail that both the team and the auditor can rely on.
Audit status, open findings by severity and any corrective actions at risk of missing deadlines.
How it works
How Fussion_GRC works in this domain
Fussion_GRC consumes data from your existing tools. It does not perform security scanning. It connects to the tools that already hold audit data, then does the following:
- 01Builds the audit scope from the frameworks and controls in scope.
- 02Answers auditor requests from existing evidence where it is current.
- 03Converts findings into corrective actions with owners and due dates.
- 04Keeps a full, time-stamped audit trail of every request and response.
Data in
Exactly where the data comes from
| Source tool | Data received | Typical sync |
|---|---|---|
| Compliance module | Controls, framework mapping and scope | Real time |
| Evidence repository | Automatically collected and uploaded evidence | Real time |
| Jira / ServiceNow | Status of remediation tickets for findings | Every 15 minutes |
| Auditor workspace | Requests, comments and sample selections | On event |
Typical frequencies; exact intervals depend on each tool's API limits and your configuration. Connector availability varies — see integrations.
Data flow
From your tools to the boardroom
- 1. Framework
- 2. Control
- 3. Evidence
- 4. Auditor request
- 5. Finding
- 6. CAR closure
Automation
Automation and workflows
Workflows created
- Framework → control → evidence → auditor request → finding → CAR → closure
- Auditor sample request → owner provides evidence → reviewer approves → shared
- CAR overdue → escalation to CISO
Actions for leaders
- Respond to open auditor requests
- Accept or dispute a finding
- Approve corrective action closure
Controls & evidence
Controls and evidence
Controls are defined once and mapped across frameworks. See supported frameworks.
Controls
- Annual internal audit plan
- Findings tracked to closure
- Management response for every finding
- Verification of corrective actions
Evidence generated
- Audit plan and scope
- Request and response log
- Findings register
- CAR closure evidence
AI assistance
How Fussion AI helps
Answers come from your own Fussion_GRC data, with sources. Learn about Fussion AI.
Questions you can ask
- "Show me controls with missing evidence for next month's audit."
- "Draft a management response for this finding."
- "Which findings from last year are still open?"
- Hundreds of auditor requests answered through email and shared drives.
- The same evidence requested and supplied again every year.
- Findings and corrective actions that drift past their deadlines.
Every point links to its source record. Recommendation only — a named owner approves decisions.
Dashboard
Dashboard example
Roles
Who uses this domain
CISO
Audits consume weeks of senior time. Requests arrive by email, evidence is shared over file links, and findings are tracked in a separate spreadsheet. A CISO needs one controlled trail that both the team and the auditor can rely on.
CIO
Sees how audit affects IT services, investment priorities and the systems the business depends on.
Security Manager
Runs day-to-day audit operations from one queue instead of separate tool consoles.
GRC Manager
Maps audit controls to frameworks, tracks evidence freshness and prepares audits.
Control Owner
The requests assigned to them and corrective actions they must complete.
Auditor
A dedicated, read-only workspace with requests, evidence and a complete history.
Technical Owner
Receives specific, prioritised tasks in Jira or ServiceNow with the context needed to fix them.
Executive
Audit status, open findings by severity and any corrective actions at risk of missing deadlines.
Integrations
Tools you can connect
- Jira
- ServiceNow
- SharePoint
- Google Drive
- Confluence
- Microsoft Teams
Named tools show typical sources; availability may be planned, roadmap or custom connector. Confirm during a demo.
See all integrationsOutcomes
Business outcomes
Example
Example workflow
- 1System
New signal from Compliance module
- 2Fussion_GRC
Builds the audit scope from the frameworks and controls in scope.
- 3Control owner
Framework → control → evidence → auditor request → finding → CAR → closure
- 4GRC manager
Evidence attached: Audit plan and scope
- 5CISO
Respond to open auditor requests
FAQ
Frequently asked questions
Can external auditors log in?
Yes, through a limited workspace that only shows the audit they are working on and the evidence you have chosen to share.
Do we still need our internal audit tool?
Fussion_GRC covers security and compliance audits. If you have an enterprise internal audit tool, findings can be synchronised with it.
Does Fussion_GRC scan our environment?
Fussion_GRC consumes data from your existing tools. It does not perform security scanning.
