Skip to content

Audits

An audit is a self-contained workspace for one compliance effort. It brings together assessments, evidence, documents, tasks and approvals in one place, and the whole experience adapts automatically to the framework you’re working against.

The audit list

The audit list shows every compliance effort you can access, with its framework, linked workspace, creation date and current status. Select one to open its overview.

The overview

The overview is the central hub for an audit. Because Governy adapts to the chosen framework, two audits can look quite different depending on whether they follow ISO 27001, GDPR, CyFun, NIS2, DORA or a custom framework. The header shows the audit name, framework, workspace and — when applicable — a banner indicating the audit is locked.

Charts and metrics

The overview presents the visualisations that make sense for the active framework:

VisualisationShown for
Compliance donutAll frameworks — share of requirements in each result state
Radar chartFrameworks organised by domain — score per domain or control family
Domain bar chartStandard frameworks — compliance per domain
GDPR breakdownGDPR — article-level compliance
CyFun heatmapCyFun — maturity levels across the five categories
Metadata & status cardsAll frameworks — framework, dates, lock state and item counts

Control explorer

An interactive tree of every requirement in the audit. Browse the hierarchy and select any item to open its assessment.

Shortcuts to Evidence, Planning and Documentation.

One platform, many frameworks

Governy is built to support any number of compliance frameworks at the same time. Each audit follows exactly one framework, but your organisation can run several audits in parallel — one per framework — all from the same platform. Adding a new framework never requires technical work: once it’s available, it can be selected for a new audit and the interface adjusts itself.

Sections of an audit

Every audit offers a consistent set of sections, with a few that appear only for the frameworks that need them:

SectionPurpose
OverviewCharts, metrics and quick links
AssessmentSelf-assessment of every requirement
Statement of ApplicabilityISO 27001 only — applicability decisions
EvidenceThe audit’s evidence library
DocumentationDocument library with version history
PlanningTask board and scheduling
Approval CenterReview, approve or reject assessments
UsersManage who has access to the workspace

How frameworks change the experience

FrameworkAssessment journeysHighlights
ISO 27001Clauses (4–10) + Statement of ApplicabilityApplicability decisions, “New 2022” badges, 93 Annex A controls
GDPRArticle-focused assessmentOnly relevant articles, per-article breakdown
CyFunAssessment by maturity groupMaturity switcher, category heatmap
NIS2 / DORASingle assessmentStandard multi-domain layout
CustomSingle assessmentFully functional with no setup work

Locked audits

When an administrator locks an audit, a banner appears and assessment fields become read-only for everyone — preserving the record. Approvers can still approve or reject, and auditees can still provide evidence.