Skip to main content

Audit Management

Run every audit in one place, from plan to close

de.iterate is an Australian GRC platform with audit management built in. The Audit Centre handles your audit lifecycle, from the annual plan to the last corrective action. Findings, evidence and actions stay linked, so nothing slips through the cracks between one audit and the next.

Instead of managing policies in one place, risks in another, evidence in folders, and audits through a last-minute scramble, de.iterate connects the whole system. That means better visibility, clearer ownership, stronger assurance and less time lost to manual admin. The current platform spans policies, assurance tasks, registers, evidence, reporting, Trust Centre capabilities, auditor access and support for multiple frameworks.

We help you get your ducks in a row.

deiterate-platform
policy-calendar

Sound familiar?

Thursday afternoon, 4pm

Last year’s findings are in a PDF. The corrective actions are in a spreadsheet. The person who agreed to fix the big one thought someone else was handling it.

Larger organisations have more findings and more places to keep them. Internal audit tracks its own in a register, the external auditor’s live in the management letter, the penetration tester’s are in a PDF on the security drive, and the regulator’s sit in a letter addressed to the CEO. Each quarter someone in risk compiles them into a single spreadsheet for the audit committee, by hand. Half the actions are assigned to a department rather than a person, a third have said “in progress” for over a year, and nobody is sure whether the finding closed by the external auditor is the same one internal audit raised again in June.

Then a calendar reminder pops up saying “corrective actions due”, and the room goes very quiet.

How de.iterate handles audit management

An audit runs smoothly when the program is planned, the auditor can see what they need without asking, and every finding ends up with a named owner and a date. de.iterate covers the whole cycle. Audits are scheduled and tracked in one place, the auditor works from a portal rather than an inbox, findings and corrective actions sit in registers linked to the audit that raised them, and the write-up is drafted for you rather than from scratch.

plan-annual-audit

Plan the year's audits in one place

Plan your annual audit program, schedule engagements and track each audit through its phases. Certification, surveillance and internal audits all sit in the de.iterate Audit Centre.

compliance-management

Give every finding an owner and a finish line

Findings and corrective actions each have their own register, linked to the audit that raised them. Every action has an owner and is tracked through to closure.

auditor-portal-1

Swap the folder of attachments for a login

The Auditor Portal gives your external auditor their own login to review your documents, controls and evidence. You'll have fewer email chains and a much calmer audit week. Auditors love de.iterate.

prove-read-understood

Bring every finding into one register

Findings from internal audits, external auditors, penetration tests and regulators all land in the same register, each linked to the controls and risks it relates to. You can see when two audits have raised the same issue, close it once, and show both auditors the same evidence.

key-risk-indicator

Spend less time writing up reports

Export an evidence pack for your auditor, ready to hand over. For internal audits, the platform even drafts the report for you to review, edit and approve.

connect-policy-obligation

Report to the audit committee easily

Dashboards show open findings, overdue actions and closure rates by owner, business unit and audit, drawn from the live registers. The quarterly pack reflects the position on the day it’s presented, and the person who used to compile it by hand gets their quarter back.

assurance-task-mock-up

Also included

    • Evidence Store: evidence linked to the task, control or requirement it supports
    • Testing history and evidence export for your external auditor
    • Assurance coverage mapped to your enterprise risks, showing which risks are well tested and which are running on hope
    • AI-powered assurance: gap analysis of uploaded documents, with suggested tasks and control mappings and improvements
    • Human approval on every automated suggestion, with its reasoning and confidence recorded

Frequently Asked Questions

Most questions about audits come down to who does what: what de.iterate handles, what your certification body handles, and what’s left for you. The answers below draw the lines, from who runs the audit to what your auditor sees when they log in.

Does de.iterate perform our certification audit?

We would if we could. ISO 17021-1 requires certification bodies to stay impartial, so an accredited external certification body runs your audit. de.iterate gets you ready for it and supports you through it.

Can someone from de.iterate attend our audit?

Yes. The de.iterate team can attend your audit virtually or in person. Book a demo and chat with one of our experts to learn more.

What's the difference between a surveillance audit and a recertification audit?

Surveillance audits usually happen every year after certification, to check your management system is still working. A recertification audit happens every three years and takes a fuller look at the whole system.

Can we run internal audits in de.iterate?

Yes. Plan and run internal audits in the de.iterate Audit Centre alongside your external ones. The platform can even draft the internal audit report for you to review, edit and approve.

How do we track corrective actions?

What does our external auditor see?

Through the de.iterate Auditor Portal, your auditor gets their own login to review your documents, controls and evidence. You can also export an evidence pack for them to review offline.

Can we report audit progress to our board?

Yes. Custom dashboards in de.iterate show your board and management team where each audit is up to and which findings are still open.

What makes de.iterate different

From setup to scale, every feature is designed to help your team save time, stay focused, and drive meaningful results.

Expert support, not just software

de.iterate combines technology with hands-on support from experienced GRC professionals based in Australia. From onboarding through to certification, our team works with you to build momentum quickly, helping many organisations get audit-ready in less than 12 weeks and providing practical support through external audits and ongoing compliance activities.

Continuous compliance, not annual panic

Great compliance is not built in the two weeks before an audit. de.iterate helps you stay ready year-round with assurance tasks, checklists, live registers, reporting and a compliance calendar that keeps momentum going.

Practical enough to use, powerful enough to scale

From start-ups to enterprise, de.iterate supports multiple frameworks in one system, including ISO 27001, ISO 27701, ISO 9001, ISO 14001, ISO 45001, Privacy Acts, SOC 2, DIP, Essential Eight and more. You can grow your compliance maturity without rebuilding everything from scratch.

Key Features

A smarter way to manage compliance

de.iterate combines policies, training, registers, evidence, reporting and assurance workflows in one integrated management system, helping you reduce complexity, stay audit-ready and turn governance, risk management and compliance into business as usual. Every feature is designed to save time, strengthen accountability and make GRC compliance easier to manage across your organisation.
compliance-management

Enterprise Risk Management

 A risk register with a pulse, with inherent and residual scoring, heatmaps and risk appetite. 

board-reporting

Compliance Management

 Every obligation traced to the evidence that meets it, across 25+ frameworks.

policy-management

Policy Management

 Plain-English policies, clear approvals and proof your staff have read them. 

controls-management

Controls Management

 Scheduled controls testing, with the evidence ready before your auditor asks. 

it-cyber-security-consultants

Cyber and IT Risk

 Your whole ISMS, from asset register to Statement of Applicability. 

AI-gov

AI Governance

 ISO 42001, AI impact assessments and an inventory of the AI in your business. 

data-privacy

Privacy and Data Governance

 Find your personal information, see where it goes and keep your privacy policy current.

quality-safety-enviro

Quality, Safety & Environment

 ISO 9001, ISO 14001 and ISO 45001, running alongside everything else you manage. 

risk-drift

Third Party Risk Management

 Keep tabs on the suppliers holding a slice of your risk. 

Multiple compliance frameworks, without extra effort

 

With de.iterate, the complexity of managing multiple frameworks doesn’t translate into increased workload. Our unified platform serves as a central hub for overseeing all your compliance activities, whether you’re working with bespoke frameworks or seeking to meet the criteria of the most sought-after security and privacy standards and certifications.

ISO 27001

Information Security Management Systems

The international standard that sets out the requirements for data protection systems. It’s all about keeping data safe and secure.
ISO 9001

Quality Management Systems

This standard defines the requirements for quality management. It’s all about ensuring your business consistently delivers high-quality products and services.
ISO 45001

Occupational Health and Safety Management Systems

The standard that specifies the requirements for an effective OH&S management system. Create a safer, healthier workplace.
ISO 14001

Environmental Management Systems

The global standard for building EMS. It gives you a structure to identify environmental impacts, manage obligations, strengthen governance.

ISO 42001

Artificial Intelligence Management Systems

This standard specifies the requirements for managing AI systems responsibly and ethically. It helps ensure trustworthy development and use of AI.

SOC 2

System and Organisation Control 2

This specifies how organisations should manage their customer’s data. It is one of the most sought-after security framework for SaaS companies. 

Privacy Acts

Australia, New Zealand, Canada, France, Italy, US and UK

Country-specific legislative frameworks established to protect individuals’ personal information from misuse, interference, unauthorised access, modification, and disclosure.

RRFR

Right Fit for Risk

The Australian Government’s Department of Employment and Workplace Relations uses the External Systems Accreditation Framework and the RFFR approach to assess and accredit third party service providers and systems.

DISP

Defence Industry Security Program

DISP is a critical initiative that ensures businesses in the defence supply chain meet stringent security requirements. DISP compliance is essential for companies that engage in Defence tenders, contracts and projects.

Simple monthly pricing, based on the frameworks you need

de.iterate pricing is structured around the compliance frameworks you choose to access, giving you the flexibility to build a program that fits your organisation’s needs. Every plan includes access to the de.iterate platform and its feature set, from automated and expert-led onboarding, through to migration support, assurance workflows, live registers, compliance reporting and the core documentation needed to run and maintain your management system with confidence.

AUD
GBP
Starter (per month)

$179£100

  • Essential Eight

  • SMB 1001

  • Privacy Acts

  • DISP

  • Cyber Essentials

Business (per month)

$2,100£1,250

  • ISO 27001

  • ISO 27701

  • ISO 42001

  • ISO 9001

  • ISO 45001

  • ISO 14001

  • SOC 2

  • NIST CSF 2.0

  • NIST 800-53

  • NIST 800-172

  • NIST 800-172

  • GDPR

  • Essential Eight

  • SMB 1001

  • Privacy Acts

  • DISP

  • Cyber Essentials

  • DORA

  • NIS2

  • CIS v8

  • EU AI Act

  • TISAX

Enterprise (per month)

$3,500£2,000

  • ISO 27001

  • ISO 27701

  • ISO 42001

  • ISO 9001

  • ISO 45001

  • ISO 14001

  • SOC 2

  • NIST CSF 2.0

  • NIST 800-53

  • NIST 800-171

  • NIST 800-172

  • GDPR

  • Essential Eight

  • SMB 1001

  • Privacy Acts

  • DISP

  • ISM

  • SOCI

  • Right Fit for Risk (RFFR)

  • Cyber Essentials

  • DORA

  • NIS2

  • CIS c8

  • EU AI Act

  • TISAX

Make audit week boring (in the best possible way). 

We'll walk you through an audit in de.iterate, from the plan to the last closed action.