Compliance Tools
The Auditor Portal gives your external auditor a time-bounded, read-only workspace scoped to a specific audit engagement. They can browse evidence, auto-match their PBC list, and use pre-populated working paper templates — without modifying anything. It is one piece of the wider auditor experience Quox provides.
Creating an engagement
An admin creates an engagement by specifying:
- Auditor email and name — who will access the portal
- Firm name — the audit firm
- Framework — which compliance framework (ISO 27001, SOC 2, GDPR, etc.)
- Audit period — start and end dates
- Duration — how long the auditor has access, in days (90 by default)
The auditor receives an invitation. Their access expires automatically — no manual revocation needed.
What auditors can do
| Action | Allowed |
|---|---|
| Browse evidence by control | Yes |
| View VOLT chain integrity | Yes |
| Download assurance packs | Yes |
| Upload PBC list for matching | Yes |
| View working paper templates | Yes |
| Modify any data | No |
| Access other organisations | No |
| See data outside the audit period | No |
PBC auto-match
The auditor uploads their standard Prepared by Client (PBC) request list — typically an Excel or CSV file with 80-200 line items like "access review records" or "change management tickets."
Quox automatically matches each item against its evidence store using keyword recognition. For each item, it shows:
- Matched — evidence found, with the specific controls and evidence types
- Manual — no automatic match; the auditor needs to upload this evidence manually
Multi-word phrases (like "change management") score higher confidence than single keywords.
Working paper templates
For each control the auditor is testing, Quox generates a pre-populated working paper template containing:
- Objective — what the auditor is verifying
- Population — the full set of events (e.g., "847 AOCL L1 identity resolution events")
- Sample size — calculated from the population (25 for populations over 250, 15 for populations of 51 to 250, or the full population for 50 or fewer)
- Evidence source — which protocol data (VOLT, AEE, WARD)
- VOLT integrity — whether the hash chain is intact
- WARD witnesses — how many events are externally witnessed
- Test procedure — 6-step testing methodology
The auditor reviews the pre-populated data and adds their conclusions.
Frequently asked questions
What can our external auditor actually do inside the portal?
They can browse evidence by control, view VOLT chain integrity, download assurance packs, upload a PBC list for matching, and view working paper templates. They cannot modify any data, access other organisations, or see data outside the audit period.
How long does an auditor keep access, and do we have to remember to cut it off?
When creating the engagement, an admin sets an access duration in days, 90 by default. The auditor's access expires automatically, with no manual revocation needed.
How does the PBC auto-match feature work?
The auditor uploads their standard Prepared by Client request list, typically an Excel or CSV file with 80 to 200 line items. Quox automatically matches each item against its evidence store using keyword recognition, marking each as Matched (evidence found) or Manual (no automatic match, needs manual upload). Multi-word phrases score higher confidence than single keywords.
What's inside a working paper template?
Objective, population, sample size (calculated from the population: 25 for populations over 250, 15 for populations of 51 to 250, or the full population for 50 or fewer), evidence source, VOLT integrity, WARD witnesses, and a 6-step test procedure. The auditor reviews the pre-populated data and adds their own conclusions.
Glossary
| Term | Definition |
|---|---|
| PBC List | Prepared by Client — the list of documents and evidence the auditor requires |
| Working Papers | The auditor's documentation of testing performed and conclusions reached |
| Engagement | A formal audit relationship with defined scope, timeline, and access |
| Assurance Pack | A signed, self-contained JSON bundle containing WARD chain, VOLT bundles, and audit events for a period |