IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP

Documentation

Create a client, program and guided assessment

Professional / MSP · Updated 9 October 2026

Follow the numbered steps, then check the result before continuing. Choose only the procedure that matches your task.

Before you begin

  • For MSP, verify the server connection first. Use an account allowed to create clients/programs.
  • Know the organization, framework, assessment boundary and review period. The examples below are fictional; enter your actual assessed organization.
  • The active framework changes some navigation labels. ISO controls and CMMC requirements are different workspaces, but client/program selection remains at the top.

1. Create and select the client

  1. Open Assessment · Multi-framework → Clients. Enter Client code, Client name, Industry and Primary domain. A fictional example is code DEMO01, name Example Operations, industry Technology, domain demodomain.com.
  2. Click Create Client. If the list has not refreshed, click Refresh. Confirm that the new client appears with the intended code and name.
  3. Use the top Active client selector to select that client. Read the selected name before making further changes; creating a client is not a substitute for selecting the intended working context.
  4. If CAGE/NCAGE identifiers are required, use Clients → Manage client CAGE / NCAGE for the selected assessed client. These identifiers do not replace the internal Client ID or your own report-branding identity.
Check before continuingThe intended organization is displayed as Active client and is the context for the following framework and program steps.

2. Select frameworks and create the program

  1. Open Frameworks & Standards. Find the required profile in the alphabetical list, select its Use checkbox and click Save selection. Read the description beside the profile; it explains what requires review.
  2. Open Certification Portfolio. Choose Framework / standard, enter a meaningful Program name and describe the Scope. Example scope: “Corporate identity and managed Windows servers; review period October–December 2026.” Use your actual approved boundary.
  3. Click Add program. Select the resulting row. In Selected program details, review the name and scope and enter the applicable Owner, Assessor, Reviewer and target audit details. Click Save selected.
  4. Choose that program in the top Active program selector. Confirm both the client and program names before opening requirements or collecting evidence.
Check before continuingThe framework program exists under the correct client and appears as Active program. Its scope is explicit rather than inferred from the framework name.

3. Complete one requirement in Guided Audit Prep

  1. Open Guided Audit Prep. Read the active requirement identifier, What this requires, What the auditor will look for, evidence examples and What you need to do next.
  2. Under Confirm applicability and responsibility, select Applicability and enter Owner, Reviewer and Next review. Use Not Applicable only with a justified scope decision, not because evidence is missing.
  3. Under Describe implementation, choose the observed Implementation status and enter the Implementation narrative / notes / N/A justification. Describe what exists and where; do not select Implemented simply because a collector ran.
  4. Under Collect and review evidence, use Upload & link for a new file or select an existing item and click Link existing. Use Preview evidence and then Review linked evidence to record a version-specific review. Follow the separate evidence review guide.
  5. Under Complete the auditor workpaper, enter the audit period, population description/count, sample method/size, Expected result and Observed result. Include factual assets, dates, counts and exceptions in Observed result.
  6. Set Evidence quality, Scope reconciliation and any Exception decision/expiry according to your review. Fill Prepared by, Independent approver and Workpaper conclusion. An accepted evidence file does not complete these separate workpaper fields.
  7. If a finding remains unresolved, use Fix It and Retest where applicable, then update the evidence and workpaper. Leave unresolved work pending instead of bypassing it.
  8. Read the completion checklist. Click Complete & Continue → only when it is satisfied. Use Save & Exit to retain work and resume later. Read the save/status message before leaving the requirement.
Check before continuingThe requirement’s saved assessment, evidence review and workpaper agree. Remaining requirements and program gates may still prevent the final auditor export.

If something goes wrong

No requirements appear

Check Active client, Active program and the selected framework. Selecting frameworks and creating a portfolio program are separate steps.

Complete & Continue will not finish

Read the completion checklist. Check workpaper fields, evidence quality, scope reconciliation, independent approval, findings and any framework-specific objective checks.

Data appears in the wrong context

Stop editing and reselect the intended client/program. Do not duplicate records until you confirm where the original data was saved.