Every action in Verisq — assessment submission, control state change, risk acceptance, DSAR fulfillment, evidence upload — recorded with actor, timestamp, before-state, and after-state. The Audit Packet PDF consolidates the artifacts auditors request first.
Append-only audit log with cryptographic chaining for high-integrity events. Tampering is mathematically detectable.
Cover, program certificates, framework coverage matrix, vendor portfolio summary, training coverage, risk register, privacy program summary, evidence index — one PDF.
External auditor access scoped to a single engagement. Comments per control, sample requests, evidence review in-place.
Documents under hold are non-deletable regardless of retention policy. Supports litigation hold requirements.
Cover page, tenant identifying information, generation timestamp and a platform attestation that the packet reflects live program state.
Every currently valid Certificate of Diligence inlined — TPRM, ERM, Privacy, Policy, Training and more.
Per-framework control coverage with evidence pointers: for each control, which policies, assessments and training satisfy it.
Vendor count by tier, assessment status and outstanding findings, highlighting critical and high-risk vendors.
Per-course and per-track completion rates, plus open risks by severity, lifecycle state and source type.
A pointer index to every supporting artefact in the tenant's Data Rooms — the auditor's roadmap to the evidence behind the summary.
Verisq's Audit Defensibility is part of the Trust Operations Platform — one data model, one audit trail, one auditor seat.